feat(docker): install uv/uvx, libsecret-1-0 and pnpm (#487)

* fix(docker): install pnpm in the Compose server image

`dsh plugin` spawns a literal `pnpm` with no npm fallback, so the Run
menu's "DeepSeek - add a terminal profile" button failed with
`dsh: pnpm not found on PATH` (exit 127) on the server image. The agent
image already installs pnpm for the same reason (#352). Pin pnpm@12.6.0
in the runtime-writable CLI prefix and note it in the DeepSeek doc.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GuHtuPiHXdykq9T6rKQJ9n

* feat(docker): install uv and uvx in server and agent images

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GuHtuPiHXdykq9T6rKQJ9n

* feat(docker): install libsecret-1-0 for the Azure DevOps MCP

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GuHtuPiHXdykq9T6rKQJ9n

* feat(docker): add sudo to the agent image

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GuHtuPiHXdykq9T6rKQJ9n

* feat(docker): install sudo with passwordless access for the agent user

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GuHtuPiHXdykq9T6rKQJ9n

* Revert "feat(docker): install sudo with passwordless access for the agent user"

This reverts commit b070c9ee65.

* Revert "feat(docker): add sudo to the agent image"

This reverts commit e98127a804.

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Devvyn
2026-09-24 23:08:41 +02:00
committed by GitHub
co-authored by Claude Sonnet 5
parent b80d47aff8
commit 77ba41f8da
5 changed files with 33 additions and 1 deletions
+5
View File
@@ -0,0 +1,5 @@
---
"aicodeman": patch
---
Install pnpm in the Docker Compose server image. `dsh plugin` spawns a literal `pnpm` with no npm fallback, so the Run menu's "DeepSeek - add a terminal profile" button failed with `dsh: pnpm not found on PATH` in that image. Because this changes `server.Dockerfile`, the in-app updater will ask Compose deployments to rebuild the image (`Update-Codeman.sh`) rather than apply this release in place.
+7
View File
@@ -0,0 +1,7 @@
---
"aicodeman": patch
---
Install `uv` and `uvx` in the Compose server image and the agent image, so MCP servers launched with `uvx` (such as the Nginx Proxy Manager MCP) can be enabled by Codex instead of failing with `uvx` not found. The server image also carries `pnpm` for `dsh plugin`.
Both images also install `libsecret-1-0`, the native library the `keytar` dependency of the Azure DevOps MCP (`@azure-devops/mcp`) needs; without it the server crashes before answering the MCP initialize handshake.
+5
View File
@@ -17,6 +17,7 @@ FROM node:22-bookworm-slim
RUN apt-get update \ RUN apt-get update \
&& apt-get install -y --no-install-recommends \ && apt-get install -y --no-install-recommends \
git \ git \
libsecret-1-0 \
tmux \ tmux \
ripgrep \ ripgrep \
curl \ curl \
@@ -126,6 +127,10 @@ RUN set -eux; \
# A different order is a different RUN string, which is a different layer hash and # A different order is a different RUN string, which is a different layer hash and
# so a needless cache miss between a bare `docker build` and a scripted one. # so a needless cache miss between a bare `docker build` and a scripted one.
ARG CLI_NPM_PACKAGES="@anthropic-ai/claude-code opencode-ai @openai/codex @google/gemini-cli" ARG CLI_NPM_PACKAGES="@anthropic-ai/claude-code opencode-ai @openai/codex @google/gemini-cli"
# uv/uvx: MCP servers are commonly launched with `uvx <package>` (e.g. the Nginx
# Proxy Manager MCP), and Codex failed to enable them with "uvx not found". Copied
# from the pinned upstream image into root-owned /usr/local/bin, never pip-installed.
COPY --from=ghcr.io/astral-sh/uv:0.9 /uv /uvx /usr/local/bin/
RUN npm install -g ${CLI_NPM_PACKAGES} \ RUN npm install -g ${CLI_NPM_PACKAGES} \
&& npm cache clean --force && npm cache clean --force
+13
View File
@@ -39,6 +39,7 @@ RUN apt-get update \
curl \ curl \
g++ \ g++ \
git \ git \
libsecret-1-0 \
make \ make \
openssh-client \ openssh-client \
procps \ procps \
@@ -212,13 +213,25 @@ RUN set -eux; \
# minimal image of this exact shape). The four CLIs live only in this prefix, # minimal image of this exact shape). The four CLIs live only in this prefix,
# so they still resolve; entrypoint.sh additionally pins its own PATH to the # so they still resolve; entrypoint.sh additionally pins its own PATH to the
# system directories for the root part of the start. # system directories for the root part of the start.
# uv/uvx: MCP servers are commonly launched with `uvx <package>` (e.g. the Nginx
# Proxy Manager MCP), and Codex failed to enable them with "uvx not found". Copied
# from the pinned upstream image into root-owned /usr/local/bin, never pip-installed.
COPY --from=ghcr.io/astral-sh/uv:0.9 /uv /uvx /usr/local/bin/
ENV NPM_CONFIG_PREFIX=/opt/codeman-cli ENV NPM_CONFIG_PREFIX=/opt/codeman-cli
ENV PATH=$PATH:/opt/codeman-cli/bin ENV PATH=$PATH:/opt/codeman-cli/bin
# pnpm is not an agent CLI: it is here because `dsh plugin` (DeepSeek Harness, which
# this image leaves to be installed at runtime, see SERVER_INTENTIONAL_OMISSIONS in
# test/docker-agent-image-coverage.test.ts) spawns a literal `pnpm` with no npm
# fallback, so the Run menu's "DeepSeek - add a terminal profile" button failed
# with `dsh: pnpm not found on PATH` (exit 127) on this image. The agent image
# already carries it for the same reason (#352). It lives in the same
# runtime-writable prefix as the CLIs, so a session can update it in place.
RUN npm install --global \ RUN npm install --global \
@anthropic-ai/claude-code@2.1.258 \ @anthropic-ai/claude-code@2.1.258 \
@google/gemini-cli@0.58.0 \ @google/gemini-cli@0.58.0 \
@openai/codex@0.152.1 \ @openai/codex@0.152.1 \
opencode-ai@1.18.26 \ opencode-ai@1.18.26 \
pnpm@12.6.0 \
&& npm cache clean --force && npm cache clean --force
# Keep the web server and every local Codeman session unprivileged. PUID and # Keep the web server and every local Codeman session unprivileged. PUID and
+3 -1
View File
@@ -53,7 +53,9 @@ that spawns a literal `pnpm` with no npm fallback, so without one it exits 127 w
surfaces that same line as the install error. `npm install -g pnpm` (or surfaces that same line as the install error. `npm install -g pnpm` (or
`corepack enable pnpm`) is the fix. This is what broke the Docker agent image in `corepack enable pnpm`) is the fix. This is what broke the Docker agent image in
[#352](https://github.com/Ark0N/Codeman/issues/352); the image now installs pnpm [#352](https://github.com/Ark0N/Codeman/issues/352); the image now installs pnpm
alongside `dsh`. alongside `dsh`. The Compose server image (`docker/server.Dockerfile`) does not
ship `dsh`, since it is installed at runtime, but it does ship pnpm so the UI
button works there too.
Codeman's default is `@deepseek-harness-tui/dsh-tui` because it is by a wide Codeman's default is `@deepseek-harness-tui/dsh-tui` because it is by a wide
margin the most used community TUI, it is MIT, and it implements the status margin the most used community TUI, it is MIT, and it implements the status