From e98127a80414736c47f5c349038dacd23d2948c2 Mon Sep 17 00:00:00 2001 From: Devvyn <22340871+opticon454@users.noreply.github.com> Date: Thu, 24 Sep 2026 22:17:22 +0800 Subject: [PATCH] feat(docker): add sudo to the agent image Co-Authored-By: Claude Sonnet 5 Claude-Session: https://claude.ai/code/session_01GuHtuPiHXdykq9T6rKQJ9n --- .changeset/uvxdocker1.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.changeset/uvxdocker1.md b/.changeset/uvxdocker1.md index b4c74474..0535c953 100644 --- a/.changeset/uvxdocker1.md +++ b/.changeset/uvxdocker1.md @@ -5,3 +5,5 @@ Install `uv` and `uvx` in the Compose server image and the agent image, so MCP servers launched with `uvx` (such as the Nginx Proxy Manager MCP) can be enabled by Codex instead of failing with `uvx` not found. The server image also carries `pnpm` for `dsh plugin`. Both images also install `libsecret-1-0`, the native library the `keytar` dependency of the Azure DevOps MCP (`@azure-devops/mcp`) needs; without it the server crashes before answering the MCP initialize handshake. + +The agent image also installs `sudo` with passwordless access for the `agent` user, so a session can install system packages itself. The Compose server image is unchanged here: it runs with `no-new-privileges` and `cap_drop: ALL`, where `sudo` cannot work.