mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-09-30 12:39:42 +02:00
Codeman running under docker/docker-compose.yaml lost the ability to update
itself from App Settings -> Updates. The image had no .git (excluded by
.dockerignore), so the install reported as "unknown"; there was no init system
for detectSupervisor() to find; the runtime stage had neither devDependencies
nor a build toolchain; and a pull into the baked /opt/codeman would have landed
in the container's writable layer and been discarded by the next `up`.
Restore it through configuration rather than a second updater, so the release
channel, auto-stash, status file and boot reconcile are all reused unchanged:
- The checkout Compose builds from is bind-mounted over /opt/codeman, so the
update's git checkout and rebuild land on the host and survive recreation.
- The restart is the server exiting; `restart: unless-stopped` relaunches the
container on the new dist/. This is the one supervisor whose updater does NOT
outlive the restart, which is safe only because the terminal "restarting"
marker is written first.
- node_modules and dist are named volumes over the bind mount, so
container-compiled native modules never enter the host checkout.
- The runtime image keeps devDependencies and gains python3/make/g++, since
`npm run build` is tsc + esbuild and node-pty has no Linux prebuild.
An in-place container update applies code only, because a restart reuses the
existing image and config. evaluateEnvironmentGate() reads the target release's
own files with `git show <tag>:<path>` and refuses when server.Dockerfile or
docker-compose.yaml changed, when .env.example gained keys the user's .env
lacks, or when the restart policy would not bring the container back. The
missing-key check matters most: Compose resolves an unset ${VAR} to the empty
string and starts anyway, so a new required setting would otherwise arrive as a
silently blank variable. Every unknown fails open, and the gate is re-evaluated
server-side on POST /api/system/update.
The four global agent CLIs are pinned, because an unpinned CLI bump is the one
environment change no diff-derived gate can see; pinning turns it into a
Dockerfile change the gate already detects.
Adds test/docker-compose-env-parity.test.ts as the merge-side guard (every
compose ${VAR} has an .env.example entry and the reverse) and
test/docker-self-update.test.ts for the pure gate decisions.
Documented in docs/docker-self-update.md.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013yAQ2y9t81jzSfpStUxx5T
77 lines
3.2 KiB
Bash
77 lines
3.2 KiB
Bash
# =============================================================================
|
|
# Codeman Docker Compose environment template
|
|
# Copy this file to .env and set the values for the Docker host.
|
|
# =============================================================================
|
|
|
|
TZ=Australia/Perth
|
|
|
|
# Optional overrides for direct `docker compose` use. The Bash start script
|
|
# detects these values from CODEMAN_APPDATA_PATH automatically. Compose uses
|
|
# 1000:1000 when the variables are omitted.
|
|
# PUID=1000
|
|
# PGID=1000
|
|
|
|
# Name of the account that runs Codeman and all local CLI sessions. Changing
|
|
# this value rebuilds the image with a matching account.
|
|
CODEMAN_RUNTIME_USER=opencode
|
|
|
|
# Required. Persistent Codeman application data, CLI credentials, and session
|
|
# state are stored here on the host and mounted at the runtime account's home
|
|
# directory in the container.
|
|
CODEMAN_APPDATA_PATH=/mnt/user/appdata/Coding/codeman
|
|
|
|
# Optional. Absolute host path of this Codeman checkout, mounted at
|
|
# /opt/codeman so App Settings -> Updates can update Codeman in place. The Bash
|
|
# start script detects it from the compose file's own location, so it only needs
|
|
# setting for direct `docker compose` use or a checkout kept elsewhere. Point it
|
|
# at a directory that is not a git checkout and in-app updates are unavailable.
|
|
# CODEMAN_REPO_PATH=/mnt/user/appdata/Coding/codeman/app
|
|
|
|
# Required for Docker cases. This must be an absolute path on the Docker host.
|
|
# Codeman and each isolated case use this same path, so it cannot be a
|
|
# container-only path such as /home/opencode/codeman-cases.
|
|
CODEMAN_CASES_PATH=/mnt/user/appdata/Coding/codeman/codeman-cases
|
|
|
|
# Required. Network bind address, host port, and local image tag.
|
|
CODEMAN_HOST=0.0.0.0
|
|
CODEMAN_PORT=3000
|
|
CODEMAN_IMAGE=codeman:local
|
|
|
|
# Required for any network-accessible Codeman instance. Use a unique, strong
|
|
# password. This file is safe to commit; copy it to .env and set the value.
|
|
CODEMAN_PASSWORD=changeme
|
|
|
|
# Required. Username for Codeman HTTP Basic authentication.
|
|
CODEMAN_USERNAME=admin
|
|
|
|
# Optional: authenticate Gemini CLI without an interactive login.
|
|
GEMINI_API_KEY=
|
|
|
|
# Linux default. On Docker Desktop, use the socket path supported by your
|
|
# Docker installation when it differs from /var/run/docker.sock.
|
|
DOCKER_SOCKET=/var/run/docker.sock
|
|
|
|
# Optional override for direct `docker compose` use. The Bash start script
|
|
# detects this from DOCKER_SOCKET automatically. The direct Compose default is
|
|
# 999, but the correct value depends on the Docker host.
|
|
# DOCKER_SOCKET_GID=999
|
|
|
|
# Set to 1 only when Docker-case hook callbacks are required.
|
|
CODEMAN_DOCKER_BRIDGE_HOOKS=0
|
|
|
|
# Set to 1 when `docker info` reports `SwapLimit=false`. The case memory limit
|
|
# remains active; Codeman omits --memory-swap and filters the daemon's exact
|
|
# unsupported-swap warning while preserving all other Docker create errors.
|
|
CODEMAN_DOCKER_DISABLE_SWAP_LIMIT=0
|
|
|
|
# Required only when applying the macvlan example in README.md.
|
|
CODEMAN_MACVLAN_NETWORK=br0.11
|
|
CODEMAN_IPV4_ADDRESS=10.10.11.236
|
|
CODEMAN_MAC_ADDRESS=02:10:11:00:00:EC
|
|
|
|
# Required only when creating a new managed macvlan network, rather than using
|
|
# the external-network macvlan example.
|
|
CODEMAN_MACVLAN_PARENT=br0.11
|
|
CODEMAN_MACVLAN_SUBNET=10.10.11.0/24
|
|
CODEMAN_MACVLAN_GATEWAY=10.10.11.1
|