mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-09-30 12:39:42 +02:00
Add Case -> Clone Repo could only reach public repositories in the Docker deployment. This lets a deployment opt in to the GitHub CLI and the Azure CLI (+ azure-devops extension) as git credential helpers. Codeman itself still collects no credentials. - server.Dockerfile / agent.Dockerfile: CODEMAN_INSTALL_GH / CODEMAN_INSTALL_AZ build args (0 or 1, default 0; anything else stops the build). Off leaves no apt repository, package, extension, helper script or credential entry, so a default build is unchanged. On installs from the vendors' apt repositories and configures system gitconfig helpers: github.com / gist.github.com -> `gh auth git-credential`, dev.azure.com / *.visualstudio.com -> new docker/git-credential-azure-cli (an Entra ID token from `az account get-access-token`, or AZURE_DEVOPS_EXT_PAT). A helper whose CLI is not signed in prints nothing, so a private clone still fails fast. - The extension lives in AZURE_EXTENSION_DIR outside HOME (/opt/codeman-az-extensions, runtime-owned; /opt/az-extensions, gid-0 group-writable in the agent image). - Hosts turn them on in docker-compose.override.yml: `build: args:` for the server image, `environment:` CODEMAN_AGENT_IMAGE_INSTALL_GH / _AZ for the agent image. build-agent-image.mjs and the in-app auto-build share one env -> ARG table (pinned by the parity test) and pass nothing when unset. docker-compose.yaml is untouched; .env.example only gains a comment, so the self-updater's environment gate sees no new keys. - Docker cases seed the gh sign-in (~/.config/gh/hosts.yml, config.yml) and the az sign-in files from ~/.azure per file, read-only, like pi/grok. - The Clone Repo AUTH_REQUIRED message says how to sign the server's git in instead of claiming private repositories cannot be cloned. - Docs: docker/README.md "Private repositories", docker-compose.md, docker-cases.md, the Quick-Start / Core-Concepts / Docker-Cases wiki pages, security-architecture.md, architecture-invariants.md, changeset. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0167CiuzLrmjYWxwKp3rMWjw
91 lines
4.0 KiB
Bash
91 lines
4.0 KiB
Bash
# =============================================================================
|
|
# Codeman Docker Compose environment template
|
|
# Copy this file to .env and set the values for the Docker host.
|
|
# =============================================================================
|
|
|
|
TZ=Australia/Perth
|
|
|
|
# Optional overrides for direct `docker compose` use. The Bash start script
|
|
# detects these values from CODEMAN_APPDATA_PATH automatically. Compose uses
|
|
# 1000:1000 when the variables are omitted.
|
|
# PUID=1000
|
|
# PGID=1000
|
|
|
|
# Name of the account that runs Codeman and all local CLI sessions. Changing
|
|
# this value rebuilds the image with a matching account.
|
|
CODEMAN_RUNTIME_USER=codeman
|
|
|
|
# Required. Persistent Codeman application data, CLI credentials, and session
|
|
# state are stored here on the host and mounted at the runtime account's home
|
|
# directory in the container.
|
|
CODEMAN_APPDATA_PATH=/mnt/user/appdata/codeman
|
|
|
|
# Optional. Absolute host path of this Codeman checkout, mounted at
|
|
# /opt/codeman so App Settings -> Updates can update Codeman in place. The Bash
|
|
# start script detects it from the compose file's own location, so it only needs
|
|
# setting for direct `docker compose` use or a checkout kept elsewhere. Point it
|
|
# at a directory that is not a git checkout and in-app updates are unavailable.
|
|
# CODEMAN_REPO_PATH=/mnt/user/appdata/codeman/app
|
|
|
|
# Required for Docker cases. This must be an absolute path on the Docker host.
|
|
# Codeman and each isolated case use this same path, so it cannot be a
|
|
# container-only path such as /home/codeman/codeman-cases.
|
|
CODEMAN_CASES_PATH=/mnt/user/appdata/codeman/codeman-cases
|
|
|
|
# Required. Network bind address, host port, and local image tag.
|
|
CODEMAN_HOST=0.0.0.0
|
|
CODEMAN_PORT=3000
|
|
CODEMAN_IMAGE=codeman:local
|
|
|
|
# Required for any network-accessible Codeman instance. Use a unique, strong
|
|
# password. This file is safe to commit; copy it to .env and set the value.
|
|
CODEMAN_PASSWORD=changeme
|
|
|
|
# Required. Username for Codeman HTTP Basic authentication.
|
|
CODEMAN_USERNAME=admin
|
|
|
|
# Optional. Extra Host-header allowlist entries for a reverse-proxied domain
|
|
# (comma-separated; a bare `.suffix` matches every subdomain). Without it a
|
|
# proxied request is rejected with `403 Forbidden: host not allowed`. See
|
|
# README.md, "Reverse-proxy host allowlist".
|
|
# CODEMAN_ALLOWED_HOSTS=codeman.example.com,.internal.example.com
|
|
|
|
# The GitHub CLI (gh) and the Azure CLI (az, with the azure-devops extension)
|
|
# can be built into the images as git credential helpers, so Codeman can clone
|
|
# private GitHub and Azure DevOps repositories. Both are OFF by default and are
|
|
# NOT set here: turn them on in docker-compose.override.yml with the build args
|
|
# CODEMAN_INSTALL_GH / CODEMAN_INSTALL_AZ and, for the Docker-case agent image,
|
|
# the environment variables CODEMAN_AGENT_IMAGE_INSTALL_GH / _AZ. See
|
|
# README.md, "Private repositories".
|
|
|
|
# Optional: authenticate Gemini CLI without an interactive login.
|
|
GEMINI_API_KEY=
|
|
|
|
# Linux default. On Docker Desktop, use the socket path supported by your
|
|
# Docker installation when it differs from /var/run/docker.sock.
|
|
DOCKER_SOCKET=/var/run/docker.sock
|
|
|
|
# Optional override for direct `docker compose` use. The Bash start script
|
|
# detects this from DOCKER_SOCKET automatically. The direct Compose default is
|
|
# 999, but the correct value depends on the Docker host.
|
|
# DOCKER_SOCKET_GID=999
|
|
|
|
# Set to 1 only when Docker-case hook callbacks are required.
|
|
CODEMAN_DOCKER_BRIDGE_HOOKS=0
|
|
|
|
# Set to 1 when `docker info` reports `SwapLimit=false`. The case memory limit
|
|
# remains active; Codeman omits --memory-swap and filters the daemon's exact
|
|
# unsupported-swap warning while preserving all other Docker create errors.
|
|
CODEMAN_DOCKER_DISABLE_SWAP_LIMIT=0
|
|
|
|
# Required only when applying the macvlan example in README.md.
|
|
CODEMAN_MACVLAN_NETWORK=br0.11
|
|
CODEMAN_IPV4_ADDRESS=10.10.11.236
|
|
CODEMAN_MAC_ADDRESS=02:10:11:00:00:EC
|
|
|
|
# Required only when creating a new managed macvlan network, rather than using
|
|
# the external-network macvlan example.
|
|
CODEMAN_MACVLAN_PARENT=br0.11
|
|
CODEMAN_MACVLAN_SUBNET=10.10.11.0/24
|
|
CODEMAN_MACVLAN_GATEWAY=10.10.11.1
|