Repository navigation
Expand file tree
/
Copy pathcompose.yaml
More file actions
114 lines (111 loc) · 3.88 KB
/
Copy pathcompose.yaml
File metadata and controls
114 lines (111 loc) · 3.88 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
services:
opencode:
build:
context: .
image: opencode-remote:chrome-mcp
restart: unless-stopped
environment:
OPENCHAMBER_PASSWORD: ${OPENCHAMBER_PASSWORD:?OPENCHAMBER_PASSWORD must be set}
GIT_USER_NAME: ${GIT_USER_NAME:-}
GIT_USER_EMAIL: ${GIT_USER_EMAIL:-}
CONTEXT7_API_KEY: ${CONTEXT7_API_KEY:-}
OPENCODE_CONFIG: /etc/opencode/opencode.json
ports:
- "${OPENCHAMBER_PORT:-3000}:3000"
- "${SSHD_PORT:-2222}:2222"
- "${MOSH_PORT:-60000}:60000/udp"
volumes:
- "${WORKSPACE:-.}:/workspace"
- ./config/opencode.json:/etc/opencode/opencode.json:ro
- "${SSH_AUTHORIZED_KEYS_DIR:-${HOME}/.ssh}:/home/dev/.ssh:ro"
- ssh-host-keys:/etc/ssh/host-keys
- opencode-config:/home/dev/.config/opencode
- opencode-share:/home/dev/.local/share/opencode
- opencode-state:/home/dev/.local/state/opencode
- openchamber-config:/home/dev/.config/openchamber
# Browser VS Code. Deliberately NOT on the opencode container's network
# (unlike the chrome sidecar above): in its own network namespace VS Code's
# Ports panel can only forward ports inside this container, so the opencode
# container's Chrome DevTools endpoint (:9222, loopback-only) and
# unpublished OpenCode API (:4096) stay out of its reach. Do not "simplify"
# this to network_mode: service:opencode.
code-server:
image: codercom/code-server:latest
# `latest` floats — always pull so `docker compose up` picks up new
# releases instead of freezing on whatever was pulled first.
pull_policy: always
restart: unless-stopped
environment:
# Falls back to OPENCHAMBER_PASSWORD when CODE_SERVER_PASSWORD is unset.
PASSWORD: ${CODE_SERVER_PASSWORD:-${OPENCHAMBER_PASSWORD}}
VSCODE_OPTIONS: --disable-telemetry
ports:
- "${CODE_SERVER_PORT:-8080}:8080"
# The image's `coder` user is UID 1000, same as `dev`, so files written to
# the shared workspace keep consistent ownership across the containers.
# The image ships git, curl and openssh-client; the read-only key mount
# (same directory the opencode container's sshd reads) enables git over
# SSH from VS Code terminals.
working_dir: /workspace
volumes:
- "${WORKSPACE:-.}:/workspace"
- "${SSH_AUTHORIZED_KEYS_DIR:-${HOME}/.ssh}:/home/coder/.ssh:ro"
- code-server-data:/home/coder/.local/share/code-server
healthcheck:
test:
- CMD
- curl
- -fsS
- http://127.0.0.1:8080/healthz
interval: 10s
timeout: 5s
retries: 6
start_period: 20s
chrome:
image: ghcr.io/puppeteer/puppeteer:25.9.0
network_mode: service:opencode
restart: unless-stopped
init: true
read_only: true
cap_drop:
- ALL
security_opt:
- no-new-privileges:true
shm_size: 1gb
tmpfs:
- /tmp:size=1g,mode=1777
environment:
HOME: /tmp/chrome-home
PUPPETEER_CACHE_DIR: /home/pptruser/.cache/puppeteer
command:
- sh
- -c
- |
mkdir -p "$${HOME}" /tmp/chrome-profile
CHROME="$$(node --input-type=module -e 'import puppeteer from "puppeteer"; process.stdout.write(await puppeteer.executablePath())')"
exec "$${CHROME}" \
--headless \
--no-sandbox \
--remote-debugging-address=127.0.0.1 \
--remote-debugging-port=9222 \
--user-data-dir=/tmp/chrome-profile \
--no-first-run \
--no-default-browser-check \
--disable-background-networking
healthcheck:
test:
- CMD
- node
- -e
- fetch('http://127.0.0.1:9222/json/version').then(r=>{if(!r.ok)process.exit(1)}).catch(()=>process.exit(1))
interval: 10s
timeout: 5s
retries: 6
start_period: 20s
volumes:
ssh-host-keys:
opencode-config:
opencode-share:
opencode-state:
openchamber-config:
code-server-data: