mirror of
https://github.com/0xWheatyz/handler.git
synced 2026-08-30 05:26:23 +00:00
feat: bundle agent executables + web-driven claude login
Two changes so an operator can stand up and authenticate Handler entirely from the browser, with a self-contained control image. Bundle executables in the control image (Dockerfile.control) - Node.js (NodeSource) + the Claude Code CLI, mise (official apt repo), and forge (git-pkgs/forge, built in a Go stage) join the existing git/tmux/ssh. No more bring-your-own binaries: live agent spawning, the verification gate, CI resolution, and the login flow all work out of the box. Installed under /usr so the /var/lib/handler VOLUME never masks them; mise apt source pinned to $TARGETARCH for the multi-arch (amd64/arm64) build. Claude login from the web UI - New login_start / login_submit command types (migration 0005) drive the interactive `claude /login` through the same enqueue→worker handoff every other control action uses — the API container has no claude binary. - control/login.py opens `claude` in a dedicated tmux session, sends /login, selects the subscription account, and scrapes the claude.com authorization URL (tmux.capture_pane, -pJ so a wrapped URL rejoins); a second command feeds back the pasted code. Fully mockable via the tmux seam. - API: POST /login/start, POST /login/submit (admin-gated). - Dashboard: a "Claude Login" pane — a button that starts the flow, embeds the URL in an iframe (with a new-tab fallback, since claude.com may refuse framing), and takes the code to finish. Also un-ignores frontend/lib/ (a broad Python `lib/` rule was swallowing the UI's own api client + formatters, breaking rebuilds from a fresh clone) and reconstructs those two source files; rebuilt static export committed. Tests: control/login unit tests (tmux faked), worker dispatch, and API route tests. Full suite green (195 tests), ruff clean. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YKVyBmKvWDVgrFC9WER2f2
This commit is contained in:
+39
-5
@@ -5,6 +5,13 @@
|
||||
# database, and the /var/lib/handler data volume with the API image (see Dockerfile),
|
||||
# but runs the control process instead of uvicorn.
|
||||
|
||||
# ---- forge build stage: compile the git-forge CLI (git-pkgs/forge, Go) ----
|
||||
# Built here and copied into the runtime image as a single static binary, so the runtime
|
||||
# stage needs no Go toolchain. `forge` gives the CI poller its cross-forge `ci list`.
|
||||
FROM golang:1.22-bookworm AS forge-builder
|
||||
ENV CGO_ENABLED=0
|
||||
RUN go install github.com/git-pkgs/forge/cmd/forge@latest
|
||||
|
||||
# ---- build stage: install the package + deps into an isolated venv ----
|
||||
FROM python:3.11-slim AS builder
|
||||
|
||||
@@ -22,14 +29,41 @@ RUN pip install .
|
||||
# ---- runtime stage ----
|
||||
FROM python:3.11-slim
|
||||
|
||||
# git + tmux are the live-spawning dependencies the control layer shells out to
|
||||
# (README "Requirements"); openssh-client covers git-over-ssh remotes. The `claude`
|
||||
# and `forge` binaries are bring-your-own — layer or mount them in for live agent
|
||||
# spawning and CI resolution; the poller degrades gracefully when forge is absent.
|
||||
# Every executable the control layer shells out to is now bundled — no bring-your-own
|
||||
# binaries — so the container can spawn live agents, run the verification gate, resolve CI,
|
||||
# and drive the claude web-login flow out of the box:
|
||||
# git / openssh-client — clone/push over https + ssh remotes
|
||||
# tmux — one detached session per agent (and per login attempt)
|
||||
# node + claude — the Claude Code CLI the agents *are*, and the /login flow the
|
||||
# dashboard drives (see control/login.py)
|
||||
# mise — the per-project task runner the test/build gates invoke
|
||||
# forge — the cross-forge CLI the CI poller reads run status from
|
||||
# Node comes from NodeSource (>=18 is required by Claude Code); mise from its official apt
|
||||
# repo; forge from the build stage above. Installed under /usr/{bin,local/bin} — outside the
|
||||
# /var/lib/handler VOLUME — so the volume mount never masks them at runtime. The image is
|
||||
# built for amd64 and arm64: NodeSource + forge detect the arch, and the mise apt source is
|
||||
# pinned to $TARGETARCH (buildx sets it; the Debian arch names match) so the arm64 build
|
||||
# doesn't pull an amd64-only list.
|
||||
ARG TARGETARCH=amd64
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends git tmux openssh-client \
|
||||
&& apt-get install -y --no-install-recommends \
|
||||
git tmux openssh-client curl ca-certificates gnupg \
|
||||
&& install -dm 755 /etc/apt/keyrings \
|
||||
&& curl -fsSL https://deb.nodesource.com/setup_20.x | bash - \
|
||||
&& apt-get install -y --no-install-recommends nodejs \
|
||||
&& npm install -g @anthropic-ai/claude-code \
|
||||
&& npm cache clean --force \
|
||||
&& curl -fsSL https://mise.jdx.dev/gpg-key.pub \
|
||||
| gpg --dearmor -o /etc/apt/keyrings/mise-archive-keyring.gpg \
|
||||
&& echo "deb [signed-by=/etc/apt/keyrings/mise-archive-keyring.gpg arch=${TARGETARCH}] https://mise.jdx.dev/deb stable main" \
|
||||
> /etc/apt/sources.list.d/mise.list \
|
||||
&& apt-get update \
|
||||
&& apt-get install -y --no-install-recommends mise \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# The cross-forge CLI compiled in the build stage above (github.com/git-pkgs/forge).
|
||||
COPY --from=forge-builder /go/bin/forge /usr/local/bin/forge
|
||||
|
||||
ENV PATH="/opt/venv/bin:$PATH" \
|
||||
PYTHONUNBUFFERED=1 \
|
||||
# SQLite fallback lives on the /var/lib/handler volume; point DATABASE_URL at the
|
||||
|
||||
Reference in New Issue
Block a user