Files
synapbus/image-build
Algis DumbrisandClaude Opus 4.6 121d05f875 feat(docker): auto-stage host OAuth credentials into agent containers
The docker harness now detects and stages host CLI auth files
(~/.gemini/oauth_creds.json, ~/.claude/.credentials.json) into a
writable agent-home directory mounted at /home/agent. This lets
containerized agents reuse the host's Gemini Pro / Claude Pro OAuth
sessions without manual secret management or API keys.

Only auth files are copied — not the host's settings.json or MCP
configs (which contain stale localhost URLs that would hang Gemini CLI
inside containers). The staged dir is writable so CLIs can create
projects.json, history, etc. alongside the auth files.

Also sets GEMINI_DEFAULT_AUTH_TYPE=oauth-personal and
GEMINI_CLI_NO_RELAUNCH=true when OAuth creds are detected, writes
Claude's hasCompletedOnboarding flag, and simplifies the doc-gardener
example to use the harness-level credential staging instead of manual
HOME directory seeding.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 09:17:54 +03:00
..

SynapBus container images

The docker harness backend (internal/harness/docker/) runs each agent inside an ephemeral container. This directory holds the canonical agent image SynapBus's bundled examples reference.

synapbus-agent

The default image. Debian bookworm-slim base with:

  • gemini CLI (@google/gemini-cli)
  • claude CLI (@anthropic-ai/claude-code)
  • tini as PID 1 (signal forwarding + zombie reaping)
  • Standard tooling the example wrappers use: jq, sqlite3, curl, git, python3
  • Non-root agent user (uid 1000, gid 1000) matching the typical host user

No SynapBus binary lives in the image. Agents reach the SynapBus MCP server on the host at host.docker.internal:<port> — the harness rewrites .gemini/settings.json URLs from 127.0.0.1 to the gateway hostname automatically.

Build

Local single-arch:

docker build -t synapbus-agent:latest image-build/synapbus-agent

Multi-arch via buildx (recommended for sharing the image):

docker buildx build \
    --platform linux/amd64,linux/arm64 \
    -t synapbus-agent:latest \
    --load \
    image-build/synapbus-agent

Pin specific CLI versions with build args:

docker build \
    --build-arg GEMINI_CLI_VERSION=0.37.1 \
    --build-arg CLAUDE_CODE_VERSION=1.0.0 \
    -t synapbus-agent:0.37.1 \
    image-build/synapbus-agent

Wire an agent to use it

In harness_config_json add a docker block:

{
  "gemini_md": "...",
  "mcp_servers": [...],
  "env": {...},
  "docker": {
    "image": "synapbus-agent:latest",
    "memory": "1g",
    "cpus": "1.0",
    "network": "bridge"
  }
}

The reactor will pick the docker backend automatically when it sees the docker.image field. Default security posture: --cap-drop=ALL, --security-opt=no-new-privileges, --read-only root with tmpfs /tmp, --pids-limit=512, --user=<host uid:gid>. Override via the typed fields in the docker block (memory, cpus, cap_add, extra_mounts, read_only_root, user).