The docker harness now detects and stages host CLI auth files (~/.gemini/oauth_creds.json, ~/.claude/.credentials.json) into a writable agent-home directory mounted at /home/agent. This lets containerized agents reuse the host's Gemini Pro / Claude Pro OAuth sessions without manual secret management or API keys. Only auth files are copied — not the host's settings.json or MCP configs (which contain stale localhost URLs that would hang Gemini CLI inside containers). The staged dir is writable so CLIs can create projects.json, history, etc. alongside the auth files. Also sets GEMINI_DEFAULT_AUTH_TYPE=oauth-personal and GEMINI_CLI_NO_RELAUNCH=true when OAuth creds are detected, writes Claude's hasCompletedOnboarding flag, and simplifies the doc-gardener example to use the harness-level credential staging instead of manual HOME directory seeding. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
SynapBus container images
The docker harness backend (internal/harness/docker/) runs each agent
inside an ephemeral container. This directory holds the canonical agent
image SynapBus's bundled examples reference.
synapbus-agent
The default image. Debian bookworm-slim base with:
geminiCLI (@google/gemini-cli)claudeCLI (@anthropic-ai/claude-code)tinias PID 1 (signal forwarding + zombie reaping)- Standard tooling the example wrappers use:
jq,sqlite3,curl,git,python3 - Non-root
agentuser (uid 1000, gid 1000) matching the typical host user
No SynapBus binary lives in the image. Agents reach the SynapBus MCP
server on the host at host.docker.internal:<port> — the harness
rewrites .gemini/settings.json URLs from 127.0.0.1 to the gateway
hostname automatically.
Build
Local single-arch:
docker build -t synapbus-agent:latest image-build/synapbus-agent
Multi-arch via buildx (recommended for sharing the image):
docker buildx build \
--platform linux/amd64,linux/arm64 \
-t synapbus-agent:latest \
--load \
image-build/synapbus-agent
Pin specific CLI versions with build args:
docker build \
--build-arg GEMINI_CLI_VERSION=0.37.1 \
--build-arg CLAUDE_CODE_VERSION=1.0.0 \
-t synapbus-agent:0.37.1 \
image-build/synapbus-agent
Wire an agent to use it
In harness_config_json add a docker block:
{
"gemini_md": "...",
"mcp_servers": [...],
"env": {...},
"docker": {
"image": "synapbus-agent:latest",
"memory": "1g",
"cpus": "1.0",
"network": "bridge"
}
}
The reactor will pick the docker backend automatically when it sees the
docker.image field. Default security posture: --cap-drop=ALL,
--security-opt=no-new-privileges, --read-only root with tmpfs
/tmp, --pids-limit=512, --user=<host uid:gid>. Override via the
typed fields in the docker block (memory, cpus, cap_add,
extra_mounts, read_only_root, user).