Sign inSign up

docker/sbx-kit-claude-mem:latest

Multi-platform
Manifest digest

sha256:87af5a1b100605f2afec6fc71f25ff3b7eec547a72326958c3fd39fedcdeae5b

Last pushed

9 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:87af5a1b100605f2afec6fc71f25ff3b7eec547a72326958c3fd39fedcdeae5b

yaml
schemaVersion: "3"
displayName: claude-mem (persistent memory)
description: 'Persistent context across Claude Code sessions: captures session activity into SQLite+FTS5, compresses with the Agent SDK, and injects relevant memory at session start. Tracks the latest claude-mem release.'
version: 1.0.0
kind: mixin
requires:
    - claude
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        install:
            allow:
                - registry.npmjs.org
                - '*.npmjs.org'
                - bun.sh
                - astral.sh
                - github.com
                - api.github.com
                - objects.githubusercontent.com
                - release-assets.githubusercontent.com
                - raw.githubusercontent.com
                - pypi.org
                - files.pythonhosted.org
                - chroma-onnx-models.s3.amazonaws.com
        runtime:
            allow:
                - chroma-onnx-models.s3.amazonaws.com
                - archive.ubuntu.com
                - security.ubuntu.com
                - ports.ubuntu.com
                - download.docker.com
    - type: com.docker.sandbox/port@1
      config:
        container: 37700
        name: memory-viewer
      description: claude-mem worker — viewer UI and live activity stream
    - type: com.docker.sandbox/lifecycle@1
      config:
        install:
            - command: npm config set proxy $HTTP_PROXY && npm config set https-proxy $HTTPS_PROXY || true
              description: Point npm at the sandbox egress proxy
              env:
                - HTTP_PROXY
                - HTTPS_PROXY
              user: "1000"
            - command: npm_config_legacy_peer_deps=true npx -y claude-mem@latest install --provider claude
              description: Install latest claude-mem (plugin, marketplace registration, bun deps)
              env:
                - HTTP_PROXY
                - HTTPS_PROXY
              user: "1000"
        startup:
            - command:
                - sh
                - -c
                - |
                  set -e
                  exec > /tmp/claude-mem-reconcile.log 2>&1
                  # Runs on every exit, including early failures, so root never
                  # leaves /home/agent/.claude or settings.json root-owned.
                  # Enumerated, not recursive: ~/.claude holds runtime-managed
                  # content this kit doesn't own, so a recursive chown would take
                  # ownership of paths outside the kit's control. Paths are
                  # existence-checked because under `set -e` a chown that fails on
                  # a path this script never created would replace the script's
                  # exit status from inside the trap, turning a tolerated early
                  # failure into a failed install.
                  S=/home/agent/.claude/settings.json
                  trap 'for p in /home/agent/.claude "$S"; do if [ -e "$p" ]; then chown agent:agent "$p"; fi; done' EXIT
                  mkdir -p /home/agent/.claude
                  # Wait for the platform's own settings write to land first — at
                  # create time the engine seeds this file late in the sequence and
                  # overwrites whatever exists; merging before that loses our key.
                  i=0
                  found=0
                  while [ $i -lt 60 ]; do
                    if grep -q themeId "$S" 2>/dev/null; then found=1; break; fi
                    sleep 1; i=$((i+1))
                  done
                  if [ "$found" = "1" ]; then
                    echo "platform settings present after ${i}s"
                  else
                    echo "timed out after ${i}s waiting for platform settings; proceeding anyway"
                  fi
                  MODE="${SBX_CRED_ANTHROPIC_MODE:-none}" node -e '
                    const fs = require("fs");
                    const p = process.argv[1];
                    let s = {};
                    try { s = JSON.parse(fs.readFileSync(p, "utf8")); } catch {}
                    const defaults = {
                      themeId: 1,
                      alwaysThinkingEnabled: true,
                      defaultMode: "bypassPermissions",
                      bypassPermissionsModeAccepted: true,
                    };
                    const SENTINEL = "echo proxy-managed";
                    if (process.env.MODE !== "none") defaults.apiKeyHelper = SENTINEL;
                    for (const k of Object.keys(defaults)) if (!(k in s)) s[k] = defaults[k];
                    // Only clear our own sentinel, never a user-customized helper.
                    if (process.env.MODE === "none" && s.apiKeyHelper === SENTINEL) delete s.apiKeyHelper;
                    s.enabledPlugins = s.enabledPlugins || {};
                    if (!("claude-mem@thedotmack" in s.enabledPlugins)) s.enabledPlugins["claude-mem@thedotmack"] = true;
                    fs.writeFileSync(p, JSON.stringify(s, null, 2));
                    console.log("reconciled");
                  ' "$S"
              description: Reconcile settings.json — ensure platform keys and claude-mem's enabledPlugins both present (ordering-immune, idempotent)
              env:
                - SBX_CRED_ANTHROPIC_MODE
              user: "0"
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/claude-mem/claude-mem-context.md