Sign inSign up

docker/sbx-kit-codex-app-server:latest

Multi-platform
Manifest digest

sha256:14d947bc8922bcbc8f9e6b07c68200beffa47fd43e956309f90cbd7b605ddf33

Last pushed

9 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:14d947bc8922bcbc8f9e6b07c68200beffa47fd43e956309f90cbd7b605ddf33

yaml
schemaVersion: "3"
displayName: Codex app-server (via SSH)
description: Runs sshd in the sandbox and pre-populates `authorized_keys` from the host's forwarded SSH agent, so the Codex Mac GUI can add the sandbox as an SSH Connection and drive `codex app-server` remotely. The kit requests port 22 through the port capability, so the runtime exposes sshd on an ephemeral host port at sandbox start.
version: 1.0.0
kind: mixin
requires:
    - codex
    - deb/apt
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        install:
            allow:
                - archive.ubuntu.com
                - security.ubuntu.com
                - ports.ubuntu.com
                - download.docker.com
    - type: com.docker.sandbox/port@1
      config:
        container: 22
        name: sshd
        transport: tcp
    - type: com.docker.sandbox/lifecycle@1
      config:
        files:
            - content: |
                #!/bin/sh
                # sbx runs startup hooks with a clean env (no SSH_AUTH_SOCK), so
                # naïve `ssh-add -L` fails on every wake. Snapshot SSH_AUTH_SOCK
                # from PID 1's environ — the socket file itself is available at
                # startup time, just not the env var pointing at it.
                if [ -z "$SSH_AUTH_SOCK" ]; then
                    SSH_AUTH_SOCK=$(tr '\0' '\n' < /proc/1/environ | grep -m1 '^SSH_AUTH_SOCK=' | cut -d= -f2-)
                    export SSH_AUTH_SOCK
                fi
                if [ ! -S "$SSH_AUTH_SOCK" ]; then
                    echo "[sbx-codex] no agent socket; keeping existing authorized_keys" >&2
                    exit 0
                fi
                keys=$(ssh-add -L 2>&1)
                if [ $? -ne 0 ] || [ -z "$keys" ]; then
                    echo "[sbx-codex] ssh-add returned no keys; keeping existing authorized_keys" >&2
                    exit 0
                fi
                printf '%s\n' "$keys" > /home/agent/.ssh/authorized_keys
                chmod 600 /home/agent/.ssh/authorized_keys
              description: Refresh /home/agent/.ssh/authorized_keys from the forwarded SSH agent. Invoked by the startup hook; safe to invoke manually too.
              mode: "0755"
              path: /home/agent/.local/bin/refresh-authorized-keys
        install:
            - command: apt-get update -qq && apt-get install -y -qq openssh-server
              description: Install openssh-server
              user: "0"
            - command: ssh-keygen -A
              description: Generate sshd host keys
              user: "0"
            - command: install -d -m 0700 -o agent -g agent /home/agent/.ssh
              description: Ensure /home/agent/.ssh exists with correct ownership
              user: "0"
            - command: |
                cat > /usr/local/bin/codex <<'EOF'
                #!/bin/bash
                # sshd starts processes with a clean env, so codex spawned via SSH
                # (which is how the Codex Mac GUI's Connections flow drives it)
                # doesn't see HTTPS_PROXY, PROXY_CA_CERT_B64, the chatgpt-proxy
                # bearer-token sentinel mechanism, SSH_AUTH_SOCK (which git-ssh-sign
                # needs at signing time), etc. Snapshot the relevant vars from
                # PID 1's environment and re-export them before handing off to
                # the real codex binary.
                while IFS= read -rd '' kv; do
                  case "$kv" in
                    HTTP_PROXY=*|HTTPS_PROXY=*|NO_PROXY=*|\
                    http_proxy=*|https_proxy=*|no_proxy=*|\
                    PROXY_CA_CERT_B64=*|NODE_USE_ENV_PROXY=*|NODE_EXTRA_CA_CERTS=*|\
                    SSL_CERT_FILE=*|REQUESTS_CA_BUNDLE=*|JAVA_TOOL_OPTIONS=*|\
                    CODEX_HOME=*|GH_TOKEN=*|SSH_AUTH_SOCK=*)
                      export "$kv"
                      ;;
                  esac
                done < /proc/1/environ
                exec /usr/local/share/npm-global/bin/codex "$@"
                EOF
                chmod 0755 /usr/local/bin/codex
              description: Shadow `codex` on PATH with a bridge that imports PID 1's proxy env before exec'ing the real binary
              user: "0"
        startup:
            - command:
                - /home/agent/.local/bin/refresh-authorized-keys
              description: Refresh authorized_keys from the forwarded SSH agent
              env:
                - SSH_AUTH_SOCK
              user: "1000"
            - command:
                - sh
                - -c
                - pgrep -x sshd >/dev/null || { mkdir -p /var/run/sshd && /usr/sbin/sshd > /tmp/sshd.log 2>&1; }
              description: Start sshd if not already running (recreates /var/run/sshd which is tmpfs-cleared on container restart)
              user: "0"
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/codex-app-server/codex-app-server-context.md