Sign inSign up

docker/sbx-kit-copilot-mixin:1.0.86

Multi-platform
Manifest digest

sha256:39f6cae986d802d1a40c283ca90723d9b57e2e9a3abc0aff0e8f28ad11dc9e62

Last pushed

9 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:39f6cae986d802d1a40c283ca90723d9b57e2e9a3abc0aff0e8f28ad11dc9e62

yaml
schemaVersion: "3"
displayName: GitHub Copilot (mixin)
description: GitHub's Copilot CLI as a mixin — the CLI in an overlay, with the GitHub and Copilot credentials, scoped egress, and the trusted-folder and MCP-gateway seeds the agent needs. Layer it onto a shell base and run `copilot`.
version: 1.0.86
kind: mixin
provides:
    - [email protected]
requires:
    - deb/jq
    - deb/util-linux
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - api.business.githubcopilot.com
                - api.enterprise.githubcopilot.com
                - api.github.com
                - api.githubcopilot.com
                - api.individual.githubcopilot.com
                - copilot.github.com
                - github.com
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.github.com
                  format: Bearer %s
                  header: Authorization
                - domain: github.com
                  format: Bearer %s
                  header: Authorization
            name: GH_TOKEN
        phase: runtime
        service: github
      description: GitHub API access for git and gh
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.business.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.enterprise.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.individual.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: copilot.github.com
                  format: Bearer %s
                  header: Authorization
            name: COPILOT_GITHUB_TOKEN
        phase: runtime
        service: copilot
      description: Copilot request access, separable from the broader github token
    - type: com.docker.sandbox/lifecycle@1
      config:
        install:
            - command: mkdir -p /home/agent/.copilot && chown agent:agent /home/agent/.copilot
              description: Ensure .copilot is owned by agent before bind mounts and the config seed run
              user: "0"
            - command: |
                set -e
                cfg=/home/agent/.copilot/config.json
                if [ -e "$cfg" ]; then exit 0; fi
                if [ -z "$WORKSPACE_DIR" ]; then
                  echo "WORKSPACE_DIR unset; skipping Copilot trusted-folder seed" >&2
                  exit 0
                fi
                esc=$(printf '%s' "$WORKSPACE_DIR" | sed 's/\\/\\\\/g; s/"/\\"/g')
                printf '{"trusted_folders": ["%s"]}\n' "$esc" > "$cfg"
              description: Copilot config with trusted workspace folder
              env:
                - WORKSPACE_DIR
              user: agent
        startup:
            - command:
                - sh
                - -c
                - |
                  set -e
                  [ -n "$MCP_GATEWAY_URL" ] || exit 0
                  cfg="$HOME/.copilot/mcp-config.json"
                  dir=$(dirname "$cfg")
                  mkdir -p "$dir"
                  gateway=$(cat <<EOF
                  {
                    "mcpServers": {
                      "mcp-gateway": {
                        "type": "http",
                        "url": "$MCP_GATEWAY_URL",
                        "headers": {
                          "Authorization": "Bearer $MCP_SENTINEL_TOKEN_NAME"
                        },
                        "tools": ["*"]
                      }
                    }
                  }
                  EOF
                  )
                  # Two overlapping starts would read-modify-write the same file.
                  exec 9>>"$dir/.mcp-config.lock"
                  flock 9
                  # mv would nest the config inside a directory here and still exit 0.
                  if [ -e "$cfg" ] && [ ! -f "$cfg" ]; then
                    echo "mcp-config.json is not a regular file; leaving the MCP gateway unregistered" >&2
                    exit 0
                  fi
                  if ! merged=$({ if [ -s "$cfg" ]; then cat "$cfg"; else echo '{}'; fi; printf '%s\n' "$gateway"; } | jq -s '
                      if length != 2 or (.[0] | type) != "object" or ((.[0].mcpServers // {}) | type) != "object" then
                        error("mcp-config.json must hold one JSON object whose mcpServers is an object")
                      else
                        .[0] + {mcpServers: ((.[0].mcpServers // {}) + .[1].mcpServers)}
                      end'); then
                    echo "mcp-config.json is not readable as JSON; leaving the MCP gateway unregistered" >&2
                    exit 0
                  fi
                  # The temp name is unpredictable, so a stale or crashed leftover is never installed.
                  tmp=$(mktemp "$dir/mcp-config.json.XXXXXX")
                  trap 'rm -f "$tmp"' EXIT
                  printf '%s\n' "$merged" > "$tmp"
                  mv -f "$tmp" "$cfg"
              description: Register the sandbox MCP gateway in ~/.copilot/mcp-config.json
              env:
                - MCP_GATEWAY_URL
                - MCP_SENTINEL_TOKEN_NAME
              user: agent
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/copilot-mixin/copilot-mixin-context.md
args:
    version:
        default: 1.0.86
        description: GitHub Copilot CLI release to install
        pattern: ^[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z.]+)?$
        buildArg: COPILOT_VERSION