Sign inSign up

docker/sbx-kit-opencode-mixin:1.18.31

Multi-platform
Manifest digest

sha256:9c6b01ac11c8170d98af582bead4a785615b0c6da2c16f7c1820b96b22a9b2c6

Last pushed

9 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:9c6b01ac11c8170d98af582bead4a785615b0c6da2c16f7c1820b96b22a9b2c6

yaml
schemaVersion: "3"
displayName: OpenCode (mixin)
description: OpenCode as a mixin -- node and the CLI in an overlay, with seven optional proxy-managed provider credentials, the MCP registration and the Copilot seed. Layer it onto a shell base and run `opencode`.
sourceUrl: https://github.com/sst/opencode
version: 1.18.31
kind: mixin
provides:
    - [email protected]
requires:
    - deb/jq
    - deb/util-linux
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - api.anthropic.com
                - claude.ai
                - console.anthropic.com
                - api.business.githubcopilot.com
                - api.enterprise.githubcopilot.com
                - api.github.com
                - api.githubcopilot.com
                - api.individual.githubcopilot.com
                - copilot.github.com
                - github.com
                - raw.githubusercontent.com
                - aiplatform.googleapis.com
                - generativelanguage.googleapis.com
                - oauth2.googleapis.com
                - vertexai.googleapis.com
                - api.groq.com
                - api.openai.com
                - openai.com
                - openrouter.ai
                - api.x.ai
                - auth.openai.com
                - chatgpt.com
                - '*.githubusercontent.com'
                - codeload.github.com
                - registry.npmjs.org
                - opencode.ai
                - '*.opencode.ai'
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.anthropic.com
                  format: '%s'
                  header: x-api-key
                - domain: claude.ai
                  format: '%s'
                  header: x-api-key
                - domain: console.anthropic.com
                  format: '%s'
                  header: x-api-key
            name: ANTHROPIC_API_KEY
            proxyManaged: true
        phase: runtime
        service: anthropic
      description: Anthropic API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.business.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.enterprise.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.github.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.individual.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: copilot.github.com
                  format: Bearer %s
                  header: Authorization
                - domain: github.com
                  format: Bearer %s
                  header: Authorization
                - domain: raw.githubusercontent.com
                  format: Bearer %s
                  header: Authorization
            name: ""
        phase: runtime
        service: github
      description: GitHub and Copilot access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: aiplatform.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
                - domain: generativelanguage.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
                - domain: oauth2.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
                - domain: vertexai.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
            name: GOOGLE_GENERATIVE_AI_API_KEY
            proxyManaged: true
        phase: runtime
        service: google
      description: Google AI API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.groq.com
                  format: Bearer %s
                  header: Authorization
            name: GROQ_API_KEY
            proxyManaged: true
        phase: runtime
        service: groq
      description: Groq API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.openai.com
                  format: Bearer %s
                  header: Authorization
                - domain: openai.com
                  format: Bearer %s
                  header: Authorization
            name: OPENAI_API_KEY
            proxyManaged: true
        oauth:
            credentialFile:
                path: ~/.local/share/opencode/auth.json
                structure:
                    openai:
                        access: '{{.AccessToken}}'
                        expires: '{{.ExpiresAt}}'
                        refresh: '{{.RefreshToken}}'
                        type: oauth
            resourceHosts:
                - chatgpt.com
            sentinels:
                accessToken: oai-oat01-proxy-managed
                refreshToken: oai-ort01-proxy-managed
            tokenEndpoint:
                host: auth.openai.com
                path: /oauth/token
        phase: runtime
        service: openai
      description: OpenAI API access (API key or ChatGPT OAuth)
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: openrouter.ai
                  format: Bearer %s
                  header: Authorization
            name: OPENROUTER_API_KEY
            proxyManaged: true
        phase: runtime
        service: openrouter
      description: OpenRouter API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.x.ai
                  format: Bearer %s
                  header: Authorization
            name: XAI_API_KEY
            proxyManaged: true
        phase: runtime
        service: xai
      description: xAI API access
    - type: com.docker.sandbox/lifecycle@1
      config:
        startup:
            - command:
                - sh
                - -c
                - |
                  set -e
                  [ -n "$MCP_GATEWAY_URL" ] || exit 0
                  mkdir -p "$HOME/.config/opencode"
                  cat > "$HOME/.config/opencode/opencode.json" <<EOF
                  {
                    "\$schema": "https://opencode.ai/config.json",
                    "mcp": {
                      "mcp-gateway": {
                        "type": "remote",
                        "url": "$MCP_GATEWAY_URL",
                        "enabled": true,
                        "headers": {
                          "Authorization": "Bearer $MCP_SENTINEL_TOKEN_NAME"
                        }
                      }
                    }
                  }
                  EOF
              description: Register the sandbox MCP gateway in ~/.config/opencode/opencode.json
              env:
                - MCP_GATEWAY_URL
                - MCP_SENTINEL_TOKEN_NAME
              user: agent
            - command:
                - sh
                - -c
                - |
                  set -e
                  umask 077
                  # Local sandboxes always carry GH_TOKEN and say via the mode var whether a
                  # credential backs it; cloud sets GH_TOKEN only when one does and no mode var.
                  [ -n "${GH_TOKEN:-}" ] || exit 0
                  [ "${SBX_CRED_GITHUB_MODE:-}" != none ] || exit 0
                  auth="$HOME/.local/share/opencode/auth.json"
                  mkdir -p "$(dirname "$auth")"
                  # A canceled start can leave its seed running; retries must recheck auth.json after it finishes.
                  exec 9>>"$(dirname "$auth")/.copilot-seed.lock"
                  flock 9
                  # mv would nest the seed inside a directory here and still exit 0.
                  if [ -e "$auth" ] && [ ! -f "$auth" ]; then
                    echo "auth.json is not a regular file; leaving the GitHub Copilot provider unseeded" >&2
                    exit 0
                  fi
                  # Every start re-fires this seed. One pass keeps an entry that fits OpenCode's Oauth schema and still
                  # carries the token as refresh (so an exchanged access survives), leaves a malformed file alone, and re-seeds the rest.
                  if ! merged=$({ if [ -s "$auth" ]; then cat "$auth"; else echo '{}'; fi; } | jq -s --arg token "$GH_TOKEN" '
                      if length != 1 or (.[0] | type) != "object" then error("auth.json must hold exactly one JSON object")
                      elif (.[0]."github-copilot" | type == "object" and .type == "oauth" and .refresh == $token
                            and (.access | type) == "string" and (.expires | type == "number" and . >= 0 and . == floor)
                            and ((has("accountId") | not) or (.accountId | type) == "string")
                            and ((has("enterpriseUrl") | not) or (.enterpriseUrl | type) == "string")) then empty
                      else .[0] | ."github-copilot" = {type: "oauth", refresh: $token, access: $token, expires: 0} end'); then
                    echo "auth.json is not a single JSON object; leaving the GitHub Copilot provider unseeded" >&2
                    exit 0
                  fi
                  [ -n "$merged" ] || exit 0
                  # The temp name is unpredictable, so a stale or crashed leftover is never installed. The
                  # same uid owns this directory, so no write pattern here is a boundary against a co-resident process.
                  tmp=$(mktemp "$(dirname "$auth")/auth.json.XXXXXX")
                  trap 'rm -f "$tmp"' EXIT
                  printf '%s\n' "$merged" > "$tmp"
                  mv -f "$tmp" "$auth"
              description: Seed OpenCode's GitHub Copilot provider from the GH_TOKEN sentinel
              env:
                - GH_TOKEN
                - SBX_CRED_GITHUB_MODE
              user: agent
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/opencode-mixin/opencode-mixin-context.md
args:
    version:
        default: 1.18.31
        description: OpenCode release to install
        pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
        buildArg: OPENCODE_VERSION