Sign inSign up

docker/sbx-kit-opencode-mixin:latest

Multi-platform
Manifest digest

sha256:0833c7531999fc02e0f941f61952bc437d1e4138c9dab35fe6e871646f3ebeee

Last pushed

3 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:0833c7531999fc02e0f941f61952bc437d1e4138c9dab35fe6e871646f3ebeee

yaml
schemaVersion: "3"
displayName: OpenCode (mixin)
author: Docker, Inc.
description: OpenCode as a mixin — node and the CLI in an overlay, with seven optional proxy-managed provider credentials. Layer it onto a shell base and run `opencode`.
sourceUrl: https://github.com/sst/opencode
kind: mixin
provides:
    - [email protected]
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - api.anthropic.com:443
                - claude.ai:443
                - console.anthropic.com:443
                - api.business.githubcopilot.com:443
                - api.enterprise.githubcopilot.com:443
                - api.github.com:443
                - api.githubcopilot.com:443
                - api.individual.githubcopilot.com:443
                - copilot.github.com:443
                - github.com:443
                - '*.githubusercontent.com:443'
                - raw.githubusercontent.com:443
                - codeload.github.com:443
                - aiplatform.googleapis.com:443
                - generativelanguage.googleapis.com:443
                - oauth2.googleapis.com:443
                - vertexai.googleapis.com:443
                - api.groq.com:443
                - api.openai.com:443
                - openai.com:443
                - auth.openai.com:443
                - chatgpt.com:443
                - openrouter.ai:443
                - api.x.ai:443
                - registry.npmjs.org:443
                - opencode.ai:443
                - '*.opencode.ai:443'
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.anthropic.com
                  format: '%s'
                  header: x-api-key
                - domain: claude.ai
                  format: '%s'
                  header: x-api-key
                - domain: console.anthropic.com
                  format: '%s'
                  header: x-api-key
            name: ANTHROPIC_API_KEY
            proxyManaged: true
        phase: runtime
        service: anthropic
      description: Anthropic API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.business.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.enterprise.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.github.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.individual.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: copilot.github.com
                  format: Bearer %s
                  header: Authorization
                - domain: github.com
                  format: Bearer %s
                  header: Authorization
                - domain: raw.githubusercontent.com
                  format: Bearer %s
                  header: Authorization
            name: GITHUB_TOKEN
            proxyManaged: true
        phase: runtime
        service: github
      description: GitHub and Copilot access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: aiplatform.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
                - domain: generativelanguage.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
                - domain: oauth2.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
                - domain: vertexai.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
            name: GOOGLE_GENERATIVE_AI_API_KEY
            proxyManaged: true
        phase: runtime
        service: google
      description: Google AI API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.groq.com
                  format: Bearer %s
                  header: Authorization
            name: GROQ_API_KEY
            proxyManaged: true
        phase: runtime
        service: groq
      description: Groq API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.openai.com
                  format: Bearer %s
                  header: Authorization
                - domain: openai.com
                  format: Bearer %s
                  header: Authorization
            name: OPENAI_API_KEY
            proxyManaged: true
        oauth:
            credentialFile:
                path: ~/.local/share/opencode/auth.json
                structure:
                    openai:
                        access: '{{.AccessToken}}'
                        expires: '{{.ExpiresAt}}'
                        refresh: '{{.RefreshToken}}'
                        type: oauth
            resourceHosts:
                - chatgpt.com
            sentinels:
                accessToken: oai-oat01-proxy-managed
                refreshToken: oai-ort01-proxy-managed
            tokenEndpoint:
                host: auth.openai.com
                path: /oauth/token
        phase: runtime
        service: openai
      description: OpenAI API access (API key or ChatGPT OAuth)
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: openrouter.ai
                  format: Bearer %s
                  header: Authorization
            name: OPENROUTER_API_KEY
            proxyManaged: true
        phase: runtime
        service: openrouter
      description: OpenRouter API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.x.ai
                  format: Bearer %s
                  header: Authorization
            name: XAI_API_KEY
            proxyManaged: true
        phase: runtime
        service: xai
      description: xAI API access
    - type: com.docker.sandbox/lifecycle@1
      config:
        startup:
            - command: |
                set -e
                [ -n "$MCP_GATEWAY_URL" ] || exit 0
                mkdir -p "$HOME/.config/opencode"
                cfg="$HOME/.config/opencode/opencode.json"
                frag=/tmp/sandbox-mcp-gateway.json
                jq -n --arg url "$MCP_GATEWAY_URL" --arg auth "Bearer $MCP_SENTINEL_TOKEN_NAME" \
                  '{"$schema": "https://opencode.ai/config.json", mcp: {"mcp-gateway": {type: "remote", url: $url, enabled: true, headers: {Authorization: $auth}}}}' > "$frag"
                [ -f "$cfg" ] || echo '{}' > "$cfg"
                jq -s '.[0] * .[1]' "$cfg" "$frag" > "$cfg.tmp"
                mv "$cfg.tmp" "$cfg"
                rm -f "$frag"
              description: Register the sandbox MCP gateway by merging into opencode.json
              env:
                - MCP_GATEWAY_URL
                - MCP_SENTINEL_TOKEN_NAME
              user: agent
    - type: com.docker.sandbox/agent-skills@1
      optional: true
      config:
        path: /home/agent/.config/opencode/skills
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/opencode-mixin/opencode-context.md
args:
    version:
        default: 1.18.33
        description: OpenCode release to install
        pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
        buildArg: OPENCODE_VERSION
dockerfile: ./opencode-mixin.dockerfile