Sign inSign up

docker/sbx-kit-openhands-mixin:latest

Multi-platform
Manifest digest

sha256:3b94a4649fc325bad16e6813657e644ac8eb274e79fc5eedad110e7b6ede6249

Last pushed

9 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:3b94a4649fc325bad16e6813657e644ac8eb274e79fc5eedad110e7b6ede6249

yaml
schemaVersion: "3"
displayName: OpenHands (mixin)
description: OpenHands as a mixin — the `uv`-installed CLI and its managed CPython in an overlay, with the Anthropic, Google and OpenAI credentials and the hook that resolves which Anthropic auth the host actually holds. Layer it onto a shell base and run `openhands`.
version: 1.16.0
kind: mixin
provides:
    - [email protected]
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - api.anthropic.com
                - platform.claude.com
                - api.openai.com
                - generativelanguage.googleapis.com
                - github.com
                - api.github.com
                - raw.githubusercontent.com
                - pypi.org
                - registry.npmjs.org
                - api.tavily.com
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.anthropic.com
                  format: '%s'
                  header: x-api-key
            name: ANTHROPIC_API_KEY
            proxyManaged: true
        oauth:
            credentialFile:
                path: ~/.claude/.credentials.json
                structure:
                    claudeAiOauth:
                        accessToken: '{{.AccessToken}}'
                        expiresAt: '{{.ExpiresAt}}'
                        refreshToken: '{{.RefreshToken}}'
                        scopes: '{{.Scopes}}'
            resourceHosts:
                - api.anthropic.com
            sentinels:
                accessToken: sk-ant-oat01-proxy-managed
                refreshToken: sk-ant-ort01-proxy-managed
            tokenEndpoint:
                host: platform.claude.com
                path: /v1/oauth/token
        phase: runtime
        service: anthropic
      description: Anthropic API access (API key or claude.ai OAuth)
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: generativelanguage.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
            name: GEMINI_API_KEY
            proxyManaged: true
        phase: runtime
        service: google
      description: Google Gemini API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.openai.com
                  format: Bearer %s
                  header: Authorization
            name: OPENAI_API_KEY
            proxyManaged: true
        phase: runtime
        service: openai
      description: OpenAI API access
    - type: com.docker.sandbox/lifecycle@1
      config:
        startup:
            - command:
                - sh
                - /home/agent/.local/bin/openhands-anthropic-auth.sh
              description: Resolve whether Anthropic auth is an API key, an OAuth login, or absent, and record it for `openhands-start` and `sbx exec` shells
              env:
                - SBX_CRED_ANTHROPIC_MODE
              user: "1000"
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/openhands-mixin/openhands-mixin-context.md
args:
    version:
        default: 1.16.0
        description: OpenHands release to install
        pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
        buildArg: OPENHANDS_VERSION