Sign inSign up

docker/sbx-kit-picoclaw-mixin:latest

Multi-platform
Manifest digest

sha256:e798062f8ba063502f0cac5c1f5da6cee2e65c16bc8e3b3b8f112f8e5ae8e6d4

Last pushed

9 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:e798062f8ba063502f0cac5c1f5da6cee2e65c16bc8e3b3b8f112f8e5ae8e6d4

yaml
schemaVersion: "3"
displayName: PicoClaw (mixin)
description: PicoClaw as a mixin — the pinned, SHA256-verified static binary in an overlay, with the Anthropic credential (API key or claude.ai OAuth), the published gateway and webhook ports, and the hooks that resolve the credential and bring the gateway up. Layer it onto a shell base and run `picoclaw`.
sourceUrl: https://github.com/sipeed/picoclaw
kind: mixin
provides:
    - [email protected]
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - api.anthropic.com
                - claude.ai
                - console.anthropic.com
                - platform.claude.com
                - '*.telegram.org'
                - '*.discord.com'
                - gateway.discord.gg
                - '*.whatsapp.com'
                - '*.whatsapp.net'
                - '*.slack.com'
    - type: com.docker.sandbox/port@1
      config:
        container: 18790
        name: gateway
    - type: com.docker.sandbox/port@1
      config:
        container: 18791
        name: webhook
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.anthropic.com
                  format: '%s'
                  header: x-api-key
                - domain: claude.ai
                  format: '%s'
                  header: x-api-key
                - domain: console.anthropic.com
                  format: '%s'
                  header: x-api-key
            name: ANTHROPIC_API_KEY
            proxyManaged: true
        oauth:
            credentialFile:
                path: ~/.picoclaw/auth.json
                structure:
                    credentials:
                        anthropic:
                            access_token: '{{.AccessToken}}'
                            auth_method: oauth
                            provider: anthropic
                            refresh_token: '{{.RefreshToken}}'
            resourceHosts:
                - api.anthropic.com
            sentinels:
                accessToken: sk-ant-oat01-proxy-managed
                refreshToken: sk-ant-ort01-proxy-managed
            tokenEndpoint:
                host: platform.claude.com
                path: /v1/oauth/token
        phase: runtime
        service: anthropic
      description: Anthropic API access (API key or claude.ai OAuth)
    - type: com.docker.sandbox/lifecycle@1
      config:
        startup:
            - command:
                - sh
                - /home/agent/.local/bin/picoclaw-anthropic-auth.sh
              description: Resolve the host's Anthropic credential into config.json at sandbox start
              env:
                - PICOCLAW_HOME
                - ANTHROPIC_API_KEY
              user: "1000"
            - background: true
              command: |
                curl -fsS -m 2 http://127.0.0.1:18790/health >/dev/null 2>&1 && exit 0
                mkdir -p /home/agent/.picoclaw
                export HOME=/home/agent
                exec /usr/local/bin/picoclaw gateway > /home/agent/.picoclaw/gateway.log 2>&1
              description: Start the picoclaw gateway in the background (health at :18790/health)
              user: "1000"
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/picoclaw-mixin/picoclaw-mixin-context.md
args:
    version:
        default: 0.2.9
        description: PicoClaw release to install
        pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
        buildArg: PICOCLAW_VERSION