Sign inSign up

johnkjell36161/ace-intake-kit:0.1.0

Manifest digest

sha256:5d3428f91699bafbeabddb95d2ac8b5d37d15e205576617869c7b44346a7e314

Last pushed

6 days by johnkjell36161

Type

Sandbox Kit

Manifest digest

sha256:5d3428f91699bafbeabddb95d2ac8b5d37d15e205576617869c7b44346a7e314

yaml
schemaVersion: "2"
kind: mixin
name: dhi-intake-kit
version: 0.1.0
displayName: DHI Intake Steel-Thread Kit
description: 'Steel-thread kit for the DHI intake team: carries the image-triage skill contract ([email protected], digest-locked by skills.lock) into AI Factory sandboxes for the producer and verifier roles. Installs pinned, checksum-verified uv, gh, yq and jq plus a uv-managed CPython 3.12.14, lays the lab root (lab/, skills/image-triage/, data/, run, uv.lock, skills.lock) out under /opt/dhi-intake-kit/triage-skill-lab with a venv baked from uv.lock, self-tests it (lock --check, the steel-thread good/bad fixtures, one offline pre-stage run), and writes /opt/dhi-intake-kit/MARKER. Puts two wrappers on PATH: verify_all (./run verify-all) and triage_pre (the pre stage of ./run triage for one image name). Built from the ace repository by scripts/kit-build.sh; see docs/wp3-kit.md.'
sourceURL: https://github.com/docker-hardened-images/ace/tree/main/kit
setup:
    install:
        - command: |
            set -eu
            missing=""
            for c in curl tar gzip sha256sum; do
              command -v "$c" >/dev/null 2>&1 || missing="$missing $c"
            done
            [ -s /etc/ssl/certs/ca-certificates.crt ] || missing="$missing ca-certificates"
            if [ -n "$missing" ]; then
              echo "dhi-intake-kit: installing prerequisites (missing:$missing)"
              for attempt in 1 2 3; do
                if apt-get update -q; then break; fi
                if [ "$attempt" -eq 3 ]; then echo "dhi-intake-kit: apt-get update failed" >&2; exit 1; fi
                sleep 3
              done
              DEBIAN_FRONTEND=noninteractive apt-get install -y -q --no-install-recommends \
                curl ca-certificates tar gzip coreutils
              rm -rf /var/lib/apt/lists/*
            fi
          user: "0"
          description: Assert curl, tar, gzip, sha256sum and CA certificates; apt-get install them only when one is missing.
        - command: |
            set -eu
            K=/opt/dhi-intake-kit
            install -d -m 0755 "$K" "$K/bin" "$K/tools" "$K/tools/bin" "$K/cache" "$K/python"
            chown 1000:1000 "$K" "$K/bin" "$K/tools" "$K/tools/bin" "$K/cache" "$K/python"
          user: "0"
          description: Create /opt/dhi-intake-kit/{bin,tools/bin,cache,python} owned by agent.
        - command: |
            set -eu
            T=/opt/dhi-intake-kit/tools
            UV_VERSION=0.12.17
            GH_VERSION=2.100.0
            YQ_VERSION=4.53.6
            JQ_VERSION=1.8.2
            case "$(uname -m)" in
              x86_64|amd64)
                A=amd64; UV_TRIPLE=x86_64-unknown-linux-gnu
                UV_SHA256=fa82fd8dde8e8eefdecada6aa0889666556cfceb690d06e0c3bca49eb3070a63
                GH_SHA256=e4d4bb4498e8d007abe545b6568926793ace1b6447da598294a610018cb164be
                YQ_SHA256=c5f056448f973ae7d39b5401949648a78f2dc1947d6a8eb65be60d5c504b9385
                JQ_SHA256=b1c22172dd303f3be49e935aa56aa48a8b7a46e0bc838b4997d3bb451495870f
                ;;
              aarch64|arm64)
                A=arm64; UV_TRIPLE=aarch64-unknown-linux-gnu
                UV_SHA256=d636d1b678e9e7f367ecb22b46bd1cabbed234d6bc3b4d96365d2b507f72f86c
                GH_SHA256=ea4e7a581a32ccad6cc7923cb1576ac5859ba4b9a16ab22eb8f8a96e78e2e961
                YQ_SHA256=88a1016bc1d657375a35864e4f44b6f333df8ff97b559f51bba0adcb2169df09
                JQ_SHA256=8b85c817833814ddca00a144c33705546355afccf0cf39b188f3cdb48b852309
                ;;
              *) echo "dhi-intake-kit: unsupported architecture $(uname -m)" >&2; exit 1 ;;
            esac
            tmp="$(mktemp -d)"
            trap 'rm -rf "$tmp"' EXIT
            fetch() {
              curl -fsSL --proto '=https' --tlsv1.2 --retry 3 --retry-delay 2 -o "$3" "$1"
              if ! echo "$2  $3" | sha256sum -c - >/dev/null 2>&1; then
                echo "dhi-intake-kit: SHA-256 mismatch for $1 (want $2, got $(sha256sum "$3" | cut -d' ' -f1))" >&2
                exit 1
              fi
            }
            done_already() { [ -f "$T/.$1-$2-$A" ]; }
            mark() { rm -f "$T"/."$1"-*; touch "$T/.$1-$2-$A"; }
            if ! done_already uv "$UV_VERSION"; then
              fetch "https://github.com/astral-sh/uv/releases/download/${UV_VERSION}/uv-${UV_TRIPLE}.tar.gz" "$UV_SHA256" "$tmp/uv.tar.gz"
              tar -xzf "$tmp/uv.tar.gz" -C "$tmp"
              install -m 0755 "$tmp/uv-${UV_TRIPLE}/uv" "$tmp/uv-${UV_TRIPLE}/uvx" "$T/bin/"
              mark uv "$UV_VERSION"
            fi
            if ! done_already gh "$GH_VERSION"; then
              fetch "https://github.com/cli/cli/releases/download/v${GH_VERSION}/gh_${GH_VERSION}_linux_${A}.tar.gz" "$GH_SHA256" "$tmp/gh.tar.gz"
              tar -xzf "$tmp/gh.tar.gz" -C "$tmp"
              install -m 0755 "$tmp/gh_${GH_VERSION}_linux_${A}/bin/gh" "$T/bin/gh"
              mark gh "$GH_VERSION"
            fi
            if ! done_already yq "$YQ_VERSION"; then
              fetch "https://github.com/mikefarah/yq/releases/download/v${YQ_VERSION}/yq_linux_${A}" "$YQ_SHA256" "$tmp/yq"
              install -m 0755 "$tmp/yq" "$T/bin/yq"
              mark yq "$YQ_VERSION"
            fi
            if ! done_already jq "$JQ_VERSION"; then
              fetch "https://github.com/jqlang/jq/releases/download/jq-${JQ_VERSION}/jq-linux-${A}" "$JQ_SHA256" "$tmp/jq"
              install -m 0755 "$tmp/jq" "$T/bin/jq"
              mark jq "$JQ_VERSION"
            fi
            for t in uv uvx gh yq jq; do
              command -v "$t" >/dev/null 2>&1 || ln -sfn "$T/bin/$t" "/usr/local/bin/$t"
            done
            chown -R 1000:1000 "$T"
            echo "dhi-intake-kit: tools $("$T/bin/uv" --version) | $("$T/bin/gh" --version | head -n1) | $("$T/bin/yq" --version) | $("$T/bin/jq" --version)"
          user: "0"
          description: Install uv 0.12.17, gh 2.100.0, yq 4.53.6 and jq 1.8.2 (linux amd64 or arm64) from their GitHub releases into /opt/dhi-intake-kit/tools/bin, each SHA-256 verified; idempotent via per-version stamps.
        - command: |
            set -eu
            K=/opt/dhi-intake-kit
            PY_VERSION=3.12.14
            if [ ! -f "$K/python/.dhi-intake-kit-$PY_VERSION" ]; then
              UV_PYTHON_INSTALL_DIR="$K/python" UV_CACHE_DIR="$K/cache/uv" UV_NO_PROGRESS=1 \
                "$K/tools/bin/uv" python install "$PY_VERSION" --no-bin
              touch "$K/python/.dhi-intake-kit-$PY_VERSION"
            fi
            chown -R 1000:1000 "$K/python" "$K/cache"
          user: "0"
          description: Install CPython 3.12.14 with the pinned uv into /opt/dhi-intake-kit/python (no shims on PATH); idempotent via a version stamp.
    startup:
        - command:
            - sh
            - -c
            - bash /home/agent/.dhi-intake-kit/libexec/materialize.sh
          user: "1000"
          description: Copy the staged lab payload to /opt/dhi-intake-kit/triage-skill-lab, uv sync --frozen (runtime deps from uv.lock), install the verify_all and triage_pre wrappers, run the lock/fixture self-tests and write /opt/dhi-intake-kit/MARKER.
        - command:
            - sh
            - -c
            - bash /home/agent/.dhi-intake-kit/libexec/selfcheck.sh || true
          user: "1000"
          description: Check that MARKER exists and the venv imports lab.verify_all; log one line; never fail.