Sign inSign up

olegselajev241/agy-sbx-kit-mixin:latest

Multi-platform
Manifest digest

sha256:88ea45c7dcbb3bfb5e6d2e0b0f21b71d5755eca8bd560a1238969395a0f761ee

Last pushed

3 days by olegselajev241

Type

Sandbox Kit

Manifest digest

sha256:88ea45c7dcbb3bfb5e6d2e0b0f21b71d5755eca8bd560a1238969395a0f761ee

yaml
schemaVersion: "3"
displayName: Antigravity CLI (agy) (mixin)
description: Add Google's Antigravity CLI and its sandbox configuration to another v3 workload, then run agy from that environment.
sourceUrl: https://github.com/shelajev/agy-sbx-kit
version: 1.0.2
licenses:
    - Apache-2.0
kind: mixin
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - antigravity.google:443
                - antigravity-unleash.goog:443
                - antigravity-cli-auto-updater-974169037036.us-central1.run.app:443
                - storage.googleapis.com:443
                - accounts.google.com:443
                - lh3.googleusercontent.com:443
                - oauth2.googleapis.com:443
                - play.googleapis.com:443
                - www.googleapis.com:443
                - aicode.googleapis.com:443
                - cloudaicompanion.googleapis.com:443
                - cloudcode-pa.googleapis.com:443
                - daily-cloudcode-pa.googleapis.com:443
                - generativelanguage.googleapis.com:443
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        oauth:
            credentialFile:
                path: ~/.gemini/antigravity-cli/antigravity-oauth-token
                structure:
                    auth_method: consumer
                    token:
                        access_token: '{{.AccessToken}}'
                        expiry: "9999-12-31T23:59:59Z"
                        refresh_token: '{{.RefreshToken}}'
                        token_type: Bearer
            resourceHosts:
                - aicode.googleapis.com
                - cloudaicompanion.googleapis.com
                - cloudcode-pa.googleapis.com
                - daily-cloudcode-pa.googleapis.com
                - generativelanguage.googleapis.com
                - www.googleapis.com
            sentinels:
                accessToken: agy-oauth-access-proxy-managed
                refreshToken: agy-oauth-refresh-proxy-managed
            tokenEndpoint:
                host: oauth2.googleapis.com
                path: /token
        phase: runtime
        service: antigravity
      description: Google OAuth session used by Antigravity CLI
    - type: com.docker.sandbox/lifecycle@1
      config:
        install:
            - command: |
                set -eu
                settings_dir="$HOME/.gemini/antigravity-cli"
                settings="$settings_dir/settings.json"
                [ ! -e "$settings" ] || exit 0
                mkdir -p "$settings_dir"
                ws="${WORKSPACE_DIR:-/workspace}"
                esc=$(printf '%s' "$ws" | sed 's/\\/\\\\/g; s/"/\\"/g; s/\t/\\t/g; s/\r/\\r/g')
                printf '%s\n' "{
                  \"agentMode\": \"accept-edits\",
                  \"artifactReviewMode\": \"always-proceed\",
                  \"fileAccessPolicy\": \"allow\",
                  \"internetAccessPolicy\": \"allow\",
                  \"nonWorkspaceFileAccess\": \"allow\",
                  \"permissions\": {
                    \"allow\": [
                      \"command(*)\",
                      \"execute_url(*)\",
                      \"mcp(*)\",
                      \"read_file(*)\",
                      \"read_url(*)\",
                      \"write_file(*)\"
                    ]
                  },
                  \"toolExecutionPolicy\": \"always-proceed\",
                  \"trustedWorkspaces\": [\"$esc\"]
                }" > "$settings"
                chmod 0600 "$settings"
              description: Seed permissive Antigravity settings for sandboxed operation
              env:
                - WORKSPACE_DIR
              user: agent