Charm's multi-provider AI coding agent as a mixin -- the Crush binary in an overlay, with proxy-m...
195
Charm's multi-provider AI coding agent as a mixin -- the Crush binary in an overlay, with proxy-mediated auth for 15 model providers and the egress they need. Layer it onto a shell base and run `crush`.
| Name | Required | Default | Description |
|---|---|---|---|
version | Optional | 0.95.0 | Crush release to install from Charm's apt repository |
[email protected]| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/credential@1 | Optional | Anthropic API access | |
com.docker.sandbox/credential@1 | Optional | AWS Bedrock access | |
com.docker.sandbox/credential@1 | Optional | Azure OpenAI access | |
com.docker.sandbox/credential@1 | Optional | Cerebras API access | |
com.docker.sandbox/credential@1 | Optional | Google AI API access | |
com.docker.sandbox/credential@1 | Optional | Groq API access | |
com.docker.sandbox/credential@1 | Optional | Hugging Face inference access | |
com.docker.sandbox/credential@1 | Optional | io.net API access | |
com.docker.sandbox/credential@1 | Optional | MiniMax API access | |
com.docker.sandbox/credential@1 | Optional | Mistral API access | |
com.docker.sandbox/credential@1 | Optional | OpenAI API access | |
com.docker.sandbox/credential@1 | Optional | OpenRouter API access | |
com.docker.sandbox/credential@1 | Optional | Synthetic API access | |
com.docker.sandbox/credential@1 | Optional | Vercel v0 API access | |
com.docker.sandbox/credential@1 | Optional | Z.ai API access | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit docker/sbx-kit-crush-mixin:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxNote
Experimental: Sandbox Kit v3This kit uses the experimental Sandbox Kit specification, specifically v3. The format and runtime behavior may change before v3 is stable.
The mixin form of the crush kit:
Crush in an overlay that lands on a
shell workload, instead of a whole sandbox of its own.
A kind: mixin kit carrying the Crush binary as a filesystem delta, with the
same declarations the workload makes — fifteen optional proxy-managed provider
credentials and the runtime allow list covering exactly the hosts they inject
into, Bedrock regions enumerated because the allow grammar has no
middle-position wildcard.
Crush installs from Charm's apt repository, which is the case where relocation
is not available at all: apt-get --root wants its own dpkg database, keyring
trust and a bootstrapped base under the target root. So
crush-mixin.dockerfile runs the unmodified apt install in a build stage on
the workload's own base and carries out exactly the paths dpkg -L crush
reports, via tar so modes and symlinks survive. Reading the package's file
list rather than hard-coding a prefix means a Charm packaging change that
moved the binary fails the build instead of producing an empty overlay.
$ sbx create --kit <shell-workload> --kit ./crush-mixin
$ crush --yolo
ENTRYPOINT: the base workload's stays, and
crush is something you run from its shell — which is also where --yolo,
carried by the standalone kit's CMD, has to be passed by hand.agent-sessions@1. The session verbs append to the workload's launch
argv, and that is the base's shell here, not Crush. The standalone
crush kit is the one that declares them.AGENTS.md profile, sbx@1 and the sandbox identity, and the
platform floor — bash, the agent user, git, a CA store.crush and crush-mixin both provide crush, so they are alternatives:
composing the two together is refused, one capability having one provider.
Pulls:
78
Last week