-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile.alpine
More file actions
149 lines (133 loc) · 8.36 KB
/
Copy pathDockerfile.alpine
File metadata and controls
149 lines (133 loc) · 8.36 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
# ==============================================================================
# ROCI GHOST MACHINE - ALPINE LINUX TEMPLATE
# ==============================================================================
FROM alpine:latest
# Build Arguments & Versions
ARG GHOST_USER=developer
ARG HOST_UID=1000
ARG HOST_GID=1000
ARG GO_VERSION=1.24.2
ARG HELIX_VERSION=25.01.1
ARG LAZYGIT_VERSION=0.61.1
# 1. Environment & UTF-8
ENV LANG=C.UTF-8
ENV LC_ALL=C.UTF-8
# 2. Base System & Build Tools
RUN apk update && apk add --no-cache \
bash curl gnupg git wget unzip ca-certificates sudo shadow \
build-base gdb make cmake \
python3 py3-pip pipx \
htop btop net-tools glances sysstat inxi ncdu tree \
zip p7zip nmap lsof xclip \
nnn fzf ripgrep tmux \
bat eza zoxide fd jq \
kitty kitty-terminfo \
openssh-server figlet fortune \
&& mkdir -p /var/run/sshd \
&& ssh-keygen -A \
&& rm -rf /var/cache/apk/* /tmp/* /var/tmp/*
# 3. Node.js (Latest Current)
RUN apk add --no-cache nodejs npm \
&& rm -rf /var/cache/apk/* /tmp/* /var/tmp/*
# 4. Go & Rust Runtimes
RUN ARCH=$(uname -m) && \
if [ "$ARCH" = "x86_64" ]; then GO_ARCH="amd64"; elif [ "$ARCH" = "aarch64" ]; then GO_ARCH="arm64"; else GO_ARCH="amd64"; fi && \
curl -fsSL "https://go.dev/dl/go${GO_VERSION}.linux-${GO_ARCH}.tar.gz" | tar -C /usr/local -xz && \
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y --profile minimal --no-modify-path && \
cp /root/.cargo/bin/* /usr/local/bin/ 2>/dev/null || true
ENV PATH=$PATH:/usr/local/go/bin:/root/.cargo/bin
# 5. Bun & Python UV Runtimes
RUN curl -fsSL https://bun.sh/install | bash && \
curl -fsSL https://astral.sh/uv/install.sh | bash && \
cp /root/.local/bin/uv* /usr/local/bin/ 2>/dev/null || true
ENV PATH=$PATH:/root/.bun/bin:/root/.local/bin
# 6. Terminal IDEs (Micro, Helix, Lazygit, Fastfetch)
RUN apk add --no-cache micro \
&& ARCH=$(uname -m) && \
if [ "$ARCH" = "x86_64" ]; then HELIX_ARCH="x86_64"; LAZY_ARCH="x86_64"; FF_ARCH="linux-amd64"; \
elif [ "$ARCH" = "aarch64" ]; then HELIX_ARCH="aarch64"; LAZY_ARCH="arm64"; FF_ARCH="linux-aarch64"; \
fi && \
curl -fsSL "https://github.com/helix-editor/helix/releases/download/${HELIX_VERSION}/helix-${HELIX_VERSION}-${HELIX_ARCH}-linux.tar.xz" | tar xJ && \
mv helix-${HELIX_VERSION}-${HELIX_ARCH}-linux/hx /usr/local/bin/ && \
mkdir -p /root/.config/helix && mv helix-${HELIX_VERSION}-${HELIX_ARCH}-linux/runtime /root/.config/helix/ && \
rm -rf helix-${HELIX_VERSION}-${HELIX_ARCH}-linux && \
curl -fsSL "https://github.com/jesseduffield/lazygit/releases/download/v${LAZYGIT_VERSION}/lazygit_${LAZYGIT_VERSION}_Linux_${LAZY_ARCH}.tar.gz" | tar xz lazygit && \
install lazygit /usr/local/bin && rm -f lazygit && \
curl -fsSL "https://github.com/fastfetch-cli/fastfetch/releases/latest/download/fastfetch-${FF_ARCH}.tar.gz" | tar xz && \
install fastfetch-*/usr/bin/fastfetch /usr/local/bin/fastfetch && rm -rf fastfetch-* \
&& rm -rf /var/cache/apk/* /tmp/* /var/tmp/*
# 7. AI Harness CLIs (Antigravity CLI, OpenCode, RTK)
RUN npm install -g opencode-ai \
&& ARCH=$(uname -m) && \
if [ "$ARCH" = "x86_64" ]; then RTK_ARCH="x86_64-unknown-linux-musl"; \
elif [ "$ARCH" = "aarch64" ]; then RTK_ARCH="aarch64-unknown-linux-gnu"; \
fi && \
curl -fsSL "https://github.com/rtk-ai/rtk/releases/latest/download/rtk-${RTK_ARCH}.tar.gz" | tar xz && \
install rtk /usr/local/bin/rtk && rm -f rtk \
&& (curl -fsSL https://antigravity.ai/install.sh | bash 2>/dev/null || true) \
&& if [ -f /root/.local/bin/agy ]; then ln -sf /root/.local/bin/agy /usr/local/bin/agy && ln -sf /root/.local/bin/agy /usr/local/bin/antigravity; fi \
&& npm cache clean --force
# 8. UI/UX STACK (1. Oh-My-Bash, 2. Alias-Hub, 3. Neofetch-ASCII)
RUN bash -c "$(wget -qO- https://raw.githubusercontent.com/ohmybash/oh-my-bash/master/tools/install.sh)" --unattended \
&& bash -c "$(wget -qO- https://raw.githubusercontent.com/1999AZZAR/alias-hub/master/install.sh)" || true \
&& git clone --depth=1 https://github.com/1999AZZAR/neofetch_ascii.git /root/.local/share/neofetch_ascii \
&& [ -f /root/.config/fastfetch/config.jsonc ] && sed -i 's/"format": "{1}"/"format": "{all}"/g' /root/.config/fastfetch/config.jsonc || true
# 9. SSH Configuration
RUN sed -i 's/#PermitRootLogin prohibit-password/PermitRootLogin yes/' /etc/ssh/sshd_config \
&& echo 'root:ghost' | chpasswd
# 10. HeLa MCP Ecosystem (Profile: headless-server) & Google Conductor Plugin
RUN git clone --depth=1 https://github.com/1999AZZAR/hela-mcp-ecosystem.git /opt/mcp-ecosystem \
&& cd /opt/mcp-ecosystem \
&& sed -i 's|1999AZZAR/research-mcp-server|1999AZZAR/research-assistant-mcp-server|g' config/inventory.json \
&& ./setup.sh --profile headless-server --client antigravity --non-interactive \
&& mkdir -p /root/.mcp /root/.config/opencode \
&& node scripts/generate-config.mjs headless-server --backend antigravity --root /opt/mcp-ecosystem --out /root/.mcp/config.json \
&& node scripts/generate-config.mjs headless-server --backend opencode --root /opt/mcp-ecosystem --out /root/.config/opencode/config.json \
&& ln -sf /opt/mcp-ecosystem /root/MCPservers \
&& echo '#!/bin/bash\nnode /opt/mcp-ecosystem/chaining-mcp-server/dist/index.js "$@"' > /usr/local/bin/mcp-mitosis \
&& echo '#!/bin/bash\nnode /opt/mcp-ecosystem/Project-Guardian-mcp-server/dist/index.js "$@"' > /usr/local/bin/mcp-genome \
&& echo '#!/bin/bash\nnode /opt/mcp-ecosystem/filesystem-mcp-server/dist/index.js "$@"' > /usr/local/bin/mcp-membrane \
&& echo '#!/bin/bash\nnode /opt/mcp-ecosystem/terminal-mcp-server/build/index.js "$@"' > /usr/local/bin/mcp-nucleus \
&& echo '#!/bin/bash\nnode /opt/mcp-ecosystem/menager-mcp-server/build/index.js "$@"' > /usr/local/bin/mcp-ribosome \
&& echo '#!/bin/bash\nnode /opt/mcp-ecosystem/research-mcp-server/dist/index.js "$@"' > /usr/local/bin/mcp-enzyme \
&& echo '#!/bin/bash\nnode /opt/mcp-ecosystem/the-designer/dist/index.js "$@"' > /usr/local/bin/mcp-phenotype \
&& chmod +x /usr/local/bin/mcp-* \
&& git clone --depth=1 https://github.com/gemini-cli-extensions/conductor.git /opt/conductor \
&& mkdir -p /root/.agents/plugins /root/.agents/skills /root/.gemini/config/plugins \
&& ln -sf /opt/conductor /root/.agents/plugins/conductor \
&& ln -sf /opt/conductor /root/.gemini/config/plugins/conductor \
&& for skill in conductor-setup conductor-new-track conductor-implement conductor-status conductor-revert conductor-review; do \
ln -sf /opt/conductor/skills/$skill /root/.agents/skills/$skill; \
done \
&& npm cache clean --force
# 11. Non-Root User & Sudoers Setup
RUN if getent group ${HOST_GID} >/dev/null; then \
EXISTING_GRP=$(getent group ${HOST_GID} | cut -d: -f1); \
else \
addgroup -g ${HOST_GID} ${GHOST_USER}; \
EXISTING_GRP=${GHOST_USER}; \
fi && \
if id -u ${HOST_UID} >/dev/null 2>&1; then \
EXISTING_USR=$(id -un ${HOST_UID}); \
else \
adduser -u ${HOST_UID} -G ${EXISTING_GRP} -D -s /bin/bash ${GHOST_USER}; \
fi && \
mkdir -p /etc/sudoers.d && \
echo "${GHOST_USER} ALL=(ALL) ALL" > /etc/sudoers.d/${GHOST_USER} && \
chmod 0440 /etc/sudoers.d/${GHOST_USER} && \
echo "${GHOST_USER}:ghost" | chpasswd && \
mkdir -p /home/${GHOST_USER}/.ssh /home/${GHOST_USER}/.mcp /home/${GHOST_USER}/.config/opencode /home/${GHOST_USER}/.agents/plugins /home/${GHOST_USER}/.agents/skills /home/${GHOST_USER}/.gemini/config/plugins /home/${GHOST_USER}/.local/bin /home/${GHOST_USER}/.cargo/bin && \
cp /root/.mcp/config.json /home/${GHOST_USER}/.mcp/config.json 2>/dev/null || true && \
cp /root/.config/opencode/config.json /home/${GHOST_USER}/.config/opencode/config.json 2>/dev/null || true && \
cp/config.json/config.json 2>/dev/null || true && \
ln -sf /opt/conductor /home/${GHOST_USER}/.agents/plugins/conductor && \
ln -sf /opt/conductor /home/${GHOST_USER}/.gemini/config/plugins/conductor && \
for skill in conductor-setup conductor-new-track conductor-implement conductor-status conductor-revert conductor-review; do \
ln -sf /opt/conductor/skills/$skill /home/${GHOST_USER}/.agents/skills/$skill; \
done && \
chown -R ${GHOST_USER}:${EXISTING_GRP} /home/${GHOST_USER}
COPY entrypoint.sh /entrypoint.sh
RUN chmod +x /entrypoint.sh
EXPOSE 22
ENTRYPOINT ["/entrypoint.sh"]
CMD ["/usr/sbin/sshd", "-D"]