Repository navigation
Expand file tree
/
Copy pathDockerfile.runner
More file actions
38 lines (34 loc) · 1.71 KB
/
Copy pathDockerfile.runner
File metadata and controls
38 lines (34 loc) · 1.71 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
FROM ruby:4.0-slim
RUN apt-get update && apt-get install -y \
build-essential \
git \
&& rm -rf /var/lib/apt/lists/*
# Node + the OpenSpec CLI, for the `pd` (product development) pipeline. OpenSpec
# runs in the RUNNER, never in the harness container: pi-guards.ts there permits
# read-only git and nothing else, and widening it for a non-git binary would
# undo the container's whole posture. The runner is the trusted orchestrator, so
# this is the right home — but it does hold both API tokens, hence the pin and
# the build-time-only install (no runtime package fetches).
# openspec's engines field wants Node >= 20.19; setup_24.x satisfies it. 24
# because the Node 20 line died 2026-04-30 and the JS images are all on 24.
#
# curl is installed and purged inside this one layer: nothing at runtime shells
# out to it, and the runner holds both API tokens, so it does not need a general
# HTTP client sitting in the image. ca-certificates is marked manual first, or
# --auto-remove would take it along with curl and break every HTTPS call.
ENV OPENSPEC_VERSION=1.13.2
RUN apt-get update \
&& apt-get install -y --no-install-recommends curl ca-certificates \
&& apt-mark manual ca-certificates \
&& curl -fsSL https://deb.nodesource.com/setup_24.x | bash - \
&& apt-get install -y nodejs \
&& npm install -g "@fission-ai/openspec@${OPENSPEC_VERSION}" \
&& npm cache clean --force \
&& apt-get purge -y --auto-remove curl \
&& rm -rf /var/lib/apt/lists/*
# --system (not --global): the runner runs as the host uid at runtime, not root,
# so the setting must live in system config rather than root's ~/.gitconfig.
RUN git config --system --add safe.directory '*'
WORKDIR /app
COPY Gemfile Gemfile.lock ./
RUN bundle install