pi-agent-suite (latest)
Published 2026-08-13 13:47:40 +00:00 by dikka
Installation
docker pull forge.dikka.dev/lab/pi-agent-suite:latestsha256:1e21ba104b8851ae06c04d46ceb6c4a046649ac6fba4944ef8f2ebc632b822f0About this package
Base image for running pi coding-agent harness workflows
Image layers
| # debian.sh --arch 'amd64' out/ 'trixie' '@1783900800' |
| RUN /bin/sh -c groupadd --gid 1000 node && useradd --uid 1000 --gid node --shell /bin/bash --create-home node # buildkit |
| ENV NODE_VERSION=24.18.0 |
| RUN /bin/sh -c ARCH= OPENSSL_ARCH= && dpkgArch="$(dpkg --print-architecture)" && case "${dpkgArch##*-}" in amd64) ARCH='x64' OPENSSL_ARCH='linux-x86_64';; ppc64el) ARCH='ppc64le' OPENSSL_ARCH='linux-ppc64le';; s390x) ARCH='s390x' OPENSSL_ARCH='linux*-s390x';; arm64) ARCH='arm64' OPENSSL_ARCH='linux-aarch64';; armhf) ARCH='armv7l' OPENSSL_ARCH='linux-armv4';; *) echo "unsupported architecture"; exit 1 ;; esac && set -ex && apt-get update && apt-get install -y ca-certificates curl wget gnupg dirmngr xz-utils libatomic1 --no-install-recommends && rm -rf /var/lib/apt/lists/* && export GNUPGHOME="$(mktemp -d)" && for key in 5BE8A3F6C8A5C01D106C0AD820B1A390B168D356 DD792F5973C6DE52C432CBDAC77ABFA00DDBF2B7 CC68F5A3106FF448322E48ED27F5E38D5B0A215F 8FCCA13FEF1D0C2E91008E09770F7A9A5AE15600 890C08DB8579162FEE0DF9DB8BEAB4DFCF555EF4 C82FA3AE1CBEDC6BE46B9360C43CEC45C17AB93C 108F52B48DB57BB0CC439B2997B01419BD92F80A A363A499291CBBC940DD62E41F10027AF002F8B0 ; do { gpg --batch --keyserver hkps://keys.openpgp.org --recv-keys "$key" && gpg --batch --fingerprint "$key"; } || { gpg --batch --keyserver keyserver.ubuntu.com --recv-keys "$key" && gpg --batch --fingerprint "$key"; } ; done && curl -fsSLO --compressed "https://nodejs.org/dist/v$NODE_VERSION/node-v$NODE_VERSION-linux-$ARCH.tar.xz" && curl -fsSLO --compressed "https://nodejs.org/dist/v$NODE_VERSION/SHASUMS256.txt.asc" && gpg --batch --decrypt --output SHASUMS256.txt SHASUMS256.txt.asc && gpgconf --kill all && rm -rf "$GNUPGHOME" && grep " node-v$NODE_VERSION-linux-$ARCH.tar.xz\$" SHASUMS256.txt | sha256sum -c - && tar -xJf "node-v$NODE_VERSION-linux-$ARCH.tar.xz" -C /usr/local --strip-components=1 --no-same-owner && rm "node-v$NODE_VERSION-linux-$ARCH.tar.xz" SHASUMS256.txt.asc SHASUMS256.txt && find /usr/local/include/node/openssl/archs -mindepth 1 -maxdepth 1 ! -name "$OPENSSL_ARCH" -exec rm -rf {} \; && apt-mark auto '.*' > /dev/null && find /usr/local -type f -executable -exec ldd '{}' ';' | awk '/=>/ { so = $(NF-1); if (index(so, "/usr/local/") == 1) { next }; gsub("^/(usr/)?", "", so); print so }' | sort -u | xargs -r dpkg-query --search | cut -d: -f1 | sort -u | xargs -r apt-mark manual && apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false && ln -s /usr/local/bin/node /usr/local/bin/nodejs && node --version && npm --version && rm -rf /tmp/* # buildkit |
| ENV YARN_VERSION=1.22.22 |
| RUN /bin/sh -c set -ex && savedAptMark="$(apt-mark showmanual)" && apt-get update && apt-get install -y ca-certificates curl wget gnupg dirmngr --no-install-recommends && rm -rf /var/lib/apt/lists/* && export GNUPGHOME="$(mktemp -d)" && for key in 6A010C5166006599AA17F08146C2130DFD2497F5 ; do { gpg --batch --keyserver hkps://keys.openpgp.org --recv-keys "$key" && gpg --batch --fingerprint "$key"; } || { gpg --batch --keyserver keyserver.ubuntu.com --recv-keys "$key" && gpg --batch --fingerprint "$key"; } ; done && curl -fsSLO --compressed "https://yarnpkg.com/downloads/$YARN_VERSION/yarn-v$YARN_VERSION.tar.gz" && curl -fsSLO --compressed "https://yarnpkg.com/downloads/$YARN_VERSION/yarn-v$YARN_VERSION.tar.gz.asc" && gpg --batch --verify yarn-v$YARN_VERSION.tar.gz.asc yarn-v$YARN_VERSION.tar.gz && gpgconf --kill all && rm -rf "$GNUPGHOME" && mkdir -p /opt && tar -xzf yarn-v$YARN_VERSION.tar.gz -C /opt/ && ln -s /opt/yarn-v$YARN_VERSION/bin/yarn /usr/local/bin/yarn && ln -s /opt/yarn-v$YARN_VERSION/bin/yarnpkg /usr/local/bin/yarnpkg && rm yarn-v$YARN_VERSION.tar.gz.asc yarn-v$YARN_VERSION.tar.gz && apt-mark auto '.*' > /dev/null && { [ -z "$savedAptMark" ] || apt-mark manual $savedAptMark > /dev/null; } && find /usr/local -type f -executable -exec ldd '{}' ';' | awk '/=>/ { so = $(NF-1); if (index(so, "/usr/local/") == 1) { next }; gsub("^/(usr/)?", "", so); print so }' | sort -u | xargs -r dpkg-query --search | cut -d: -f1 | sort -u | xargs -r apt-mark manual && apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false && yarn --version && rm -rf /tmp/* # buildkit |
| COPY docker-entrypoint.sh /usr/local/bin/ # buildkit |
| ENTRYPOINT ["docker-entrypoint.sh"] |
| CMD ["node"] |
| LABEL org.opencontainers.image.title=pi agent harness base org.opencontainers.image.description=Base image for running pi coding-agent harness workflows |
| ENV DEBIAN_FRONTEND=noninteractive GIT_PAGER=cat NODE_ENV=production NPM_CONFIG_AUDIT=false NPM_CONFIG_FUND=false PAGER=cat |
| SHELL [/bin/bash -o pipefail -c] |
| RUN /bin/bash -o pipefail -c apt-get update && apt-get install -y --no-install-recommends bash bzip2 ca-certificates curl fd-find file git gnupg gzip jq less lsof patch procps psmisc ripgrep tar tree unzip wget xz-utils zip zstd && rm -rf /var/lib/apt/lists/* # buildkit |
| RUN /bin/bash -o pipefail -c groupmod --new-name agent node && usermod --login agent --home /home/agent --move-home --shell /bin/bash node && mkdir -p /home/agent/.pi/agent /workspace /opt/pi-rest && chown -R agent:agent /home/agent /workspace /opt/pi-rest # buildkit |
| COPY --chown=agent:agent /src/server/dist/server.js /opt/pi-rest/server.js # buildkit |
| COPY --chown=agent:agent /src/server/package.json /src/server/package-lock.json /opt/pi-rest/ # buildkit |
| COPY --chown=agent:agent /src/server/node_modules /opt/pi-rest/node_modules # buildkit |
| COPY --chown=agent:agent extensions/azure-opaque-retry /home/agent/.pi/agent/extensions/azure-opaque-retry # buildkit |
| RUN /bin/bash -o pipefail -c ln -s /opt/pi-rest/node_modules/.bin/pi /usr/local/bin/pi # buildkit |
| USER agent |
| WORKDIR /workspace |
| EXPOSE [3000/tcp] |
| CMD ["node" "/opt/pi-rest/server.js"] |
| USER root |
| COPY autonomous/extensions /opt/pi-resources/autonomous/extensions # buildkit |
| COPY extensions/quiescence /home/agent/.pi/agent/extensions/quiescence # buildkit |
| COPY extensions/azure-opaque-retry /home/agent/.pi/agent/extensions/azure-opaque-retry # buildkit |
| COPY autonomous/extensions/default-tools /home/agent/.pi/agent/extensions/default-tools # buildkit |
| RUN /bin/bash -o pipefail -c mkdir -p /home/agent/.pi/agent && printf '%s\n' '{' ' "extensions": [' ' "/opt/pi-resources/autonomous/extensions/runtime-policy/index.ts"' ' ]' '}' > /home/agent/.pi/agent/settings.json && chown -R agent:agent /home/agent/.pi /opt/pi-resources # buildkit |
| USER agent |
| WORKDIR /workspace |
| ARG UV_VERSION=0.11.12 |
| ARG PYTHON_VERSION=3.12.13 |
| ARG JDK_VERSION=21 |
| ARG TYPESCRIPT_VERSION=6.0.3 |
| ARG RUST_TOOLCHAIN=1.97.0 |
| USER root |
| ENV JAVA_HOME=/opt/java/openjdk MAVEN_CONFIG=/home/agent/.m2 CARGO_HOME=/home/agent/.cargo RUSTUP_HOME=/home/agent/.rustup UV_TOOL_BIN_DIR=/home/agent/.local/bin |
| ENV PATH=/home/agent/.cargo/bin:/home/agent/.local/bin:/opt/java/openjdk/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin |
| RUN |5 UV_VERSION=0.11.12 PYTHON_VERSION=3.12.13 JDK_VERSION=21 TYPESCRIPT_VERSION=6.0.3 RUST_TOOLCHAIN=1.97.0 /bin/bash -o pipefail -c set -euo pipefail && apt-get update && apt-get install -y --no-install-recommends build-essential cmake just libssl-dev maven "openjdk-${JDK_VERSION}-jdk-headless" openssh-client pkg-config rsync shellcheck sqlite3 && jvm_arch="$(dpkg --print-architecture)" && mkdir -p "$(dirname "${JAVA_HOME}")" && ln -s "/usr/lib/jvm/java-${JDK_VERSION}-openjdk-${jvm_arch}" "${JAVA_HOME}" && rm -rf /var/lib/apt/lists/* # buildkit |
| RUN |5 UV_VERSION=0.11.12 PYTHON_VERSION=3.12.13 JDK_VERSION=21 TYPESCRIPT_VERSION=6.0.3 RUST_TOOLCHAIN=1.97.0 /bin/bash -o pipefail -c npm install --global "typescript@${TYPESCRIPT_VERSION}" && npm cache clean --force # buildkit |
| RUN |5 UV_VERSION=0.11.12 PYTHON_VERSION=3.12.13 JDK_VERSION=21 TYPESCRIPT_VERSION=6.0.3 RUST_TOOLCHAIN=1.97.0 /bin/bash -o pipefail -c curl --proto '=https' --tlsv1.2 -LsSf https://astral.sh/uv/${UV_VERSION}/install.sh | env UV_UNMANAGED_INSTALL="/usr/local/bin" sh # buildkit |
| COPY extensions/azure-opaque-retry /home/agent/.pi/agent/extensions/azure-opaque-retry # buildkit |
| COPY suite/extensions /opt/pi-resources/suite/extensions # buildkit |
| COPY java/extensions /opt/pi-resources/java/extensions # buildkit |
| COPY extensions/todo /opt/pi-resources/suite/extensions/todo # buildkit |
| COPY extensions/subagents /opt/pi-resources/suite/extensions/subagents # buildkit |
| RUN |5 UV_VERSION=0.11.12 PYTHON_VERSION=3.12.13 JDK_VERSION=21 TYPESCRIPT_VERSION=6.0.3 RUST_TOOLCHAIN=1.97.0 /bin/bash -o pipefail -c mkdir -p /opt/pi-resources/suite /home/agent/.pi/agent /home/agent/.local/bin /home/agent/.m2 && chown -R agent:agent /opt/pi-resources/suite /opt/pi-resources/java /home/agent/.pi /home/agent/.local /home/agent/.m2 # buildkit |
| USER agent |
| RUN |5 UV_VERSION=0.11.12 PYTHON_VERSION=3.12.13 JDK_VERSION=21 TYPESCRIPT_VERSION=6.0.3 RUST_TOOLCHAIN=1.97.0 /bin/bash -o pipefail -c set -euo pipefail && uv python install "${PYTHON_VERSION}" && python_minor="$(printf '%s\n' "${PYTHON_VERSION}" | awk -F. '{print $1 "." $2}')" && ln -sf "/home/agent/.local/bin/python${python_minor}" /home/agent/.local/bin/python3 && printf '%s\n' '{' ' "extensions": [' ' "/opt/pi-resources/autonomous/extensions/runtime-policy/index.ts",' ' "/opt/pi-resources/suite/extensions/python-policy/index.ts",' ' "/opt/pi-resources/java/extensions/java-policy/index.ts",' ' "/opt/pi-resources/suite/extensions/todo/index.ts",' ' "/opt/pi-resources/suite/extensions/subagents/index.ts"' ' ]' '}' > /home/agent/.pi/agent/settings.json # buildkit |
| RUN |5 UV_VERSION=0.11.12 PYTHON_VERSION=3.12.13 JDK_VERSION=21 TYPESCRIPT_VERSION=6.0.3 RUST_TOOLCHAIN=1.97.0 /bin/bash -o pipefail -c set -euo pipefail && curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y --profile minimal --default-toolchain "${RUST_TOOLCHAIN}" && rustup component add --toolchain "${RUST_TOOLCHAIN}" rustfmt clippy && cargo --version && rustc --version && rustfmt --version && cargo clippy --version # buildkit |
| WORKDIR /workspace |
Labels
| Key | Value |
|---|---|
| org.opencontainers.image.description | Base image for running pi coding-agent harness workflows |
| org.opencontainers.image.title | pi agent harness base |
Details
2026-08-13 13:47:40 +00:00
Versions (3)
View all
Container
17
OCI / Docker
linux/amd64
721 MiB