feat: Railiance package and deploy (HARNESS-WP-0001-T06)

Container image, k8s namespace/deployment/smoke job, host venv install path,
and deterministic agent-harness smoke (sandbox commit+push+hub) for remote
verification without Claude Code on the worker host.
This commit is contained in:
tegwick 2026-07-18 10:48:44 +02:00
parent 4144eba160
commit 67f1791491
15 changed files with 520 additions and 1 deletions

35
Containerfile Normal file
View file

@ -0,0 +1,35 @@
# agent-harness — shared unattended agent runtime (Railiance / local).
# Build: docker build -f Containerfile -t agent-harness:local .
# Optional llm-connect sibling: docker build --build-arg WITH_LLM_CONNECT=1 ...
FROM python:3.12-slim
ENV PYTHONDONTWRITEBYTECODE=1 \
PYTHONUNBUFFERED=1 \
PATH="/home/harness/.local/bin:$PATH" \
STATE_HUB_URL=http://state-hub.state-hub.svc.cluster.local:8000
WORKDIR /app
RUN apt-get update \
&& apt-get install -y --no-install-recommends git openssh-client ca-certificates \
&& rm -rf /var/lib/apt/lists/* \
&& groupadd -g 10001 harness \
&& useradd -u 10001 -g 10001 -m -s /usr/sbin/nologin harness
COPY pyproject.toml README.md ./
COPY agent_harness ./agent_harness
# Populated by `make image` from ../llm-connect when present.
COPY llm_connect_vendor ./llm_connect_vendor
RUN pip install --no-cache-dir "httpx>=0.27" "PyYAML>=6.0" \
&& pip install --no-cache-dir --no-deps . \
&& if [ -f llm_connect_vendor/pyproject.toml ]; then \
pip install --no-cache-dir ./llm_connect_vendor; \
fi \
&& rm -rf /root/.cache/pip
USER 10001:10001
# No long-running HTTP API yet — image is invoked as CLI (run / smoke / validate).
ENTRYPOINT ["agent-harness"]
CMD ["profiles"]