rein-aharness/Containerfile
tegwick f6930ad115 Rename package, CLI, and deploy artifacts to rein-aharness (HARNESS-WP-0002-T02)
agent_harness -> rein_aharness (package + all imports), CLI command
agent-harness -> rein-aharness, Docker image tag, k8s namespace/labels/
names, Makefile targets, deploy script env var/paths. In-repo identity
strings (hub event source, metrics harness field, default assignee,
argparse prog name, commit author identity) updated to match.

Historical documents left untouched on purpose: docs/adr/ADR-001-agent-harness-architecture.md,
docs/architecture.md (dated v0.1 snapshot), workplans/HARNESS-WP-0001
(completed under the old name), and the SSH host alias
"forgejo-agent-harness" (external ~/.ssh/config entry, not owned here).

Verified: 47/47 tests pass, CLI runs correctly from a fresh venv,
`make image` builds and the resulting container runs correctly.

deploy/README.md gained an explicit rename cutover checklist for what
this session cannot safely do unattended -- moving the host-side
secrets dir and checkout on railiance01, and not deleting the old k8s
namespace until the new one is confirmed working. The actual live
cutover (running that checklist against the real Railiance deployment)
is not attempted here -- real production surgery on binky-control's
live automation, needs the operator present.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-26 14:22:18 +02:00

35 lines
1.2 KiB
Docker

# rein-aharness — shared unattended agent runtime (Railiance / local).
# Build: docker build -f Containerfile -t rein-aharness:local .
# Optional llm-connect sibling: docker build --build-arg WITH_LLM_CONNECT=1 ...
FROM python:3.12-slim
ENV PYTHONDONTWRITEBYTECODE=1 \
PYTHONUNBUFFERED=1 \
PATH="/home/harness/.local/bin:$PATH" \
STATE_HUB_URL=http://state-hub.state-hub.svc.cluster.local:8000
WORKDIR /app
RUN apt-get update \
&& apt-get install -y --no-install-recommends git openssh-client ca-certificates \
&& rm -rf /var/lib/apt/lists/* \
&& groupadd -g 10001 harness \
&& useradd -u 10001 -g 10001 -m -s /usr/sbin/nologin harness
COPY pyproject.toml README.md ./
COPY rein_aharness ./rein_aharness
# Populated by `make image` from ../llm-connect when present.
COPY llm_connect_vendor ./llm_connect_vendor
RUN pip install --no-cache-dir "httpx>=0.27" "PyYAML>=6.0" \
&& pip install --no-cache-dir --no-deps . \
&& if [ -f llm_connect_vendor/pyproject.toml ]; then \
pip install --no-cache-dir ./llm_connect_vendor; \
fi \
&& rm -rf /root/.cache/pip
USER 10001:10001
# No long-running HTTP API yet — image is invoked as CLI (run / smoke / validate).
ENTRYPOINT ["rein-aharness"]
CMD ["profiles"]