mirror of
https://github.com/tiennm99/goclaw.git
synced 2026-10-03 07:12:50 +00:00
Runtime package management with security hardening: - pkg-helper: root-privileged daemon for apk install/uninstall via Unix socket - HTTP API: /v1/packages (list/install/uninstall/runtimes), admin role required for writes - Shell deny groups: 15 configurable groups (per-agent overrides via context) - Packages UI: Web page for managing system/pip/npm packages with confirmation dialogs - Docker: privilege separation (root entrypoint → su-exec drop), init for zombie reaping - Security: umask socket creation, persist file validation, deny pattern hardening (Node.js fetch/http, Python from/import, curl localhost, sensitive env vars) - Auth: empty gateway token → admin role (dev/single-user mode)
71 lines
1.9 KiB
YAML
71 lines
1.9 KiB
YAML
# Base docker-compose — shared service definition.
|
|
# Pre-built images: ghcr.io/nextlevelbuilder/goclaw (also on Docker Hub: digitop/goclaw)
|
|
#
|
|
# Combine with overlays for your deployment:
|
|
#
|
|
# Recommended (+ Web Dashboard, pre-built images):
|
|
# docker compose -f docker-compose.yml -f docker-compose.postgres.yml -f docker-compose.selfservice.yml up -d
|
|
#
|
|
# Build from source (add --build):
|
|
# docker compose -f docker-compose.yml -f docker-compose.postgres.yml -f docker-compose.selfservice.yml up -d --build
|
|
#
|
|
# Without dashboard: docker compose -f docker-compose.yml -f docker-compose.postgres.yml up -d
|
|
# With OTel tracing: docker compose -f docker-compose.yml -f docker-compose.postgres.yml -f docker-compose.otel.yml up -d --build
|
|
|
|
services:
|
|
goclaw:
|
|
image: ghcr.io/nextlevelbuilder/goclaw:latest
|
|
build:
|
|
context: .
|
|
dockerfile: Dockerfile
|
|
args:
|
|
ENABLE_OTEL: "false"
|
|
ENABLE_PYTHON: "true"
|
|
ports:
|
|
- "${GOCLAW_PORT:-18790}:18790"
|
|
env_file:
|
|
- path: .env
|
|
required: false
|
|
environment:
|
|
- GOCLAW_HOST=0.0.0.0
|
|
- GOCLAW_PORT=18790
|
|
- GOCLAW_CONFIG=/app/data/config.json
|
|
- GOCLAW_GATEWAY_TOKEN=${GOCLAW_GATEWAY_TOKEN:-}
|
|
- GOCLAW_ENCRYPTION_KEY=${GOCLAW_ENCRYPTION_KEY:-}
|
|
- GOCLAW_SKILLS_DIR=/app/data/skills
|
|
# Debug
|
|
- GOCLAW_TRACE_VERBOSE=${GOCLAW_TRACE_VERBOSE:-0}
|
|
volumes:
|
|
- goclaw-data:/app/data
|
|
- goclaw-workspace:/app/workspace
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
init: true
|
|
cap_drop:
|
|
- ALL
|
|
cap_add:
|
|
- SETUID
|
|
- SETGID
|
|
- CHOWN
|
|
tmpfs:
|
|
- /tmp:rw,noexec,nosuid,size=256m
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 1G
|
|
cpus: '2.0'
|
|
pids: 200
|
|
networks:
|
|
- default
|
|
- shared
|
|
restart: unless-stopped
|
|
|
|
volumes:
|
|
goclaw-data:
|
|
goclaw-workspace:
|
|
|
|
networks:
|
|
shared:
|
|
name: shared
|
|
driver: bridge
|