anvilsign in

collin/anvil

1# anvil-worker image — LOCAL DEVELOPMENT ONLY.
2#
3# Production runners are native processes on their own host (a launchd agent on
4# the Mac mini, see ../../docs/remote-runners.md § Isolation on macOS). This
5# image exists so `compose.override.yaml` can bring up two runners next to the
6# local forge and exercise concurrency and platform routing without a second
7# machine. Do not deploy it: a containerized runner needs the host's Docker
8# socket mounted in, which is the root-equivalent hold moving CI off the forge
9# was meant to remove. That trade is already made locally — the dev compose
10# file mounts the same socket into anvil for agent sessions.
11#
12# Same shape as ../../Dockerfile: no compilation here, just a COPY of the
13# static x86_64-musl binary that `./deploy/build.sh --worker` stages.
14
15FROM ubuntu:26.04
16
17# ca-certificates so the claim loop can talk to an https:// forge. The local
18# one is plain http over the compose network, but the image should not be the
19# reason a runner cannot reach a real instance.
20RUN apt-get update \
21 && apt-get install -y --no-install-recommends ca-certificates \
22 && rm -rf /var/lib/apt/lists/* \
23 && useradd --system --user-group --home-dir /nonexistent worker
24
25COPY deploy/anvil-worker /usr/local/bin/anvil-worker
26
27# Unprivileged in the container; compose grants the docker group separately
28# (`group_add`), which is the only host access the runner needs.
29USER worker
30
31ENTRYPOINT ["/usr/local/bin/anvil-worker"]