anvilsign in

collin/anvil

1# anvil-worker image — LOCAL DEVELOPMENT ONLY.
2#
3# Production runners are native processes on their own host (a launchd agent on
4# the Mac mini, see ../../docs/remote-runners.md § Isolation on macOS; the
5# plist for it stays in deploy/worker/, which is not a Docker artifact). This
6# image exists so `compose.override.yaml` can bring up two runners next to the
7# local forge and exercise concurrency and platform routing without a second
8# machine. Do not deploy it: a containerized runner needs the host's Docker
9# socket mounted in, which is the root-equivalent hold moving CI off the forge
10# was meant to remove. That trade is already made locally — the dev compose
11# file mounts the same socket into anvil for agent sessions.
12#
13# Same shape as ../anvil/Dockerfile: no compilation here, just a COPY of the
14# static x86_64-musl binary that `./deploy/build.sh --worker` stages.
15
16FROM ubuntu:26.04
17
18# ca-certificates so the claim loop can talk to an https:// forge. The local
19# one is plain http over the compose network, but the image should not be the
20# reason a runner cannot reach a real instance.
21RUN apt-get update \
22 && apt-get install -y --no-install-recommends ca-certificates \
23 && rm -rf /var/lib/apt/lists/* \
24 && useradd --system --user-group --home-dir /nonexistent worker
25
26COPY docker/worker/anvil-worker /usr/local/bin/anvil-worker
27
28# Unprivileged in the container; compose grants the docker group separately
29# (`group_add`), which is the only host access the runner needs.
30USER worker
31
32ENTRYPOINT ["/usr/local/bin/anvil-worker"]