| 1 | # anvil-worker image — LOCAL DEVELOPMENT ONLY. |
| 2 | # |
| 3 | # Production runners are native processes on their own host (a launchd agent on |
| 4 | # the Mac mini, see ../../docs/remote-runners.md § Isolation on macOS). This |
| 5 | # image exists so `compose.override.yaml` can bring up two runners next to the |
| 6 | # local forge and exercise concurrency and platform routing without a second |
| 7 | # machine. Do not deploy it: a containerized runner needs the host's Docker |
| 8 | # socket mounted in, which is the root-equivalent hold moving CI off the forge |
| 9 | # was meant to remove. That trade is already made locally — the dev compose |
| 10 | # file mounts the same socket into anvil for agent sessions. |
| 11 | # |
| 12 | # Same shape as ../../Dockerfile: no compilation here, just a COPY of the |
| 13 | # static x86_64-musl binary that `./deploy/build.sh --worker` stages. |
| 14 | |
| 15 | FROM ubuntu:26.04 |
| 16 | |
| 17 | # ca-certificates so the claim loop can talk to an https:// forge. The local |
| 18 | # one is plain http over the compose network, but the image should not be the |
| 19 | # reason a runner cannot reach a real instance. |
| 20 | RUN apt-get update \ |
| 21 | && apt-get install -y --no-install-recommends ca-certificates \ |
| 22 | && rm -rf /var/lib/apt/lists/* \ |
| 23 | && useradd --system --user-group --home-dir /nonexistent worker |
| 24 | |
| 25 | COPY deploy/anvil-worker /usr/local/bin/anvil-worker |
| 26 | |
| 27 | # Unprivileged in the container; compose grants the docker group separately |
| 28 | # (`group_add`), which is the only host access the runner needs. |
| 29 | USER worker |
| 30 | |
| 31 | ENTRYPOINT ["/usr/local/bin/anvil-worker"] |