forked from 0xcaff/codex-web
-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathDockerfile
More file actions
146 lines (128 loc) · 4.44 KB
/
Copy pathDockerfile
File metadata and controls
146 lines (128 loc) · 4.44 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
# syntax=docker/dockerfile:1.7
ARG NODE_IMAGE=node:22-bookworm-slim
FROM ${NODE_IMAGE} AS builder
ARG CODEX_APP_VERSION=26.818.61809
ENV NODE_ENV=production
RUN apt-get update \
&& apt-get install -y --no-install-recommends \
ca-certificates \
curl \
g++ \
make \
patch \
python3 \
unzip \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /app
COPY package.json package-lock.json ./
RUN npm ci --include=dev --ignore-scripts \
&& npm rebuild better-sqlite3 node-pty
COPY assets/ ./assets/
COPY patches/ ./patches/
COPY scripts/enable_linux_remote_control_keys.mjs ./scripts/enable_linux_remote_control_keys.mjs
COPY scripts/remove_upstream_csp.mjs ./scripts/remove_upstream_csp.mjs
COPY scripts/prepare_asar ./scripts/prepare_asar
COPY scripts/smoke_test_terminal_pty.mjs ./scripts/smoke_test_terminal_pty.mjs
COPY src/ ./src/
COPY vite.browser.config.ts ./
RUN curl --fail --location --retry 3 --retry-delay 2 \
--output /tmp/codex-app.zip \
"https://persistent.oaistatic.com/codex-app-prod/ChatGPT-darwin-arm64-${CODEX_APP_VERSION}.zip" \
&& HOSTED_CODEX_APP_ZIP=/tmp/codex-app.zip npm run build \
&& node scripts/smoke_test_terminal_pty.mjs \
&& rm -rf /tmp/codex-app.zip scratch/ChatGPT.app \
&& npm prune --omit=dev --ignore-scripts \
&& chmod -R a+rX /app
FROM ${NODE_IMAGE} AS runtime
ARG CODEX_VERSION=0.149.1
ARG GCLOUD_VERSION=578.0.0-0
ARG GH_VERSION=2.98.0
RUN apt-get update \
&& apt-get install -y --no-install-recommends \
ca-certificates \
curl \
gnupg \
&& install -d -m 755 /etc/apt/keyrings \
&& curl --fail --silent --show-error --location \
https://packages.cloud.google.com/apt/doc/apt-key.gpg \
| gpg --dearmor -o /etc/apt/keyrings/cloud.google.gpg \
&& curl --fail --silent --show-error --location \
--output /etc/apt/keyrings/githubcli-archive-keyring.gpg \
https://cli.github.com/packages/githubcli-archive-keyring.gpg \
&& chmod a+r \
/etc/apt/keyrings/cloud.google.gpg \
/etc/apt/keyrings/githubcli-archive-keyring.gpg \
&& printf '%s\n' \
'deb [signed-by=/etc/apt/keyrings/cloud.google.gpg] https://packages.cloud.google.com/apt cloud-sdk main' \
> /etc/apt/sources.list.d/google-cloud-sdk.list \
&& printf '%s\n' \
"deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" \
> /etc/apt/sources.list.d/github-cli.list \
&& apt-get update \
&& apt-get install -y --no-install-recommends \
build-essential \
fd-find \
file \
gh="${GH_VERSION}" \
git \
git-lfs \
google-cloud-cli="${GCLOUD_VERSION}" \
iproute2 \
iputils-ping \
jq \
less \
lsof \
nano \
netcat-openbsd \
openssh-client \
pkg-config \
procps \
psmisc \
python-is-python3 \
python3 \
python3-dev \
python3-pip \
python3-venv \
ripgrep \
rsync \
sqlite3 \
tini \
tree \
unzip \
xz-utils \
zip \
&& npm install --global "@openai/codex@${CODEX_VERSION}" \
&& ln -s /usr/bin/fdfind /usr/local/bin/fd \
&& git lfs install --system --skip-repo \
&& useradd --create-home --shell /bin/bash --uid 10001 codex \
&& install -d -o codex -g codex -m 700 \
/data \
/home/codex/.ssh \
/run/secrets/codex-ssh \
&& rm -rf /var/lib/apt/lists/* /root/.npm
WORKDIR /app
COPY --from=builder /app /app
COPY docker/entrypoint.sh /usr/local/bin/codex-web-entrypoint
COPY docker/oauth-callback-bridge.mjs /usr/local/lib/codex-web/oauth-callback-bridge.mjs
COPY docker/state-sync.mjs /usr/local/lib/codex-web/state-sync.mjs
RUN chmod 0755 /usr/local/bin/codex-web-entrypoint \
&& chmod 0644 \
/usr/local/lib/codex-web/oauth-callback-bridge.mjs \
/usr/local/lib/codex-web/state-sync.mjs
ENV CODEX_CLI_PATH=/usr/local/bin/codex \
CODEX_HOME=/data/codex \
CODEX_SSH_SOURCE_DIR=/run/secrets/codex-ssh \
CODEX_WEB_OAUTH_CALLBACK_BRIDGE=1 \
CODEX_WEB_OAUTH_CALLBACK_PORTS=1455,1457 \
CODEX_WEB_SOFTWARE_DEVICE_KEYS=1 \
CODEX_WEB_DATA_DIR=/data \
CODEX_WEB_HOST=0.0.0.0 \
HOME=/home/codex \
NODE_ENV=production \
PORT=8080
USER codex
EXPOSE 8080 1455 1457
VOLUME ["/data"]
HEALTHCHECK --interval=15s --timeout=5s --start-period=30s --retries=4 \
CMD ["node", "-e", "fetch('http://127.0.0.1:' + (process.env.PORT || '8080') + '/__backend/healthz').then(r => { if (!r.ok) process.exit(1) }).catch(() => process.exit(1))"]
ENTRYPOINT ["/usr/bin/tini", "--", "/usr/local/bin/codex-web-entrypoint"]