Agents (10 new, total 13): - python-fastapi-expert — chat-gw / xiaoshou / CloudCost / kb-chat-python - nestjs-expert — gongdan backend - react-frontend-expert — xiaoshou/gongdan/casdoor web - mcp-tools-architect — chat-gw tool registry + auth pipeline - celery-worker-expert — CloudCost async tasks + beat - security-auditor — OWASP + secrets + auth (read-only) - test-engineer — coverage + flaky + e2e - ci-cd-engineer — 6 repos GitHub Actions - azure-aca-expert — ACA + Bicep + Key Vault - docs-writer — README / API / runbook Team orchestration commands: - /team-feature — brainstorm → architect → split → parallel impl → QA - /team-bug-fix — triage → RCA → fix → regression test → review - /team-refactor — scope → test-first → batch → verify Infrastructure: - Dockerfile: add Azure CLI (native apt package) - docker-compose.yml: mount ~/.azure and ~/.config/gh (read-only) - scripts/enter.sh: banner showing agents/commands on start - scripts/install-plugins.sh: helper to install superpowers/OMC/agent-browser Permissions (.claude/settings.json): - Full read access: az, gh, kubectl, psql SELECT, redis GET/KEYS/INFO - Controlled write: gh pr create/comment, git push origin (not main) - Hard deny: az */update|create|delete, gh pr merge, git push --force, alembic downgrade, kubectl apply/delete, sudo, rm -rf / Docs: - CLAUDE.md: new 'Agent 团队' + '权限模型' sections - README.md: full agent roster + permission summary Note: Dockerfile changed — run 'docker compose build' to install Azure CLI
62 lines
2.7 KiB
Docker
62 lines
2.7 KiB
Docker
FROM node:22-bookworm
|
|
|
|
ARG TARGETARCH
|
|
ARG GO_VERSION=1.25.0
|
|
|
|
ENV DEBIAN_FRONTEND=noninteractive \
|
|
PATH=/usr/local/go/bin:/root/go/bin:/root/.bun/bin:/root/.local/bin:$PATH \
|
|
PYTHONDONTWRITEBYTECODE=1 \
|
|
PIP_NO_CACHE_DIR=off \
|
|
PIP_DISABLE_PIP_VERSION_CHECK=on
|
|
|
|
# 换成清华 Debian 镜像(国内网络更稳)+ apt 重试策略
|
|
RUN sed -i 's|http://deb.debian.org|https://mirrors.tuna.tsinghua.edu.cn|g; s|http://security.debian.org|https://mirrors.tuna.tsinghua.edu.cn/debian-security|g' /etc/apt/sources.list.d/debian.sources \
|
|
&& echo 'Acquire::Retries "8";' > /etc/apt/apt.conf.d/80-retries \
|
|
&& echo 'Acquire::http::Timeout "60";' >> /etc/apt/apt.conf.d/80-retries \
|
|
&& echo 'Acquire::https::Timeout "60";' >> /etc/apt/apt.conf.d/80-retries
|
|
|
|
RUN apt-get update && apt-get install -y --no-install-recommends --fix-missing \
|
|
git curl ca-certificates gnupg lsb-release \
|
|
make build-essential \
|
|
python3 python3-pip python3-venv python3-dev \
|
|
postgresql-client redis-tools \
|
|
jq ripgrep fd-find less vim-tiny tini \
|
|
&& ln -s /usr/bin/fdfind /usr/local/bin/fd \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
RUN curl -fsSL "https://go.dev/dl/go${GO_VERSION}.linux-${TARGETARCH}.tar.gz" \
|
|
| tar -C /usr/local -xz
|
|
|
|
RUN curl -fsSL https://bun.sh/install | bash
|
|
|
|
RUN npm install -g pnpm@latest @anthropic-ai/claude-code
|
|
|
|
RUN curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg \
|
|
| dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg \
|
|
&& chmod go+r /usr/share/keyrings/githubcli-archive-keyring.gpg \
|
|
&& echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" \
|
|
> /etc/apt/sources.list.d/github-cli.list \
|
|
&& apt-get update && apt-get install -y --no-install-recommends gh \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# Azure CLI(用于 azure-aca-expert agent 的只读查询)
|
|
RUN curl -sL https://packages.microsoft.com/keys/microsoft.asc \
|
|
| gpg --dearmor | tee /etc/apt/trusted.gpg.d/microsoft.gpg > /dev/null \
|
|
&& AZ_REPO=$(lsb_release -cs) \
|
|
&& echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/trusted.gpg.d/microsoft.gpg] https://packages.microsoft.com/repos/azure-cli/ $AZ_REPO main" \
|
|
> /etc/apt/sources.list.d/azure-cli.list \
|
|
&& apt-get update && apt-get install -y --no-install-recommends azure-cli \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
RUN pip install --break-system-packages --no-cache-dir \
|
|
uv ruff black pytest pytest-asyncio httpx
|
|
|
|
RUN git config --system --add safe.directory '*' \
|
|
&& git config --system pull.rebase false \
|
|
&& git config --system init.defaultBranch main
|
|
|
|
WORKDIR /workspace
|
|
|
|
ENTRYPOINT ["/usr/bin/tini", "--"]
|
|
CMD ["claude"]
|