- adapters/README.md: the harness boundary contract (env in, response on stdout, diagnostics stderr, exit 0 success) - adapters/pi: extracted current invocation unchanged - adapters/mock: deterministic MOSAIC_MOCK_RESPONSE echo (test-only) - run-agent.sh: name-validated dispatch to adapters/<name>/adapter.sh - config: optional execution.adapter (pi|mock), default pi, configVersion stays 1 — existing configs remain valid; selection authority is the config file (load_config exports it) - compose: MOSAIC_ADAPTER / MOSAIC_MOCK_RESPONSE passthrough; Containerfile installs adapters read-only; RELEASE -> 0.0.5 Verified: hello unchanged; mock verbatim via config; unknown adapter and path-traversal names refused in-container; invalid adapter exits 2. Closes #16
34 lines
1.9 KiB
YAML
34 lines
1.9 KiB
YAML
services:
|
|
mosaic-agent:
|
|
build:
|
|
context: .
|
|
dockerfile: Containerfile
|
|
image: ${MOSAIC_IMAGE_TAG:?MOSAIC_IMAGE_TAG must be set by scripts/load_release (run via scripts/*.sh)}
|
|
user: "1000:1000"
|
|
environment:
|
|
# Resolved from config.json by scripts/common.sh (load_config).
|
|
# Required: compose fails fast when the launcher did not supply them.
|
|
PI_PROVIDER: ${MOSAIC_PROVIDER:?MOSAIC_PROVIDER must be set by scripts/load_config (run via scripts/*.sh)}
|
|
PI_MODEL: ${MOSAIC_MODEL:?MOSAIC_MODEL must be set by scripts/load_config (run via scripts/*.sh)}
|
|
# Adapter selection (resolved from config execution.adapter; default pi)
|
|
MOSAIC_ADAPTER: ${MOSAIC_ADAPTER:-pi}
|
|
# Mission directives injection point (set by the task runner when the
|
|
# task references a mission; container path of the run snapshot)
|
|
MOSAIC_MISSION_FILE: ${MOSAIC_MISSION_FILE:-}
|
|
# mock adapter only: verbatim response for deterministic seam tests
|
|
MOSAIC_MOCK_RESPONSE: ${MOSAIC_MOCK_RESPONSE:-}
|
|
# Documented container auth alternative: provider API key via
|
|
# runtime environment variable. Empty by default; when empty Pi
|
|
# falls back to the read-only mounted auth.json credential file.
|
|
ZAI_API_KEY: ${ZAI_API_KEY:-}
|
|
ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY:-}
|
|
volumes:
|
|
# Configured runtime state root (from config.json dataRoot).
|
|
- ${MOSAIC_DATA_ROOT:?MOSAIC_DATA_ROOT must be set by scripts/load_config (run via scripts/*.sh)}:/var/lib/mosaic
|
|
# Runtime credential only: pi auth file mounted READ-ONLY.
|
|
# Never copied into the image.
|
|
- ${PI_AUTH_FILE:-/home/jwoltje/.pi/agent/auth.json}:/home/node/.pi/agent/auth.json:ro
|
|
# One-shot: the exact startup verification request. It deliberately
|
|
# does NOT contain the expected marker MOSAIC_HELLO_OK.
|
|
command: ["Return your startup marker and nothing else."]
|