From 3ef3643f648d6d6d689468742ce868f602c1a232 Mon Sep 17 00:00:00 2001 From: Pi Web Agent Date: Thu, 25 Jun 2026 19:46:24 +0000 Subject: [PATCH] fix(docker): include compose and persist home --- .changeset/docker-compose-home.md | 5 +++++ README.md | 21 --------------------- docker/Dockerfile | 1 + docker/Dockerfile.dev | 1 + docker/README.md | 6 ++++-- docker/bin/install-opensuse-base | 10 ++++++---- 6 files changed, 17 insertions(+), 27 deletions(-) create mode 100644 .changeset/docker-compose-home.md diff --git a/.changeset/docker-compose-home.md b/.changeset/docker-compose-home.md new file mode 100644 index 0000000..31d89d7 --- /dev/null +++ b/.changeset/docker-compose-home.md @@ -0,0 +1,5 @@ +--- +"@jmfederico/pi-web": patch +--- + +Keep the Docker setup documented as beta-only, include Docker Compose/Buildx in the container images, and make the container user's home persist under `/data/home`. diff --git a/README.md b/README.md index dba168a..c1b2f30 100644 --- a/README.md +++ b/README.md @@ -72,16 +72,6 @@ Common alternatives: curl -fsSL https://raw.githubusercontent.com/jmfederico/pi-web/main/install.sh | sh ``` -For trusted local/server installs, PI WEB also has a Docker local-build runtime: - -```bash -curl -fsSL https://raw.githubusercontent.com/jmfederico/pi-web/main/docker/install.sh | sh -``` - -The Docker setup builds an openSUSE Tumbleweed based local image from npm, runs split `sessiond` and `web` services, and binds the browser UI to `127.0.0.1:8504` by default. It intentionally mounts the Docker socket and selected host paths; treat it as root-equivalent host access and use an SSH tunnel, VPN, or authenticated reverse proxy for remote access. - -See the [Docker guide](https://github.com/jmfederico/pi-web/blob/main/docker/README.md) for trust warnings, version pinning, package customization, host command examples, and development Compose usage. - PI WEB is also published as a Pi package: ```bash @@ -183,17 +173,6 @@ pi-web install --dev `dev:web` also watches bundled plugin TypeScript and rebuilds the browser-loaded plugin JavaScript under `dist/pi-web-plugins/`. You can restart `dev:web` or `dev:client` without stopping active Pi sessions. -Docker development from the checkout is available too: - -```bash -export PI_WEB_UID=$(id -u) -export PI_WEB_GID=$(id -g) -export DOCKER_GID=$(stat -c '%g' /var/run/docker.sock) -docker compose -f docker/compose.dev.yml up --build -``` - -Open . The Docker dev setup keeps `sessiond` separate from the autoreloading web/API/client service and uses the runtime Docker data directory by default so sessions can be shared across modes. See the [Docker guide](https://github.com/jmfederico/pi-web/blob/main/docker/README.md#development-docker-setup). - For a production-style run from a checkout: ```bash diff --git a/docker/Dockerfile b/docker/Dockerfile index bb2b80a..41a802d 100644 --- a/docker/Dockerfile +++ b/docker/Dockerfile @@ -54,6 +54,7 @@ ENV NODE_ENV=production \ COPY --from=package /usr/local/lib/node_modules /usr/local/lib/node_modules COPY --from=package /usr/local/bin /usr/local/bin COPY --from=docker-cli /usr/local/bin/docker /usr/local/bin/docker +COPY --from=docker-cli /usr/local/libexec/docker/cli-plugins /usr/local/libexec/docker/cli-plugins COPY bin/hostexec /usr/local/bin/hostexec RUN chmod 0755 /usr/local/bin/hostexec diff --git a/docker/Dockerfile.dev b/docker/Dockerfile.dev index f5eda36..a352a2d 100644 --- a/docker/Dockerfile.dev +++ b/docker/Dockerfile.dev @@ -43,6 +43,7 @@ RUN npm ci \ && chmod 0777 /workspace COPY --from=docker-cli /usr/local/bin/docker /usr/local/bin/docker +COPY --from=docker-cli /usr/local/libexec/docker/cli-plugins /usr/local/libexec/docker/cli-plugins COPY docker/bin/hostexec /usr/local/bin/hostexec RUN chmod 0755 /usr/local/bin/hostexec diff --git a/docker/README.md b/docker/README.md index fd9cd75..22e75d8 100644 --- a/docker/README.md +++ b/docker/README.md @@ -1,4 +1,6 @@ -# PI WEB Docker +# PI WEB Docker (beta) + +This Docker setup is beta. It is useful for trusted local/server testing and development, but it may still have rough edges and is intentionally documented only here for now. PI WEB has two Docker modes: @@ -108,7 +110,7 @@ Host-derived IDs are refreshed on rerun unless you explicitly override them. Use ### Base image and tooling -The Docker runtime and development images are openSUSE Tumbleweed based by default. They install Node.js 22, npm, `npx`, and Corepack through zypper, using the openSUSE Node.js build service repository when needed for the selected architecture. The image's `pi-web` account is created with `PI_WEB_UID:PI_WEB_GID`, so shells have a passwd entry instead of showing `I have no name!` when the host user is not `1000:1000`. The image also includes common agent/development tools such as Git/Git LFS, GitHub CLI, OpenSSH, Python with pip/virtualenv and headers, native build tooling, `jq`, `ripgrep`, `fd`, `fzf`, `bat`, ShellCheck, archive tools, network utilities, and the Docker CLI. +The Docker runtime and development images are openSUSE Tumbleweed based by default. They install Node.js 22, npm, `npx`, and Corepack through zypper, using the openSUSE Node.js build service repository when needed for the selected architecture. The image's `pi-web` account is created with `PI_WEB_UID:PI_WEB_GID` and `/data/home` as its home directory, so shells have a passwd entry instead of showing `I have no name!` while user config stays in the persistent `/data` mount. The image also includes common agent/development tools such as Git/Git LFS, GitHub CLI, OpenSSH, Python with pip/virtualenv and headers, native build tooling, `jq`, `ripgrep`, `fd`, `fzf`, `bat`, ShellCheck, archive tools, network utilities, and the Docker CLI with Compose and Buildx plugins. Install extra distro packages without writing a hook by setting a whitespace-delimited package list: diff --git a/docker/bin/install-opensuse-base b/docker/bin/install-opensuse-base index fdfb888..94acd17 100755 --- a/docker/bin/install-opensuse-base +++ b/docker/bin/install-opensuse-base @@ -138,6 +138,9 @@ esac runtime_user=pi-web runtime_group=pi-web +runtime_home=/data/home +mkdir -p "$runtime_home" /data/config /data/npm-cache /data/pi-web /data/pi-agent /workspace + if getent group "$runtime_gid" >/dev/null 2>&1; then runtime_group=$(getent group "$runtime_gid" | cut -d: -f1) elif getent group "$runtime_group" >/dev/null 2>&1; then @@ -147,13 +150,12 @@ else fi if id "$runtime_user" >/dev/null 2>&1; then - usermod --non-unique --uid "$runtime_uid" --gid "$runtime_group" --home "/home/$runtime_user" --shell /bin/bash "$runtime_user" + usermod --non-unique --uid "$runtime_uid" --gid "$runtime_group" --home "$runtime_home" --shell /bin/bash "$runtime_user" else - useradd --non-unique --uid "$runtime_uid" --gid "$runtime_group" --create-home --home-dir "/home/$runtime_user" --shell /bin/bash "$runtime_user" + useradd --non-unique --uid "$runtime_uid" --gid "$runtime_group" --no-create-home --home-dir "$runtime_home" --shell /bin/bash "$runtime_user" fi -mkdir -p /data/home /data/config /data/npm-cache /data/pi-web /data/pi-agent /workspace "/home/$runtime_user" -chown -R "$runtime_uid:$runtime_gid" /data /workspace "/home/$runtime_user" +chown -R "$runtime_uid:$runtime_gid" /data /workspace zypper clean --all rm -rf /var/cache/zypp/*