mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-09-30 01:51:20 +00:00
VS Code's Dev Containers extension auto-copies the host's gitconfig into the container at attach time using `(dd ...) >> /home/node/.gitconfig`. A read-only bind mount of ~/.gitconfig blocks that write, so attach failed with `cannot create /home/node/.gitconfig: Read-only file system`. Making it read-write would let the append succeed, but the bind mount means the host file and the container file are the same file — VS Code's append would double the host gitconfig contents on every container start. Drop the ~/.gitconfig bind mount entirely. VS Code's auto-copy is the purpose-built mechanism for this, gives the container the host's user.name / user.email transparently, and avoids both the read-only write failure and the append-duplication trap. The container ends up with a writable /home/node/.gitconfig that's a copy of the host's, not a mount. The remaining six bind mounts (.claude, .codex, .cursor, .ssh, .config/git, .config/gh) keep their existing modes — XDG-style git config under ~/.config/git is unaffected by VS Code's auto-copy (which only targets ~/.gitconfig), so its read-only bind mount stays. Also remove the `.gitconfig` touch from ensure-host-config-dirs.cjs (now unnecessary) and update the README CLI-state table, sharing explanation, and troubleshooting row to reflect that gitconfig flows in via VS Code auto-copy rather than the bind mount.
144 lines
6.5 KiB
JSON
144 lines
6.5 KiB
JSON
// Devcontainer for GitNexus. Pre-installs Claude Code, OpenAI Codex CLI,
|
|
// and Cursor CLI alongside the Node.js native build chain. Cross-platform
|
|
// across macOS, Linux, and Windows-via-WSL2 (Windows-native is unsupported
|
|
// — see .devcontainer/README.md § Windows 11 setup). Opens via the VS Code
|
|
// Dev Containers extension.
|
|
//
|
|
// First-time setup, auth flows, and troubleshooting: .devcontainer/README.md.
|
|
{
|
|
"name": "GitNexus AI CLI Devcontainer",
|
|
|
|
"build": {
|
|
"dockerfile": "Dockerfile",
|
|
"context": ".",
|
|
"args": {
|
|
"CLAUDE_CODE_VERSION": "2.1.153",
|
|
"CODEX_VERSION": "0.134.0",
|
|
"CURSOR_VERSION": "latest",
|
|
"TZ": "${localEnv:TZ:UTC}"
|
|
}
|
|
},
|
|
|
|
// Runs on the HOST (not the container) before container create. The
|
|
// single-string form is the spec-canonical shape for cross-platform
|
|
// command-property dispatch; the object form is "named parallel tasks",
|
|
// not OS dispatch. We use Node so the same command works in cmd.exe on
|
|
// Windows and bash/zsh on Linux/macOS/WSL — the script reads `os.homedir()`
|
|
// (which respects $HOME on POSIX and %USERPROFILE% on Windows) and creates
|
|
// the host-side bind mount sources idempotently. Host prerequisite: Node
|
|
// on PATH (the only host-side toolchain dependency beyond Docker Desktop
|
|
// and the VS Code Dev Containers extension).
|
|
"initializeCommand": "node .devcontainer/ensure-host-config-dirs.cjs",
|
|
|
|
"features": {
|
|
"ghcr.io/devcontainers/features/github-cli:1": {}
|
|
},
|
|
|
|
"remoteUser": "node",
|
|
"updateRemoteUserUID": true,
|
|
|
|
"workspaceMount": "source=${localWorkspaceFolder},target=/workspace,type=bind,consistency=delegated",
|
|
"workspaceFolder": "/workspace",
|
|
|
|
// Mount topology, by group:
|
|
//
|
|
// 1. CLI config dirs — bind-mounted from the host so the developer's
|
|
// existing plugins, skills, agents, memory, settings, and credentials
|
|
// for Claude Code / Codex / Cursor + git identity + gh auth are
|
|
// immediately available inside the container, and changes inside the
|
|
// container flow back to the host. ~/.gitconfig is read-only so
|
|
// container-side `git config --global` doesn't leak to host config.
|
|
// For high-trust environments where host and container should NOT
|
|
// share credentials, swap these three CLI bind mounts for
|
|
// per-devcontainer named volumes (Anthropic's reference pattern).
|
|
//
|
|
// 2. Per-instance state — `${devcontainerId}` scoped: history and npm
|
|
// cache survive container rebuilds but stay isolated between
|
|
// sibling devcontainer instances.
|
|
//
|
|
// 3. Per-workspace-name AND per-instance state — workspace `node_modules`
|
|
// volumes use both `${localWorkspaceFolderBasename}` (debuggable in
|
|
// `docker volume ls`) and `${devcontainerId}` (collision-free between
|
|
// sibling instances of the same repo, e.g., ~/work/GitNexus vs
|
|
// ~/projects/GitNexus). Keeps tree-sitter native binaries and
|
|
// onnxruntime off the workspace bind mount (the real Win/Mac perf win).
|
|
"mounts": [
|
|
"source=${localEnv:HOME}/.claude,target=/home/node/.claude,type=bind",
|
|
"source=${localEnv:HOME}/.codex,target=/home/node/.codex,type=bind",
|
|
"source=${localEnv:HOME}/.cursor,target=/home/node/.cursor,type=bind",
|
|
"source=${localEnv:HOME}/.config/git,target=/home/node/.config/git,type=bind,readonly",
|
|
"source=${localEnv:HOME}/.ssh,target=/home/node/.ssh,type=bind,readonly",
|
|
"source=${localEnv:HOME}/.config/gh,target=/home/node/.config/gh,type=bind",
|
|
"source=commandhistory-${devcontainerId},target=/commandhistory,type=volume",
|
|
"source=npm-cache-${devcontainerId},target=/home/node/.npm,type=volume",
|
|
"source=${localWorkspaceFolderBasename}-root-node-modules-${devcontainerId},target=/workspace/node_modules,type=volume",
|
|
"source=${localWorkspaceFolderBasename}-gitnexus-node-modules-${devcontainerId},target=/workspace/gitnexus/node_modules,type=volume",
|
|
"source=${localWorkspaceFolderBasename}-gitnexus-web-node-modules-${devcontainerId},target=/workspace/gitnexus-web/node_modules,type=volume",
|
|
"source=${localWorkspaceFolderBasename}-gitnexus-shared-node-modules-${devcontainerId},target=/workspace/gitnexus-shared/node_modules,type=volume"
|
|
],
|
|
|
|
// Interactive login is the default auth path for all three CLIs;
|
|
// credentials persist in the host-bind-mounted directories (~/.claude,
|
|
// ~/.codex, ~/.cursor) declared in the mounts block above.
|
|
// API keys (ANTHROPIC_API_KEY / OPENAI_API_KEY / CURSOR_API_KEY) are NOT
|
|
// injected via containerEnv — `${localEnv:VAR}` resolves an unset host var
|
|
// to an empty string, and Cursor in particular treats `CURSOR_API_KEY=""`
|
|
// as "use this empty key" rather than "fall back to stored login", which
|
|
// would silently break `cursor-agent login`. Users who need API key auth
|
|
// should `export` the var in their container shell or carry it via their
|
|
// VS Code dotfiles repo (see .devcontainer/README.md).
|
|
"containerEnv": {
|
|
"CLAUDE_CONFIG_DIR": "/home/node/.claude",
|
|
"DISABLE_AUTOUPDATER": "1",
|
|
"HISTFILE": "/commandhistory/.zsh_history"
|
|
},
|
|
|
|
"customizations": {
|
|
"vscode": {
|
|
"extensions": [
|
|
"anthropic.claude-code",
|
|
"dbaeumer.vscode-eslint",
|
|
"esbenp.prettier-vscode",
|
|
"eamodio.gitlens"
|
|
],
|
|
"settings": {
|
|
"editor.formatOnSave": true,
|
|
"editor.defaultFormatter": "esbenp.prettier-vscode",
|
|
"editor.codeActionsOnSave": {
|
|
"source.fixAll.eslint": "explicit"
|
|
},
|
|
"files.eol": "\n",
|
|
"terminal.integrated.defaultProfile.linux": "zsh",
|
|
"terminal.integrated.profiles.linux": {
|
|
"bash": { "path": "bash", "icon": "terminal-bash" },
|
|
"zsh": { "path": "zsh" }
|
|
}
|
|
}
|
|
}
|
|
},
|
|
|
|
// 4747 (gitnexus serve) must not be remapped: gitnexus-web hardcodes
|
|
// http://localhost:4747 as the default backend URL.
|
|
"forwardPorts": [5173, 4747, 4173],
|
|
"portsAttributes": {
|
|
"5173": {
|
|
"label": "Vite dev (gitnexus-web)",
|
|
"onAutoForward": "notify"
|
|
},
|
|
"4747": {
|
|
"label": "gitnexus serve HTTP API",
|
|
"onAutoForward": "notify",
|
|
"requireLocalPort": true
|
|
},
|
|
"4173": {
|
|
"label": "Static web (Vite preview)",
|
|
"onAutoForward": "silent"
|
|
}
|
|
},
|
|
|
|
// Driver script with labeled steps lives at .devcontainer/post-create.sh
|
|
// so each step's success/failure is visible in the log without parsing
|
|
// an &&-chain. Run via `bash` explicitly so the script doesn't depend
|
|
// on its executable bit surviving the workspace bind mount.
|
|
"postCreateCommand": "bash .devcontainer/post-create.sh"
|
|
}
|