Skip to content

feat(docker): the Harness images carry the GitHub CLI - #308

Closed
teemow wants to merge 4 commits into
giantswarmfrom
feat/harness-images-github-cli
Closed

teemow wants to merge 4 commits into
giantswarmfrom
feat/harness-images-github-cli

Conversation

@teemow

@teemow teemow commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Closes #288.

Problem

A coding agent in a workspace Session works in its clone with git and the provider's CLI. The Go runtime image (go/Dockerfile) and the Claude harness image (go/harness/claude/Dockerfile) carried git but not gh, so gh pr create, gh pr view or gh run list could not run in a Session's sandbox on either Harness.

Change

  • Both images install Alpine's github-cli at the version in go/github-cli.version, the one pin. The file is bind-mounted into the apk add step, so the Makefile, the CircleCI image jobs and a plain docker build all read it without copies. github-cli~<version> accepts any Alpine rebuild (-rN) of that version, so a package rebuild does not break the build.
  • The Claude harness image moves from alpine:3.22 to alpine:3.24, the release go/Dockerfile already uses. Alpine 3.22 ships gh 2.72.0 and 3.24 ships 2.97.0, so one pin needs one Alpine release.
  • No credential is baked in or configured: gh reads GH_TOKEN from its environment when one is given.
  • Renovate tracks the pin through one custom.regex manager (Alpine 3.24's github-cli from Repology). Every other manager stays off, as before on this line.
  • e2e TestSessionShellRunsGitAndGitHubCLI runs gh --version && git --version through the model's shell tool (bash on the kagent Harness, Bash on the Claude Harness) in a Session's sandbox. It asserts that the tool's output carries both versions.

go/Dockerfile also builds the controller image, which therefore carries gh too.

Overlap

Draft PRs #147 and #126 edit the same apk add line of go/Dockerfile. The conflict is textual only: whichever lands second rebases.

Image size

Measured with local linux/amd64 builds of this branch against its base, uncompressed (docker image inspect .Size):

Image Base This PR Growth
golang-adk (go/Dockerfile; the controller image grows the same way) 149.8 MB 194.9 MB +45.1 MB
claude-harness (go/harness/claude/Dockerfile, Alpine 3.22 → 3.24) 346.0 MB 391.6 MB +45.6 MB

Nearly all of the growth is the statically linked gh binary.

Acceptance criteria

  • gh --version and git --version succeed through the bash tool in a Session's sandbox on the kagent Harness and on the claude Harness. The fork e2e TestSessionShellRunsGitAndGitHubCLI passes on kagent and claude in the gVisor lane, which builds linux/amd64. On the kagent Harness the mock model answers only a tool result that contains gh version, and the test asserts both versions in the persisted tool response. linux/arm64 is checked on the published release candidate images (gh version 2.97.0, git version 2.54.0).
  • image-scan (scan-ok) is green for both images; the sizes are above.
  • The github-cli version is pinned once (go/github-cli.version) and Renovate (renovate.json5, one custom.regex manager, Repology alpine_3_24/github-cli) tracks it. renovate-config-validator --strict passes.
  • FORK.md row, queued upstream in the fork's upstream queue (row 159).

teemow added 2 commits October 9, 2026 14:09
A coding agent in a Session works in its clone with git and the
provider's CLI: it opens and reads pull requests and CI runs. The Go
runtime image and the Claude harness image carried git but not gh.

Both images now install Alpine's github-cli at the one version in
go/github-cli.version, bind-mounted into the apk step so the Makefile,
CI and a plain docker build read the same pin; apk's ~ accepts any
Alpine rebuild of that version. The Claude harness image moves to
alpine:3.24, the release go/Dockerfile already uses, so the pin
resolves in both. No credential is configured: gh reads GH_TOKEN from
its environment when one is given.

The e2e runs gh --version and git --version through the shell tool of
a Session on the kagent and the Claude harness.

Signed-off-by: Timo Derstappen <teemow@gmail.com>
Signed-off-by: Timo Derstappen <teemow@gmail.com>
@teemow
teemow marked this pull request as ready for review October 9, 2026 12:11
@teemow
teemow requested a review from a team as a code owner October 9, 2026 12:11
teemow added 2 commits October 9, 2026 14:37
…sted

Signed-off-by: Timo Derstappen <teemow@gmail.com>
Signed-off-by: Timo Derstappen <teemow@gmail.com>
@teemow

teemow commented Oct 9, 2026

Copy link
Copy Markdown
Member Author

Agent-written note: replaced by #312, the same change on the current base (this line never merges its base into a branch).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(docker): the Harness images carry the GitHub CLI

1 participant