diff --git a/Dockerfile b/Dockerfile index 4bf41000df..60e763b70d 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,13 @@ FROM node:22-bookworm -# Install Nginx to perform HTTP header rewriting inside the container -RUN apt-get update && apt-get install -y nginx-light && rm -rf /var/lib/apt/lists/* +# Install Nginx, DBus, and Gnome Keyring for headless OS credential storage +RUN apt-get update && apt-get install -y \ + nginx-light \ + dbus-x11 \ + gnome-keyring \ + libsecret-1-0 \ + libsecret-1-dev \ + && rm -rf /var/lib/apt/lists/* WORKDIR /app @@ -13,26 +19,40 @@ COPY . . RUN pnpm install RUN pnpm run build -# Create a default directory for workspaces -RUN mkdir -p /app/workspaces +# Create default directories +RUN mkdir -p /app/workspaces /root/.local/share/keyrings -# Configure Nginx to spoof Host, Origin, and Referer headers -RUN echo 'server { \ - listen 3080; \ - location / { \ - proxy_pass http://127.0.0.1:3081; \ - proxy_set_header Host 127.0.0.1:3081; \ - proxy_set_header Origin http://127.0.0.1:3081; \ - proxy_set_header Referer http://127.0.0.1:3081/; \ - proxy_set_header X-Real-IP 127.0.0.1; \ - proxy_set_header X-Forwarded-For 127.0.0.1; \ - proxy_http_version 1.1; \ - proxy_set_header Upgrade $http_upgrade; \ - proxy_set_header Connection "upgrade"; \ - } \ -}' > /etc/nginx/sites-available/default +# Configure Nginx proxy to force local spoofing behind Dokploy/Traefik +RUN cat << 'EOF' > /etc/nginx/sites-available/default +server { + listen 3080; + location / { + proxy_pass http://127.0.0.1:3081; + proxy_set_header Host 127.0.0.1:3081; + proxy_set_header Origin http://127.0.0.1:3081; + proxy_set_header Referer http://127.0.0.1:3081/; + proxy_set_header X-Real-IP 127.0.0.1; + proxy_set_header X-Forwarded-For 127.0.0.1; + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + } +} +EOF + +# Create startup script via Heredoc to prevent shell syntax errors +RUN cat << 'EOF' > /app/entrypoint.sh +#!/bin/bash +nginx +eval $(dbus-launch --sh-syntax) +export DBUS_SESSION_BUS_ADDRESS +eval $(echo "" | gnome-keyring-daemon --unlock --components=secrets) +export GNOME_KEYRING_CONTROL +exec node --import tsx/esm apps/cli/src/bin.ts web --port 3081 --no-open +EOF + +RUN chmod +x /app/entrypoint.sh EXPOSE 3080 -# Start Nginx and launch DeepSeek Harness -CMD nginx && node --import tsx/esm apps/cli/src/bin.ts web --port 3081 --no-open \ No newline at end of file +CMD ["/app/entrypoint.sh"] \ No newline at end of file