- Install @openai/codex in Dockerfile.sandbox
- Pass developer_instructions via -c flag with proper shell escaping
- Use --yolo flag for sandbox profile (container is the sandbox)
- Mount ~/.codex into container via workmux extra_mounts config
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Change backend start command to use PORT= instead of --port flag and
cargo watch for auto-reload. Install cargo-watch in sandbox container.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The sqlx-cli install populates /opt/cargo/registry as root. Add
chmod -R a+rwX after the install so the sandbox user can write
to the registry when building.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Replace Debian's Node 18 with NodeSource Node 22. Run npm install and
generate-backend-client in the entrypoint so the frontend is ready.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The sandbox entrypoint now runs `sqlx migrate run` after creating the
database so that sqlx compile-time query checks work immediately. Also
makes /opt/cargo world-writable so arbitrary-UID sandbox users can write
to the cargo git cache and registry.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Start PostgreSQL (owned by postgres user) in entrypoint.sh with a unix
socket in /tmp so the agent can use DATABASE_URL=postgres:///windmill?host=/tmp
for sqlx migrations and cargo check.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add Dockerfile.sandbox with sudo, writable passwd/shadow, and
entrypoint that registers dynamic UIDs for full root access inside container
- Remove playwright MCP server (npx not available in sandbox)
- Move sandbox host_commands/image config to global workmux config
- Remove git from host_commands to prevent infinite fork bomb via shims
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>