mirror of
https://github.com/tiennm99/composes.git
synced 2026-10-11 03:13:16 +00:00
The image installs python, gh, glab, build-essential, sudo, zsh and nano only; go or a jvm goes into $HOME from a terminal instead. SHELL and TZ are written into compose.yml rather than read from .env, so the deploying shell's own values can no longer win over them. The entrypoint calls chpasswd, chown and gosu by absolute path, tolerates a chpasswd failure instead of taking the start down with it, turns globbing off around the agent loop, and counts an agent as installed only when its binary actually runs.
36 lines
1.5 KiB
Bash
36 lines
1.5 KiB
Bash
# Copy to .env and fill in. Never commit .env.
|
|
#
|
|
# cp .env.example .env
|
|
|
|
# Password for the daemon API and web UI. Also the paseo user's login password,
|
|
# so it is what `sudo` asks for inside a terminal.
|
|
# Generate one with: openssl rand -base64 24
|
|
PASEO_PASSWORD=
|
|
|
|
# Comma-separated DNS names allowed to reach the daemon. The domain mapped in
|
|
# Coolify/Dokploy must be listed here. IPs and localhost are always allowed.
|
|
PASEO_HOSTNAMES=
|
|
|
|
# Proxy source IPs whose X-Forwarded-Proto the daemon trusts. Without this it
|
|
# trusts loopback only, reads the request as plain HTTP behind Coolify/Dokploy,
|
|
# and tells the web UI to open ws:// from an HTTPS page -- which browsers block.
|
|
# `uniquelocal` covers the private ranges Docker bridge networks use.
|
|
PASEO_TRUSTED_PROXIES=uniquelocal
|
|
|
|
# Agent CLIs to install on start, if not already present. Space- or
|
|
# comma-separated, from: claude codex opencode copilot omp pi. Leave empty to
|
|
# install none. The first start with a new paseo-home volume downloads a few
|
|
# hundred MB per agent and takes a while; later starts only check.
|
|
AGENTS=claude codex
|
|
|
|
# Git identity for agents and terminals, as author and committer. git reads
|
|
# these directly, so no `git config` step is needed.
|
|
GIT_NAME=
|
|
GIT_EMAIL=
|
|
|
|
# Container hostname, shown as the host label in the web UI. Without it the
|
|
# label is a random container ID. Also passed in as HOST -- the name zsh's
|
|
# prompt shows. Not named HOSTNAME: the deploying shell's own HOSTNAME would
|
|
# override it.
|
|
SERVICE_HOSTNAME=paseo
|