cb2d778a8f
Sweep for vestiges of the old combined-plane model and the pre-split shared rootfs. Two are load-bearing, the rest are stale docs/comments: - Bug: macOS `enumerate_active` only excluded the gateway container from the agent list, so after the split the orchestrator container (`bot-bottle-mac-orchestrator`, also `bot-bottle-`-prefixed) was enumerated as a phantom agent. Exclude both infra containers; test covers it. - Dead code: the gateway `bootstrap.py` still carried an `orchestrator` daemon spec + `_OPT_IN_DAEMONS` + a signing-key/JWT env branch, all for the old combined container where the gateway process could also run the control plane. No backend ever requests it now — removed; the key-stripping stays as defense-in-depth. Stale-comment reframes: "the/single infra container" -> the orchestrator + gateway pair (or the specific plane); "shared rootfs / bb_role init / one published rootfs" -> the per-plane rootfs + `role_init`; the deleted Dockerfile.infra references in Dockerfile.orchestrator/.gateway; and the macOS "one infra container ... same address" docstring + its now-false share-one-address test (the planes are distinct containers with distinct addresses). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
35 lines
1.7 KiB
Docker
35 lines
1.7 KiB
Docker
# Orchestrator control-plane image (PRD 0070, #384).
|
|
#
|
|
# This is the **single definition of the orchestrator's content** — the
|
|
# `bot_bottle` package baked onto a Python runtime — referenced by BOTH:
|
|
# * the docker backend, which runs this image directly as the lean
|
|
# control-plane container; and
|
|
# * the firecracker orchestrator VM image (Dockerfile.orchestrator.fc),
|
|
# which is `FROM` this image and adds buildah for in-VM agent builds.
|
|
# Keeping the content in one place means future orchestrator deps (e.g.
|
|
# iroh) are added here once, not duplicated per backend.
|
|
#
|
|
# It stays deliberately lean: the control plane is **stdlib-only** today, so
|
|
# no third-party payload — none of the gateway's mitmproxy/git/gitleaks
|
|
# (that's Dockerfile.gateway) and no buildah (that's the firecracker
|
|
# builder, and lives only in Dockerfile.orchestrator.fc). Keeping the
|
|
# secret-dense control plane on a minimal dependency surface is the point
|
|
# (PRD 0070's "secret concentration").
|
|
#
|
|
# Shares the trixie `python:3.12-slim` base with the gateway image.
|
|
|
|
FROM python:3.12-slim
|
|
|
|
WORKDIR /app
|
|
|
|
# The orchestrator content. Baked so the image is self-contained (runs from
|
|
# a built image, no runtime bind-mount); the docker backend may still
|
|
# bind-mount /app for dev live-reload, which simply overlays this copy.
|
|
# `.dockerignore` keeps .git/docs/*.md out of the context. (Future deps like
|
|
# iroh go here too — a shared requirements installed on this same base.)
|
|
COPY bot_bottle /app/bot_bottle
|
|
|
|
# Documentation only; lifecycle.py overrides the entrypoint to
|
|
# `python3 -m bot_bottle.orchestrator` with the runtime flags.
|
|
ENTRYPOINT ["python3", "-m", "bot_bottle.orchestrator"]
|