From cc1dd66ed7c1d24005adbb55a263a823f6d05b82 Mon Sep 17 00:00:00 2001 From: Serge Gatezh <2880401+gatezh@users.noreply.github.com> Date: Thu, 19 Mar 2026 13:25:04 -0600 Subject: [PATCH 1/2] fix(ci): iptables verify + add scheduled rebuilds for fresh Claude Code MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Use `which iptables` instead of `iptables --version` in sandbox verification — nftables backend can't initialize without kernel module in unprivileged Docker on GHA runners - Add weekly schedule (Monday 6am UTC) with no-cache to pick up latest Claude Code and other tool updates Co-Authored-By: Claude Opus 4.6 (1M context) --- .github/workflows/build-claude-code.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/build-claude-code.yml b/.github/workflows/build-claude-code.yml index 7fd1ad4..6c4c7e4 100644 --- a/.github/workflows/build-claude-code.yml +++ b/.github/workflows/build-claude-code.yml @@ -5,6 +5,8 @@ on: branches: [master] paths: - "claude-code/.devcontainer/Dockerfile" + schedule: + - cron: '0 6 * * 1' workflow_dispatch: permissions: @@ -32,7 +34,7 @@ jobs: verify-command: "bun --version || true && claude --version && mise --version && fish --version" - target: sandbox image-suffix: claude-code-sandbox - verify-command: "claude --version && mise --version && fish --version && iptables --version" + verify-command: "claude --version && mise --version && fish --version && which iptables" steps: - uses: actions/checkout@v6 @@ -74,6 +76,7 @@ jobs: push: true tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }} + no-cache: ${{ github.event_name != 'push' }} cache-from: type=gha,scope=${{ matrix.target }} cache-to: type=gha,mode=max,scope=${{ matrix.target }} From 9b36c3e449d28bdac41c0904f953740e14a8dd99 Mon Sep 17 00:00:00 2001 From: Serge Gatezh <2880401+gatezh@users.noreply.github.com> Date: Thu, 19 Mar 2026 13:30:38 -0600 Subject: [PATCH 2/2] fix(ci): daily rebuilds + docs update - Schedule daily rebuild at 5am MT (11:00 UTC) with no-cache to pick up latest Claude Code and tool updates - Fix sandbox verify: use `which iptables` (nftables needs kernel module) - Update README: Playwright version, auto-rebuild docs, init-plugins wiring instructions Co-Authored-By: Claude Opus 4.6 (1M context) --- .github/workflows/build-claude-code.yml | 2 +- claude-code/README.md | 13 +++++++++++-- 2 files changed, 12 insertions(+), 3 deletions(-) diff --git a/.github/workflows/build-claude-code.yml b/.github/workflows/build-claude-code.yml index 6c4c7e4..0c73250 100644 --- a/.github/workflows/build-claude-code.yml +++ b/.github/workflows/build-claude-code.yml @@ -6,7 +6,7 @@ on: paths: - "claude-code/.devcontainer/Dockerfile" schedule: - - cron: '0 6 * * 1' + - cron: '0 11 * * *' workflow_dispatch: permissions: diff --git a/claude-code/README.md b/claude-code/README.md index a4522bc..44040ac 100644 --- a/claude-code/README.md +++ b/claude-code/README.md @@ -38,6 +38,10 @@ Both variants are built for: - `:` — pinned to a specific commit - `:` — date-based tag (e.g., `20260319`) +## Automatic Rebuilds + +The image rebuilds daily at 5am MT (11:00 UTC) with no Docker cache, picking up the latest Claude Code, Playwright, and other tools. Manual rebuilds can be triggered via the "Run workflow" button in the Actions UI. + ## Quick Start ### Default variant @@ -125,6 +129,11 @@ node = "22" ### Optional: `.devcontainer/init-plugins.sh` Claude Code plugin initialization. Runs once at container creation. Idempotent. +Wire it into `postCreateCommand` in your `devcontainer.json`: + +```jsonc +"postCreateCommand": "bash .devcontainer/init-plugins.sh" +``` ```bash #!/bin/bash @@ -204,7 +213,7 @@ If your project has additional services, create volume mounts in `devcontainer.j ## Playwright Version Strategy -The image bakes in a Playwright browser binary at a specific version (controlled by the `PLAYWRIGHT_VERSION` build arg). +The image bakes in a Playwright browser binary at a specific version (controlled by the `PLAYWRIGHT_VERSION` build arg). Daily rebuilds keep this reasonably current. - If your project's `@playwright/test` version **matches** the image — zero startup cost, browser is ready - If your project's version **differs** — Playwright auto-downloads the correct browser on first test run (~10s graceful fallback) @@ -215,7 +224,7 @@ The image bakes in a Playwright browser binary at a specific version (controlled | Arg | Default | Description | |-----|---------|-------------| | `GIT_DELTA_VERSION` | `0.18.2` | git-delta version | -| `PLAYWRIGHT_VERSION` | `1.50.1` | Playwright browser binary version | +| `PLAYWRIGHT_VERSION` | `1.58.2` | Playwright browser binary version | | `AGENT_BROWSER_VERSION` | `0.14.0` | agent-browser version (default target only) | ## Building Locally