Repository navigation
feat(ralphex-fe): rebuild from Alpine to Debian - #45
Merged
Merged
Conversation
- Without bun install, npx playwright fails due to npm 11 cache key mismatch between versioned build-time and unversioned runtime lookups Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- updateRemoteUserUID, otherPortsAttributes (silent auto-forward) - editor.formatOnSave + OXC default formatter with customization guide - window.title for multi-window distinction, NODE_OPTIONS 4GB heap - Sandbox: Claude Dark theme, coral status bar, skip permissions - Plugins: frontend-design, typescript-lsp, playwright, posthog - Firewall: allow OpenAI domains (auth, api, chatgpt) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Slim CLAUDE.md from 290 to 39 lines (core rules only) - Add .claude/rules/ with path-scoped files: dockerfile, devcontainer, workflows, new-image - Fix stale references: Biome→OXC, zsh→fish, remove AGENTS.md symlink mentions - Remove derivable content (directory tree, README patterns) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
init.sh adapted from umputun/baseimage for Debian (gosu, groupadd/groupdel). init-docker.sh copied from umputun/ralphex (credential copying from mounts). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…rixie-slim) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Drop RALPHEX_VERSION extraction (binary fetched as latest at build time) - Add ralphex-fe/files/** to trigger paths - Update verify commands for Debian (app user, Playwright cache, init scripts) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Add docker.io package (needed for wrapper's --docker flag) - Add fzf (fuzzy finder, matches official ralphex image) - Add SHELL pipefail for Bun curl|bash install (Docker best practice) - Upgrade actions/checkout to v6 Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- useradd --no-log-init prevents large sparse log files (Docker best practice) - Ralphex download separated from tar extraction to avoid masked curl failures in pipeless /bin/sh context Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- DL3002 (last USER not root): ralphex-fe entrypoint runs as root for APP_UID remapping, then drops to app user via gosu - DL3016 (pin npm versions): Claude Code intentionally unpinned — images rebuild daily to always get latest Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
docker.io package creates a docker group during installation. Use groupadd -f (idempotent) + groupmod to ensure GID 999. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- actions/checkout: v4 → v6 - docker/setup-qemu-action: v3 → v4 - docker/setup-buildx-action: v3 → v4 - docker/build-push-action: v5 → v7 Resolves Node.js 20 deprecation warnings. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
… platforms Replace sequential QEMU-based build with docker/github-builder which builds amd64 and arm64 in parallel on native runners. Verification runs on native runners (ubuntu-24.04 + ubuntu-24.04-arm). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Resolves Node.js 20 deprecation warning. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…downloads - Docker CLI: static binary from download.docker.com instead of docker.io package (avoids containerd, runc, iptables — ~55MB of unneeded deps) - Go: direct binary from go.dev/dl/ instead of apt golang-go (avoids ~200MB of Go source + build deps via apt) Both match the patterns used in the official ralphex images. End result is identical: same Go version, same Docker CLI functionality. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Dockerfile: restructured as multi-stage build — Go, Docker CLI, Hugo, and Ralphex binaries download in parallel stages (BuildKit runs independent stages concurrently). Final stage COPY --from each. CI: dropped arm64 QEMU build and QEMU setup step. arm64 is tested on native runners at merge time via docker/github-builder — no need to emulate it in pre-merge CI. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…p wget - Playwright: install only Chromium headless shell (was installing Firefox + WebKit too). This image is for headless Claude Code testing only. - apt-get: use --mount=type=cache for /var/cache/apt and /var/lib/apt/lists (Docker best practice — avoids re-downloading on layer rebuild) - npm: use --mount=type=cache for /root/.npm - Remove wget from final stage (Hugo downloads in parallel stage now) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Rebuild the
ralphex-festandalone Docker image fromnode:24-trixie-slim(Debian) instead of the Alpine-basedghcr.io/umputun/ralphexbase image, eliminating all Alpine/musl compatibility hacks while maintaining full compatibility with theralphex-dk.shdocker-wrapper script.Why
The previous Alpine-based image required painful workarounds:
gcompatshim for Hugo Extended (glibc binary on musl)PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD+ manual system Chromium +executablePathwiring (Playwright's bundled browser doesn't work on Alpine/musl)apkpackage ecosystemOn Debian, all tools work natively with zero compatibility hacks.
Changes
Core: ralphex-fe Dockerfile rewrite
node:24-trixie-slim(Debian) instead ofghcr.io/umputun/ralphex(Alpine)files/init.sh— adapted from umputun/baseimage for Debian (gosuinstead ofsu-exec,groupadd/groupdelinstead ofaddgroup/delgroup)files/init-docker.sh— from umputun/ralphex (handles~/.claudeand~/.codexmounts)appwith UID 1001, matching ralphex wrapper expectations (remappable viaAPP_UIDenv var)gcompat, system Chromium,ttf-freefont(no longer needed)PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD,PLAYWRIGHT_CHROMIUM_EXECUTABLE_PATH(Alpine-only hacks)Build optimizations
go.dev/dl/instead ofapt golang-go(matches ralphex-go pattern)download.docker.cominstead ofdocker.iopackage (avoids containerd, runc, iptables — matches ralphex base'sdocker-cli)SHELLpipefail forcurl|bash,useradd --no-log-init, download-then-extract (nocurl|tarpipes), consolidatedLABELBuild workflow: migrated to
docker/github-builderubuntu-24.04+ubuntu-24.04-arm)reusable-docker-build.ymldependencyCI improvements
actions/checkout@v6,docker/*@v4/v7,dorny/paths-filter@v4DL3002andDL3016to hadolint ignores (intentional: entrypoint handles privilege drop; Claude Code intentionally unpinned).claude/CLAUDE.mdDocumentation
docs/superpowers/plans/2026-03-23-ralphex-fe-debian-rebuild.mdHousekeeping (earlier commits on this branch)
.claude/CLAUDE.mdinto path-scoped rules under.claude/rules/bun installin sandboxpostCreateCommandVerified
🤖 Generated with Claude Code