OpenCode as a mixin -- node and the CLI in an overlay, with seven optional proxy-managed provider...
187
OpenCode as a mixin -- node and the CLI in an overlay, with seven optional proxy-managed provider credentials, the MCP registration and the Copilot seed. Layer it onto a shell base and run `opencode`.
| Name | Required | Default | Description |
|---|---|---|---|
version | Optional | 1.18.31 | OpenCode release to install |
[email protected]| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/credential@1 | Optional | Anthropic API access | |
com.docker.sandbox/credential@1 | Optional | GitHub and Copilot access | |
com.docker.sandbox/credential@1 | Optional | Google AI API access | |
com.docker.sandbox/credential@1 | Optional | Groq API access | |
com.docker.sandbox/credential@1 | Optional | OpenAI API access (API key or ChatGPT OAuth) | |
com.docker.sandbox/credential@1 | Optional | OpenRouter API access | |
com.docker.sandbox/credential@1 | Optional | xAI API access | |
com.docker.sandbox/lifecycle@1 | Required | — | |
com.docker.sandbox/agent-context@1 | Required | — | |
deb/jq, deb/util-linuxsbx run <agent> --kit docker/sbx-kit-opencode-mixin:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxNote
Experimental: Sandbox Kit v3This kit uses the experimental Sandbox Kit specification, specifically v3. The format and runtime behavior may change before v3 is stable.
OpenCode as a mixin — the same agent as
the opencode workload kit, packaged as an overlay you layer
onto a shell base instead of running as the sandbox's own image.
sbx run --kit ./opencode-mixin/ <shell-workload>
Or from a git URL targeting this repo:
sbx run --kit "git+https://github.com/docker/sbx-kits-contrib.git#dir=opencode-mixin" <shell-workload>
The base workload keeps its own launch command, so nothing starts the agent for you:
opencode
opencode run "explain this repo"
The OpenCode release is pinned by the kit's version arg, which the descriptor
hands to the recipe as OPENCODE_VERSION and also expands into
provides: ["opencode@<version>"] — so the kit advertises the release it
installs. Move it with --build-arg version=1.2.3 (npm semver, no leading
v), and keep it equal to ../opencode's default.
opencode-ai, installed with npm install -g --prefix /opt/opencode on the
same base the workload uses, plus that base's node and a launcher shim on
PATH. Unlike this repo's other agent mixins the install relocates cleanly,
so the overlay does not have to reproduce a tree at the path it was built at
— but the build stage stays on the workload's base, because that is where the
corepack hazard is real and where the --version gate means something.apt-get update hook. Those refresh the base
image's own package sources; a workload owns its base, a mixin does not.jq and flock, which the Copilot seed hook shells out to. Every
sandbox-templates base ships both; the hook exits without seeding rather than
failing if it cannot build the seed.filename: is workload-only; this kit
contributes a body through contentFile.sbx@1. A mixin's image config does not become the composed image's.Neither agent-sessions@1 nor agent-skills@1, matching the workload: the v2
TCK data omitted promptArgs because no provider credential exists on the
runner to answer a prompt, and nothing in this kit ever named a skills
directory for opencode.
Pulls:
3
Sep 14 to Sep 20