Linux container with the pi coding-agent, MemPalace, and curated dev tooling.
10K+
A self-contained Docker container for the pi coding-agent — pi + companion repos + MemPalace + a curated set of dev tooling, ready to run.
Current
:latestships pi1.0.0(resolved at build time; see Versioning).
| Tag | Architectures | Size (compressed) | What you get |
|---|---|---|---|
joakimp/pi-devbox:latest | amd64, arm64 | ~1.23 GB | Self-contained: base + pi 1.0.0 + companions |
joakimp/pi-devbox:vX.Y.Z | amd64, arm64 | same | Pinned semver release |
joakimp/pi-devbox:latest-studio | amd64, arm64 | ~1.25 GB | latest + pi-studio: browser prompt editor, KaTeX/Mermaid preview, tmux-backed literate REPLs |
joakimp/pi-devbox:vX.Y.Z-studio | amd64, arm64 | same | Pinned semver studio release |
joakimp/pi-devbox:base-latest | amd64, arm64 | ~1.17 GB | Base layer alias (internal building block; pull :latest instead) |
joakimp/pi-devbox:base-<hash> | amd64, arm64 | ~1.17 GB | Content-addressed base; immutable. Stable parent for variant rebuilds. |
pi-studio (
-studiotags): launch with/studio --no-browser --port 8765inside a pi session. The server binds127.0.0.1inside the container, so reach it via host networking or a loopback bridge (andssh -Lfor a remote host; mosh needs a parallelssh -L). Full recipe: README → Using pi-studio.
One-shot, no persistence:
docker run -it --rm \
-v "$PWD":/workspace \
-v "$HOME/.ssh":/home/developer/.ssh:ro \
-e ANTHROPIC_API_KEY="$ANTHROPIC_API_KEY" \
joakimp/pi-devbox:latest pi
For a fully-configured environment with persistent settings, MemPalace memory, neovim plugins, and shell history surviving container recreation, use docker-compose. You don't need to clone the repo — just grab two template files:
mkdir -p ~/pi-devbox && cd ~/pi-devbox
curl -O https://gitea.jordbo.se/joakimp/pi-devbox/raw/branch/main/docker-compose.yml
curl -fsSL https://gitea.jordbo.se/joakimp/pi-devbox/raw/branch/main/.env.example -o .env
# Edit .env — set WORKSPACE_PATH, an LLM API key (ANTHROPIC_API_KEY,
# OPENAI_API_KEY, GEMINI_API_KEY, or AWS_*), and your git identity.
docker compose run --rm devbox pi
Full setup guide — authentication for each provider (Anthropic, OpenAI, Gemini, AWS Bedrock SSO + static), persistence model, configuration reference, build args, troubleshooting: https://gitea.jordbo.se/joakimp/pi-devbox#readme
1.0.0 (@earendil-works/pi-coding-agent) — installed at /usr/bin/pi, pinned to an audited version (not npm latest)/opt/pi-atelier and pinned to an audited tag; the exact tag is in the image labels (se.jordbo.pi-devbox.pi-atelier-version) and /etc/pi-devbox/build-manifest.jsonext-toggle, mcp-loader, todo, ssh-controlmaster, notify, git-checkpoint, confirm-destructivefork (pi-fork) and recall (pi-observational-memory) tools/usr/local/share/pi-devbox/skills/ (e.g. pi-devbox-environment, which teaches agents the container's persistence/networking/DNS/tmux/REPL specifics) are symlinked into ~/.agents/skills/ on start, available with or without a mounted skillset repoThe entrypoint deploys/registers all of these on first container start. Re-running is idempotent and preserves user edits.
Terminal UI mode — fullscreen by default. pi 1.0.0 made the TUI fullscreen, and this image adopts upstream's default. Fullscreen uses the terminal's alternate screen, so the transcript no longer lands in your terminal's (or tmux's) native scrollback. To get the previous behaviour back, set "tuiMode": "regular" in ~/.pi/agent/settings.json, or pass pi --tui-mode regular for a single session. The bundled pi-atelier sidebar works in both modes. See the README for the related fullscreenExitOutput / fullscreenScrollbar / fullscreenCopyOnSelect / fullscreenWheelScrollLines settings — the last one behaves differently over SSH, which is how this container is usually driven.
mempalace_* tools inside piall-MiniLM-L6-v2)~/.mempalace and the host-pi and container-pi share one brain--pdf-enginedot) — diagram rendering pipelinesmagick) — image conversion / resizingeval, snapshot the DOM, screenshots) so agents can verify front-end work instead of guessingAGENT_BROWSER_EXECUTABLE_PATH is preset to the baked browser, so agent-browser open <url> works out of the box with no setuptermguicolors default; bring your own config/plugins), tmux (configured for 0-indexed sessions)tldr --update once to populate cache)uv run --with ipython ipython
uv run --with jupyterlab jupyter lab --no-browser --port 8888
uv run --with marimo marimo edit
rustup-init is on PATH; install toolchains on demand--build-arg INSTALL_GO=true if rebuilding from source/tmp/sshcm/). Mitigates ssh banner-exchange failures behind CGNAT-restricted residential ISPs (~4-flow caps). A read-only ~/.ssh carrying a per-host ControlPath (common CGNAT configs) is handled too — redirected to a writable socket dir for both pi --ssh and dssh/dscp.dssh <peer> alias; DEVBOX_LAN_ACCESS / HOST_SSH_USER).From v1.0.0 onward, pi-devbox uses semver:
pi-only variant).The pi binary version inside any given release is shown in this description (currently 1.0.0 for :latest) and asserted by smoke tests to match what's documented — version drift is caught at CI time, not on user pull.
Pre-v1.0.0 history. Tags v0.74.0…v0.79.0 followed the pi npm version directly (
v{pi_version}[letter]). Those images remain on Hub but are deprecated in favor of:latest/:v1.X.Y. The legacy:base-pi-only*tags were CI artifacts of the old opencode-devbox-based build pipeline; they will be removed in a future opencode-devbox v2.0.0.
pi-devbox is built in two phases:
Dockerfile.base) → base-<hash> tag, content-addressed over Dockerfile.base + rootfs/ + entrypoint*.sh. Rebuilt only when those change.Dockerfile.variant) → :latest and :vX.Y.Z. FROMs the base, adds the pi install + companions.base-latest is an alias of the most recent base.
User edits and pi-installed packages survive container recreation when you mount these named volumes. Use the included docker-compose.yml and they're set up automatically.
| Volume | Mount point | What it holds |
|---|---|---|
devbox-pi-config | /home/developer/.pi/ | pi settings, extension toggles, sessions, user-installed pi packages (npm install -g, pi install npm:…) |
devbox-shell-history | /home/developer/.cache/bash | bash history |
devbox-zoxide | /home/developer/.local/share/zoxide | zoxide directory jump database |
devbox-nvim-data | /home/developer/.local/share/nvim | neovim plugin & Mason package state |
devbox-uv | /home/developer/.local/share/uv | uv Python installs and tool cache |
devbox-ssh-local | /home/developer/.ssh-local | LAN-jump key (one-time host authorization survives recreate) |
Optional volumes for MemPalace (commented out by default — uncomment in docker-compose.yml to persist conversation memory across restarts):
| Volume | Mount point | What it holds |
|---|---|---|
devbox-palace | /home/developer/.mempalace | palace data (drawers, knowledge graph, embeddings) |
devbox-chroma-cache | /home/developer/.cache/chroma | ChromaDB embedding model cache (~80 MB, can be rebuilt) |
NPM_CONFIG_PREFIX is set inside the container to /home/developer/.pi/npm-global. Anything you pi install npm:<pkg> or npm install -g lands on the devbox-pi-config named volume — survives container recreation and image rebuilds. A user-installed pi wins over the baked one via PATH order, so you can pin a different pi version without rebuilding the image.
MIT (the image; pi and the bundled tools each carry their own licenses). See
LICENSE and THIRD_PARTY.md in the source repo.
Content type
Image
Digest
sha256:70e8aed77…
Size
1.2 GB
Last updated
3 days ago
docker pull joakimp/pi-devbox