Xubin Ren
634261f07a
fix: correct api-workspace path for non-root container user
...
The Dockerfile runs as user nanobot (HOME=/home/nanobot), not root.
Made-with: Cursor
2026-04-06 16:20:20 +08:00
dengjingren
d99331ad31
feat(docker): add nanobot-api service with isolated workspace
...
- Add nanobot-api service (OpenAI-compatible HTTP API on port 8900)
- Uses isolated workspace (/root/.nanobot/api-workspace) to avoid
session/memory conflicts with nanobot-gateway
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-06 16:20:20 +08:00
Xubin Ren
cef0f3f988
refactor: replace podman-seccomp.json with minimal cap_add, harden bwrap, add sandbox tests
2026-04-05 19:03:06 +00:00
kinchahoy
7913e7150a
feat: sandbox exec calls with bwrap and run container as non-root
2026-03-16 23:55:19 -07:00
Re-bin
aad1df5b9b
Simplify Docker Compose docs and remove fixed CLI container name
2026-02-17 17:55:48 +00:00
Rajasimman S
c03f2b670b
🐳 feat: add Docker Compose support for easy deployment
...
Add docker-compose.yml with gateway and CLI services, resource limits,
and comprehensive documentation for Docker Compose usage.
2026-02-17 18:50:03 +05:30