Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
21 commits
Select commit Hold shift + click to select a range
7bd9bc7
fix: make sandbox project dirs worker-writable
JZKK720 May 22, 2026
27d75df
ci: publish fork images to ghcr
JZKK720 May 22, 2026
230f84a
ci: publish latest images on main push
JZKK720 May 22, 2026
6326d79
ci: retrigger docker publish after workflow re-enable
JZKK720 May 22, 2026
fad6db6
Fix sandbox restart project dir permissions
JZKK720 May 22, 2026
0603626
Fix sandbox worker bind source in Docker
JZKK720 May 22, 2026
529ddcc
Accept Windows Docker host bind paths
JZKK720 May 22, 2026
f0c17bd
Persist sandbox job completion status
JZKK720 May 23, 2026
e30c80a
release: prepare 0.28.2-f1
JZKK720 May 23, 2026
7add978
ci(release): support dispatched fork releases
JZKK720 May 23, 2026
9bda215
ci(release): allow docker publish in release workflow
JZKK720 May 23, 2026
084126a
ci(release): pin docker reruns to the release ref
JZKK720 May 23, 2026
fcc668e
ci(release): skip msi for fork prerelease tags
JZKK720 May 23, 2026
857ebab
Fix sandbox worker image recovery
JZKK720 May 24, 2026
cb8bd7a
Add optional worker-cache compose profile
JZKK720 May 24, 2026
55c085d
chore(release): bump version to 0.28.2-f2
JZKK720 May 24, 2026
5a43e30
Add fork release status checker task
JZKK720 May 24, 2026
d2f8511
fix(telegram): fix 4 bugs causing Telegram channel to not respond
JZKK720 May 28, 2026
9370aca
Merge branch 'agents/fix-telegram-response-issue' into main
JZKK720 May 29, 2026
2f753c1
chore: intake upstream ironclaw-v0.29.0 into fork/main
May 31, 2026
da39632
chore: update WASM artifact SHA256 checksums [skip ci]
github-actions[bot] May 31, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -209,7 +209,9 @@ HEARTBEAT_NOTIFY_USER=default
# # commands directly on the host. Without this
# # set to "true", full_access is downgraded to
# # workspace_write.
# SANDBOX_IMAGE=ironclaw-worker:latest
# IRONCLAW_APP_IMAGE=ghcr.io/jzkk720/ironclaw:latest
# SANDBOX_IMAGE=ghcr.io/jzkk720/ironclaw-worker:latest
# Keep the app and worker image on the same channel/tag or digest.
# SANDBOX_TIMEOUT_SECS=120
# SANDBOX_MEMORY_LIMIT_MB=2048

Expand Down
4 changes: 3 additions & 1 deletion .gitattributes
Original file line number Diff line number Diff line change
@@ -1 +1,3 @@
tests/test-pages/**/*.html linguist-generated=true
tests/test-pages/**/*.html linguist-generated=true
migrations/*.sql text eol=lf
migrations/checksums.lock text eol=lf
46 changes: 34 additions & 12 deletions .github/workflows/docker.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,9 @@
name: Docker Image
name: Build and Publish Docker Images

on:
push:
branches:
- main
# Called by release.yml or other workflows
workflow_call:
inputs:
Expand All @@ -9,6 +12,11 @@ on:
required: false
type: boolean
default: false
source_ref:
description: "Git ref to checkout for reusable workflow runs"
required: false
type: string
default: ""
tag:
description: "Image tag override (leave empty for auto-detect)"
required: false
Expand All @@ -22,6 +30,11 @@ on:
required: false
type: boolean
default: false
source_ref:
description: "Git ref to checkout before building"
required: false
type: string
default: ""
tag:
description: "Image tag override (leave empty for auto-detect)"
required: false
Expand All @@ -32,22 +45,24 @@ on:
- cron: '0 * * * *'

env:
IMAGE_NAME: nearaidev/ironclaw
WORKER_IMAGE_NAME: nearaidev/ironclaw-worker
REGISTRY: ghcr.io
IMAGE_OWNER: jzkk720
IMAGE_NAME: ghcr.io/jzkk720/ironclaw
WORKER_IMAGE_NAME: ghcr.io/jzkk720/ironclaw-worker

jobs:
build:
name: Build & Push
runs-on: ubuntu-24.04
permissions:
contents: read
packages: read
packages: write
actions: write
steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
ref: ${{ github.event_name == 'schedule' && 'main' || '' }}
ref: ${{ github.event_name == 'workflow_call' && inputs.source_ref || github.event_name == 'workflow_dispatch' && inputs.source_ref || github.event_name == 'schedule' && 'main' || '' }}
persist-credentials: false

- name: Resolve source git commit
Expand Down Expand Up @@ -99,6 +114,12 @@ jobs:
TAGS="${TAGS},${IMAGE_NAME}:${SHA}"
WORKER_TAGS="${WORKER_IMAGE_NAME}:staging"
WORKER_TAGS="${WORKER_TAGS},${WORKER_IMAGE_NAME}:${SHA}"
elif [[ "${EVENT_NAME}" == "push" ]]; then
# Push to main: :latest + :sha-xxx
TAGS="${IMAGE_NAME}:latest"
TAGS="${TAGS},${IMAGE_NAME}:${SHA}"
WORKER_TAGS="${WORKER_IMAGE_NAME}:latest"
WORKER_TAGS="${WORKER_TAGS},${WORKER_IMAGE_NAME}:${SHA}"
else
# Manual dispatch: :sha-xxx only
TAGS="${IMAGE_NAME}:${SHA}"
Expand All @@ -114,21 +135,22 @@ jobs:
echo "worker_tags=${WORKER_TAGS}" >> "$GITHUB_OUTPUT"

# Staging builds get pre-bundled WASM extensions
if [[ "${EVENT_NAME}" == "schedule" || "${INPUT_TAG}" == "staging" ]]; then
if [[ "${EVENT_NAME}" == "schedule" || "${EVENT_NAME}" == "push" || "${INPUT_TAG}" == "staging" ]]; then
echo "target=runtime-staging" >> "$GITHUB_OUTPUT"
else
echo "target=runtime" >> "$GITHUB_OUTPUT"
fi

- name: Log in to Docker Hub
- name: Log in to GHCR
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3
with:
username: ${{ vars.DOCKER_REGISTRY_USER }}
password: ${{ secrets.DOCKER_REGISTRY_TOKEN }}
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Check if current git commit is already built
id: check
if: steps.tags.outputs.target == 'runtime-staging'
if: github.event_name == 'schedule' || inputs.tag == 'staging'
env:
SOURCE_SHA: ${{ steps.source_sha.outputs.sha }}
run: |
Expand Down Expand Up @@ -188,7 +210,7 @@ jobs:

- name: Create releases-manager app token
id: app-token
if: steps.check.outputs.skip != 'true'
if: github.repository_owner == 'nearai' && steps.check.outputs.skip != 'true'
continue-on-error: true
uses: actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349 # v2
with:
Expand All @@ -198,7 +220,7 @@ jobs:
repositories: ironclaw-dind

- name: Trigger ironclaw-dind Build & Push
if: steps.app-token.outcome == 'success' && steps.check.outputs.skip != 'true'
if: github.repository_owner == 'nearai' && steps.app-token.outcome == 'success' && steps.check.outputs.skip != 'true'
continue-on-error: true
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
Expand Down
12 changes: 7 additions & 5 deletions .github/workflows/rebuild-release-image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,8 @@ on:
type: string

env:
IMAGE_NAME: nearaidev/ironclaw
REGISTRY: ghcr.io
IMAGE_NAME: ghcr.io/jzkk720/ironclaw

jobs:
build:
Expand All @@ -22,7 +23,7 @@ jobs:
permissions:
actions: write
contents: read
packages: read
packages: write
steps:
- name: Checkout requested source
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
Expand Down Expand Up @@ -73,11 +74,12 @@ jobs:
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3

- name: Log in to Docker Hub
- name: Log in to GHCR
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3
with:
username: ${{ vars.DOCKER_REGISTRY_USER }}
password: ${{ secrets.DOCKER_REGISTRY_TOKEN }}
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Detect runtime stage
id: target
Expand Down
59 changes: 36 additions & 23 deletions .github/workflows/release-plz.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,43 +9,63 @@ jobs:

# Release unpublished packages.
release-plz-release:
if: ${{ github.repository_owner == 'nearai' }}
name: Release-plz release
runs-on: ubuntu-latest
permissions:
contents: write
actions: write
steps:
- &checkout
name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
fetch-depth: 0
persist-credentials: false
- name: Record release tags before run
shell: bash
run: |
git fetch origin --tags
git tag -l 'ironclaw-v*' | sort > "$RUNNER_TEMP/release-tags-before.txt"
- &install-rust
name: Install Rust toolchain
uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
# Generating a GitHub token, so that PRs and tags created by
# the release-plz-action can trigger actions workflows.
- name: Generate GitHub token
uses: actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349 # v2
id: generate-token
with:
# GitHub App ID secret name
app-id: ${{ secrets.GH_RELEASES_MANAGER_APP_ID }}
# GitHub App private key secret name
private-key: ${{ secrets.GH_RELEASES_MANAGER_APP_PRIVATE_KEY }}
- name: Run release-plz
uses: release-plz/action@1528104d2ca23787631a1c1f022abb64b34c1e11 # v0.5
with:
command: release
env:
GITHUB_TOKEN: ${{ steps.generate-token.outputs.token }}
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Detect newly created release tags
id: new-tags
shell: bash
run: |
git fetch origin --tags
git tag -l 'ironclaw-v*' | sort > "$RUNNER_TEMP/release-tags-after.txt"
comm -13 "$RUNNER_TEMP/release-tags-before.txt" "$RUNNER_TEMP/release-tags-after.txt" > "$RUNNER_TEMP/release-tags-new.txt"

if [ -s "$RUNNER_TEMP/release-tags-new.txt" ]; then
echo "created=true" >> "$GITHUB_OUTPUT"
echo "tags<<EOF" >> "$GITHUB_OUTPUT"
cat "$RUNNER_TEMP/release-tags-new.txt" >> "$GITHUB_OUTPUT"
echo "EOF" >> "$GITHUB_OUTPUT"
else
echo "created=false" >> "$GITHUB_OUTPUT"
fi
- name: Dispatch release workflow for new tags
if: steps.new-tags.outputs.created == 'true'
shell: bash
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
CREATED_TAGS: ${{ steps.new-tags.outputs.tags }}
run: |
while IFS= read -r tag; do
[ -n "$tag" ] || continue
gh workflow run release.yml --ref main -f release_tag="$tag"
done <<< "$CREATED_TAGS"

# Create a PR with the new versions and changelog, preparing the next release.
release-plz-pr:
if: ${{ github.repository_owner == 'nearai' }}
name: Release-plz PR
runs-on: ubuntu-latest
permissions:
Expand All @@ -58,16 +78,9 @@ jobs:
- *checkout
- *install-rust
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
- name: Generate GitHub token
uses: actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349 # v2
id: generate-token
with:
app-id: ${{ secrets.GH_RELEASES_MANAGER_APP_ID }}
private-key: ${{ secrets.GH_RELEASES_MANAGER_APP_PRIVATE_KEY }}
- name: Run release-plz
- name: Run release-plz PR
uses: release-plz/action@1528104d2ca23787631a1c1f022abb64b34c1e11 # v0.5
with:
command: release-pr
env:
GITHUB_TOKEN: ${{ steps.generate-token.outputs.token }}
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
Loading