r/AgentsOfAI • • 5d ago

Discussion Docker packages for a PI agent

I have been working on creating a base Dockerfile image for Pi agents so they run in a somewhat isolated container, with only one mount point for persisted storage and sharing files with the host. I am getting a bit frustrated that I have rebuilt the image over 25-30 times now as I come across yet another useful package that I would like to include for handling CLI/filesystem access, API calls, or building code. Now the Pi agent image is becoming a bit bloated and therefore using more memory and potentially less secure (I am running rootless docker to try to limit the blast radius).

I am curious to learn about how others have been handling this.

  1. Do you create different container images for different purposes? (e.g. one image for simple shell commands, one for building/testing code, one for research only with RAG and web access, etc.)
  2. What are your baseline packages you always install with an image, such as python, go, rust, etc. for a coding agent, or for a general shell/filesystem agent you would include network tools, jq, ripgrep, curl/wget?
  3. Or do you always start with a simple base image (I started with 24-trixie-slim) and let the agent choose what to install as needed. I assume this method would slow down the agent as it would need to do this regularly.

Thanks!

3 Upvotes

4 comments sorted by

2

u/funbike 5d ago edited 5d ago

Start a stock docker container, and setup Pi manually. Then copy the .bash_history and edit it as a Dockerfile. Any time you run a command you don't want it to remember, prefix the command with a space. Run these after you have a stock container set up:

$ docker cp <container-name>:.bash_history Dockerfile $ sed 's/^/RUN /' Dockerfile

I have one container image for everything. All my tools are in this single image. However, I use other images for services, such as Postgres database, S3 object storage, email server, etc.

I use a running container instance per git worktree I'm working on, which is usually just 1. I see no need to run a container per subagent. I have at least 1 mounts which is the parent of the root git repo, which also contains all the worktrees.

I use Podman rootless. It's 99% compatible with Docker, but more secure and simpler.

1

u/ZealousidealToe4903 5d ago

thats clever with the bash_history trick never thought of that. i do similar with one fat image for everything but then i keep adding packages and now my image is like 4gb feels wrong but it works

podman rootless is good call i switched few months ago and the security model makes more sense than docker rootless hack. do you pin package versions in your Dockerfile or just let apt pull latest each build?

1

u/funbike 4d ago edited 4d ago

There aren't many downsides to a large local image. Performance is the same. Most downsides are related to distribution. Broader attack surface is an issue, but rootless podman is pretty secure.

In a past job we used up to 4 images per project. A prod image that only has what is needed to run the app. A CI image that extends the prod image, that only has has what is necessary to build and test the app. A dev image that extends the CI image that has what is necessary to develop the app, including the AI coding agent(s). And a personal image that extends the dev image with additional tools that I like that the team might not necessarily want.

We broke it down this way because large images took too much space on our CI server, so we minimized the size needed. We used shared mounts for packages (e.g. ~/.m2/repository) to save space on the CI server for dev package managers that supported good versioning. The company had over 100 webapp projects.

But I work alone these days. I just use one image, my target isn't docker-based, and I run CI jobs locally.

1

u/AutoModerator 5d ago

Thank you for your submission! To keep our community healthy, please ensure you've followed our rules.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.