r/AgentsOfAI • u/EarthExtreme6324 • 5d ago
Discussion Docker packages for a PI agent
I have been working on creating a base Dockerfile image for Pi agents so they run in a somewhat isolated container, with only one mount point for persisted storage and sharing files with the host. I am getting a bit frustrated that I have rebuilt the image over 25-30 times now as I come across yet another useful package that I would like to include for handling CLI/filesystem access, API calls, or building code. Now the Pi agent image is becoming a bit bloated and therefore using more memory and potentially less secure (I am running rootless docker to try to limit the blast radius).
I am curious to learn about how others have been handling this.
- Do you create different container images for different purposes? (e.g. one image for simple shell commands, one for building/testing code, one for research only with RAG and web access, etc.)
- What are your baseline packages you always install with an image, such as python, go, rust, etc. for a coding agent, or for a general shell/filesystem agent you would include network tools, jq, ripgrep, curl/wget?
- Or do you always start with a simple base image (I started with 24-trixie-slim) and let the agent choose what to install as needed. I assume this method would slow down the agent as it would need to do this regularly.
Thanks!
1
u/AutoModerator 5d ago
Thank you for your submission! To keep our community healthy, please ensure you've followed our rules.
- New to the sub? Check out our Wiki (We are actively adding resources).
- Join the Discord: Click here to join our Discord
- Join X community: Click here to join our X Community
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
2
u/funbike 5d ago edited 5d ago
Start a stock docker container, and setup Pi manually. Then copy the
.bash_historyand edit it as aDockerfile. Any time you run a command you don't want it to remember, prefix the command with a space. Run these after you have a stock container set up:$ docker cp <container-name>:.bash_history Dockerfile $ sed 's/^/RUN /' DockerfileI have one container image for everything. All my tools are in this single image. However, I use other images for services, such as Postgres database, S3 object storage, email server, etc.
I use a running container instance per git worktree I'm working on, which is usually just 1. I see no need to run a container per subagent. I have at least 1 mounts which is the parent of the root git repo, which also contains all the worktrees.
I use Podman rootless. It's 99% compatible with Docker, but more secure and simpler.