# Example sandbox for the document_assistant suite.
#
# Extends the pi community sandbox with an OpenAI-compatible model provider.
# Replace this with your own production sandbox image — the suite.yaml eval
# does not change.
#
# Build (from repo root):
#   podman build --pull=always --platform linux/arm64 \
#     --build-arg LITELLM_API_URL --build-arg LITELLM_MODEL \
#     -t localhost/document-assistant-local:latest \
#     -f suites/document_assistant/sandbox_pi/Containerfile .
#
# The build args pick the model server and model; they default to a local
# server at host.openshell.internal:8321. The API key is not baked in: the
# suite passes LITELLM_API_KEY into the sandbox at run time.

FROM ghcr.io/nvidia/openshell-community/sandboxes/pi:latest

ARG LITELLM_API_URL=http://host.openshell.internal:8321/v1
ARG LITELLM_MODEL=ollama/qwen3.5:2b

USER root

# The PI SDK targets PI 1.0, newer than the PI in the community image.
RUN npm install -g @earendil-works/pi-coding-agent@1.0.0
RUN mkdir -p /sandbox/.pi/agent
COPY suites/document_assistant/sandbox_pi/models.json /sandbox/.pi/agent/models.json
RUN sed -i -e "s|@LITELLM_API_URL@|${LITELLM_API_URL}|" -e "s|@LITELLM_MODEL@|${LITELLM_MODEL}|" \
      /sandbox/.pi/agent/models.json

# Bundle the midojo pi-sdk and a report-only extension so the agent's file reads
# are reported to the control plane, making seeded-file injections visible to the
# reachability check. The SDK's only imports are type-only, so pi's bundled jiti
# loads it with no install step or runtime deps. The build context is the repo
# root; .dockerignore keeps node_modules/dist out of the copy.
#
# Install into pi's *global* agent dir (~/.pi/agent = /sandbox/.pi/agent). pi
# discovers extensions there regardless of the process working directory, whereas
# the project-local dir it also scans (<cwd>/.pi/extensions) is only found when
# cwd happens to be /sandbox. Since midojo runs the agent with cwd set to the
# seed dir (/sandbox/workdir) so it resolves bare filenames, the extension must
# live in the cwd-independent global dir or it silently won't load.
COPY pi-sdk/ /sandbox/.pi/agent/pi-sdk/
COPY suites/document_assistant/sandbox_pi/.pi/extensions/ /sandbox/.pi/agent/extensions/

RUN chown -R sandbox:sandbox /sandbox/.pi

USER sandbox
