# Example sandbox for the weather suite.
#
# Extends the pi community sandbox with the weather agent (its tools, the
# remote alerts MCP server it sends alerts with, and an OpenAI-compatible model
# provider), then adds MiDojo's PI extension and fake alerts MCP server.
# Replace this with your own production sandbox image — the suite.yaml eval
# does not change.
#
# Build (from repo root):
#   podman build --pull=always --platform linux/arm64 \
#     --build-arg LITELLM_API_URL --build-arg LITELLM_MODEL \
#     -t localhost/weather-pi:latest -f suites/weather/sandbox_pi/Containerfile .
#
# The build args pick the model server and model; they default to a local
# server at host.openshell.internal:8321. The API key is not baked in: the
# suite passes LITELLM_API_KEY into the sandbox at run time.

FROM ghcr.io/nvidia/openshell-community/sandboxes/pi:latest

ARG LITELLM_API_URL=http://host.openshell.internal:8321/v1
ARG LITELLM_MODEL=ollama/qwen3.5:2b

USER root

# The PI SDK targets PI 1.0, newer than the PI in the community image.
RUN npm install -g @earendil-works/pi-coding-agent@1.0.0

# Install into pi's global agent dir (~/.pi/agent = /sandbox/.pi/agent), which
# pi reads regardless of the process working directory. midojo runs the agent
# in /sandbox/workdir, so a project-local .pi/ would not be found.
RUN mkdir -p /sandbox/.pi/agent
# mcp.json names the owner's remote alerts service, which the suite replaces
# with the fake alerts MCP server below.
COPY suites/weather/sandbox_pi/models.json suites/weather/sandbox_pi/settings.json \
     suites/weather/sandbox_pi/AGENTS.md suites/weather/sandbox_pi/mcp.json /sandbox/.pi/agent/
RUN sed -i -e "s|@LITELLM_API_URL@|${LITELLM_API_URL}|" -e "s|@LITELLM_MODEL@|${LITELLM_MODEL}|" \
      /sandbox/.pi/agent/models.json /sandbox/.pi/agent/settings.json

# The midojo pi-sdk's only imports are type-only, so pi's bundled jiti loads it
# with no install step or runtime deps.
COPY pi-sdk/ /sandbox/.pi/agent/pi-sdk/
COPY suites/weather/sandbox_pi/.pi/extensions/ /sandbox/.pi/agent/extensions/

# The fake alerts MCP server, built on midojo's MCP SDK. The suite's
# agent_command starts it with with-fake-mcp.sh before running PI.
COPY pyproject.toml README.md /tmp/midojo/
COPY src/ /tmp/midojo/src/
RUN uv pip install --no-cache --python /sandbox/.venv/bin/python3 /tmp/midojo && rm -rf /tmp/midojo
COPY suites/weather/sandbox_pi/fake_mcp.py suites/weather/sandbox_pi/with-fake-mcp.sh /sandbox/midojo/

RUN chown -R sandbox:sandbox /sandbox/.pi /sandbox/midojo

USER sandbox
