FROM python:3.13-slim # ── System dependencies ──────────────────────────────────────────────────────── # Includes Xvfb/VNC stack, git (needed for pip's git+https installs), # and Chromium runtime libs (for the playwright-managed Chromium binary). RUN apt-get update && apt-get install -y --no-install-recommends \ xvfb \ x11vnc \ websockify \ novnc \ curl \ git \ libnss3 \ libatk1.0-0 \ libatk-bridge2.0-0 \ libcups2 \ libdrm2 \ libxkbcommon0 \ libxcomposite1 \ libxdamage1 \ libxrandr2 \ libgbm1 \ libpango-1.0-0 \ libcairo2 \ libasound2 \ libxshmfence1 \ libgtk-3-0 \ fonts-liberation \ && rm -rf /var/lib/apt/lists/* # ── Node.js 22.x ────────────────────────────────────────────────────────────── RUN curl -fsSL https://deb.nodesource.com/setup_22.x | bash - \ && apt-get install -y --no-install-recommends nodejs \ && rm -rf /var/lib/apt/lists/* # ── npm global tools: @playwright/cli + Chromium browser ────────────────────── # @playwright/cli — token-efficient browser CLI used by research agents # (playwright-cli -s=research open/snapshot/click/type …) # playwright — provides `playwright install` to download managed Chromium # Chromium is installed to /root/.cache/ms-playwright/ (default for root user) RUN npm install -g @playwright/cli playwright \ && playwright install chromium # ── Python tooling ──────────────────────────────────────────────────────────── RUN pip install uv # overlayfs inside Docker doesn't support reflinks → use copy mode to avoid EAGAIN ENV UV_LINK_MODE=copy # ── amplifierd: Amplifier session daemon ────────────────────────────────────── # Not on PyPI — source is github.com/microsoft/amplifierd. # uv pip --system installs to /usr/local/bin/amplifierd (on PATH by default). # # amplifier-foundation is also not on PyPI (it's a pure git package that # amplifierd depends on), so we install it explicitly in the same step. # amplifier-core IS on PyPI and will be resolved automatically. RUN uv pip install --system \ "amplifierd @ git+https://github.com/microsoft/amplifierd" # ── Frontend: install deps and build ────────────────────────────────────────── # Copy package manifests first so npm ci is cached independently of source changes. COPY frontend/package.json frontend/package-lock.json /app/frontend/ WORKDIR /app/frontend RUN npm ci COPY frontend/ /app/frontend/ RUN npm run build # ── Backend: install Python deps ────────────────────────────────────────────── COPY backend/pyproject.toml backend/uv.lock /app/backend/ WORKDIR /app/backend RUN uv sync --frozen # ── Application files ───────────────────────────────────────────────────────── COPY backend/*.py /app/backend/ COPY bundle/ /app/bundle/ COPY entrypoint.sh /entrypoint.sh RUN chmod +x /entrypoint.sh RUN mkdir -p /app/artifacts WORKDIR /app EXPOSE 8080 6080 ENV DISPLAY=:99 ENV AMPLIFIERD_URL=http://localhost:8410 ENV BUNDLE_NAME=research-workbench ENTRYPOINT ["/entrypoint.sh"]