Skip to content

feat(opencode): prototype Alpine runtime and startup compatibility gate - #58

Closed
xnoto wants to merge 5 commits into
mainfrom
feat/opencode-alpine-runtime
Closed

xnoto wants to merge 5 commits into
mainfrom
feat/opencode-alpine-runtime

Conversation

@xnoto

@xnoto xnoto commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Owner-approved thin derivative of the digest-pinned official OpenCode 1.18.29 Alpine image, plus official apk prerequisites including Node and gcompat. Plugins are installed at startup into persistent HOME, not baked in or activated by the image.

BLOCKED: actual local ONNX embedding write fails with __vsnprintf_chk: symbol not found. Keep draft; do not publish or select this image in the chart.

Driving request: test the upstream-Alpine-first approach and measure cold/warm startup. Maintainer: makeitworkcloud. No alternate base, custom ONNX, unofficial glibc graft, remote embeddings or paid provider calls.

Type of change

  • Feature / enhancement
  • Documentation
  • Container image
  • CI / reusable workflow

Validation

  • Required pull-request checks pass — runtime gate FAILED, not waived.
  • Generated or centrally distributed files were not hand-edited.

Latest tested head 4aa256927c02577f253b2cbb8a09652c021e99ff; base 2ac081d679726ebe2730bc90ed266b519f8531c8. Run 36366947984 reached terminal failure. Hygiene/detection and image build passed; runtime failed; publication/attestation skipped. No local execution claimed.

Verified Linux/amd64 runtime: Alpine 3.24.1, Node 24.18.1, gcompat 1.1.0-r4; effective UID/GID1000, dropped-capability and read-only-root assertions passed. Cold configuration readiness measured 20.376 seconds; combined plugin registration/memory API readiness 21.288 seconds. These are one CI observation, not production guarantees or successful embedding readiness.

POST /api/memories returned HTTP200 with an application-level error: the present ONNX binding failed relocation because __vsnprintf_chk was not found. The request-specific bounded diagnostic is the root evidence; the legacy aggregate native/network booleans are incomplete heuristics and must not override it. No successful memory creation, recall, direct context functional probe or warm replacement was reached. No warm timing is available.

The first run failed in fixture preflight before plugin execution. Subsequent fixes added JSON image inspection, bounded error-response diagnostics, and exact installed-package metadata; they did not change the image, embedding backend or acceptance criteria. The second run also failed the first memory write but lacked precise error reporting.

Pre-PR architecture/adversarial/security/scoped-DevOps reviews ADVANCE and QA COVERED applied to the bounded prototype at 603307a; subsequent diagnostic/metadata refinements were primary-reviewed. These reviews do not override the failed runtime result or establish final-head production readiness. The pre-commit-only status comment was corrected to avoid implying aggregate image success.

Context-mode host registration is not execution through OpenCode's host/schema/permission/hooks. The direct Node checks are complementary and were not reached in this failed run. No provider or custom host bridge is introduced. Transitive package/model/apk inputs remain non-hermetic; no ARM64/Kubernetes claims.

Impact and rollout

Changed: opencode-server/Containerfile, README.md, tests/{runtime.py,probe.mjs,http.mjs}; root image inventory; .github/workflows/buildah.yml scoped detection and pre-push test gate.

Producer: images -> prospective GHCR opencode-server image. Future consumer: charts/opencode-server. Current chart image defaults, init images, production plugin configuration, GitOps selection and live service are unchanged. No chart replacement PR is submitted against this failed candidate.

PR builds do not push. A separately confirmed main merge could publish latest/SHA tags only if its runtime gate succeeds; attestations are post-publication. Scoped detection means a future workflow-only main change can rebuild/publish opencode-server. Other images retain prior selection. Charts publication, automatic GitOps pin merge, Argo reconciliation and deployed functional tests are distinct later gates.

Stop at this compatibility result. An alternate runtime requires a new owner decision. No merge, publication, workflow dispatch/rerun, cluster activation, exec, sync or restart was performed. Rollback now is closing the unmerged proposal; production is unaffected. Later image rollback would not undo plugin data migrations.

Safety and secrets

  • No plaintext secrets, decrypted SOPS, state, kubeconfigs, tokens or private endpoints; API marker is public synthetic fixture data.
  • No local OpenTofu operations run or claimed.
  • Publication consequences and rollback boundaries described above.

CI uses unique disposable volumes, no production home or credentials, loopback-only listeners and no published host ports. Cold package/model egress is allowed; the planned warm run disables networking. Cleanup succeeded. Diagnostics are bounded and redact paths/URLs/credential patterns; raw configs/auth/logs are not printed. AI-assisted implementation and independent specialist review.

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Pre-commit passed

Pre-commit validation passed. Image build and runtime-gate results are separate. View the workflow run.

@xnoto

xnoto commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Closing at the owner's request. The intended direction is chart-managed dependency bootstrapping with the upstream OpenCode image, not proceeding with this custom-image proposal. No chart bootstrap implementation is approved or delivered by this closure.

The prototype and diagnostic evidence remain recoverable on feat/opencode-alpine-runtime at 4aa256927c02577f253b2cbb8a09652c021e99ff. CI demonstrated startup/plugin registration but failed the real ONNX embedding write with __vsnprintf_chk: symbol not found; this remains a compatibility constraint regardless of where installation commands run.

Nothing was merged or published, and no chart, GitOps, or live-service change was made. Branch retained; unrelated PRs are out of scope.

@xnoto xnoto closed this Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant