wuran commited on
Commit
ddacf56
·
verified ·
1 Parent(s): 10f43b3

Create Dockerfile

Browse files
Files changed (1) hide show
  1. Dockerfile +129 -0
Dockerfile ADDED
@@ -0,0 +1,129 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ # 核心镜像:Node 22 slim 保证了环境的现代性与轻量化
2
+ FROM node:22-slim
3
+
4
+ # 1. 安装系统依赖
5
+ # 包含:git (拉取依赖), openssh-client (解决构建报错), build-essential/g++/make (编译原生模块), python3 (运行同步脚本)
6
+ RUN apt-get update && apt-get install -y --no-install-recommends \
7
+ git openssh-client build-essential python3 python3-pip \
8
+ g++ make ca-certificates \
9
+ && rm -rf /var/lib/apt/lists/*
10
+
11
+ # 2. 安装 Hugging Face 命令行工具
12
+ RUN pip3 install --no-cache-dir huggingface_hub --break-system-packages
13
+
14
+ # 3. 构建环境优化
15
+ # 修复 Git 证书问题并将所有 SSH 协议重定向为 HTTPS
16
+ RUN update-ca-certificates && \
17
+ git config --global http.sslVerify false && \
18
+ git config --global url."https://github.com/".insteadOf ssh://git@github.com/
19
+
20
+ # 4. 全局安装 OpenClaw
21
+ RUN npm install -g openclaw@latest --unsafe-perm
22
+
23
+ # 5. 设置环境变量
24
+ ENV PORT=7860 \
25
+ OPENCLAW_GATEWAY_MODE=local \
26
+ HOME=/root
27
+
28
+ # 6. 核心同步引擎 (sync.py)
29
+ # 针对 OpenClaw 新版 MEMORY.md 机制进行了全路径覆盖
30
+ RUN echo 'import os, sys, tarfile\n\
31
+ from huggingface_hub import HfApi, hf_hub_download\n\
32
+ from datetime import datetime, timedelta\n\
33
+ api = HfApi()\n\
34
+ repo_id = os.getenv("HF_DATASET")\n\
35
+ token = os.getenv("HF_TOKEN")\n\
36
+ \n\
37
+ def restore():\n\
38
+ try:\n\
39
+ print(f"--- [SYNC] 启动恢复流程, 目标仓库: {repo_id} ---")\n\
40
+ if not repo_id or not token:\n\
41
+ print("--- [SYNC] 跳过恢复: 未配置 HF_DATASET 或 HF_TOKEN ---")\n\
42
+ return False\n\
43
+ files = api.list_repo_files(repo_id=repo_id, repo_type="dataset", token=token)\n\
44
+ now = datetime.now()\n\
45
+ for i in range(5):\n\
46
+ day = (now - timedelta(days=i)).strftime("%Y-%m-%d")\n\
47
+ name = f"backup_{day}.tar.gz"\n\
48
+ if name in files:\n\
49
+ print(f"--- [SYNC] 发现备份文件: {name}, 正在下载... ---")\n\
50
+ path = hf_hub_download(repo_id=repo_id, filename=name, repo_type="dataset", token=token)\n\
51
+ with tarfile.open(path, "r:gz") as tar:\n\
52
+ tar.extractall(path="/root/.openclaw/")\n\
53
+ print(f"--- [SYNC] 恢复成功! 数据已覆盖至 /root/.openclaw/ ---")\n\
54
+ return True\n\
55
+ print("--- [SYNC] 未找到最近 5 天的备份包 ---")\n\
56
+ except Exception as e:\n\
57
+ print(f"--- [SYNC] 恢复异常: {e} ---")\n\
58
+ \n\
59
+ def backup():\n\
60
+ try:\n\
61
+ day = datetime.now().strftime("%Y-%m-%d")\n\
62
+ name = f"backup_{day}.tar.gz"\n\
63
+ print(f"--- [SYNC] 正在执行全量备份: {name} ---")\n\
64
+ with tarfile.open(name, "w:gz") as tar:\n\
65
+ # 路径说明:sessions(网关历史), workspace(记忆文件), agents(配置), memory(旧版目录)\n\
66
+ for target in ["sessions", "workspace", "agents", "memory", "openclaw.json"]:\n\
67
+ full_path = f"/root/.openclaw/{target}"\n\
68
+ if os.path.exists(full_path):\n\
69
+ tar.add(full_path, arcname=target)\n\
70
+ api.upload_file(path_or_fileobj=name, path_in_repo=name, repo_id=repo_id, repo_type="dataset", token=token)\n\
71
+ print(f"--- [SYNC] 备份上传成功! ---")\n\
72
+ except Exception as e:\n\
73
+ print(f"--- [SYNC] 备份失败: {e} ---")\n\
74
+ \n\
75
+ if __name__ == "__main__":\n\
76
+ if len(sys.argv) > 1 and sys.argv[1] == "backup":\n\
77
+ backup()\n\
78
+ else:\n\
79
+ restore()' > /usr/local/bin/sync.py
80
+
81
+ # 7. 容器入口脚本 (start-openclaw)
82
+ # 负责恢复数据 -> 生成配置 -> 启动网关 -> 定时备份
83
+ RUN echo '#!/bin/bash\n\
84
+ set -e\n\
85
+ mkdir -p /root/.openclaw/sessions\n\
86
+ mkdir -p /root/.openclaw/workspace\n\
87
+ \n\
88
+ # 启动前执行数据恢复\n\
89
+ python3 /usr/local/bin/sync.py restore\n\
90
+ \n\
91
+ # 清理 API Base 地址\n\
92
+ CLEAN_BASE=$(echo "$OPENAI_API_BASE" | sed "s|/chat/completions||g" | sed "s|/v1/|/v1|g" | sed "s|/v1$|/v1|g")\n\
93
+ \n\
94
+ # 生成 openclaw.json 配置文件\n\
95
+ cat > /root/.openclaw/openclaw.json <<EOF\n\
96
+ {\n\
97
+ "models": {\n\
98
+ "providers": {\n\
99
+ "siliconflow": {\n\
100
+ "baseUrl": "$CLEAN_BASE",\n\
101
+ "apiKey": "$OPENAI_API_KEY",\n\
102
+ "api": "openai-completions",\n\
103
+ "models": [{ "id": "$MODEL", "name": "DeepSeek", "contextWindow": 128000 }]\n\
104
+ }\n\
105
+ }\n\
106
+ },\n\
107
+ "agents": { "defaults": { "model": { "primary": "siliconflow/$MODEL" } } },\n\
108
+ "gateway": {\n\
109
+ "mode": "local", "bind": "lan", "port": $PORT,\n\
110
+ "trustedProxies": ["0.0.0.0/0", "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16"],\n\
111
+ "auth": { "mode": "token", "token": "$OPENCLAW_GATEWAY_PASSWORD" },\n\
112
+ "controlUi": { "allowInsecureAuth": true }\n\
113
+ }\n\
114
+ }\n\
115
+ EOF\n\
116
+ \n\
117
+ # 启动定时备份进程 (每 3 小时执行一次,增强安全性)\n\
118
+ (while true; do\n\
119
+ sleep 10800\n\
120
+ python3 /usr/local/bin/sync.py backup\n\
121
+ done) &\n\
122
+ \n\
123
+ # 启动 OpenClaw 网关\n\
124
+ openclaw doctor --fix\n\
125
+ exec openclaw gateway run --port $PORT\n\
126
+ ' > /usr/local/bin/start-openclaw && chmod +x /usr/local/bin/start-openclaw
127
+
128
+ EXPOSE 7860
129
+ CMD ["/usr/local/bin/start-openclaw"]