Sign inSign up

sbx/crush-mixin:latest

Multi-platform
Manifest digest

sha256:b52393e9429c01b0f70f343099e78a18f277badb970dadfb64357ddf69549dd6

Last pushed

about 16 hours by sbx

Type

Sandbox Kit

Manifest digest

sha256:b52393e9429c01b0f70f343099e78a18f277badb970dadfb64357ddf69549dd6

yaml
schemaVersion: "3"
displayName: Crush (mixin)
description: Charm's multi-provider AI coding agent as a mixin -- the Crush binary in an overlay, with proxy-mediated auth for 15 model providers and the egress they need. Layer it onto a shell base and run `crush`.
version: 0.95.0
kind: mixin
provides:
    - [email protected]
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - api.anthropic.com
                - api.openai.com
                - '*.openai.azure.com'
                - generativelanguage.googleapis.com
                - api.mistral.ai
                - api.groq.com
                - groq.com
                - api.cerebras.ai
                - openrouter.ai
                - api-inference.huggingface.co
                - api.io.net
                - api.minimax.chat
                - api.synthetic.com
                - api.zai.com
                - v0.dev
                - bedrock-runtime.us-east-1.amazonaws.com
                - bedrock.us-east-1.amazonaws.com
                - bedrock-runtime.us-east-2.amazonaws.com
                - bedrock.us-east-2.amazonaws.com
                - bedrock-runtime.us-west-2.amazonaws.com
                - bedrock.us-west-2.amazonaws.com
                - bedrock-runtime.eu-central-1.amazonaws.com
                - bedrock.eu-central-1.amazonaws.com
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.anthropic.com
                  format: '%s'
                  header: x-api-key
            name: ANTHROPIC_API_KEY
            proxyManaged: true
        phase: runtime
        service: anthropic
      description: Anthropic API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: bedrock-runtime.us-east-1.amazonaws.com
                  format: AWS4-HMAC-SHA256 Credential=%s/
                  header: Authorization
                - domain: bedrock.us-east-1.amazonaws.com
                  format: AWS4-HMAC-SHA256 Credential=%s/
                  header: Authorization
                - domain: bedrock-runtime.us-east-2.amazonaws.com
                  format: AWS4-HMAC-SHA256 Credential=%s/
                  header: Authorization
                - domain: bedrock.us-east-2.amazonaws.com
                  format: AWS4-HMAC-SHA256 Credential=%s/
                  header: Authorization
                - domain: bedrock-runtime.us-west-2.amazonaws.com
                  format: AWS4-HMAC-SHA256 Credential=%s/
                  header: Authorization
                - domain: bedrock.us-west-2.amazonaws.com
                  format: AWS4-HMAC-SHA256 Credential=%s/
                  header: Authorization
                - domain: bedrock-runtime.eu-central-1.amazonaws.com
                  format: AWS4-HMAC-SHA256 Credential=%s/
                  header: Authorization
                - domain: bedrock.eu-central-1.amazonaws.com
                  format: AWS4-HMAC-SHA256 Credential=%s/
                  header: Authorization
            name: AWS_ACCESS_KEY_ID
            proxyManaged: true
        phase: runtime
        service: aws
      description: AWS Bedrock access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: '*.openai.azure.com'
                  format: '%s'
                  header: api-key
            name: AZURE_OPENAI_API_KEY
            proxyManaged: true
        phase: runtime
        service: azure-openai
      description: Azure OpenAI access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.cerebras.ai
                  format: Bearer %s
                  header: Authorization
            name: CEREBRAS_API_KEY
            proxyManaged: true
        phase: runtime
        service: cerebras
      description: Cerebras API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: generativelanguage.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
            name: GEMINI_API_KEY
            proxyManaged: true
        phase: runtime
        service: google
      description: Google AI API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.groq.com
                  format: Bearer %s
                  header: Authorization
                - domain: groq.com
                  format: Bearer %s
                  header: Authorization
            name: GROQ_API_KEY
            proxyManaged: true
        phase: runtime
        service: groq
      description: Groq API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api-inference.huggingface.co
                  format: Bearer %s
                  header: Authorization
            name: HF_TOKEN
            proxyManaged: true
        phase: runtime
        service: huggingface
      description: Hugging Face inference access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.io.net
                  format: Bearer %s
                  header: Authorization
            name: IONET_API_KEY
            proxyManaged: true
        phase: runtime
        service: ionet
      description: io.net API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.minimax.chat
                  format: Bearer %s
                  header: Authorization
            name: MINIMAX_API_KEY
            proxyManaged: true
        phase: runtime
        service: minimax
      description: MiniMax API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.mistral.ai
                  format: Bearer %s
                  header: Authorization
            name: MISTRAL_API_KEY
            proxyManaged: true
        phase: runtime
        service: mistral
      description: Mistral API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.openai.com
                  format: Bearer %s
                  header: Authorization
            name: OPENAI_API_KEY
            proxyManaged: true
        phase: runtime
        service: openai
      description: OpenAI API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: openrouter.ai
                  format: Bearer %s
                  header: Authorization
            name: OPENROUTER_API_KEY
            proxyManaged: true
        phase: runtime
        service: openrouter
      description: OpenRouter API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.synthetic.com
                  format: Bearer %s
                  header: Authorization
            name: SYNTHETIC_API_KEY
            proxyManaged: true
        phase: runtime
        service: synthetic
      description: Synthetic API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: v0.dev
                  format: Bearer %s
                  header: Authorization
            name: VERCEL_API_KEY
            proxyManaged: true
        phase: runtime
        service: vercel
      description: Vercel v0 API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.zai.com
                  format: Bearer %s
                  header: Authorization
            name: ZAI_API_KEY
            proxyManaged: true
        phase: runtime
        service: zai
      description: Z.ai API access
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/crush-mixin/crush-mixin-context.md
args:
    version:
        default: 0.95.0
        description: Crush release to install from Charm's apt repository
        pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
        buildArg: CRUSH_VERSION