sha256:b52393e9429c01b0f70f343099e78a18f277badb970dadfb64357ddf69549dd6
Last pushed
about 16 hours by sbx
Type
Sandbox Kit
Manifest digest
sha256:b52393e9429c01b0f70f343099e78a18f277badb970dadfb64357ddf69549dd6
schemaVersion: "3"
displayName: Crush (mixin)
description: Charm's multi-provider AI coding agent as a mixin -- the Crush binary in an overlay, with proxy-mediated auth for 15 model providers and the egress they need. Layer it onto a shell base and run `crush`.
version: 0.95.0
kind: mixin
provides:
- [email protected]
capabilities:
- type: com.docker.sandbox/network-policy@1
config:
runtime:
allow:
- api.anthropic.com
- api.openai.com
- '*.openai.azure.com'
- generativelanguage.googleapis.com
- api.mistral.ai
- api.groq.com
- groq.com
- api.cerebras.ai
- openrouter.ai
- api-inference.huggingface.co
- api.io.net
- api.minimax.chat
- api.synthetic.com
- api.zai.com
- v0.dev
- bedrock-runtime.us-east-1.amazonaws.com
- bedrock.us-east-1.amazonaws.com
- bedrock-runtime.us-east-2.amazonaws.com
- bedrock.us-east-2.amazonaws.com
- bedrock-runtime.us-west-2.amazonaws.com
- bedrock.us-west-2.amazonaws.com
- bedrock-runtime.eu-central-1.amazonaws.com
- bedrock.eu-central-1.amazonaws.com
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.anthropic.com
format: '%s'
header: x-api-key
name: ANTHROPIC_API_KEY
proxyManaged: true
phase: runtime
service: anthropic
description: Anthropic API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: bedrock-runtime.us-east-1.amazonaws.com
format: AWS4-HMAC-SHA256 Credential=%s/
header: Authorization
- domain: bedrock.us-east-1.amazonaws.com
format: AWS4-HMAC-SHA256 Credential=%s/
header: Authorization
- domain: bedrock-runtime.us-east-2.amazonaws.com
format: AWS4-HMAC-SHA256 Credential=%s/
header: Authorization
- domain: bedrock.us-east-2.amazonaws.com
format: AWS4-HMAC-SHA256 Credential=%s/
header: Authorization
- domain: bedrock-runtime.us-west-2.amazonaws.com
format: AWS4-HMAC-SHA256 Credential=%s/
header: Authorization
- domain: bedrock.us-west-2.amazonaws.com
format: AWS4-HMAC-SHA256 Credential=%s/
header: Authorization
- domain: bedrock-runtime.eu-central-1.amazonaws.com
format: AWS4-HMAC-SHA256 Credential=%s/
header: Authorization
- domain: bedrock.eu-central-1.amazonaws.com
format: AWS4-HMAC-SHA256 Credential=%s/
header: Authorization
name: AWS_ACCESS_KEY_ID
proxyManaged: true
phase: runtime
service: aws
description: AWS Bedrock access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: '*.openai.azure.com'
format: '%s'
header: api-key
name: AZURE_OPENAI_API_KEY
proxyManaged: true
phase: runtime
service: azure-openai
description: Azure OpenAI access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.cerebras.ai
format: Bearer %s
header: Authorization
name: CEREBRAS_API_KEY
proxyManaged: true
phase: runtime
service: cerebras
description: Cerebras API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: generativelanguage.googleapis.com
format: '%s'
header: x-goog-api-key
name: GEMINI_API_KEY
proxyManaged: true
phase: runtime
service: google
description: Google AI API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.groq.com
format: Bearer %s
header: Authorization
- domain: groq.com
format: Bearer %s
header: Authorization
name: GROQ_API_KEY
proxyManaged: true
phase: runtime
service: groq
description: Groq API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api-inference.huggingface.co
format: Bearer %s
header: Authorization
name: HF_TOKEN
proxyManaged: true
phase: runtime
service: huggingface
description: Hugging Face inference access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.io.net
format: Bearer %s
header: Authorization
name: IONET_API_KEY
proxyManaged: true
phase: runtime
service: ionet
description: io.net API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.minimax.chat
format: Bearer %s
header: Authorization
name: MINIMAX_API_KEY
proxyManaged: true
phase: runtime
service: minimax
description: MiniMax API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.mistral.ai
format: Bearer %s
header: Authorization
name: MISTRAL_API_KEY
proxyManaged: true
phase: runtime
service: mistral
description: Mistral API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.openai.com
format: Bearer %s
header: Authorization
name: OPENAI_API_KEY
proxyManaged: true
phase: runtime
service: openai
description: OpenAI API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: openrouter.ai
format: Bearer %s
header: Authorization
name: OPENROUTER_API_KEY
proxyManaged: true
phase: runtime
service: openrouter
description: OpenRouter API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.synthetic.com
format: Bearer %s
header: Authorization
name: SYNTHETIC_API_KEY
proxyManaged: true
phase: runtime
service: synthetic
description: Synthetic API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: v0.dev
format: Bearer %s
header: Authorization
name: VERCEL_API_KEY
proxyManaged: true
phase: runtime
service: vercel
description: Vercel v0 API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.zai.com
format: Bearer %s
header: Authorization
name: ZAI_API_KEY
proxyManaged: true
phase: runtime
service: zai
description: Z.ai API access
- type: com.docker.sandbox/agent-context@1
config:
contentFile: /usr/share/sandbox/kit/crush-mixin/crush-mixin-context.md
args:
version:
default: 0.95.0
description: Crush release to install from Charm's apt repository
pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
buildArg: CRUSH_VERSION