Successfully implemented automatic image building with embedded Containerfile and change detection for jail-ai. This feature provides a zero-configuration experience while allowing users to customize their development environment.
Created a comprehensive image management module with the following functionality:
Key Functions:
ensure_image_available(image_name)- Main entry point that ensures the default image is builtensure_containerfile_exists()- Creates config directory and writes embedded Containerfile if not presentcalculate_file_hash()- Computes SHA256 hash of Containerfile for change detectionhas_containerfile_changed()- Compares current hash with stored hash to detect modificationsbuild_image_from_containerfile()- Builds image using podman with inherited stdio for progress visibilityimage_exists()- Checks if an image exists locally
Features:
- Embedded Containerfile using
include_str!macro - XDG Base Directory specification compliant (
~/.config/jail-ai/or$XDG_CONFIG_HOME/jail-ai/) - SHA256 hashing for efficient change detection
- Automatic rebuild when Containerfile changes
- Only manages default image; custom images use pull-only logic
Modified the create() method to:
- Import and use the new
imagemodule - Check if the requested image is the default image
- If default: use
ensure_image_available()for automatic building - If custom: use existing pull logic
- Maintains backward compatibility
config/Containerfile (209 lines)
- Copy of the repository's Containerfile for reference
- Will be copied to
~/.config/jail-ai/Containerfileon first use
config/README.md (51 lines)
- Comprehensive documentation on customization
- Explains automatic rebuilding behavior
- Provides manual build commands
- Documents configuration file locations
- Import image module
- Use
image::DEFAULT_IMAGE_NAMEconstant instead of hardcoded string - Maintains consistency across codebase
- Added
DEFAULT_IMAGEconstant - Updated all
default_valueattributes to use the constant - Ensures single source of truth for default image name
- Import new
imagemodule - Replace hardcoded image name with
image::DEFAULT_IMAGE_NAME - Maintains existing functionality
CLAUDE.md:
- Added automatic building information to Container Image section
- Updated usage examples to remove manual build-image requirement
- Added reference to config/README.md
Makefile:
- Updated
build-imagetarget description to note it's optional - Removed
build-imagedependency fromdev-jailandexample-createtargets - Added notes about automatic building
- Upgraded from v0.16.0 to v0.17.0 (minor version bump for new feature)
- User runs
jail-ai createorjail-ai claude - Image module checks if default image exists
- If not, config directory is created at
~/.config/jail-ai/ - Embedded Containerfile is written to
~/.config/jail-ai/Containerfile - Image is built using podman with progress output shown to user
- SHA256 hash of Containerfile is stored in
~/.config/jail-ai/.containerfile.sha256 - Jail is created using the built image
- User runs jail-ai command
- Image module checks if default image exists (yes)
- Calculates current Containerfile hash
- Compares with stored hash (matches)
- Skips build, proceeds with jail creation
- User edits
~/.config/jail-ai/Containerfile - User runs jail-ai command
- Image module calculates new hash
- Detects mismatch with stored hash
- Automatically rebuilds image with new Containerfile
- Updates stored hash
- Proceeds with jail creation using updated image
- Zero Configuration: Users can start immediately without manual image building
- Customizable: Users can edit
~/.config/jail-ai/Containerfileto add tools or modify setup - Automatic Updates: Changes to Containerfile are detected and applied automatically
- Efficient: SHA256 hashing ensures rebuilds only happen when necessary
- Transparent: Build progress is shown to users with inherited stdio
- Backward Compatible: Custom images via
--imageflag still work as before - Clean Separation: Only manages default image; doesn't interfere with user's custom images
- All 15 existing tests pass
- 3 new tests added for image module:
test_embedded_containerfile_not_empty- Verifies embedded Containerfiletest_default_image_name- Checks constant valuetest_calculate_hash_consistency- Validates hash calculation
- Clippy passes with no warnings
- Code formatted with rustfmt
Possible improvements for future versions:
- Support for multiple Containerfile variants (minimal, full, custom)
- Image layer caching optimization
- Parallel building for multiple images
- Integration with container registries for pre-built images
- Containerfile templates system
- Build progress indicators with percentage
- Embedded Containerfile: Compiled into binary at build time
- User Containerfile:
~/.config/jail-ai/Containerfile(or$XDG_CONFIG_HOME/jail-ai/Containerfile) - Hash Cache:
~/.config/jail-ai/.containerfile.sha256 - Reference Containerfile:
config/Containerfilein repository
# First run - automatically builds image
jail-ai create my-agent
# Customize the image
vim ~/.config/jail-ai/Containerfile
# Next run - automatically detects changes and rebuilds
jail-ai create another-agent
# Use custom image (skips automatic build)
jail-ai create custom --image alpine:latest
# Manual build (optional)
make build-image- Rust Version: Works with existing toolchain (edition 2021)
- Dependencies: Only added usage of existing
sha2crate - Platforms: Linux (podman required for building)
- Backends: Automatic building only works with podman backend
- The automatic building feature only applies to the default image (
localhost/jail-ai-env:latest) - Custom images specified via
--imageflag are not automatically built - If podman is not available, appropriate error messages are shown
- The embedded Containerfile is identical to the repository's Containerfile at build time
- Users can safely customize their copy without affecting other users or installations