Workspace Images
Production-ready, multi-arch Docker images for isolated agent execution with built-in observability, token compression, and security hardening.
Syntropic137 runs AI agents inside isolated workspace containers. Each workspace is a disposable Docker container pre-loaded with everything an agent needs: the agent CLIs, language tooling, and observability hooks. The same container serves both harnesses, so whether a phase declares agent.provider: claude or agent.provider: codex, the container boundary is the same. On top of the container, codex phases can declare sandbox: workspace-write, which codex enforces inside it.
What's in a Workspace Image
Workspace images are built by agentic-workspace and published to GHCR. Three images matter:
| Image | Harnesses | Notes |
|---|---|---|
ghcr.io/agentparadise/agentic-workspace-buildfloor | claude and codex | The default. omni-agent plus build tooling (build-essential, pkg-config, unzip, rustup, pnpm, bun). SYN_WORKSPACE_DOCKER_IMAGE pins it by digest. |
ghcr.io/agentparadise/agentic-workspace-omni-agent | claude and codex | The lighter base, without the extra build/language tooling. |
ghcr.io/agentparadise/agentic-workspace-claude | claude and codex | The heaviest image. Adds LSP servers and the Rust toolchain, which back Claude Code LSP plugin identifiers and are harness-specific weight. |
All three images ship both CLIs, pinned to explicit versions. What varies is the tooling stacked around them:
| Component | omni-agent | buildfloor | claude |
|---|---|---|---|
| Claude CLI | Yes | Yes | Yes |
| Codex CLI | Yes | Yes | Yes |
| Python 3.12 + uv | Yes | Yes | Yes |
| Node.js 22 LTS | Yes | Yes | Yes |
| GitHub CLI | Yes | Yes | Yes |
| RTK token compression | Yes | Yes | No |
| Build tooling (build-essential, pkg-config, unzip, rustup, pnpm, bun) | No | Yes | No |
| Rust toolchain | No | No | Yes |
| LSP servers (pyright, typescript-language-server, rust-analyzer) | No | No | Yes |
| Claude Code plugins (sdlc, workspace, observability, delegation) | Yes | Yes | Yes |
The plugins and LSP servers exist to back Claude Code features. A codex phase does not use them on either image.
Version Manifest
Not currently produced. ADR-056 specifies a machine-readable
/opt/agentic/version.json in every image, but no provider Dockerfile or the
build staging script creates or copies it. The consumer treats the field as
optional and records None when it is absent, so nothing breaks, but no
workspace event carries component versions today. The shape below is the
specified format, not an observed one.
The intended manifest, which orchestrators would read after container creation:
{
"provider": "omni-agent",
"provider_version": "1.7.1",
"components": {
"claude_cli": "2.1.281",
"codex_cli": "0.156.1",
"rtk": "0.48.0",
"node": "22",
"python": "3.12"
},
"build_commit": "e63b4458",
"built_at": "2026-04-04T16:58:05Z"
}Were it generated, Syntropic137 would record it in the IsolationStartedEvent,
enabling version-aware dashboards and audit trails.
Multi-Architecture Support
Images are built for both linux/amd64 and linux/arm64:
- amd64: Pre-built static binaries (fast builds)
- arm64: prebuilt release binaries per architecture. RTK takes upstream's glibc build on arm64 and its static musl build on amd64
Next Steps
- Features: RTK, OTel observability, LSP, plugins
- Security: Non-root execution, secret injection, supply chain
- Configuration: Environment variables, custom images, tool setup
Syntropic137 Docs v0.33.1 · Last updated March 2026