Workspaces

Workspace Images

Production-ready, multi-arch Docker images for isolated agent execution with built-in observability, token compression, and security hardening.

Syntropic137 runs AI agents inside isolated workspace containers. Each workspace is a disposable Docker container pre-loaded with everything an agent needs: the agent CLIs, language tooling, and observability hooks. The same container serves both harnesses, so whether a phase declares agent.provider: claude or agent.provider: codex, the container boundary is the same. On top of the container, codex phases can declare sandbox: workspace-write, which codex enforces inside it.

What's in a Workspace Image

Workspace images are built by agentic-workspace and published to GHCR. Three images matter:

ImageHarnessesNotes
ghcr.io/agentparadise/agentic-workspace-buildfloorclaude and codexThe default. omni-agent plus build tooling (build-essential, pkg-config, unzip, rustup, pnpm, bun). SYN_WORKSPACE_DOCKER_IMAGE pins it by digest.
ghcr.io/agentparadise/agentic-workspace-omni-agentclaude and codexThe lighter base, without the extra build/language tooling.
ghcr.io/agentparadise/agentic-workspace-claudeclaude and codexThe heaviest image. Adds LSP servers and the Rust toolchain, which back Claude Code LSP plugin identifiers and are harness-specific weight.

All three images ship both CLIs, pinned to explicit versions. What varies is the tooling stacked around them:

Componentomni-agentbuildfloorclaude
Claude CLIYesYesYes
Codex CLIYesYesYes
Python 3.12 + uvYesYesYes
Node.js 22 LTSYesYesYes
GitHub CLIYesYesYes
RTK token compressionYesYesNo
Build tooling (build-essential, pkg-config, unzip, rustup, pnpm, bun)NoYesNo
Rust toolchainNoNoYes
LSP servers (pyright, typescript-language-server, rust-analyzer)NoNoYes
Claude Code plugins (sdlc, workspace, observability, delegation)YesYesYes

The plugins and LSP servers exist to back Claude Code features. A codex phase does not use them on either image.

Version Manifest

Not currently produced. ADR-056 specifies a machine-readable /opt/agentic/version.json in every image, but no provider Dockerfile or the build staging script creates or copies it. The consumer treats the field as optional and records None when it is absent, so nothing breaks, but no workspace event carries component versions today. The shape below is the specified format, not an observed one.

The intended manifest, which orchestrators would read after container creation:

{
  "provider": "omni-agent",
  "provider_version": "1.7.1",
  "components": {
    "claude_cli": "2.1.281",
    "codex_cli": "0.156.1",
    "rtk": "0.48.0",
    "node": "22",
    "python": "3.12"
  },
  "build_commit": "e63b4458",
  "built_at": "2026-04-04T16:58:05Z"
}

Were it generated, Syntropic137 would record it in the IsolationStartedEvent, enabling version-aware dashboards and audit trails.

Multi-Architecture Support

Images are built for both linux/amd64 and linux/arm64:

  • amd64: Pre-built static binaries (fast builds)
  • arm64: prebuilt release binaries per architecture. RTK takes upstream's glibc build on arm64 and its static musl build on amd64

Next Steps

  • Features: RTK, OTel observability, LSP, plugins
  • Security: Non-root execution, secret injection, supply chain
  • Configuration: Environment variables, custom images, tool setup

Syntropic137 Docs v0.33.1 · Last updated March 2026

On this page