A SimpleX Chat bot that answers arithmetic (closes #1)
check / check (push) Successful in 54s

Remove the template's HTTP service, database and fx wiring. Add exact
arithmetic on go/parser and go/constant, a client that runs simplex-chat
as a child process and drives its WebSocket API, and the bot, which keeps
an auto-accepting address and replies to each message. The image adds the
checksum-pinned simplex-chat v7.0.2 on Ubuntu 22.04.

Model: opus-5-5
This commit is contained in:
clawbot
2026-09-26 22:01:51 +00:00
parent f8ce8cef83
commit 16649e0f2f
66 changed files with 2119 additions and 5059 deletions
+26 -18
View File
@@ -71,8 +71,7 @@ RUN go test -count=1 -timeout 90s -race -cover ./... || \
{ echo "--- Rerunning with -v for details ---"; \
go test -count=1 -timeout 90s -race -v ./...; exit 1; }
# Static build; modernc.org/sqlite is pure Go, so CGO_ENABLED=0 yields
# a fully static binary that runs on the Alpine runtime.
# Static build, so the binary runs on any runtime base.
ARG VERSION=dev
RUN CGO_ENABLED=0 go build -trimpath \
-ldflags "-s -w -X main.version=${VERSION}" \
@@ -82,33 +81,42 @@ RUN CGO_ENABLED=0 go build -trimpath \
# BuildKit builds whichever stage is last and appending one drops lint,
# builder and their checks out of the run. Nothing asserts the name; it
# is here so that failure reads as `[runtime n/m]` in the build log.
# alpine:3.22, 2026-08-07
FROM alpine:3.22@sha256:14358309a308569c32bdc37e2e0e9694be33a9d99e68afb0f5ff33cc1f695dce AS runtime
# Ubuntu 22.04 because it is the release the SimpleX Chat client below
# is built for, and it already has every library that client links
# (glibc, OpenSSL 3, GMP, zlib), so nothing is installed on top.
# ubuntu:22.04, 2026-09-26
FROM ubuntu:22.04@sha256:b8b6ee6aa931ecd9d0d952abc34dc0e5f7c6a30c6bb71b079fe399fde0329c02 AS runtime
RUN apk --no-cache add ca-certificates
# The SimpleX Chat command-line client, which the bot starts and talks
# to. BuildKit checks the download against the checksum and fails the
# build on a mismatch; a new release means changing both the URL and
# the checksum. This is the x86_64 build, so the image is x86_64 only;
# an arm64 image would need the aarch64 build and its own checksum.
# simplex-chat v7.0.2 (simplex-chat-ubuntu-22_04-x86_64), 2026-09-26
ADD --chmod=0755 \
--checksum=sha256:5afb1d25efe5ccf564a1ab124bc7f410a7a73171c974a4d8b7f4d8f2e3d62e77 \
https://github.com/simplex-chat/simplex-chat/releases/download/v7.0.2/simplex-chat-ubuntu-22_04-x86_64 \
/usr/local/bin/simplex-chat
# Create non-root user
RUN addgroup -g 1000 -S simplexcalc && \
adduser -u 1000 -S simplexcalc -G simplexcalc
RUN groupadd --gid 1000 simplexcalc && \
useradd --uid 1000 --gid simplexcalc --home-dir /var/lib/simplexcalc \
--no-create-home --shell /usr/sbin/nologin simplexcalc
WORKDIR /app
# Copy binary from builder
COPY --from=builder /build/bin/simplexcalc /app/simplexcalc
# Data directory: the sqlite database lives here. Mount a volume over
# it in production; everything else in the image is read-only.
RUN mkdir -p /var/lib/simplexcalc
RUN chown -R simplexcalc:simplexcalc /app /var/lib/simplexcalc
# Data directory: the SimpleX database, which holds the bot's profile,
# its keys, its address and its contacts. Mount a volume over it;
# without one, the bot gets a new address every time the container is
# recreated.
RUN mkdir -p /var/lib/simplexcalc && \
chown simplexcalc:simplexcalc /var/lib/simplexcalc
USER simplexcalc
ENV DATA_DIR=/var/lib/simplexcalc
EXPOSE 8080
HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \
CMD wget --no-verbose --tries=1 --spider http://localhost:8080/.well-known/healthcheck.json || exit 1
CMD ["/app/simplexcalc", "serve"]
CMD ["/app/simplexcalc", "run"]