Devcontainer addon
Give the repository a reproducible, isolated development container — one that people, editors and coding agents can all use. In DWP v7 (v7.0.0) this addon integrates devcontainer-kit, an MIT product that works without Deep Work Plan, and replaces the template the pack used to carry. It is optional: a repository is fully conformant without it.
What devcontainer-kit provides
- A template, built on the Dev Containers specification, that
dck initrenders into the repository:devcontainer.json, a compose file anddocker/local/. Run again later, it reconciles and never clobbers your edits; any change to an existing file is shown first and needs consent. dck, a launcher that runs the container from a plain terminal —setup,up,shell,ssh,rebuild,doctor— with or without VS Code or Cursor.- Base images in three flavours,
python-3.13,node-24anddebian, that ship without coding agents. - An entrypoint library for persistent volumes, SSH and the environment of SSH sessions, instead of a hand-copied entrypoint per repository.
- Herdr machines. Each container can join Herdr over a loopback-only SSH server, so agents in it become reachable peers.
Install
git clone --branch v0.1.4 https://github.com/DailybotHQ/devcontainer-kit && ./devcontainer-kit/install.sh
cd your-repo && dck init
Requirements: bash 3.2 or newer and python3 3.11 or newer on a Linux or macOS host, and Docker with Compose v2 for the container commands. Verify a release with its SHA256SUMS asset.
| Item | Value |
|---|---|
| Product | DailybotHQ/devcontainer-kit, tag v0.1.4, interface 1 |
| Registry key | devcontainer in .dwp/config.json |
| Per-repository config | .devcontainer/dck.toml |
| Detection | dck doctor --json |
Layers are opt-in
The base images carry the development tools — git, gh, ripgrep, an SSH server, Herdr, and Neovim with DeepWorkPlan Vim pinned by tag — and no coding agent, no reporting CLI and no secret. Everything else is a layer you turn on in dck.toml:
| Layer | Default | What it adds |
|---|---|---|
agents |
off | Installs coding-agents-kit and the CLIs you list, each with its own persistent volume. No permission-bypass flag is set. |
editor |
on | Neovim with DeepWorkPlan Vim; off gives a plain editor. |
Security defaults
- Every published port binds
127.0.0.1unlessdck.tomlsetsbind. - SSH agent forwarding from the host; host private keys are never copied into a container.
- SSH host keys are generated at runtime into a per-project volume, never baked into an image; the server accepts public keys only, with no root login and no passwords.
- The template adds no
cap_add, noprivilegedmode and no Docker socket. - Base images and tools are pinned by version and verified by checksum; compose references the base image by digest whenever the digest can be resolved.
Notes
Optional and never required. A repository is fully conformant with zero optional addons. v0.1 supports Linux and macOS hosts.