Skip to content

feat: support GitHub Copilot and Claude Code in Theia profiles - #127

Draft
ndoschek wants to merge 4 commits into
eclipse-enclave:mainfrom
ndoschek:feat/theia-agent-providers
Draft

ndoschek wants to merge 4 commits into
eclipse-enclave:mainfrom
ndoschek:feat/theia-agent-providers

Conversation

@ndoschek

Copy link
Copy Markdown
Contributor

What it does

Theia's GitHub Copilot and Claude Code providers run a CLI or SDK from the Theia backend inside the container, which the image didn't provide. This adds two opt-in features:

  • copilot-cli installs the GitHub Copilot CLI. No token is needed; the sign-in runs in Theia.
  • claude-agent-sdk installs the Claude Agent SDK into ~/.local and sets CLAUDE_AGENT_SDK_PATH. Until Theia reads that variable, point ai-features.claudeCode.executablePath at the SDK.

Two general fixes were needed along the way:

  • enclave-agent-npm-install now installs into ~/.local itself. Feature install scripts calling it directly failed silently before.
  • SSL_CERT_FILE, REQUESTS_CA_BUNDLE and NODE_EXTRA_CA_CERTS are now set on the container, not only exported by the entrypoint. Processes started with docker exec, such as IDE backends, didn't trust the gateway CA, so the Copilot sign-in failed.

How to test

  • Prerequisite: the Theia IDE or Theia IDE Next CLI launcher is installed. If it isn't, download Theia IDE or Theia IDE Next and start the AppImage; it offers to install the CLI launcher. You can also create or update the CLI launcher from within the application with the command Theia IDE: Create CLI Launcher.
  • Run enclave --tool theia --features +copilot-cli,+claude-agent-sdk or enclave --tool theia-next --features +copilot-cli,+claude-agent-sdk. This rebuilds the image with both features.
  • GitHub Copilot:
    • In Theia, open AI Configuration > Providers & Models, select GitHub Copilot and sign in. Enter the device code on github.com and confirm in Theia; the sign-in should complete.
    • In the AI Chat, assign a Copilot model to an agent and confirm that a chat request returns a response.
  • Claude Code:
    • Export ANTHROPIC_API_KEY on the host, or set ai-features.claudeCode.apiKey in Theia's settings.
    • Set ai-features.claudeCode.executablePath to /home/agent/.local/lib/node_modules/@anthropic-ai/claude-agent-sdk/sdk.mjs.
    • In the AI Chat, ask the Claude Code agent to list the project's files and confirm it responds.

Follow-ups

  • Codex: Theia's remote backend doesn't include @openai/codex-sdk, so the Codex agent fails before starting. This needs investigation on the Theia side first.
  • The first Copilot request in a new container is slow, because the CLI unpacks itself on first run. This could be done at image build time instead.

Breaking changes

  • This PR introduces breaking changes and has been coordinated with maintainers.

Review checklist

@ndoschek

Copy link
Copy Markdown
Contributor Author

Hi @xai, as discussed offline, could you have a first look at this approach of dealing with features for tools or if we could/should go another route?
I'll loop in the review bot at a later point then.
TIA!

@github-actions

Copy link
Copy Markdown

enclave-agent-npm-install relied on enclave-install-tool to export the
npm prefix. Feature install scripts call the helper directly, so npm
targeted the root-owned private runtime dir, failed, and the build only
warned. The helper now exports the ~/.local prefix it already assumed.
The entrypoint exported SSL_CERT_FILE, REQUESTS_CA_BUNDLE and
NODE_EXTRA_CA_CERTS only to its own descendants, and update-ca-certificates
fails as the agent user. IDE backends attach with docker exec, so they and
the tools they spawn did not trust the gateway, for example the Copilot
CLI sign-in failed on api.github.com.

The variables are now set on the container, and the entrypoint writes the
combined bundle to a fixed path they can point at.
Theia's Copilot provider runs the copilot CLI from its backend inside the
container, so the CLI has to be installed in the image. No credential is
declared: Theia signs in with `copilot login --device-code` and strips
token variables from the CLI's environment. The GitHub allowlist fragment
already covers the sign-in and Copilot API hosts. The feature sets
failOnInstallError so a failed install cannot pass silently.

The Theia READMEs now list all AI providers in one table.
…vider

Theia's Claude Code provider loads @anthropic-ai/claude-agent-sdk from its
backend inside the container and only searches `npm root -g`, which follows
the nvm version and is missing without node-dev. The feature installs the
SDK with the private agent Node runtime into ~/.local and sets
CLAUDE_AGENT_SDK_PATH for Theia versions that read it; older ones need the
ai-features.claudeCode.executablePath preference.
@ndoschek
ndoschek force-pushed the feat/theia-agent-providers branch from bca2c2e to b3a5b25 Compare October 2, 2026 08:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant