Conversation
Contributor
Author
|
Hi @xai, as discussed offline, could you have a first look at this approach of dealing with features for tools or if we could/should go another route? |
|
🚀 Deployed preview to https://eclipse-enclave.github.io/enclave-website-previews/pr-previews/pr-127/ |
enclave-agent-npm-install relied on enclave-install-tool to export the npm prefix. Feature install scripts call the helper directly, so npm targeted the root-owned private runtime dir, failed, and the build only warned. The helper now exports the ~/.local prefix it already assumed.
The entrypoint exported SSL_CERT_FILE, REQUESTS_CA_BUNDLE and NODE_EXTRA_CA_CERTS only to its own descendants, and update-ca-certificates fails as the agent user. IDE backends attach with docker exec, so they and the tools they spawn did not trust the gateway, for example the Copilot CLI sign-in failed on api.github.com. The variables are now set on the container, and the entrypoint writes the combined bundle to a fixed path they can point at.
Theia's Copilot provider runs the copilot CLI from its backend inside the container, so the CLI has to be installed in the image. No credential is declared: Theia signs in with `copilot login --device-code` and strips token variables from the CLI's environment. The GitHub allowlist fragment already covers the sign-in and Copilot API hosts. The feature sets failOnInstallError so a failed install cannot pass silently. The Theia READMEs now list all AI providers in one table.
…vider Theia's Claude Code provider loads @anthropic-ai/claude-agent-sdk from its backend inside the container and only searches `npm root -g`, which follows the nvm version and is missing without node-dev. The feature installs the SDK with the private agent Node runtime into ~/.local and sets CLAUDE_AGENT_SDK_PATH for Theia versions that read it; older ones need the ai-features.claudeCode.executablePath preference.
ndoschek
force-pushed
the
feat/theia-agent-providers
branch
from
October 2, 2026 08:43
bca2c2e to
b3a5b25
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What it does
Theia's GitHub Copilot and Claude Code providers run a CLI or SDK from the Theia backend inside the container, which the image didn't provide. This adds two opt-in features:
copilot-cliinstalls the GitHub Copilot CLI. No token is needed; the sign-in runs in Theia.claude-agent-sdkinstalls the Claude Agent SDK into~/.localand setsCLAUDE_AGENT_SDK_PATH. Until Theia reads that variable, pointai-features.claudeCode.executablePathat the SDK.Two general fixes were needed along the way:
enclave-agent-npm-installnow installs into~/.localitself. Feature install scripts calling it directly failed silently before.SSL_CERT_FILE,REQUESTS_CA_BUNDLEandNODE_EXTRA_CA_CERTSare now set on the container, not only exported by the entrypoint. Processes started withdocker exec, such as IDE backends, didn't trust the gateway CA, so the Copilot sign-in failed.How to test
Theia IDE: Create CLI Launcher.enclave --tool theia --features +copilot-cli,+claude-agent-sdkorenclave --tool theia-next --features +copilot-cli,+claude-agent-sdk. This rebuilds the image with both features.ANTHROPIC_API_KEYon the host, or setai-features.claudeCode.apiKeyin Theia's settings.ai-features.claudeCode.executablePathto/home/agent/.local/lib/node_modules/@anthropic-ai/claude-agent-sdk/sdk.mjs.Follow-ups
@openai/codex-sdk, so the Codex agent fails before starting. This needs investigation on the Theia side first.Breaking changes
Review checklist