Ryker_Feng 7aa314b4c1
feat: add Lark CLI integration (#3971)
* feat: add lark cli integration

* fix: polish lark integration actions

* feat: support lark incremental permissions

* fix: detect lark authorization completion

* fix: harden lark integration install

* feat: expand lark auth scopes and reuse host auth in sandbox

Default lark auth to least-privilege (recommend=false, base sign-in only)
and expose the full set of lark-cli --domain business domains as native
--domain grants instead of a 4-domain read-only mapping. Resolve the
skill pack from the latest larksuite/cli GitHub release at install time
with content-hash integrity, and surface version/runtime drift in status.

Share the per-user lark-cli config/data profile between the Gateway
Settings auth flow and agent conversations by mounting the integration
dirs into the AIO sandbox and injecting the matching env for lark-cli
commands, with an allowlisted extra_mounts path in the provisioner/K8s
backend and traversal guards on integration paths.

* style: fix lint issues from ruff and prettier

Sort imports in the provisioner PVC test and re-wrap two long i18n
description strings to satisfy backend ruff and frontend prettier CI.

* fix(lark): address managed integration review feedback

* fix(frontend): stabilize integrations settings e2e

* test(sandbox): isolate remote backend legacy visibility check

* test: fix backend unit failures after merge

* Harden Lark integration review fixes

* Format Lark integration E2E test

* fix(lark): harden sandbox credential exposure and status disclosure

Address willem_bd's security review on PR #3971:

- Mount the per-user lark-cli config dir (long-lived appSecret) read-only
  into the AIO sandbox; only the refreshable-token data dir stays writable.
- Redact host filesystem paths (install_path, cli.path) from
  GET /lark/status and the config/auth complete responses for non-admin
  callers, fail-closed on any auth error.
- Document the npm postinstall trade-off (--ignore-scripts is not viable
  because @larksuite/cli fetches its platform binary in postinstall).
- Document the sandbox credential trust boundary in AGENTS.md and README,
  pointing at the sidecar-broker follow-up (#4338).

---------

Co-authored-by: Willem Jiang <willem.jiang@gmail.com>
2026-07-26 08:09:17 +08:00

64 lines
2.6 KiB
Docker

# syntax=docker/dockerfile:1
#
# DeerFlow "lark-cli init" image (Pattern A).
#
# Purpose: provide the sandbox `lark-cli` runtime binary to a Kubernetes sandbox
# Pod via an init container + shared `emptyDir`, instead of downloading Linux
# binaries from GitHub at install time and mounting them via hostPath/PVC.
#
# At BUILD time (network available) this image downloads and SHA-256-verifies the
# official `larksuite/cli` Linux release binaries and stages the runtime layout:
#
# /opt/lark-cli/bin/lark-cli # arch-dispatch launcher (uname -m)
# /opt/lark-cli/linux-amd64/lark-cli
# /opt/lark-cli/linux-arm64/lark-cli
# /opt/lark-cli/.deerflow-lark-cli-runtime.json # {"version": "vX.Y.Z"}
#
# This layout is byte-identical to what the Gateway writer
# (`_write_lark_cli_sandbox_launcher`) produces and what
# `_validate_lark_cli_sandbox_runtime` enforces, so the sandbox PATH contract
# (`/mnt/integrations/lark-cli/runtime/bin/lark-cli`) is unchanged.
#
# At RUN time the default command copies `/opt/lark-cli/.` into the shared
# emptyDir mounted at `/mnt/integrations/lark-cli/runtime` and exits.
#
# The image tag should encode the lark-cli version so it can be bumped
# independently of the upstream `all-in-one-sandbox` image.
#
# Build (defaults to the pinned version below):
# docker build -t deer-flow/lark-cli-init:v1.0.65 \
# --build-arg LARK_CLI_VERSION=v1.0.65 docker/lark-cli-init
FROM debian:bookworm-slim AS builder
ARG APT_MIRROR
# Version tag on the larksuite/cli GitHub releases (with or without leading "v").
ARG LARK_CLI_VERSION=v1.0.65
RUN if [ -n "${APT_MIRROR}" ]; then \
sed -i "s|deb.debian.org|${APT_MIRROR}|g" /etc/apt/sources.list.d/debian.sources 2>/dev/null || true; \
sed -i "s|deb.debian.org|${APT_MIRROR}|g" /etc/apt/sources.list 2>/dev/null || true; \
fi
RUN apt-get update && apt-get install -y --no-install-recommends \
ca-certificates \
curl \
&& rm -rf /var/lib/apt/lists/*
COPY build-runtime.sh /usr/local/bin/build-runtime.sh
RUN chmod +x /usr/local/bin/build-runtime.sh \
&& LARK_CLI_VERSION="${LARK_CLI_VERSION}" /usr/local/bin/build-runtime.sh /opt/lark-cli
# ── Final image: minimal, just the staged runtime + a copy entrypoint ────────
FROM debian:bookworm-slim
COPY --from=builder /opt/lark-cli /opt/lark-cli
COPY entrypoint.sh /usr/local/bin/lark-cli-init
RUN chmod +x /usr/local/bin/lark-cli-init
# Destination is the emptyDir the provisioner mounts into both this init
# container and the main sandbox container.
ENV LARK_CLI_RUNTIME_DEST=/mnt/integrations/lark-cli/runtime
ENTRYPOINT ["/usr/local/bin/lark-cli-init"]