feat: add one-click Deploy to Render support

Adds a Render Blueprint (render.yaml) and supporting pieces so nanobot can
be deployed to Render in one click, with persistent memory across deploys.

- render.yaml: web service + 1GB persistent disk mounted at
  /home/nanobot/.nanobot. Prompts for ANTHROPIC_API_KEY and
  NANOBOT_WEB_TOKEN at deploy time (sync: false).
- render-config.json: committed gateway config that wires secrets via
  ${VAR} placeholders (resolved at runtime). Nothing secret is committed.
- entrypoint.sh: adds a branch gated on RENDER=true that copies the config
  onto the mounted disk, chowns the root-owned mount, and drops to the
  non-root nanobot user via setpriv. Local (non-Render) path is unchanged.
- Dockerfile: COPY render-config.json; USER nanobot -> USER root so the
  entrypoint can chown the freshly-mounted disk before dropping privileges;
  add PYTHONUNBUFFERED/PYTHONFAULTHANDLER for diagnosable crash output.
- README.md: Deploy to Render button + section.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Ho1yShif
2026-07-18 17:39:59 +08:00
committed by Xubin Ren
co-authored by Claude Opus 4.8
parent afed32b013
commit 770d89b430
5 changed files with 118 additions and 1 deletions
+33
View File
@@ -0,0 +1,33 @@
{
"agents": {
"defaults": {
"model": "anthropic/claude-opus-4-8",
"provider": "auto"
}
},
"providers": {
"anthropic": {
"apiKey": "${ANTHROPIC_API_KEY}"
}
},
"gateway": {
"host": "127.0.0.1",
"port": 18790
},
"channels": {
"websocket": {
"enabled": true,
"host": "0.0.0.0",
"port": 8765,
"token": "${NANOBOT_WEB_TOKEN}",
"websocketRequiresToken": true
}
},
"tools": {
"restrictToWorkspace": true,
"webuiAllowRemotePackageInstall": false,
"my": {
"allowSet": false
}
}
}