Files
fusion/docs/docker.md
gsxdsm 7e3c68249e feat(dashboard): bearer-token auth with browser persistence + MIT license
Pre-release polish. Two related changes bundled because they both land the
project on public-release footing:

Dashboard auth
- fn dashboard now gates the HTTP API + terminal/badge WebSockets behind a
  bearer token by default. Token resolution order: --token flag,
  FUSION_DASHBOARD_TOKEN env, FUSION_DAEMON_TOKEN env (back-compat), or an
  auto-generated fn_<32 hex>. --no-auth disables. The startup banner prints
  a click-to-open URL with ?token=<token> embedded.
- Auth middleware now also accepts fn_token=<token> as a query-string
  fallback so EventSource and WebSocket clients (which can't set custom
  headers) still authenticate.
- setupTerminalWebSocket / setupBadgeWebSocket now refuse unauthenticated
  upgrades with a proper 401 + socket close.
- Frontend: new auth.ts module captures ?token= off the URL into
  localStorage (key fn.authToken), strips it from the visible URL via
  replaceState, and installs a window.fetch wrapper that injects
  Authorization: Bearer <token> on every same-origin /api/* request.
  EventSource/WebSocket URL builders (api.ts, sse-bus.ts, useTerminal,
  useBadgeWebSocket) route through appendTokenQuery().

MIT license
- LICENSE file at repo root.
- license: "MIT" on root package.json and every packages/*/package.json,
  plus description/bugs metadata on the CLI package.

Docs
- docs/cli-reference.md documents --token / --no-auth / FUSION_DASHBOARD_TOKEN
  and the click-to-open auth flow.
- docs/getting-started.md, docs/docker.md, README.md point at the new flow
  and the CLI reference section.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-21 20:12:00 -07:00

91 lines
2.1 KiB
Markdown

# Running Fusion in Docker
This guide shows how to build and run Fusion in a container.
## Build the image
```bash
docker build -t fusion .
```
## Run the dashboard
Mount your project into `/project` and publish the dashboard port:
```bash
docker run -p 4040:4040 -v /path/to/project:/project fusion
```
By default, the container runs:
```bash
fn dashboard
```
on port `4040`.
## Environment variables
Pass provider credentials and integrations with `-e` flags:
```bash
-e ANTHROPIC_API_KEY=...
-e OPENAI_API_KEY=...
-e GITHUB_TOKEN=...
-e FUSION_DASHBOARD_TOKEN=fn_your_stable_token # optional; persists across restarts
```
Add any other provider keys your setup requires (for example `OPENROUTER_API_KEY`).
### Dashboard authentication
The dashboard is bearer-token protected by default. In a container the
auto-generated token appears in `docker logs` on startup — copy it, or set
`FUSION_DASHBOARD_TOKEN` (or the back-compat `FUSION_DAEMON_TOKEN`) to a
stable value so the token survives restarts. See
[CLI reference → fn dashboard → Authentication](./cli-reference.md#fn-dashboard)
for the full flow.
## Pass additional CLI flags
You can append normal CLI arguments after the image name:
```bash
docker run fusion dashboard --port 8080
```
If you change the dashboard port, also update Docker port mapping:
```bash
docker run -p 8080:8080 fusion dashboard --port 8080
```
## Persistence
Fusion state lives in `.fusion` under the mounted project. You can mount it explicitly:
```bash
docker run -p 4040:4040 \
-v /path/to/project:/project \
-v /path/to/project/.fusion:/project/.fusion \
fusion
```
## Complete example
```bash
docker run --rm \
-p 4040:4040 \
-v /path/to/project:/project \
-v /path/to/project/.fusion:/project/.fusion \
-e ANTHROPIC_API_KEY=your_key \
-e OPENAI_API_KEY=your_key \
-e GITHUB_TOKEN=your_token \
fusion dashboard --port 4040
```
## Notes
- The container runs as the non-root `node` user.
- `git` must be available in the project volume for worktree operations (`.git` metadata and repository history are required).