#!/usr/bin/env bash # Install opencode + provider config (+ Playwright MCP for browser agents). # # Required env (provided by the workflow step): OLLAMA_URL OLLAMA_CLOUD_API_KEY NAME SKILLS # AGENTS GITHUB_PATH HOME set -eu curl -fsSL https://opencode.ai/install | bash echo "$HOME/.opencode/bin" >> "$GITHUB_PATH" mkdir -p ~/.config/opencode # Playwright browser MCP only for agents that need to drive a web app MCP='{}' case "$NAME" in senior|lead|qa) echo "Enabling Playwright MCP for @$NAME" MCP='{"playwright":{"type":"local","command":["npx","-y","@playwright/mcp@latest","--headless"],"enabled":true}}' npx -y playwright install --with-deps chromium || npx -y playwright install chromium || true ;; esac # Per-agent skill scoping. Skills are loaded on-demand by opencode: only a skill's one-line # `description` ever appears in an agent's list, and the full SKILL.md body # (curl/API how-to) is loaded ONLY when the agent calls the `skill` tool — it is never in any # system prompt. To also hide the summary from agents that shouldn't use a skill, we deny all # skills by default and allow only the ones in this agent's registry list (passed via $SKILLS). # A denied skill is hidden entirely (name + description omitted), so e.g. @junior never sees # gitea-api at all; it just knows from the roster that @senior/@lead can, and asks them. SKILLS="${SKILLS:-[]}" PERM=$(jq -nc --argjson s "$SKILLS" ' {skill: ( {"*":"deny"} + (reduce $s[] as $k ({}; . + {($k):"allow"})) )}') # Derive the Ollama Cloud `models:` map from the agent registry itself — single source of truth, # so the provider config and the agent→model mapping in route.sh can't drift. Registry model IDs # are prefixed `ollama-cloud/...`; the provider's are the unprefixed IDs. `// {}` keeps it valid # JSON when no agent uses an ollama-cloud model (e.g. a repo where every agent is anthropic/*). AGENTS="${AGENTS:-{}}" CMODELS=$(printf '%s' "$AGENTS" | jq -c '([.[].model | select(startswith("ollama-cloud/")) | sub("^ollama-cloud/";"")] | unique | map({(.):{}}) | add) // {}') # Two ollama providers: local self-hosted (ornith) + Ollama Cloud (derived above). jq -n --argjson mcp "$MCP" --argjson perm "$PERM" --argjson cmodels "$CMODELS" --arg url "$OLLAMA_URL" --arg ckey "$OLLAMA_CLOUD_API_KEY" '{ provider: { ollama: {npm:"@ai-sdk/openai-compatible", options:{baseURL:($url+"/v1")}, models:{"ornith:35b":{}}}, "ollama-cloud": {npm:"@ai-sdk/openai-compatible", options:{baseURL:"https://ollama.com/v1", apiKey:$ckey}, models:$cmodels} }, permission: $perm, mcp: $mcp }' > ~/.config/opencode/opencode.json echo "opencode config (secrets masked):"; cat ~/.config/opencode/opencode.json