Hardened Go 1.24+ Development Container for AI Agents
High-throughput Go container preloaded with gopls, golangci-lint, delve debugger, Go 1.24+ toolchain, 4-pane TMUX IDE, and stdio Model Context Protocol (MCP) server.
// pkg/server/handler.go · Go 1.24 Generic Stream Handler
func HandleStream[T any](ctx context.Context, in <-chan T) (Stats, error) {
var stats Stats
for {
select {
case <-ctx.Done():
return stats, fmt.Errorf("cancelled: %w", ctx.Err())
case val, ok := <-in:
if !ok { return stats, nil }
stats.Process(val)
}
}
}Engineered for Go Developers & Terminal AI Agents
High-concurrency Go workflows powered by gopls LSP, golangci-lint, and native MCP container tooling.
Go 1.24+ Toolchain
Pre-installed with Go official toolchain, gopls language server, golangci-lint, and dlv debugger.
4-Pane TMUX IDE (Prefix + i)
Dedicated split layout with File Tree Explorer, Neovim (gopls + Treesitter), bash shell, and AI Agent pane.
Parallel AI Task Worktrees (muxtree)
Automate Git worktrees paired with separate TMUX sessions for concurrent multi-agent and human feature branches.
Model Context Protocol (MCP)
Stdio JSON-RPC 2.0 interface exposing go test execution, package discovery, and repository diagnostics to Claude Code and Cursor.
Quick Start in 30 Seconds
Disposable developer environment running anywhere Docker or Podman runs.
# 1. Clone the repository
git clone https://github.com/sebastienrousseau/godev.git
cd godev
# 2. Build and launch 4-pane TMUX IDE
make up
# 3. Mobile WebTTY (port 7681) & Mosh roaming
make web
make mosh
Unified Multi-Language Suite
Every container shares an identical security baseline, TMUX shortcuts, and MCP interfaces.
| Container | Language Stack | Built-in Tooling | Version |
|---|---|---|---|
| langdev | Core Foundation | TMUX IDE, MCP server, ai-pack, WebTTY, OSC 52 | v0.0.4 |
| pythondev | Python 3.12+ | uv, ruff, mypy, pytest, debugpy, Pyright | v0.0.4 |
| rustdev | Rust 1.85+ | rustup, rust-analyzer, clippy, cargo-audit, sccache | v0.0.4 |
| godev | Go 1.24+ | gopls, golangci-lint, delve, Go toolchain | v0.0.4 |
| javadev | Java 21+ | OpenJDK 21, Maven, Gradle, JDTLS | v0.0.4 |
| kotlindev | Kotlin 2.1+ | kotlinc, OpenJDK 21, Gradle, Maven, KLS | v0.0.4 |
| swiftdev | Swift 6.0+ | Swift toolchain, SourceKit-LSP, swift-format | v0.0.4 |
Zero-Trust Hardened Security
Strict security guarantees verified in CI and container runtime.
Unprivileged Non-Root
Runs as unprivileged dev user (UID/GID 1000). Drops all Linux capabilities (cap_drop: [ALL]) with no-new-privileges:true.
Read-Only Root Filesystem
Immutable rootfs prevents container modification or persistent malware. Writable state is restricted to explicit tmpfs mounts.
Supply Chain Integrity
Base images pinned to cryptographic SHA256 digests. Zero unpinned curl-to-sh scripts. Automated CycloneDX SBOM generation.
Hermetic CI & SAST
100% unit tested with Bats, ShellCheck linting, Hadolint OCI auditing, and Trivy CVE vulnerability scans.
Frequently Asked Questions
Are GOCACHE and GOMODCACHE preserved?
Yes. Configurable volume mounts support persisting the Go module cache across container runs.
How fast is the container cold start?
Under 500 milliseconds. All Go toolchain binaries and Neovim plugins are pre-baked.