Full Docker suite (pnpm test:docker:all)
Builds the shared live-test image, packs OpenClaw once as an npm tarball, builds/reuses a bare Node/Git runner image plus a functional image that installs that tarball into /app, then runs Docker smoke lanes through a weighted scheduler. scripts/package-openclaw-for-docker.mjs is the stable local/CI package packer entrypoint and validates the tarball plus dist/postinstall-inventory.json before Docker consumes it.
- Bare image (
OPENCLAW_DOCKER_E2E_BARE_IMAGE): installer/update/plugin-dependency lanes; mounts the prebuilt tarball instead of copied repo sources. - Functional image (
OPENCLAW_DOCKER_E2E_FUNCTIONAL_IMAGE): normal built-app functionality lanes. - Lane definitions:
scripts/lib/docker-e2e-scenarios.mts. Planner:scripts/lib/docker-e2e-plan.mts. Executor:scripts/test-docker-all.mjs. node scripts/test-docker-all.mjs --plan-jsonemits the scheduler-owned CI plan (lanes, image kinds, package/live-image needs, state scenarios, credential checks) without building or running Docker.
Env var pattern for resource caps is
OPENCLAW_DOCKER_ALL_<RESOURCE>_LIMIT (resource name uppercased, non-alphanumerics collapsed to _).
Other behavior: the runner preflights Docker by default, cleans stale OpenClaw E2E containers, shares provider CLI tool caches between compatible lanes, and stops scheduling new pooled lanes after the first failure unless OPENCLAW_DOCKER_ALL_FAIL_FAST=0 is set. If one lane exceeds the effective weight/resource cap on a low-parallelism host, it can still start from an empty pool and run alone until it releases capacity. Per-lane logs, summary.json, failures.json, and phase timings write under .artifacts/docker-tests/<run-id>/; use pnpm test:docker:timings <summary.json> to inspect slow lanes and pnpm test:docker:rerun <run-id|summary.json|failures.json> to print cheap targeted rerun commands.
Notable Docker lanes
Anthropic runtime-context cache regression
Runpnpm test:docker:live-anthropic-cache with ANTHROPIC_API_KEY to verify
the package-installed Anthropic provider and managed transport against
claude-sonnet-4-6. The functional image uses the prepared candidate package;
OPENCLAW_SKIP_DOCKER_BUILD=1 reuses an existing image.
First run pnpm test:docker:live-anthropic-cache --mock for secretless HTTP/SSE
proof through the same installed builders. Mock output labels its synthetic
usage; only the default live mode proves provider cache reads and writes.
Each builder makes four requests: initial conversation, two actual tool-result
continuations, and the next user turn. The harness moves a synthetic temporary
runtime-context carrier to the request tail and checks that it never becomes a
cache breakpoint or part of a cached prefix. The initial conversation must write
at least 4,096 cache tokens; subsequent reads must reach 90% of that write and
grow after each continuation, while new writes stay below 25% of the initial
write. A short system prompt prevents a system-only cache hit from satisfying
the conversation floor. Every request has a 90-second deadline and no retries.
This blocking lane runs in the stable/full Full Release Validation Docker core
chunk. Logs contain token usage and breakpoint positions, with synthetic prompt
contents kept out of output. Gateway session lifecycle and retained runtime
context remain covered by their owner tests.
Sandbox compatibility lanes
Onboarding E2E (Docker)
Optional; only needed for containerized onboarding smoke tests. Full cold-start flow in a clean Linux container:openclaw health.