{"slug": "a-roc-for-you", "title": "A 🪨 roc for you", "summary": "A developer released roc, an open-source Rust tool that launches AI coding agents — opencode, goose, Claude Code and Codex — inside disposable Docker containers with 1:1 host path mounts and a policy-enforced MCP gateway. The tool pools multiple LM Studio, Ollama or OpenAI-compatible model workers (the author runs four 16GB models with 256K-token contexts on a single 256GB Mac Studio) so agents can run unattended against a rolling context window.", "body_md": "[https://github.com/andreimerlescu/roc](https://github.com/andreimerlescu/roc)\n\nThis is `roc` a new #rust project that I wrote with Claude Cowork Opus 5.5 Max. I needed: \n\n`claude` (code), `codex` (openAI), `goose` (by block), or `opencode`. `roc` to run on a single Mac Studio that has 256GB of RAM with multiple parallel loaded models (concurrency set to 1).\nI was sick of having to babysit the agent. In an isolated environment, please, go build. *Implement AGENTS.md* is such a powerful prompt to use.\n\nI configured my `roc` 🪨 to support 4 concurrent models at the same time. They are each 16GB in size and they do a pretty good job. Each have a context window of 256K tokens. This means that I have 4 concurrent workers with a window of 1M tokens before a flush of any quarter. It's configured to use a rolling window and connect to LMStudio when it runs. \n\n`roc -h` returns:\n\n```\nroc (run opencode container): launch AI coding agents (opencode, goose, claude code, codex) against LM Studio, Ollama or any OpenAI-compatible model inside a disposable Docker container with 1:1 host path mounts and a policy-enforced MCP gateway.\n\nUsage: roc [OPTIONS] [-- <AGENT_ARGS>...]\n\nArguments:\n  [AGENT_ARGS]...  Arguments for the agent (after --)\n\nOptions:\n      --provider <KIND>       Model server: lmstudio | ollama | openai | none (saved to state) [env: ROC_PROVIDER=]\n      --ai-host <URL>         OpenAI-compatible base URL, e.g. http://127.0.0.1:1234/v1 (saved to state) [env: ROC_AI_HOST=]\n      --ai-api-token <TOKEN>  API token for the model server (never saved; default: $ROC_AI_API_TOKEN)\n      --ai-model <ID>         Model id; LM Studio workers are <model>, <model>:2, … (saved to state)\n      --qty <N>               Number of model workers in the pool (saved to state)\n      --state <PATH>          State file [env: ROC_STATE=]\n      --binary <NAME>         Agent: opencode | goose | claudecode | codex\n  -w, --write-dir <CSV>       Read-write directories (CSV, repeatable), mounted 1:1\n  -r, --read-dir <CSV>        Read-only directories (CSV, repeatable), mounted 1:1\n      --workdir <PATH>        Working directory inside the container (default: current dir if mounted)\n      --image <IMAGE>         Agent image [env: ROC_IMAGE=]\n      --worker <N>            Use this worker number (default: lowest available)\n      --wait <SECS>           Wait up to SECS for a worker to become available [default: 0]\n      --publish <CSV>         Publish agent container ports on host 127.0.0.1 (CSV: 5173,8080:80)\n      --env <CSV>             Extra env for the agent (CSV): NAME passes the host value, NAME=VALUE sets it\n      --list                  Show worker status: `Q #N: running|available|offline`\n      --json                  With -list: machine readable JSON\n      --cleanup               Remove resources of dead sessions and orphaned roc containers\n      --init                  Guided setup: asks questions and writes the state file and agent configs\n      --yes                   With -init: accept every default without asking (also used when stdin is not a terminal)\n      --agent-config          Show (and create) this config's agent files for -binary, and where they apply\n      --force                 With -init: overwrite an existing state file (a backup is kept)\n      --show-state            Print the state file\n      --build-image           Build the agent image from the Dockerfile embedded in roc\n      --with-playwright       With -build-image: include Playwright + Chromium for the playwright MCP\n      --dry-run               Print what would run (docker command and generated configs) and exit\n      --assume-available      Do not probe the model server; treat every free worker as available\n      --keep-images           Keep images the agent built/pulled when the session ends\n      --no-mcp                Do not start the MCP gateway or configure MCP servers\n      --save                  Save -binary, -image, -read-dir, -write-dir and -publish as defaults\n  -h, --help                  Print help\n  -V, --version               Print version\n\nEXAMPLES:\n  roc -init                      # guided setup\n  roc -list\n  roc -write-dir ~/friends_of/planning -read-dir ~/work\n  roc -ai-model qwen3.8-27b -qty 4 -binary opencode \\\n      -write-dir \"~/friends_of/planning,~/friends_of/knowledge\" -read-dir \"~/work,~/statuses\"\n  roc -provider ollama -ai-model qwen3:27b -qty 2\n  roc -provider openai -ai-host https://api.openai.com/v1 -ai-model gpt-5 -qty 8\n  roc -binary codex -worker 3 -- --search\n  roc -agent-config -binary claudecode\n  roc -cleanup\n\nFlags may be written with one dash (-list) or two (--list).\nDocs: https://github.com/andreimerlescu/roc\n```\n\nYou'll need to have `docker` running and you'll need to run `roc -build-image` in order to get the container that can run the `roc` session. `roc` doesn't run in the container, the `opencode`, `codex`, `claude`, and `goose` binaries are installed via the Dockerfile and used there. My `roc` is using `-binary opencode`.\n\nOnce you have the container you can run `roc -init` and begin the setup process. It writes your answers to your state file, or you can use the `-save` option after supplying your items manually. That writes them to the state file. Don't pass your API keys in CLI arguments since they are leaked in history. \n\nFor my setup, I am using 4 worker agents that I am calling Q #1, Q #2, Q #3 and Q #4 since that's short for `Qwen` and the models are trained off from Qwen3.8-27b for mlx. Since `-worker 4` is set on my hardware, the first time I run `roc` the Q #1 is assigned first. Then the second time I run `roc` then Q #2 is selected. Then #3 and then #4. \n\nI share `roc` with you so that you too can set your agents up for success and let them build in an isolated environment.\n\nFeel free to perform your own security review or code review of the project.\n\nPSA If you have web endpoints that you use services like `httpd` or `nginx` to protect, consider placing `concert` in front of it as an enhanced x402 supporting *waiting room reverse proxy* that has fast lane support and is also open source under Apache 2.0. \n\n[https://github.com/andreimerlescu/concert](https://github.com/andreimerlescu/concert) \n\nEnjoy!\n\nWith great power comes great responsibility!", "url": "https://wpnews.pro/news/a-roc-for-you", "canonical_source": "https://dev.to/andreimerlescu/a-roc-for-you-5hkk", "published_at": "2026-10-08 02:36:37+00:00", "updated_at": "2026-10-08 02:46:53.555771+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools", "agent-protocols", "mlops"], "entities": ["roc", "Rust", "Claude Code", "Codex", "goose", "opencode", "LM Studio", "Ollama"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/a-roc-for-you", "markdown": "https://wpnews.pro/news/a-roc-for-you.md", "text": "https://wpnews.pro/news/a-roc-for-you.txt", "jsonld": "https://wpnews.pro/news/a-roc-for-you.jsonld"}}