Portable, hardened TypeScript development container with TMUX IDE, Model Context Protocol (MCP) AI agent tooling, pnpm, vtsls, Biome, Vitest, mobile WebTTY, and dotfiles bootstrap.
- Quick start
- The suite
- 2026 Developer & AI Capabilities
- Architecture & Design
- Security Model
- Portability
- Development & Lifecycle
- Documentation
- License
Clone this repository and spin up a complete, hardened TypeScript terminal IDE in seconds:
git clone https://github.com/sebastienrousseau/tsdev.git
cd tsdev
make up # builds the image and launches the 4-pane TMUX IDEAccess your development environment from any iPad, tablet, or web browser:
make web # starts dark-themed WebTTY at http://localhost:7681
make web-auth # starts WebTTY with password authentication
make mosh # starts roaming UDP shell that survives cellular IP handovers
make doctor # runs system diagnostics (container engine, tools, linters, clipboard)When you are done:
make trash # removes container image and build cache cleanlytsdev is the TypeScript member of the langdev suite:
| Repository | Language Stack | Built-In Tooling | Status |
|---|---|---|---|
langdev |
Core Foundation | Hardened runtime, TMUX IDE, MCP server, ai-pack, WebTTY |
v0.0.4 |
tsdev |
TypeScript 5.8+ | Node 22, pnpm, vtsls, biome, eslint, vitest, tsx |
v0.0.1 |
jsdev |
JavaScript ES2024+ | Node 22, npm, pnpm, biome, eslint, prettier |
v0.0.1 |
pythondev |
Python 3.12+ | uv, ruff, mypy, pytest, debugpy, Pyright |
v0.0.4 |
rustdev |
Rust 1.85+ | rustup, rust-analyzer, clippy, cargo-audit, sccache |
v0.0.4 |
godev |
Go 1.24+ | gopls, golangci-lint, delve, Go toolchain |
v0.0.4 |
javadev |
Java 21+ | OpenJDK 21, Maven, Gradle, JDTLS | v0.0.4 |
kotlindev |
Kotlin 2.1+ | kotlinc, OpenJDK 21, Gradle, Maven, KLS |
v0.0.4 |
swiftdev |
Swift 6.0+ | Swift toolchain, SourceKit-LSP, swift-format |
v0.0.4 |
Every container in the suite includes native, pre-configured tooling for modern AI-assisted engineering:
- Left Panel (20% W): Intelligent project explorer (
langdev-explorer,yazi) with visual Git branch status. - Center-Top (56% W, 70% H): Editor pane loaded with Neovim and language LSP (
vtsls+biome). - Center-Bottom (56% W, 30% H): Integrated bash terminal with pnpm and Node 22 on PATH.
- Right Panel (24% W): Dedicated AI Agent terminal (Claude Code, Agy, Aider, Ollama).
- Automates Git worktrees paired with dedicated TMUX sessions (
muxtree new <branch>,muxtree list,muxtree switch). - Allows human developers and autonomous AI agents to work on separate features concurrently in isolated branches without workspace collisions.
- Standard JSON-RPC 2.0 stdio MCP server exposing container workspace tools (
list_files,read_file,git_status,git_diff,run_tests,run_command). - Pre-configured
common/mcp.jsonconfiguration template for Claude Code, Cursor, and Aider.
tsdev separates the stable runtime from your personal configuration:
- Hardened Base: Alpine Linux with unprivileged non-root user (
dev:1000), read-only root filesystem, dropped Linux capabilities (cap-drop ALL), and no-new-privileges. - User Dotfiles: Cloned and applied at container build time from your chezmoi dotfiles repository.
- TypeScript Toolchain: Pre-installed and verified into
/opt/langdev/toolchain.
- Read-Only Root Filesystem: Rootfs is immutable. Ephemeral paths (
/tmp,~/.cache,~/.local/state) use restricted tmpfs mounts. - Dropped Capabilities: All POSIX capabilities are dropped (
--cap-drop ALL). - No Privilege Escalation: Enforces
no-new-privileges:true. - Zero Secrets in Image: Environment variables and secrets are mounted at runtime via
.envand never baked into layers.
Builds and runs identically with both Docker and Podman:
# Docker
make build
make up
# Podman
make build ENGINE=podman
make up ENGINE=podmanmake test # Run BATS test suite with coverage
make lint # Run hadolint on Containerfile and shellcheck on scripts
make doctor # Run local diagnosticsLicensed under either of:
- Apache License, Version 2.0 (LICENSE-APACHE)
- MIT license (LICENSE-MIT) at your option.