environments
The environment-strategy umbrella for robium. Every robium build needs an answer
to "how does this run, identically, on my laptop and on whatever server it ends
up on" before the first line of application code is written. This skill decides
uv vs venv vs Docker, and — once Docker is chosen — how to get GPU passthrough
and remote/headless display right. It does not own multi-module application
Dockerfiles or compose wiring across nodes; that's integration.
When to use this skill
- Starting any new robotics project and the environment strategy isn't decided
yet — this is a required early step, not an optional one.
- The trigger phrases in the description: 'uv', 'venv', 'virtualenv', 'docker
for this project', 'reproducible environment', 'GPU in container'.
- Debugging "works on my machine but not on the server" — almost always an
environment-parity bug, not an application bug.
- Cross-references — go to the sibling skill instead when the question is:
- Wiring multiple app modules together, Dockerfiles for a multi-node app, or
compose files spanning services →
integration (this skill covers a
single environment's shape; integration covers the app that runs in it).
- Remote visualization once headless is decided →
foxglove.
- ROS 2-specific package/build questions once Docker + ROS 2 is chosen →
ros2.
- Picking a manipulation/training framework once the env is settled →
lerobot.
- The whole-stack decision this feeds into →
architect (load that first if
you haven't; it routes here).
Key directives
- Delegation posture: embed. The decision logic (uv vs venv vs Docker) and
the concrete patterns (pyproject.toml shape, Dockerfile shape, GPU/display
flags) live in this skill and its references — this is a foundational,
every-build concern, not a thin pointer to someone else's docs.
- Environment before code. Decide and record the environment strategy
before writing application code. An undecided environment is an open risk,
not a detail to fix later.
- Never
pip install into the system Python. Not on the host, not inside
a container's base image. Every install goes into a project-scoped uv
environment (uv sync, uv run) or, inside Docker, a venv managed the same
way. The only sanctioned exception is a deliberate, explicit --system
flag (or UV_SYSTEM_PYTHON=1) inside a container build stage that is itself
disposable — see references/uv-patterns.md.
- Every project states its env strategy in the architecture brief. If
you're routed here from
architect, write the choice (uv / venv / Docker,
and why) into docs/architecture-brief.md's env-strategy section before
moving on — don't let it live only in your head or in a Dockerfile no one
reads.
- Local == remote is the acceptance test. An environment strategy isn't
done until you can state, concretely, why the same commands produce the
same result on a laptop and on a headless remote server (same base image
digest or lockfile, same Python/CUDA versions, no host-only assumptions). If
you can't state that, the strategy isn't finished — see the parity
checklist in
references/docker-patterns.md.
- Never write image tags or version numbers from memory. Verify current
uv usage against docs.astral.sh/uv, current
ROS 2 image tags against
hub.docker.com/_/ros, and NVIDIA Container
Toolkit steps against
docs.nvidia.com
before committing them to a real project. Every example in this skill is
marked
status: unverified for exactly this reason — treat it as a
starting shape to re-check, not a pinned truth.
Quick start
1. Answer one question: does this project need ROS 2 or other system-level
dependencies (apt packages, native libs, a specific OS)?
- No — pure-Python (ML training/inference, data tooling, a plain script):
use uv.
uv init, define dependencies in pyproject.toml, commit
uv.lock, run everything through uv run. See
references/uv-patterns.md and examples/pyproject-uv.toml.
- Yes — ROS 2, system packages, or a robot's exact host OS matters:
use Docker, built on an official ROS 2 image, with uv installed inside
for any pure-Python pieces of the workspace. See
references/docker-patterns.md and examples/Dockerfile.ros2.
- Both — ROS 2 in one place, a heavy pure-Python ML stack in another:
still Docker, but run uv inside the container for the Python side rather
than fighting the container's system Python. See
references/docker-patterns.md.
2. If Docker, and the project needs a GPU (training, Isaac Sim, CUDA
inference): confirm nvidia-container-toolkit is installed on the host
(Linux only), and run with docker run --gpus all …. See
references/gpu-and-remote.md and examples/Dockerfile.gpu-ml.
3. If the project runs on a headless/remote server: don't reach for X11
forwarding as the default — route visualization to foxglove (web-based,
works over SSH/remote with no display). Reserve X11/Wayland forwarding for
local-Linux-only, single-user cases. See references/gpu-and-remote.md.
4. Record the decision. Write the chosen strategy (and why) into
docs/architecture-brief.md's environment-strategy section.
Decision guidance
Does the project need ROS 2, system apt packages, or a specific OS?
│
├─ No → pure-Python stack
│ └─ uv
│ - `uv init`, pyproject.toml + uv.lock (commit the lock file)
│ - `uv run <cmd>` for everything — never activate-and-forget
│ - `uv venv` only if you need a venv without full project management
│ - See references/uv-patterns.md
│
├─ Yes, and it's ROS 2 / system deps only → Docker
│ └─ Base on an official ROS 2 image (hub.docker.com/_/ros); add a project
│ venv with uv inside only if there's Python glue code beyond ROS 2 nodes.
│ See references/docker-patterns.md, examples/Dockerfile.ros2.
│
└─ Yes, mixed: ROS 2/system deps AND a heavy pure-Python ML stack → Docker
└─ Docker for the system layer, uv for the Python layer *inside* the
container (multi-stage build: uv resolves deps in a builder stage, the
runtime stage copies the resulting venv). Do not `pip install` into
the container's system Python even though you're already in Docker.
See references/docker-patterns.md, examples/Dockerfile.gpu-ml.
Local vs remote parity checklist (the acceptance test from Key
directives — walk this before calling an environment strategy done):
Platform gotchas
- macOS has no native ROS 2. There is no supported native ROS 2 install
on macOS/Apple Silicon — any ROS 2 project on a Mac dev machine goes
straight to Docker, even for local development. Don't try to install ROS 2
natively on macOS as a shortcut. If plain Docker Desktop performance or
networking is a problem, Lima (a lightweight Linux VM manager for macOS)
is a solid alternative for running Docker/containers, and falling back to
a Linux machine (local or remote) is always an option too.
- GPU containers need
nvidia-container-toolkit, and it's Linux-only.
GPU passthrough into Docker (--gpus all) requires the NVIDIA Container
Toolkit installed on the host, and NVIDIA's own install guide covers
Linux distributions only (Ubuntu/Debian/RHEL/Fedora/SUSE) — there is no
first-party Windows/macOS host path. A remote Linux GPU server is the
reliable target for GPU workloads; a local macOS dev machine cannot run
GPU containers at all. See references/gpu-and-remote.md.
- X11/Wayland forwarding vs headless + web viz. Forwarding a display out
of a container (X11 sockets,
DISPLAY env, xhost) works for local-Linux
development but breaks down over SSH to a remote server and doesn't work
from macOS/Windows hosts without extra tooling. For anything remote or
cross-platform, default to headless containers plus web-based
visualization — route that to the foxglove skill rather than fighting
display forwarding.
Customization
- Different Python version: pin it explicitly —
uv python pin <version> for uv projects, or the base image tag for Docker (e.g. the
Python tag on the official ROS 2 / python images) — rather than relying
on whatever the environment happens to have.
- Different ROS 2 distro: swap the base image tag in
examples/Dockerfile.ros2 (e.g. jazzy ↔ lyrical); re-verify the tag
exists on hub.docker.com/_/ros first —
see architect's Platform gotchas for the current distro
recommendation (Lyrical Luth generally; Jazzy Jalisco for the Nav2
vertical).
- Different GPU / CUDA version: swap the
nvidia/cuda base tag in
examples/Dockerfile.gpu-ml to match the target host's driver-supported
CUDA version — check with nvidia-smi on that host, don't assume.
- Adding system packages to a uv-only project: that's the signal to
graduate from uv to Docker, not to reach for
pip install --system or
host-level apt install as a workaround — see the decision tree above.
References
references/uv-patterns.md — pyproject.toml shape, uv sync/uv run,
lockfiles, dependency groups, and when to graduate to Docker.
references/docker-patterns.md — multi-stage Docker builds with uv inside,
official ROS 2 image tags and variants, local/remote parity mechanics.
references/gpu-and-remote.md — NVIDIA Container Toolkit setup, --gpus all, headless/remote display strategy and the handoff to foxglove.
examples/pyproject-uv.toml — minimal pure-Python uv project (status:
unverified).
examples/Dockerfile.ros2 — ROS 2 workspace container with uv for the
Python-glue layer (status: unverified).
examples/Dockerfile.gpu-ml — GPU-enabled multi-stage uv build for an ML
training/inference container (status: unverified).
- Upstream: uv docs, uv + Docker
guide, official ROS
2 images, NVIDIA Container Toolkit
docs.
Sibling skills:
architect (routes here early), integration
(multi-module app Dockerfiles/compose — not duplicated here), foxglove
(remote/headless visualization), ros2, lerobot.
Changelog
- 1.1.0 (2026-07-11): nav-trial absorption — parity checklist gains the
buildx-cache caveat (
down --rmi local ≠ cold rebuild; add docker builder prune for a true cold check). Dockerfile.ros2 shape exercised
successfully via adaptation in a real arm64 build (not verbatim, so the
example stays unverified).
1---2name: environments-33description: Virtual-environment-first setup for robotics projects: decide uv/venv vs Docker, make local and remote-server runs reproduce identically, handle GPU passthrough and headless/display forwarding. Use when: setting up any new robotics project environment; 'uv', 'venv', 'virtualenv', 'docker for this project', 'reproducible environment', 'works locally but not on the server', 'GPU in container'. Load early in any robium build, right after architect. Decision rule of thumb: pure-Python ML stacks → uv; anything needing ROS 2 or system deps → Docker. Not for: multi-module application Dockerfiles and compose wiring (integration skill).4---56# environments78The environment-strategy umbrella for robium. Every robium build needs an answer9to "how does this run, identically, on my laptop and on whatever server it ends10up on" before the first line of application code is written. This skill decides11uv vs venv vs Docker, and — once Docker is chosen — how to get GPU passthrough12and remote/headless display right. It does not own multi-module application13Dockerfiles or compose wiring across nodes; that's `integration`.1415## When to use this skill1617- Starting any new robotics project and the environment strategy isn't decided18 yet — this is a required early step, not an optional one.19- The trigger phrases in the description: 'uv', 'venv', 'virtualenv', 'docker20 for this project', 'reproducible environment', 'GPU in container'.21- Debugging "works on my machine but not on the server" — almost always an22 environment-parity bug, not an application bug.23- Cross-references — go to the sibling skill instead when the question is:24 - Wiring multiple app modules together, Dockerfiles for a multi-node app, or25 compose files spanning services → `integration` (this skill covers a26 *single* environment's shape; `integration` covers the app that runs in it).27 - Remote visualization once headless is decided → `foxglove`.28 - ROS 2-specific package/build questions once Docker + ROS 2 is chosen →29 `ros2`.30 - Picking a manipulation/training framework once the env is settled →31 `lerobot`.32 - The whole-stack decision this feeds into → `architect` (load that first if33 you haven't; it routes here).3435## Key directives3637- **Delegation posture: embed.** The decision logic (uv vs venv vs Docker) and38 the concrete patterns (pyproject.toml shape, Dockerfile shape, GPU/display39 flags) live in this skill and its references — this is a foundational,40 every-build concern, not a thin pointer to someone else's docs.41- **Environment before code.** Decide and record the environment strategy42 before writing application code. An undecided environment is an open risk,43 not a detail to fix later.44- **Never `pip install` into the system Python.** Not on the host, not inside45 a container's base image. Every install goes into a project-scoped uv46 environment (`uv sync`, `uv run`) or, inside Docker, a venv managed the same47 way. The only sanctioned exception is a deliberate, explicit `--system`48 flag (or `UV_SYSTEM_PYTHON=1`) inside a container build stage that is itself49 disposable — see `references/uv-patterns.md`.50- **Every project states its env strategy in the architecture brief.** If51 you're routed here from `architect`, write the choice (uv / venv / Docker,52 and why) into `docs/architecture-brief.md`'s env-strategy section before53 moving on — don't let it live only in your head or in a Dockerfile no one54 reads.55- **Local == remote is the acceptance test.** An environment strategy isn't56 done until you can state, concretely, why the same commands produce the57 same result on a laptop and on a headless remote server (same base image58 digest or lockfile, same Python/CUDA versions, no host-only assumptions). If59 you can't state that, the strategy isn't finished — see the parity60 checklist in `references/docker-patterns.md`.61- **Never write image tags or version numbers from memory.** Verify current62 uv usage against [docs.astral.sh/uv](https://docs.astral.sh/uv/), current63 ROS 2 image tags against64 [hub.docker.com/_/ros](https://hub.docker.com/_/ros), and NVIDIA Container65 Toolkit steps against66 [docs.nvidia.com](https://docs.nvidia.com/datacenter/cloud-native/container-toolkit/latest/)67 before committing them to a real project. Every example in this skill is68 marked `status: unverified` for exactly this reason — treat it as a69 starting shape to re-check, not a pinned truth.7071## Quick start7273**1. Answer one question: does this project need ROS 2 or other system-level74dependencies (apt packages, native libs, a specific OS)?**7576- **No — pure-Python (ML training/inference, data tooling, a plain script):**77 use **uv**. `uv init`, define dependencies in `pyproject.toml`, commit78 `uv.lock`, run everything through `uv run`. See79 `references/uv-patterns.md` and `examples/pyproject-uv.toml`.80- **Yes — ROS 2, system packages, or a robot's exact host OS matters:**81 use **Docker**, built on an official ROS 2 image, with uv installed inside82 for any pure-Python pieces of the workspace. See83 `references/docker-patterns.md` and `examples/Dockerfile.ros2`.84- **Both — ROS 2 in one place, a heavy pure-Python ML stack in another:**85 still Docker, but run uv *inside* the container for the Python side rather86 than fighting the container's system Python. See87 `references/docker-patterns.md`.8889**2. If Docker, and the project needs a GPU (training, Isaac Sim, CUDA90inference):** confirm `nvidia-container-toolkit` is installed on the host91(Linux only), and run with `docker run --gpus all …`. See92`references/gpu-and-remote.md` and `examples/Dockerfile.gpu-ml`.9394**3. If the project runs on a headless/remote server:** don't reach for X1195forwarding as the default — route visualization to `foxglove` (web-based,96works over SSH/remote with no display). Reserve X11/Wayland forwarding for97local-Linux-only, single-user cases. See `references/gpu-and-remote.md`.9899**4. Record the decision.** Write the chosen strategy (and why) into100`docs/architecture-brief.md`'s environment-strategy section.101102## Decision guidance103104```105Does the project need ROS 2, system apt packages, or a specific OS?106│107├─ No → pure-Python stack108│ └─ uv109│ - `uv init`, pyproject.toml + uv.lock (commit the lock file)110│ - `uv run <cmd>` for everything — never activate-and-forget111│ - `uv venv` only if you need a venv without full project management112│ - See references/uv-patterns.md113│114├─ Yes, and it's ROS 2 / system deps only → Docker115│ └─ Base on an official ROS 2 image (hub.docker.com/_/ros); add a project116│ venv with uv inside only if there's Python glue code beyond ROS 2 nodes.117│ See references/docker-patterns.md, examples/Dockerfile.ros2.118│119└─ Yes, mixed: ROS 2/system deps AND a heavy pure-Python ML stack → Docker120 └─ Docker for the system layer, uv for the Python layer *inside* the121 container (multi-stage build: uv resolves deps in a builder stage, the122 runtime stage copies the resulting venv). Do not `pip install` into123 the container's system Python even though you're already in Docker.124 See references/docker-patterns.md, examples/Dockerfile.gpu-ml.125```126127**Local vs remote parity checklist** (the acceptance test from Key128directives — walk this before calling an environment strategy done):129130- [ ] Base image is pinned to a specific tag (and ideally digest), not131 `latest` — so "remote" can't silently drift from "local".132- [ ] `uv.lock` (or the container image itself) is the single source of133 truth for dependency versions — no "just pip install X" steps documented134 as a workaround anywhere.135- [ ] GPU projects: the CUDA version baked into the image matches what the136 remote host's driver supports (see `references/gpu-and-remote.md`) — don't137 assume the dev laptop's CUDA matches the server's.138- [ ] No hardcoded local paths, display assumptions, or "run this manual step139 first" instructions that only work on one machine.140- [ ] The same `docker run` / `uv run` invocation (modulo GPU flags) is141 documented for both local and remote use.142- [ ] "Clean-room" claims name what was actually cold: `docker compose down143 --rmi local` removes the image but NOT the buildx layer cache, so a144 rebuild-and-pass after it proves the committed build definition works —145 not that a cold host (fresh apt downloads) reproduces it. A truly cold146 check additionally needs `docker builder prune`. Verified 2026-07-11147 (nav-trial).148149## Platform gotchas150151- **macOS has no native ROS 2.** There is no supported native ROS 2 install152 on macOS/Apple Silicon — any ROS 2 project on a Mac dev machine goes153 straight to Docker, even for local development. Don't try to install ROS 2154 natively on macOS as a shortcut. If plain Docker Desktop performance or155 networking is a problem, Lima (a lightweight Linux VM manager for macOS)156 is a solid alternative for running Docker/containers, and falling back to157 a Linux machine (local or remote) is always an option too.158- **GPU containers need `nvidia-container-toolkit`, and it's Linux-only.**159 GPU passthrough into Docker (`--gpus all`) requires the NVIDIA Container160 Toolkit installed on the *host*, and NVIDIA's own install guide covers161 Linux distributions only (Ubuntu/Debian/RHEL/Fedora/SUSE) — there is no162 first-party Windows/macOS host path. A remote Linux GPU server is the163 reliable target for GPU workloads; a local macOS dev machine cannot run164 GPU containers at all. See `references/gpu-and-remote.md`.165- **X11/Wayland forwarding vs headless + web viz.** Forwarding a display out166 of a container (X11 sockets, `DISPLAY` env, `xhost`) works for local-Linux167 development but breaks down over SSH to a remote server and doesn't work168 from macOS/Windows hosts without extra tooling. For anything remote or169 cross-platform, default to headless containers plus web-based170 visualization — route that to the `foxglove` skill rather than fighting171 display forwarding.172173## Customization174175- **Different Python version:** pin it explicitly — `uv python pin176 <version>` for uv projects, or the base image tag for Docker (e.g. the177 Python tag on the official ROS 2 / `python` images) — rather than relying178 on whatever the environment happens to have.179- **Different ROS 2 distro:** swap the base image tag in180 `examples/Dockerfile.ros2` (e.g. `jazzy` ↔ `lyrical`); re-verify the tag181 exists on [hub.docker.com/_/ros](https://hub.docker.com/_/ros) first —182 see `architect`'s Platform gotchas for the current distro183 recommendation (Lyrical Luth generally; Jazzy Jalisco for the Nav2184 vertical).185- **Different GPU / CUDA version:** swap the `nvidia/cuda` base tag in186 `examples/Dockerfile.gpu-ml` to match the target host's driver-supported187 CUDA version — check with `nvidia-smi` on that host, don't assume.188- **Adding system packages to a uv-only project:** that's the signal to189 graduate from uv to Docker, not to reach for `pip install --system` or190 host-level `apt install` as a workaround — see the decision tree above.191192## References193194- `references/uv-patterns.md` — pyproject.toml shape, `uv sync`/`uv run`,195 lockfiles, dependency groups, and when to graduate to Docker.196- `references/docker-patterns.md` — multi-stage Docker builds with uv inside,197 official ROS 2 image tags and variants, local/remote parity mechanics.198- `references/gpu-and-remote.md` — NVIDIA Container Toolkit setup, `--gpus199 all`, headless/remote display strategy and the handoff to `foxglove`.200- `examples/pyproject-uv.toml` — minimal pure-Python uv project (status:201 unverified).202- `examples/Dockerfile.ros2` — ROS 2 workspace container with uv for the203 Python-glue layer (status: unverified).204- `examples/Dockerfile.gpu-ml` — GPU-enabled multi-stage uv build for an ML205 training/inference container (status: unverified).206- Upstream: [uv docs](https://docs.astral.sh/uv/), [uv + Docker207 guide](https://docs.astral.sh/uv/guides/integration/docker/), [official ROS208 2 images](https://hub.docker.com/_/ros), [NVIDIA Container Toolkit209 docs](https://docs.nvidia.com/datacenter/cloud-native/container-toolkit/latest/).210 Sibling skills: `architect` (routes here early), `integration`211 (multi-module app Dockerfiles/compose — not duplicated here), `foxglove`212 (remote/headless visualization), `ros2`, `lerobot`.213214## Changelog215216<!-- One dated line per battle-tested change, added by skill-author hardening sessions. -->217218- 1.1.0 (2026-07-11): nav-trial absorption — parity checklist gains the219 buildx-cache caveat (`down --rmi local` ≠ cold rebuild; add `docker220 builder prune` for a true cold check). Dockerfile.ros2 shape exercised221 successfully via adaptation in a real arm64 build (not verbatim, so the222 example stays unverified).