Commit Graph

5 Commits

Author SHA1 Message Date
Lucio Lelii ea6e6ac443 Deploy postgres-mcp beside the other servers
A postgres-mcp service on its own internal control network and an egress one, a /postgres/* route in both
Caddyfiles (and :3105 in the loopback one), and the variables, documented in ENVIRONMENT.md and the
example environment. Its external mode is off until POSTGRES_MCP_ALLOWED_HOSTS lists the hosts it may use.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-02 20:04:52 +02:00
Lucio Lelii 4f0d78b81d Let the caddy-data init cross folders another user owns
With only CAP_CHOWN a root cannot enter a folder an earlier run left owned by another user with
owner-only permissions, so chown -R exited 1 and the gateway never started. DAC_OVERRIDE and
FOWNER are what it needs; reproduced with a volume of such files before and after.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-02 18:33:59 +02:00
Lucio Lelii 7f9fae3538 Let the gateway write its certificate and config as the user it runs as
Caddy runs as MCP_UID but its /data volume belonged to root (or to the user of an earlier run) and
its /config tmpfs started out owned by root, so it could not store a certificate or even create its
config folder: port 80 answered, port 443 failed the TLS handshake.

The tmpfs now takes the uid and gid, and a one-shot caddy-data-init service gives the /data volume
to the same user each time the stack starts; the gateway waits for it.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-02 18:30:40 +02:00
Lucio Lelii 6a501e91c0 Pass MINIO_MCP_INTERNAL_BUCKET_EXPIRE_DAYS to the MinIO MCP
Execution buckets expire after 7 days by default; 0 keeps the files for ever.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-02 17:42:30 +02:00
Lucio Lelii 2e89c7e0b7 Deploy the MCP servers from published images
The compose files, the gateway's Caddyfiles, the egress proxy's configuration and
the example .env, moved out of the mcps repository. That repository builds the four
servers and publishes their images to Docker Hub (luciolelii/*); this one only pulls
them, so a server needs neither the sources nor a build toolchain, and a deploy is a
new image tag.

The compose file names its images by one tag, MCP_IMAGE_TAG, defaulting to the build
it was last checked against. File names are unchanged, so existing commands and the
project name - and with it the volumes - stay as they were.

The dev-server image is built with a fixed user, 10001:10001, and the two volumes the
worker mounts take their owner from it; MCP_UID and MCP_GID therefore stay at 10001
and the workspace directory is given to that user, which the docs now say.

The VM settings in .env.example are commented out. They were live, so copying the file
to a laptop started Caddy in HTTPS mode and had it ask a certificate authority for the
production host name from a machine that is not that host.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-02 11:48:15 +02:00