From 6a501e91c0c48a3dcf25db6750c460430866021b Mon Sep 17 00:00:00 2001 From: Lucio Lelii Date: Fri, 2 Oct 2026 17:42:30 +0200 Subject: [PATCH] Pass MINIO_MCP_INTERNAL_BUCKET_EXPIRE_DAYS to the MinIO MCP Execution buckets expire after 7 days by default; 0 keeps the files for ever. Co-Authored-By: Claude Sonnet 5.5 --- ENVIRONMENT.md | 2 ++ mcp-stack.compose.yml | 1 + mcp-stack.env.example | 3 +++ 3 files changed, 6 insertions(+) diff --git a/ENVIRONMENT.md b/ENVIRONMENT.md index d384da8..300c73c 100644 --- a/ENVIRONMENT.md +++ b/ENVIRONMENT.md @@ -49,6 +49,7 @@ Generate a token with `openssl rand -hex 32`. | Variable | Default | Meaning | |---|---|---| | `MINIO_MCP_INTERNAL_BUCKET_PREFIX` | `exec-` | Every internal-mode bucket is ``. Cannot be empty; at most 27 lowercase letters, digits or `-`. It is the boundary that keeps the API key inside buckets this server made. | +| `MINIO_MCP_INTERNAL_BUCKET_EXPIRE_DAYS` | `7` | Lifecycle rule set on an execution's bucket when this server creates it: objects are deleted that many days after they were written. `0` sets none. The empty bucket stays. Needs permission to set a bucket lifecycle; if refused, the session still opens and a warning is logged. | | `MINIO_MCP_ALLOWED_ENDPOINTS` | empty (any) | Comma-separated S3 origins, e.g. `https://s3.example.org`. **Set it on an exposed server.** It applies to both modes, so the internal MinIO's endpoint must be on it. | | `MINIO_MCP_DEFAULT_REGION` | `us-east-1` | Region when a session names none. | | `MINIO_MCP_MAX_OBJECT_BYTES` | `1048576` (1 MiB) | Limit for one read and one write. Ceiling 32 MiB. | @@ -186,6 +187,7 @@ cannot be set through `.env`. Defaults shown are the ones in the code. |---|---|---| | `MINIO_MCP_API_KEYS` | none, **required** | | | `MINIO_MCP_INTERNAL_BUCKET_PREFIX` | `exec-` | See above. | +| `MINIO_MCP_INTERNAL_BUCKET_EXPIRE_DAYS` | `7` | See above. | | `MINIO_MCP_ALLOWED_ENDPOINTS` | empty (any) | | | `MINIO_MCP_DEFAULT_REGION` | `us-east-1` | | | `MINIO_MCP_MAX_OBJECT_BYTES` | `1048576` | Ceiling 32 MiB. | diff --git a/mcp-stack.compose.yml b/mcp-stack.compose.yml index 7ee8b5b..b73f6cc 100644 --- a/mcp-stack.compose.yml +++ b/mcp-stack.compose.yml @@ -203,6 +203,7 @@ services: # created on first use. Only the prefix is this server's. The endpoint is reached over # minio-egress and, when the allowlist above is set, has to be on it. MINIO_MCP_INTERNAL_BUCKET_PREFIX: ${MINIO_MCP_INTERNAL_BUCKET_PREFIX:-exec-} + MINIO_MCP_INTERNAL_BUCKET_EXPIRE_DAYS: ${MINIO_MCP_INTERNAL_BUCKET_EXPIRE_DAYS:-7} user: "${MCP_UID:-10001}:${MCP_GID:-10001}" read_only: true tmpfs: diff --git a/mcp-stack.env.example b/mcp-stack.env.example index 4bb1f8d..bf3e7d7 100644 --- a/mcp-stack.env.example +++ b/mcp-stack.env.example @@ -26,6 +26,9 @@ MINIO_MCP_MAX_OBJECT_BYTES=1048576 # buckets, and the endpoint must be on MINIO_MCP_ALLOWED_ENDPOINTS when that is set. # MINIO_MCP_INTERNAL_BUCKET_PREFIX=exec- +# Days after which the files of an execution's bucket are deleted (a lifecycle rule set when the +# bucket is created). 0 keeps them for ever. The empty bucket itself stays. +MINIO_MCP_INTERNAL_BUCKET_EXPIRE_DAYS=7 # Use a dedicated project directory, never a home directory or filesystem root. MCP_WORKSPACE_HOST_PATH=/absolute/path/to/project