Caddy runs as MCP_UID but its /data volume belonged to root (or to the user of an earlier run) and its /config tmpfs started out owned by root, so it could not store a certificate or even create its config folder: port 80 answered, port 443 failed the TLS handshake. The tmpfs now takes the uid and gid, and a one-shot caddy-data-init service gives the /data volume to the same user each time the stack starts; the gateway waits for it. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
|---|---|---|
| browser-mcp | ||
| dev-server-mcp | ||
| .gitignore | ||
| ENVIRONMENT.md | ||
| MCP-STACK.md | ||
| README.md | ||
| egress-proxy.squid.conf | ||
| mcp-stack.Caddyfile | ||
| mcp-stack.compose.yml | ||
| mcp-stack.env.example | ||
| mcp-stack.vm.Caddyfile | ||
| mcp-stack.vm.compose.yml | ||
README.md
MCP stack - Docker Compose deployment
Runs the MCP servers (coding agent, development server, browser,
MinIO) behind one Caddy gateway. The servers’ code and their images live
in the mcps repository; this repository only deploys them
from Docker Hub (luciolelii/*), so the host needs no
sources and no build toolchain.
cp mcp-stack.env.example .env # then fill it in: see ENVIRONMENT.md
docker compose --env-file .env -f mcp-stack.compose.yml pull
docker compose --env-file .env -f mcp-stack.compose.yml up -dOn a dedicated VM add -f mcp-stack.vm.compose.yml to
both commands.
- MCP-STACK.md - what runs, how to start and update it, security notes.
- ENVIRONMENT.md - every environment variable, required and optional.