112 lines
6.5 KiB
Plaintext
112 lines
6.5 KiB
Plaintext
# Which build of the four MCP images to run, as published to Docker Hub under luciolelii/. A commit
|
|
# hash of the `mcps` repository, or `latest`. Leave it unset to take the one the compose file names.
|
|
# MCP_IMAGE_TAG=921d54c
|
|
|
|
# Generate each token independently, for example: openssl rand -hex 32
|
|
CODING_AGENT_MCP_API_KEYS=agent=replace-with-at-least-32-random-characters
|
|
DEV_SERVER_MCP_API_KEYS=agent=replace-with-a-different-32-char-token
|
|
BROWSER_MCP_API_KEYS=agent=replace-with-a-third-32-char-token
|
|
MINIO_MCP_API_KEYS=agent=replace-with-a-fourth-32-char-token
|
|
POSTGRES_MCP_API_KEYS=agent=replace-with-a-fifth-32-char-token
|
|
DEV_SERVER_WORKER_TOKEN=replace-with-a-private-worker-token-32-chars
|
|
|
|
# External mode: URL, bucket and credentials are passed once to minio_open_session, not configured
|
|
# on this long-running container. It can therefore hold sessions to different MinIO installations.
|
|
MINIO_MCP_DEFAULT_REGION=us-east-1
|
|
MINIO_MCP_MAX_CONNECTIONS_PER_SESSION=8
|
|
# Optional comma-separated S3 endpoint origins. Leave empty only when every MCP client is trusted
|
|
# to make this server connect to arbitrary HTTP(S) destinations.
|
|
MINIO_MCP_ALLOWED_ENDPOINTS=
|
|
# Applies independently to reads and writes. Base64 overhead is handled by the HTTP body limit.
|
|
MINIO_MCP_MAX_OBJECT_BYTES=1048576
|
|
|
|
# The internal mode is chosen by the catalog entry minio-mcp-internal rather than by the model, and
|
|
# its MinIO endpoint and keys are that entry's headers in the workflow manager's catalog - not
|
|
# variables here. The session arrives with x-minio-scope set to the execution's id, and this server
|
|
# creates the bucket <prefix><execution id> on first use. Those keys must be allowed to create
|
|
# buckets, and the endpoint must be on MINIO_MCP_ALLOWED_ENDPOINTS when that is set.
|
|
#
|
|
MINIO_MCP_INTERNAL_BUCKET_PREFIX=exec-
|
|
# Days after which the files of an execution's bucket are deleted (a lifecycle rule set when the
|
|
# bucket is created). 0 keeps them for ever. The empty bucket itself stays.
|
|
MINIO_MCP_INTERNAL_BUCKET_EXPIRE_DAYS=7
|
|
|
|
# PostgreSQL MCP. External mode: host, database and credentials are passed once to postgres_open_session.
|
|
# It is OFF while this list is empty - the model could otherwise aim the server at any address it can reach -
|
|
# so name the hosts it may use, comma-separated. For the internal mode the list is optional.
|
|
POSTGRES_MCP_ALLOWED_HOSTS=
|
|
POSTGRES_MCP_MAX_ROWS=1000
|
|
POSTGRES_MCP_MAX_RESULT_BYTES=1048576
|
|
POSTGRES_MCP_STATEMENT_TIMEOUT_MS=30000
|
|
#
|
|
# The internal mode is chosen by the catalog entry postgres-mcp-internal, and its host and credentials are
|
|
# that entry's headers in the workflow manager's catalog - not variables here. The session arrives with
|
|
# x-postgres-scope set to the execution's id, and this server makes the database and the user
|
|
# <prefix><execution id> on first use. The catalog's user needs CREATEDB and CREATEROLE, and the secret in
|
|
# its headers has to be the same as the executionRoleSecret of the manager's own storages.json entry.
|
|
POSTGRES_MCP_INTERNAL_DATABASE_PREFIX=exec_
|
|
|
|
# Use a dedicated project directory, never a home directory or filesystem root.
|
|
MCP_WORKSPACE_HOST_PATH=/absolute/path/to/project
|
|
# Whoever owns the workspace directory on the host. This file is read literally - no shell runs
|
|
# over it - so write the numbers that 'id -u' and 'id -g' print, not the commands themselves.
|
|
# Keep 10001: the dev-server image is built with that user, and the volumes the worker mounts take
|
|
# their owner from it. Give the workspace directory to 10001:10001 (sudo chown -R 10001:10001 <dir>)
|
|
# rather than changing these.
|
|
MCP_UID=10001
|
|
MCP_GID=10001
|
|
|
|
# Copy services.example.json and edit the copy. It is mounted read-only.
|
|
DEV_SERVER_SERVICES_CONFIG=./dev-server-mcp/services.example.json
|
|
|
|
# What a caller may run, which is narrower than what the image carries on purpose. npx is left out
|
|
# because it fetches and runs an arbitrary package by name.
|
|
DEV_SERVER_ALLOWED_COMMANDS=node,npm,python3,./mvnw
|
|
|
|
# One instance per execution, each on its own port. Size the range and the cap by memory: two
|
|
# frontend builds saturate the worker's 2 GB, and a Spring project's .m2 is 300 MB of disk apiece.
|
|
DEV_SERVER_PORT_RANGE=5200-5219
|
|
DEV_SERVER_MAX_INSTANCES=4
|
|
|
|
# Every port an execution can be given has to be reachable by the browser, and the allowlist is by
|
|
# exact origin - so the range is spelled out here. Keep it aligned with DEV_SERVER_PORT_RANGE.
|
|
BROWSER_MCP_ALLOWED_ORIGINS=http://dev-server-worker:5173,http://dev-server-worker:5200-5219
|
|
|
|
CODING_AGENT_MCP_PORT=3101
|
|
DEV_SERVER_MCP_PORT=3102
|
|
BROWSER_MCP_PORT=3103
|
|
MINIO_MCP_PORT=3104
|
|
|
|
# The gateway publishes every server under one host by path, which is what the catalog expects.
|
|
MCP_GATEWAY_PORT=3100
|
|
|
|
### Dedicated VM ###
|
|
# Used with the overlay:
|
|
# docker compose --env-file .env -f mcp-stack.compose.yml -f mcp-stack.vm.compose.yml up -d
|
|
#
|
|
# Caddy obtains the certificate itself, from Let's Encrypt, as long as the host answers on 80 or
|
|
# 443 from the internet. Worth knowing when the name is chosen: CAA is evaluated on the canonical
|
|
# name, so a name that is a CNAME into a zone authorising Let's Encrypt is issued without trouble -
|
|
# the way the institute's existing hosts are - while a name resolving straight to an address under
|
|
# isti.cnr.it would be refused, since that zone authorises digicert and sectigo for plain names.
|
|
# Either way Caddy's log says which happened, and the manual fallback is in mcp-stack.vm.Caddyfile.
|
|
# Left commented so that copying this file onto a laptop never starts Caddy in HTTPS mode, which
|
|
# would try to obtain a certificate for the name below from a machine that is not that host.
|
|
# Uncomment all four on the VM.
|
|
# MCP_GATEWAY_CADDYFILE=./mcp-stack.vm.Caddyfile
|
|
# MCP_SITE_ADDRESS=mcp-stack.isti.cnr.it
|
|
# MCP_TLS_CONTACT=lucio.lelii@isti.cnr.it
|
|
# MCP_BIND_ADDRESS=0.0.0.0
|
|
|
|
# The public address a person opens a preview at - the same host the gateway serves, since the
|
|
# preview rides the /preview/ route on it. Leave unset on a laptop stack: without it the dev loop
|
|
# still works (the browser reaches instances internally) and no preview links are handed out.
|
|
DEV_SERVER_PREVIEW_BASE_URL=https://mcp.sse.cloud.isti.cnr.it
|
|
|
|
# Two clocks on a running instance. Idle asks whether anybody is still looking - a preview request
|
|
# or an MCP call resets it - and running out stops the process while keeping the copy, so coming
|
|
# back costs a restart and not a reinstall. The absolute one runs regardless and discards
|
|
# everything, which is the only thing that ever gives the disk back.
|
|
DEV_SERVER_IDLE_TIMEOUT_SECONDS=7200
|
|
DEV_SERVER_MAX_LIFETIME_SECONDS=86400
|