Compare commits
3 Commits
fix/inject
...
7716e424f9
| Author | SHA1 | Date | |
|---|---|---|---|
| 7716e424f9 | |||
|
|
f097c0f4d5 | ||
| c79bdab51b |
36
deploy/Dockerfile.gitea-mcp
Normal file
36
deploy/Dockerfile.gitea-mcp
Normal file
@@ -0,0 +1,36 @@
|
||||
# gitea-mcp-server, rebuilt on a shell-bearing base.
|
||||
#
|
||||
# WHY THIS EXISTS
|
||||
# ---------------
|
||||
# Upstream `docker.gitea.com/gitea-mcp-server` is distroless: `Cmd` is
|
||||
# ["/app/gitea-mcp"] and there is no /bin/sh at any path (verified by exec'ing
|
||||
# every candidate against the running pod).
|
||||
#
|
||||
# That is fine until the server needs `secretDelivery: injector`. The OpenBao
|
||||
# agent renders secrets to a FILE, so mcpd wraps the container command as
|
||||
# `sh -c '. /vault/secrets/<name>; exec "$0" "$@"'` — which needs a shell. With
|
||||
# no shell the pod cannot source its own credentials, and gitea was the single
|
||||
# server in the fleet blocked on this.
|
||||
#
|
||||
# Copying one static Go binary onto debian:stable-slim is cheaper than building
|
||||
# and maintaining a static "envexec" shim, and follows the precedent already set
|
||||
# by deploy/Dockerfile.docmost-mcp — this repo already rebuilds third-party MCP
|
||||
# servers when it needs to change how they run.
|
||||
#
|
||||
# ca-certificates is required, not incidental: the binary talks HTTPS to
|
||||
# https://mysources.co.uk and a distroless base ships its own trust store which
|
||||
# we are leaving behind.
|
||||
FROM debian:stable-slim
|
||||
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends ca-certificates \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
COPY --from=docker.gitea.com/gitea-mcp-server:latest /app/gitea-mcp /usr/local/bin/gitea-mcp
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# Kept as ENTRYPOINT so the plain (non-injected) path behaves exactly like
|
||||
# upstream. mcpd REPLACES this with the sourcing wrapper when the server opts
|
||||
# into injected delivery — that is why a shell has to exist in the image.
|
||||
ENTRYPOINT ["/usr/local/bin/gitea-mcp"]
|
||||
36
scripts/build-gitea-mcp.sh
Executable file
36
scripts/build-gitea-mcp.sh
Executable file
@@ -0,0 +1,36 @@
|
||||
#!/bin/bash
|
||||
# Build gitea-mcp Docker image and push to Gitea container registry
|
||||
set -e
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
|
||||
PROJECT_ROOT="$(dirname "$SCRIPT_DIR")"
|
||||
cd "$PROJECT_ROOT"
|
||||
|
||||
# Load .env for GITEA_TOKEN
|
||||
if [ -f .env ]; then
|
||||
set -a; source .env; set +a
|
||||
fi
|
||||
|
||||
# Push directly to internal address (external proxy has body size limit)
|
||||
REGISTRY="10.0.0.194:3012"
|
||||
IMAGE="gitea-mcp"
|
||||
TAG="${1:-latest}"
|
||||
|
||||
echo "==> Building gitea-mcp image..."
|
||||
podman build -t "$IMAGE:$TAG" -f deploy/Dockerfile.gitea-mcp .
|
||||
|
||||
echo "==> Tagging as $REGISTRY/michal/$IMAGE:$TAG..."
|
||||
podman tag "$IMAGE:$TAG" "$REGISTRY/michal/$IMAGE:$TAG"
|
||||
|
||||
echo "==> Logging in to $REGISTRY..."
|
||||
podman login --tls-verify=false -u michal -p "$GITEA_TOKEN" "$REGISTRY"
|
||||
|
||||
echo "==> Pushing to $REGISTRY/michal/$IMAGE:$TAG..."
|
||||
podman push --tls-verify=false "$REGISTRY/michal/$IMAGE:$TAG"
|
||||
|
||||
# Ensure package is linked to the repository
|
||||
source "$SCRIPT_DIR/link-package.sh"
|
||||
link_package "container" "$IMAGE"
|
||||
|
||||
echo "==> Done!"
|
||||
echo " Image: $REGISTRY/michal/$IMAGE:$TAG"
|
||||
Reference in New Issue
Block a user