services: postgres: image: postgres:16-alpine container_name: mcpctl-postgres restart: unless-stopped environment: POSTGRES_USER: ${POSTGRES_USER} POSTGRES_PASSWORD: ${POSTGRES_PASSWORD} POSTGRES_DB: ${POSTGRES_DB} volumes: - mcpctl-pgdata:/var/lib/postgresql/data healthcheck: test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER}"] interval: 5s timeout: 5s retries: 5 networks: - mcpctl mcpd: image: mysources.co.uk/michal/mcpd:latest container_name: mcpctl-mcpd restart: unless-stopped ports: - "${MCPD_PORT:-3100}:3100" environment: DATABASE_URL: postgresql://${POSTGRES_USER}:${POSTGRES_PASSWORD}@postgres:5432/${POSTGRES_DB} MCPD_PORT: "3100" MCPD_HOST: "0.0.0.0" MCPD_LOG_LEVEL: ${MCPD_LOG_LEVEL:-info} MCPD_NODE_RUNNER_IMAGE: mysources.co.uk/michal/mcpctl-node-runner:latest MCPD_PYTHON_RUNNER_IMAGE: mysources.co.uk/michal/mcpctl-python-runner:latest MCPD_RATE_LIMIT_MAX: "2000" MCPD_MCP_NETWORK: mcp-servers depends_on: postgres: condition: service_healthy volumes: - /var/run/docker.sock:/var/run/docker.sock - mcpctl-backup:/data/backup networks: - mcpctl - mcp-servers healthcheck: test: ["CMD-SHELL", "wget -q --spider http://localhost:3100/healthz || exit 1"] interval: 10s timeout: 5s retries: 3 start_period: 15s # --- websearch profile ------------------------------------------------- # Opt-in: `docker compose --profile websearch up -d`. # # Only the SearXNG *engine* lives here — it is plain infrastructure, not an # MCP server, so mcpctl has nothing to manage it with. The MCP servers that # sit in front of it (`searxng`, `duckduckgo`, `docs-mcp`) are mcpctl # resources created from templates. Needs no API key. searxng: image: docker.io/searxng/searxng:latest container_name: mcpctl-searxng profiles: ["websearch"] restart: unless-stopped environment: SEARXNG_BASE_URL: http://mcpctl-searxng:8080/ SEARXNG_SECRET: ${SEARXNG_SECRET:-mcpctl-searxng-internal-only} # The limiter guards public instances from bots and needs Valkey to work. # This one binds no host port and is reachable only from mcp-servers. SEARXNG_LIMITER: "false" volumes: - ./searxng/settings.yml:/etc/searxng/settings.yml:ro - mcpctl-searxng-cache:/var/cache/searxng networks: - mcp-servers healthcheck: # Probes the JSON API specifically — a healthy HTML UI with `json` missing # from search.formats is exactly the failure mode worth catching here. test: ["CMD-SHELL", "wget -q -O /dev/null 'http://localhost:8080/search?q=ping&format=json' || exit 1"] interval: 30s timeout: 10s retries: 3 start_period: 20s networks: mcpctl: driver: bridge mcp-servers: name: mcp-servers driver: bridge # Not internal — MCP servers need outbound access for external APIs. # Isolation enforced by not binding host ports on MCP containers. volumes: mcpctl-pgdata: mcpctl-backup: mcpctl-searxng-cache: