Some checks failed
CI/CD / lint (pull_request) Successful in 1m17s
CI/CD / typecheck (pull_request) Successful in 2m39s
CI/CD / test (pull_request) Successful in 1m27s
CI/CD / build (pull_request) Successful in 2m28s
CI/CD / smoke (pull_request) Failing after 3m4s
CI/CD / publish (pull_request) Has been skipped
Two corrections to the shell-bearing rebuild. **Pin by digest.** It copied from `:latest`, so a rebuild silently ships whatever upstream has moved to. When a probe started failing right after a rebuild I could not tell a version change from a broken build, and burned time on the wrong one — the binary's own `--version` prints 1.1.0 while the image label says 1.6.0, so that was a red herring too. Now pinned to sha256:dda8d56e…, which IS the running 1.6.0. **CMD, not ENTRYPOINT.** Upstream sets `Cmd: ["/app/gitea-mcp"]` with no entrypoint. mcpd maps a server's `command` to k8s `args`, which REPLACES Cmd but only APPENDS to an ENTRYPOINT — so the ENTRYPOINT form would have changed how the binary is invoked for any server that sets a command. Matching upstream's shape keeps the non-injected path byte-identical. gitea also needs `entrypoint` on its server row: its `command` is [], so there is nothing for the injector wrapper to wrap without it. Set to ["/usr/local/bin/gitea-mcp"] via apply -f (patch cannot express an array). Verified live: gitea RUNNING/healthy on secretDelivery: injector, with vault-agent-init present and the command wrapped as ["/bin/sh","-c",". /vault/secrets/gitea-creds; exec \"$0\" \"$@\"", "/usr/local/bin/gitea-mcp"] `get_me` — which needs read:user, the scope that started this whole session — returns the real account. Plaintext credentials across all mcpctl server pod specs: 4 -> 0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018vybEitX4FykeMatKe5Xki
44 lines
2.2 KiB
Docker
44 lines
2.2 KiB
Docker
# gitea-mcp-server, rebuilt on a shell-bearing base.
|
|
#
|
|
# WHY THIS EXISTS
|
|
# ---------------
|
|
# Upstream `docker.gitea.com/gitea-mcp-server` is distroless: `Cmd` is
|
|
# ["/app/gitea-mcp"] and there is no /bin/sh at any path (verified by exec'ing
|
|
# every candidate against the running pod).
|
|
#
|
|
# That is fine until the server needs `secretDelivery: injector`. The OpenBao
|
|
# agent renders secrets to a FILE, so mcpd wraps the container command as
|
|
# `sh -c '. /vault/secrets/<name>; exec "$0" "$@"'` — which needs a shell. With
|
|
# no shell the pod cannot source its own credentials, and gitea was the single
|
|
# server in the fleet blocked on this.
|
|
#
|
|
# Copying one static Go binary onto debian:stable-slim is cheaper than building
|
|
# and maintaining a static "envexec" shim, and follows the precedent already set
|
|
# by deploy/Dockerfile.docmost-mcp — this repo already rebuilds third-party MCP
|
|
# servers when it needs to change how they run.
|
|
#
|
|
# ca-certificates is required, not incidental: the binary talks HTTPS to
|
|
# https://mysources.co.uk and a distroless base ships its own trust store which
|
|
# we are leaving behind.
|
|
FROM debian:stable-slim
|
|
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends ca-certificates \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# Pinned by DIGEST, not :latest. `latest` moves, and a rebuild that silently
|
|
# ships a different server version is indistinguishable from a broken rebuild —
|
|
# chased exactly that here when a probe started failing after a rebuild.
|
|
# This digest is gitea-mcp-server 1.6.0 (label org.opencontainers.image.version),
|
|
# the build that was running when this image was introduced.
|
|
# To bump: skopeo inspect docker://docker.gitea.com/gitea-mcp-server:latest
|
|
COPY --from=docker.gitea.com/gitea-mcp-server@sha256:dda8d56e6a91fa89cad186becc27c7aa83d74acdd5dc69f89af840d7bb78a631 /app/gitea-mcp /usr/local/bin/gitea-mcp
|
|
|
|
WORKDIR /app
|
|
|
|
# CMD, not ENTRYPOINT — matching upstream, which sets Cmd ["/app/gitea-mcp"] and
|
|
# no entrypoint. mcpd maps a server's `command` to k8s `args`, which REPLACES
|
|
# Cmd but only appends to an ENTRYPOINT; keeping the same form means the plain
|
|
# (non-injected) path behaves byte-identically to upstream.
|
|
CMD ["/usr/local/bin/gitea-mcp"]
|