Files
mcpctl/templates/grafana.yaml
Michal a158e49ec2
Some checks failed
CI/CD / lint (pull_request) Successful in 1m12s
CI/CD / test (pull_request) Successful in 1m25s
CI/CD / typecheck (pull_request) Successful in 2m50s
CI/CD / smoke (pull_request) Failing after 1m57s
CI/CD / build (pull_request) Successful in 4m49s
CI/CD / publish (pull_request) Has been skipped
fix(templates): make the shipped templates match reality
The templates are what `create server --from-template` builds from and what
mcpd seeds on start, so drift there ships broken servers. Nothing ever read
these files in a test, and they had rotted badly.

- grafana: GRAFANA_URL now defaults to the in-cluster ClusterIP and the
  description spells out why the public hostname is wrong — reaching a
  co-located Grafana over its ingress hairpins through the per-host Envoy L7
  policy, which drops the caller's identity and returns a bare `Access denied`
  403 with a perfectly valid token. That cost a day of looking at the token.
- unifi-network: was wrong on every field that mattered. `runtime: python`
  for an npm package, an env contract (UNIFI_HOST/USERNAME/PASSWORD) the
  package doesn't read, and no probe. Now UNIFI_TARGETS with the
  classic-vs-unifi_os distinction and the :8443 egress caveat written down.
- docmost, gitea: both carried "health check disabled" comments citing a
  limitation of the old docker-exec probe, which readiness-via-proxy removed.
  Both probes verified against the live servers. gitea uses search_repos, not
  get_me, because get_me needs a `read:user` scope a repo-scoped token lacks.
- filesystem: packageName was `@anthropic/filesystem-mcp`, which 404s on npm —
  the template could never have installed. Points at the real package.
- terraform: deleted. `@anthropic/terraform-mcp` 404s too and there is no
  npm-published replacement to point it at.
- node-red: deleted, the service is gone.

Two supporting fixes:
- The seeder declared no `runtime` field and never wrote the column, so a
  template asking for the python runner silently seeded as null and got node.
- A new templates test reads every shipped file: schema-valid, a runner the
  orchestrator knows, some way to actually start, unique env names, and a
  readiness probe (without one an instance can only ever report `live`).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0114dg56YmVacyqhp5fitcTb
2026-08-09 23:53:22 +01:00

29 lines
1.1 KiB
YAML

name: grafana
version: "1.1.0"
description: Grafana MCP server for dashboards, datasources, and alerts
packageName: "@leval/mcp-grafana"
runtime: node
transport: STDIO
repositoryUrl: https://github.com/levalhq/mcp-grafana
healthCheck:
# Hits the Grafana API, so a pass proves URL + token + reachability. A
# liveness probe (tools/list) cannot: it answers from the server's own tool
# table and stays green while every Grafana call 403s.
tool: list_datasources
arguments: {}
intervalSeconds: 60
timeoutSeconds: 10
env:
- name: GRAFANA_URL
description: >-
Grafana base URL. For a Grafana in this cluster use its ClusterIP
(http://grafana.<namespace>.svc.cluster.local:3000) — NOT its public
hostname. Reaching it over the public ingress hairpins the request back
through the per-host Envoy L7 policy, which drops the caller's identity
and answers a bare `Access denied` 403 even when the token is valid.
required: true
defaultValue: http://grafana.home-automation.svc.cluster.local:3000
- name: GRAFANA_SERVICE_ACCOUNT_TOKEN
description: Grafana service account token (glsa_...)
required: true