Simplify Athena stack and recovery

This commit is contained in:
Mikei386
2026-08-25 22:27:26 +02:00
parent c4851305d1
commit 069da8b4f0
70 changed files with 887 additions and 5806 deletions
+10 -46
View File
@@ -1,5 +1,3 @@
name: mike-ai-tools
x-tool-common: &tool-common
restart: unless-stopped
read_only: true
@@ -28,7 +26,7 @@ services:
# needs both the private tool network and the explicitly separated egress
# network; keeping it on `tools` only makes search discovery work while
# every page fetch fails.
networks: [tools, egress]
networks: [tools, tools-egress]
dns: ["${AI_DNS:-1.1.1.1}"]
environment:
TINYSEARCH_MCP_URL: http://tinysearch:8000/mcp
@@ -52,7 +50,7 @@ services:
dns: ["${AI_DNS:-1.1.1.1}"]
volumes:
- ${SEARXNG_SETTINGS_FILE:-../web-search/searxng-settings.example.yml}:/etc/searxng/settings.yml:ro
networks: [tools, egress]
networks: [tools, tools-egress]
tinysearch:
<<: *tool-common
@@ -80,7 +78,7 @@ services:
SEARXNG_URL: http://searxng:8080/search
depends_on: [searxng]
cap_add: [SETUID, SETGID, CHOWN]
networks: [tools, egress]
networks: [tools, tools-egress]
# The image's built-in `tinysearch doctor` also requires a writable
# configuration directory, although normal server operation does not.
# Check the service socket instead so read-only hardening remains intact.
@@ -108,7 +106,7 @@ services:
volumes:
- ${HA_ENV_FILE:-/etc/mike-ai/homeassistant-admin-mcp.env}:/run/secrets/homeassistant.env:ro
cap_add: [CHOWN, SETUID, SETGID]
networks: [tools, egress]
networks: [tools, tools-egress]
mcp-arr:
<<: *tool-common
@@ -127,7 +125,7 @@ services:
# Upstream's generic "Execute any Radarr API action" text gives small
# models no routing boundary. This overlay changes guidance only.
- ${ARR_RADARR_PATCH:-./patches/mcp_radarr.py}:/usr/local/lib/python3.13/site-packages/arr_mcp/mcp/mcp_radarr.py:ro
networks: [tools, egress]
networks: [tools, tools-egress]
mcp-navidrome:
<<: *tool-common
@@ -153,7 +151,7 @@ services:
tmpfs:
- /tmp:rw,noexec,nosuid,nodev,size=64m
- /config:rw,noexec,nosuid,nodev,size=4m,mode=0700
networks: [tools, egress]
networks: [tools, tools-egress]
mcp-deemix:
<<: *tool-common
@@ -167,30 +165,7 @@ services:
- ${DEEMIX_MCP_ENV_FILE:-/etc/mike-ai/deemix-mcp.env}
environment:
PORT: "8000"
networks: [tools, egress]
healthcheck:
test: ["CMD", "python", "-c", "import socket; s=socket.create_connection(('127.0.0.1',8000),2); s.close()"]
interval: 30s
timeout: 5s
retries: 5
start_period: 10s
mcp-platform-context:
<<: *tool-common
build:
context: .
dockerfile: Dockerfile.platform-context
image: mike-ai/mcp-platform-context:2.0.0
container_name: mike-ai-mcp-platform-context
environment:
ATHENA_REPO_ROOT: /knowledge/repo
ATHENA_RUNTIME_FILE: /runtime/runtime.json
volumes:
- ${PLATFORM_STACK_DIR:-/opt/mike-ai/stack}:/knowledge/repo:ro
- ${PLATFORM_CONTEXT_RUNTIME_DIR:-/var/lib/mike-ai-platform-context}:/runtime:ro
# Documentation is strictly read-only. Runtime inspection and all changes
# belong to the Athena Operator instead of a second maintenance workflow.
networks: [tools]
networks: [tools, tools-egress]
healthcheck:
test: ["CMD", "python", "-c", "import socket; s=socket.create_connection(('127.0.0.1',8000),2); s.close()"]
interval: 30s
@@ -203,7 +178,7 @@ services:
build:
context: .
dockerfile: Dockerfile.athena-operator
image: mike-ai/mcp-athena-operator:3.0.0
image: mike-ai/mcp-athena-operator:3.1.0
container_name: mike-ai-mcp-athena-operator
environment:
ATHENA_OPERATOR_SOCKET: /operator/operator.sock
@@ -235,7 +210,7 @@ services:
# for broader toolsets. The token itself must also remain read-only.
GITHUB_TOOLS: search_repositories,get_file_contents,search_code
GITHUB_READ_ONLY: "1"
networks: [tools, egress]
networks: [tools, tools-egress]
healthcheck:
test: ["CMD", "python", "-c", "import socket; s=socket.create_connection(('127.0.0.1',8000),2); s.close()"]
interval: 30s
@@ -259,18 +234,7 @@ services:
- ${UNRAID_SSH_KEY:-/etc/mike-ai/keys/unraid_root}:/etc/mike-ai/keys/unraid_root:ro
- ${UNRAID_KNOWN_HOSTS:-/etc/mike-ai/ssh/known_hosts_unraid_ai}:/etc/mike-ai/ssh/known_hosts_unraid_ai:ro
- unraid-audit:/var/log/mike-ai
networks: [tools, egress]
networks:
tools:
name: mike-ai-tools
internal: true
ipam:
config: [{subnet: 172.30.40.0/24}]
egress:
name: mike-ai-tools-egress
ipam:
config: [{subnet: 172.30.50.0/24}]
networks: [tools, tools-egress]
volumes:
tinysearch-models: