Simplify Athena stack and recovery
This commit is contained in:
@@ -4,12 +4,13 @@ set -Eeuo pipefail
|
||||
[[ $EUID -eq 0 ]] || { echo "Bitte als root ausführen." >&2; exit 1; }
|
||||
|
||||
MCP_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
STACK_DIR="$(cd "$MCP_DIR/../.." && pwd)"
|
||||
STACK_ENV=${STACK_ENV:-/etc/mike-ai/stack.env}
|
||||
COMPOSE=(docker compose)
|
||||
if [[ -s $STACK_ENV ]]; then
|
||||
COMPOSE+=(--env-file "$STACK_ENV")
|
||||
fi
|
||||
COMPOSE+=(-f "$MCP_DIR/compose.yaml")
|
||||
COMPOSE+=(-f "$STACK_DIR/compose.yaml")
|
||||
export SEARXNG_SETTINGS_FILE="${SEARXNG_SETTINGS_FILE:-$MCP_DIR/../web-search/searxng-settings.yml}"
|
||||
|
||||
[[ -s $SEARXNG_SETTINGS_FILE ]] || {
|
||||
@@ -17,48 +18,44 @@ export SEARXNG_SETTINGS_FILE="${SEARXNG_SETTINGS_FILE:-$MCP_DIR/../web-search/se
|
||||
exit 1
|
||||
}
|
||||
|
||||
# The read-only platform context MCP never receives the Docker socket. A
|
||||
# root-owned timer writes a bounded metadata snapshot instead.
|
||||
install -d -m 0755 /usr/local/libexec /var/lib/mike-ai-platform-context
|
||||
install -m 0755 "$MCP_DIR/platform-context-snapshot.py" \
|
||||
/usr/local/libexec/mike-ai-platform-context-snapshot
|
||||
install -m 0644 "$MCP_DIR/../systemd/mike-ai-platform-context-snapshot.service" \
|
||||
/etc/systemd/system/mike-ai-platform-context-snapshot.service
|
||||
install -m 0644 "$MCP_DIR/../systemd/mike-ai-platform-context-snapshot.timer" \
|
||||
/etc/systemd/system/mike-ai-platform-context-snapshot.timer
|
||||
systemctl daemon-reload
|
||||
systemctl enable --now mike-ai-platform-context-snapshot.timer
|
||||
systemctl start mike-ai-platform-context-snapshot.service
|
||||
docker network inspect mike-ai-tools >/dev/null 2>&1 || \
|
||||
docker network create --internal --subnet 172.30.40.0/24 mike-ai-tools >/dev/null
|
||||
docker network inspect mike-ai-tools-egress >/dev/null 2>&1 || \
|
||||
docker network create --subnet 172.30.50.0/24 mike-ai-tools-egress >/dev/null
|
||||
|
||||
# One user-facing Athena Operator MCP controls the local AI platform through a
|
||||
# root-side executor. The facade exposes six bounded tools and no Docker socket
|
||||
# or host paths to its unprivileged container.
|
||||
# One administrative MCP exposes ATHENA.md plus the bounded host operator.
|
||||
"$MCP_DIR/../operator/install-operator.sh"
|
||||
|
||||
profiles=()
|
||||
services=(searxng tinysearch mcp-athena-operator)
|
||||
if [[ -s /etc/mike-ai/homeassistant-admin-mcp.env ]]; then
|
||||
profiles+=(--profile homeassistant)
|
||||
services+=(mcp-homeassistant)
|
||||
else
|
||||
echo "Home Assistant bleibt aus: Secret-Datei fehlt."
|
||||
fi
|
||||
if [[ -s /etc/mike-ai/arr-mcp.env ]]; then
|
||||
profiles+=(--profile arr)
|
||||
services+=(mcp-arr)
|
||||
else
|
||||
echo "ARR bleibt aus: Secret-Datei fehlt."
|
||||
fi
|
||||
if [[ -s /etc/mike-ai/navidrome-mcp.env ]]; then
|
||||
profiles+=(--profile navidrome)
|
||||
services+=(mcp-navidrome)
|
||||
else
|
||||
echo "Navidrome bleibt aus: Secret-Datei fehlt."
|
||||
fi
|
||||
if [[ -s /etc/mike-ai/deemix-mcp.env ]]; then
|
||||
profiles+=(--profile deemix)
|
||||
services+=(mcp-deemix)
|
||||
else
|
||||
echo "Deemix MCP bleibt aus: Konfigurationsdatei fehlt."
|
||||
fi
|
||||
if [[ -s /etc/mike-ai/github-mcp.env ]] && \
|
||||
grep -Eq '^GITHUB_PERSONAL_ACCESS_TOKEN=.+$' /etc/mike-ai/github-mcp.env; then
|
||||
profiles+=(--profile github)
|
||||
services+=(mcp-github)
|
||||
else
|
||||
echo "GitHub bleibt aus: dedizierter Read-only-Token fehlt."
|
||||
fi
|
||||
@@ -81,7 +78,7 @@ if ! docker run --rm --entrypoint test \
|
||||
-c 'from tinysearch.services.onnx_bundle_service import ensure_onnx_bundle_sync; ensure_onnx_bundle_sync("fast")'
|
||||
fi
|
||||
|
||||
"${COMPOSE[@]}" "${profiles[@]}" up -d --build
|
||||
"${COMPOSE[@]}" "${profiles[@]}" up -d --build "${services[@]}"
|
||||
|
||||
for webui in mike-ai-open-webui Open-WebUI; do
|
||||
if docker container inspect "$webui" >/dev/null 2>&1; then
|
||||
|
||||
Reference in New Issue
Block a user