add autonomous GitHub MCP installer

This commit is contained in:
Mikei386
2026-08-26 12:46:48 +02:00
parent 9ae7d22618
commit 588f24894d
8 changed files with 837 additions and 113 deletions
+34 -92
View File
@@ -1,107 +1,49 @@
---
name: mcphub-deployer
description: Install, update, disable, test, publish, or inspect portable MCP servers in CasaDeRoll MCPHub on Unraid. Use for MCP repositories, packages, binaries, HTTP MCPs, client registration, MCPHub repair, or moving an MCP out of Athena or Hermes.
description: Install, update, activate, disable, inspect, or roll back MCP servers in the central CasaDeRoll MCPHub. Use whenever the user provides an MCP URL, package, or GitHub repository.
---
# MCPHub Deployer
Install portable MCPs in the existing `MCPHub`; never create a separate
container and never install them inside Hermes.
Use only the `mcphub_admin_*` tools. They are the installer. Never use
`execute_code`, a terminal, SSH, Docker, Unraid tools, or edit MCPHub files.
Never create another container. Do not inspect or infer credentials.
## Fixed map
## Choose exactly one install tool
- Unraid: `192.168.1.2`; container: `MCPHub`; base URL: `http://192.168.1.2:8787`
- Appdata: `/mnt/nvme-storage/appdata/MCPHub`
- Work: `/mnt/nvme-storage/appdata/MCPHub/work/<id>`
- Extensions: `/mnt/nvme-storage/appdata/MCPHub/extensions/<id>`
- Registry: `/mnt/nvme-storage/appdata/MCPHub/config/mcp-registry.json`
- Secret: `/mnt/nvme-storage/appdata/MCPHub/secrets/<id>.env` (0600)
- Helper in container: `/opt/casaderoll/deploy-extension.py`
- Route: `http://192.168.1.2:8787/mcp/<id>`
- Existing HTTP MCP endpoint: `mcphub_admin_install_http`
- Published npm package: `mcphub_admin_install_npx`
- Published Python package: `mcphub_admin_install_uvx`
- GitHub source repository: `mcphub_admin_install_git`
Do not search for other checkouts, registries, templates, or secret stores.
Normal extensions do not modify Dockerfile, image tag, Unraid template, MCPHub
source, or Hermes config manually.
For a GitHub repository, read only the upstream README and its package manifest
to determine these fields:
## Hard credential boundary
- `runtime`: `python` or `node`
- Python `entrypoint`: the installed console-script name from `pyproject.toml`
- Node `entrypoint`: the built JavaScript path, or `bin:NAME`
- `subdirectory`: only when the package is inside a monorepo
- `arguments`: only documented server arguments
- `required_env`: names of required variables, never their values
Credentials are user input. Check only whether the dedicated secret file and
required keys exist; never print values. Never inspect other containers,
environments, mail servers, configs, histories, or passwords to find or infer
credentials. If credentials are missing, complete credential-independent build
work, stage the MCP disabled, report the exact secret path and missing key
names, then stop. Never publish or authenticate it.
Then call `mcphub_admin_install_git` once. It clones, builds, stores, registers,
and versions the MCP itself. A successful install is intentionally disabled.
Do not reproduce those steps manually.
## One-pass workflow
## Activation and proof
1. Read this skill once. Inspect only MCPHub state, the fixed registry, the
dedicated secret-file presence, and the target upstream release/source.
2. Classify once: existing HTTP MCP, packaged stdio MCP, released binary,
custom MCP, or host-bound HTTP proxy. Do not reconsider without a concrete
failed build or handshake.
3. Interpret intent: “prüfen/planen” changes nothing; “installieren/einbauen”
continues; “deaktiviert” never activates; “read-only” omits mutating tools.
4. Build only in `/tmp` or the fixed work directory. Pin versions and verify
checksums. Put runtime files in the work directory, not in the repository.
5. Write one compact manifest at `<work>/manifest.json`:
1. Report the exact missing environment key names, if any. The user fills
`/mnt/nvme-storage/appdata/MCPHub/secrets/<name>.env`; never read its values.
2. Check `mcphub_admin_git_status`.
3. Call `mcphub_admin_activate_git`. It refuses missing credentials, publishes
the server to Hermes, reloads it, and returns the live tool list.
4. Confirm success only when the returned server is connected and has tools.
Run at most one harmless read-only tool call if the user requested a test.
```json
{
"server": {
"id": "example", "hermes_id": "example", "name": "Example",
"description": "Short tool-selection description",
"url": "http://192.168.1.2:8787/mcp/example",
"clients": ["hermes"],
"deployment": {"required_env": ["EXAMPLE_TOKEN"]},
"hub": {
"type": "stdio", "secret_file": "example.env",
"command": "/usr/local/bin/run-with-env",
"args": ["/run/secrets/mcphub/example.env", "--", "node", "/app/data/extensions/example/index.js"],
"enabled": false
}
},
"artifacts": [
{"source": "/app/data/work/example/index.js", "path": "index.js", "sha256": "HEX", "mode": "0644"}
]
}
```
For an update, call the same install tool with the new pinned `ref`, then
activate it. The old release remains available. On explicit rollback use
`mcphub_admin_rollback_git` with `ROLLBACK:<name>`; it returns disabled, so
inspect and activate separately. Removal still requires `REMOVE:<name>`.
Use paths as seen inside MCPHub (`/app/data/...`) in the manifest.
6. Stage with exactly:
```sh
docker exec MCPHub python3 /opt/casaderoll/deploy-extension.py stage \
--manifest /app/data/work/<id>/manifest.json
```
The helper copies verified files, updates the registry atomically, and always
stages disabled. It technically blocks activation when the dedicated secret
or a required key is missing.
7. The helper registers the disabled server through MCPHub's official API. Do
not recreate MCPHub and do not restart Hermes, Athena, Router, Qwen,
WireGuard, Unraid, or other services.
8. If credentials are ready, activate with the helper, then verify: health;
all old routes; new handshake; `list_tools` schemas; one bounded read-only
call; no test writes or residue. Otherwise stop while disabled.
9. Ask Hermes to reload MCP connections. Hermes uses MCPHub's aggregate `/mcp`
endpoint, so no per-server client config or YAML edit is needed.
10. Report version, state, tool count, secret path (never values), tests,
client sync, durable source status, and rollback.
## Limits
- At most six preflight reads and two attempts per hypothesis.
- At most one corrected build.
- Never dump full registries, repository trees, logs, or configs; use bounded
queries and compact JSON.
- Never use one giant shell call to write several files.
- Never claim success without observed handshake and probe results.
- On failure leave the previous MCPHub running and the new extension disabled.
- Ask before destructive actions or credential rotation not explicitly asked.
## Resume
Before compression write `<work>/checkpoint.json` containing only phase,
version, completed checks, pending action, modified paths, and rollback. After
compression reload this skill and that checkpoint before continuing. Delete
the checkpoint only after success.
If a tool returns an error, report that exact error. Make at most one corrected
call for a concrete parameter mistake. Never invent a second deployment path.