Add controlled Athena platform operator

This commit is contained in:
Mikei386
2026-08-23 21:10:44 +02:00
parent 2f4bff550e
commit 94f3758795
26 changed files with 1030 additions and 752 deletions
+9 -11
View File
@@ -166,22 +166,20 @@ services:
retries: 5
start_period: 10s
mcp-athena-terminal:
mcp-athena-operator:
<<: *tool-common
build:
context: .
dockerfile: Dockerfile.athena-terminal
image: mike-ai/mcp-athena-terminal:1.0.0
container_name: mike-ai-mcp-athena-terminal
dockerfile: Dockerfile.athena-operator
image: mike-ai/mcp-athena-operator:1.0.0
container_name: mike-ai-mcp-athena-operator
environment:
ATHENA_TERMINAL_WORKSPACE: /workspace
ATHENA_TERMINAL_RUNTIME: /runtime
ATHENA_OPERATOR_SOCKET: /operator/operator.sock
volumes:
# The terminal sees only versioned source and the bounded, payload-free
# runtime snapshot. It receives no Docker socket, host filesystem,
# secrets, SSH material, devices, PID namespace or egress network.
- ${PLATFORM_STACK_DIR:-/opt/mike-ai/stack}:/workspace:ro
- ${PLATFORM_CONTEXT_RUNTIME_DIR:-/var/lib/mike-ai-platform-context}:/runtime:ro
# The unprivileged MCP facade sees only the root-owned executor socket.
# Docker, source, models, Git credentials and host paths remain on the
# executor side and are reachable only through structured operations.
- /run/mike-ai-operator:/operator:ro
networks: [tools]
healthcheck:
test: ["CMD", "python", "-c", "import socket; s=socket.create_connection(('127.0.0.1',8000),2); s.close()"]