Replace GraphQL Unraid MCP with MUA

This commit is contained in:
Mikei386
2026-08-23 22:08:31 +02:00
parent b723f820bf
commit a3297dbdd9
19 changed files with 84 additions and 76 deletions
+13 -3
View File
@@ -17,9 +17,14 @@ Prompts heraus, verhindert den früher beobachteten Kontextverbrauch von über
| `mcp-arr` | `http://mike-ai-mcp-arr:8000/mcp` | Sonarr/Radarr/Prowlarr mit serverseitiger Policy | Profil `arr` |
| `mcp-navidrome` | `http://mike-ai-mcp-navidrome:3000/mcp` | Navidrome-Bibliothek, Suche, Playlists, Favoriten und Hörverlauf | Profil `navidrome` |
| `mcp-github` | `http://mike-ai-mcp-github:8000/mcp` | offizieller GitHub-MCP, auf vier reine Repository-Lesewerkzeuge begrenzt | Profil `github` |
| `mcp-unraid-official` | `http://mike-ai-mcp-unraid-official:8000/mcp` | offizieller, read-only begrenzter Unraid-Zugang | Profil `unraid` |
| `mcp-unraid-ssh` | `http://mike-ai-mcp-unraid-ssh:8000/mcp` | erweiterte Diagnose über einen erzwungenen SSH-Befehl | optional (`extended`) |
Unraid wird produktiv ausschließlich über das auf dem HomeServer laufende
MUA-Plugin (`http://192.168.1.2:3002/mcp`) angebunden. Open WebUI führt davon
zwei Ansichten: `mua-readonly-local` für automatische Diagnose und `mua` für
bewusst aktivierte Verwaltungsaktionen. Ein GraphQL-basierter Unraid-MCP ist
nicht Bestandteil des Stacks.
Die drei Websuch-Container verwenden `AI_DNS` aus
`/etc/mike-ai/stack.env`. Der Web-MCP hängt zusätzlich am getrennten
`mike-ai-tools-egress`-Netz, weil er gefundene öffentliche Seiten nach der
@@ -88,7 +93,7 @@ passenden Server wählen:
| Entitäten, Zustände, Historie, Automationen und Dashboards | Home Assistant | Web, Unraid |
| Serien, Filme, fehlende Episoden und Indexer-Releases | Sonarr und Radarr | Web |
| Persönliche Musikbibliothek, Titel, Alben, Künstler und Playlists | Navidrome | Web, ARR |
| Lesende NAS-, Docker-, Array-, Netzwerk- und Logdiagnose | Unraid (Systemdiagnose) | MUA |
| Lesende NAS-, Docker-, Array-, Netzwerk- und Logdiagnose | MUA · Unraid-Diagnose (read-only) | MUA-Verwaltung |
| Athena-KI-Plattform entwickeln, testen, deployen, Modelle/Git/Recovery pflegen | Athena Operator | Platform Context für reine Architekturauskunft |
| Ausdrücklich benötigte MUA-Verwaltungsaktion | MUA | Unraid-Diagnose nicht parallel |
@@ -132,9 +137,14 @@ Die lokale Installation benötigt die vorhandenen Secret-Dateien:
/etc/mike-ai/arr-mcp.env
/etc/mike-ai/navidrome-mcp.env
/etc/mike-ai/github-mcp.env
/etc/mike-ai/runraid/.env
/etc/mike-ai/mua-mcp.env
```
`mua-mcp.env` enthält ausschließlich MUA-Endpunkt und Bearer-Token. Der
Installer legt daraus die vollständige MUA-Verbindung und eine strikt auf
Lesewerkzeuge begrenzte automatische Ansicht an. Die Datei ist root-only
(Modus `0600`) und wird nur verschlüsselt im Recovery-Bundle gesichert.
Die erweiterte Unraid-Diagnose benötigt zusätzlich die Konfigurationsdatei,
den eingeschränkten Schlüssel und die bekannte Hostsignatur. Sie wird nur mit
`--profile extended` gestartet.
-23
View File
@@ -213,29 +213,6 @@ services:
retries: 5
start_period: 15s
mcp-unraid-official:
<<: *tool-common
image: debian:13-slim
container_name: mike-ai-mcp-unraid-official
profiles: [unraid]
env_file:
- ${RUNRAID_ENV_FILE:-/etc/mike-ai/runraid/.env}
environment:
UNRAID_RMCP_HOST: 0.0.0.0
UNRAID_RMCP_PORT: "8000"
UNRAID_RMCP_DISABLE_HTTP_AUTH: "true"
UNRAID_NOAUTH: "true"
UNRAID_RMCP_ALLOWED_HOSTS: "mike-ai-mcp-unraid-official:8000,mike-ai-mcp-unraid-official,localhost:8000,127.0.0.1:8000"
# Public DNS cannot resolve the Fritzbox-only name. Preserve the hostname
# used by the TLS endpoint while binding it to the verified home-LAN IP.
extra_hosts:
- "homeserver.fritz.box:192.168.1.2"
volumes:
- ${RUNRAID_BINARY:-/usr/local/bin/runraid}:/usr/local/bin/unraid:ro
entrypoint: ["/usr/local/bin/unraid"]
command: ["serve"]
networks: [tools, egress]
mcp-unraid-ssh:
<<: *tool-common
profiles: [extended]
-6
View File
@@ -61,12 +61,6 @@ if [[ -s /etc/mike-ai/github-mcp.env ]] && \
else
echo "GitHub bleibt aus: dedizierter Read-only-Token fehlt."
fi
if [[ -s /etc/mike-ai/runraid/.env && -x /usr/local/bin/runraid ]]; then
profiles+=(--profile unraid)
else
echo "Unraid bleibt aus: runraid 0.4.2 oder Secret-Datei fehlt."
fi
# TinySearch keeps the embedding bundle outside the container. Download it
# once on a fresh host; subsequent rebuilds reuse the named volume.
#