Fix web MCP DNS and crawler runtime

This commit is contained in:
Mikei386
2026-08-22 11:49:47 +02:00
parent 95ed583a66
commit d86727b231
3 changed files with 32 additions and 1 deletions
+12
View File
@@ -16,6 +16,18 @@ Prompts heraus, verhindert den früher beobachteten Kontextverbrauch von über
| `mcp-unraid-official` | `http://mike-ai-mcp-unraid-official:8000/mcp` | offizieller, read-only begrenzter Unraid-Zugang | Profil `unraid` |
| `mcp-unraid-ssh` | `http://mike-ai-mcp-unraid-ssh:8000/mcp` | erweiterte Diagnose über einen erzwungenen SSH-Befehl | optional (`extended`) |
Die drei Websuch-Container verwenden `AI_DNS` aus
`/etc/mike-ai/stack.env`. Der Web-MCP hängt zusätzlich am getrennten
`mike-ai-tools-egress`-Netz, weil er gefundene öffentliche Seiten nach der
SSRF-Prüfung selbst abrufen muss. Ohne diese beiden Einstellungen kann die
Werkzeugauswahl korrekt wirken, während alle Suchmaschinen und Seitenabrufe
gleichzeitig fehlschlagen.
TinySearch bleibt als Ganzes read-only. Nur das flüchtige tmpfs-Verzeichnis
`/home/tinysearch/.crawl4ai` ist beschreibbar, weil Crawl4AI dort seinen
temporären Browser- und Sitzungszustand erzeugt. Es wird bei jedem
Container-Neustart vollständig verworfen.
TinySearch und SearXNG sind interne Abhängigkeiten des Web-MCPs und werden
nicht direkt als allgemeine Werkzeuge angeboten.
+14
View File
@@ -21,6 +21,12 @@ services:
dockerfile: mcp/Dockerfile.web
image: mike-ai/mcp-web:local
container_name: mike-ai-mcp-web
# The relay fetches and validates public result pages itself. It therefore
# needs both the private tool network and the explicitly separated egress
# network; keeping it on `tools` only makes search discovery work while
# every page fetch fails.
networks: [tools, egress]
dns: ["${AI_DNS:-1.1.1.1}"]
environment:
TINYSEARCH_MCP_URL: http://tinysearch:8000/mcp
SEARXNG_URL: http://searxng:8080
@@ -33,6 +39,7 @@ services:
<<: *tool-common
image: searxng/searxng@sha256:e45d5894bfaa0bf8773b9f283795ae57f1c15ddb29c8cecb70b3665b0ce9ec60
container_name: mike-ai-tools-searxng
dns: ["${AI_DNS:-1.1.1.1}"]
volumes:
- ${SEARXNG_SETTINGS_FILE:-../web-search/searxng-settings.example.yml}:/etc/searxng/settings.yml:ro
networks: [tools, egress]
@@ -41,6 +48,13 @@ services:
<<: *tool-common
image: marcellm01/tinysearch@sha256:5a03d5a1f1b0fabe48f2a26e05db4a84bcb611106a57ec51e42db4549976aa9c
container_name: mike-ai-tools-tinysearch
dns: ["${AI_DNS:-1.1.1.1}"]
# Crawl4AI keeps transient browser/session state here. The container stays
# read-only; only this disposable runtime directory (and /tmp from the
# common hardening block) is writable.
tmpfs:
- /tmp:rw,noexec,nosuid,nodev,size=64m
- /home/tinysearch/.crawl4ai:rw,nosuid,nodev,size=256m,mode=1777
shm_size: 1gb
volumes:
- tinysearch-models:/data/models
+6 -1
View File
@@ -4,7 +4,12 @@ set -Eeuo pipefail
[[ $EUID -eq 0 ]] || { echo "Bitte als root ausführen." >&2; exit 1; }
MCP_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
COMPOSE=(docker compose -f "$MCP_DIR/compose.yaml")
STACK_ENV=${STACK_ENV:-/etc/mike-ai/stack.env}
COMPOSE=(docker compose)
if [[ -s $STACK_ENV ]]; then
COMPOSE+=(--env-file "$STACK_ENV")
fi
COMPOSE+=(-f "$MCP_DIR/compose.yaml")
export SEARXNG_SETTINGS_FILE="${SEARXNG_SETTINGS_FILE:-$MCP_DIR/../web-search/searxng-settings.yml}"
[[ -s $SEARXNG_SETTINGS_FILE ]] || {