Fix web MCP DNS and crawler runtime
This commit is contained in:
1 parent
95ed583a66
commit
d86727b231
3 files changed
+32
-1
No files matched your search
@@ -16,6 +16,18 @@ Prompts heraus, verhindert den früher beobachteten Kontextverbrauch von über
|
|||||||
| `mcp-unraid-official` | `http://mike-ai-mcp-unraid-official:8000/mcp` | offizieller, read-only begrenzter Unraid-Zugang | Profil `unraid` |
|
| `mcp-unraid-official` | `http://mike-ai-mcp-unraid-official:8000/mcp` | offizieller, read-only begrenzter Unraid-Zugang | Profil `unraid` |
|
||||||
| `mcp-unraid-ssh` | `http://mike-ai-mcp-unraid-ssh:8000/mcp` | erweiterte Diagnose über einen erzwungenen SSH-Befehl | optional (`extended`) |
|
| `mcp-unraid-ssh` | `http://mike-ai-mcp-unraid-ssh:8000/mcp` | erweiterte Diagnose über einen erzwungenen SSH-Befehl | optional (`extended`) |
|
||||||
|
|
||||||
|
Die drei Websuch-Container verwenden `AI_DNS` aus
|
||||||
|
`/etc/mike-ai/stack.env`. Der Web-MCP hängt zusätzlich am getrennten
|
||||||
|
`mike-ai-tools-egress`-Netz, weil er gefundene öffentliche Seiten nach der
|
||||||
|
SSRF-Prüfung selbst abrufen muss. Ohne diese beiden Einstellungen kann die
|
||||||
|
Werkzeugauswahl korrekt wirken, während alle Suchmaschinen und Seitenabrufe
|
||||||
|
gleichzeitig fehlschlagen.
|
||||||
|
|
||||||
|
TinySearch bleibt als Ganzes read-only. Nur das flüchtige tmpfs-Verzeichnis
|
||||||
|
`/home/tinysearch/.crawl4ai` ist beschreibbar, weil Crawl4AI dort seinen
|
||||||
|
temporären Browser- und Sitzungszustand erzeugt. Es wird bei jedem
|
||||||
|
Container-Neustart vollständig verworfen.
|
||||||
|
|
||||||
TinySearch und SearXNG sind interne Abhängigkeiten des Web-MCPs und werden
|
TinySearch und SearXNG sind interne Abhängigkeiten des Web-MCPs und werden
|
||||||
nicht direkt als allgemeine Werkzeuge angeboten.
|
nicht direkt als allgemeine Werkzeuge angeboten.
|
||||||
|
|
||||||
|
|||||||
@@ -21,6 +21,12 @@ services:
|
|||||||
dockerfile: mcp/Dockerfile.web
|
dockerfile: mcp/Dockerfile.web
|
||||||
image: mike-ai/mcp-web:local
|
image: mike-ai/mcp-web:local
|
||||||
container_name: mike-ai-mcp-web
|
container_name: mike-ai-mcp-web
|
||||||
|
# The relay fetches and validates public result pages itself. It therefore
|
||||||
|
# needs both the private tool network and the explicitly separated egress
|
||||||
|
# network; keeping it on `tools` only makes search discovery work while
|
||||||
|
# every page fetch fails.
|
||||||
|
networks: [tools, egress]
|
||||||
|
dns: ["${AI_DNS:-1.1.1.1}"]
|
||||||
environment:
|
environment:
|
||||||
TINYSEARCH_MCP_URL: http://tinysearch:8000/mcp
|
TINYSEARCH_MCP_URL: http://tinysearch:8000/mcp
|
||||||
SEARXNG_URL: http://searxng:8080
|
SEARXNG_URL: http://searxng:8080
|
||||||
@@ -33,6 +39,7 @@ services:
|
|||||||
<<: *tool-common
|
<<: *tool-common
|
||||||
image: searxng/searxng@sha256:e45d5894bfaa0bf8773b9f283795ae57f1c15ddb29c8cecb70b3665b0ce9ec60
|
image: searxng/searxng@sha256:e45d5894bfaa0bf8773b9f283795ae57f1c15ddb29c8cecb70b3665b0ce9ec60
|
||||||
container_name: mike-ai-tools-searxng
|
container_name: mike-ai-tools-searxng
|
||||||
|
dns: ["${AI_DNS:-1.1.1.1}"]
|
||||||
volumes:
|
volumes:
|
||||||
- ${SEARXNG_SETTINGS_FILE:-../web-search/searxng-settings.example.yml}:/etc/searxng/settings.yml:ro
|
- ${SEARXNG_SETTINGS_FILE:-../web-search/searxng-settings.example.yml}:/etc/searxng/settings.yml:ro
|
||||||
networks: [tools, egress]
|
networks: [tools, egress]
|
||||||
@@ -41,6 +48,13 @@ services:
|
|||||||
<<: *tool-common
|
<<: *tool-common
|
||||||
image: marcellm01/tinysearch@sha256:5a03d5a1f1b0fabe48f2a26e05db4a84bcb611106a57ec51e42db4549976aa9c
|
image: marcellm01/tinysearch@sha256:5a03d5a1f1b0fabe48f2a26e05db4a84bcb611106a57ec51e42db4549976aa9c
|
||||||
container_name: mike-ai-tools-tinysearch
|
container_name: mike-ai-tools-tinysearch
|
||||||
|
dns: ["${AI_DNS:-1.1.1.1}"]
|
||||||
|
# Crawl4AI keeps transient browser/session state here. The container stays
|
||||||
|
# read-only; only this disposable runtime directory (and /tmp from the
|
||||||
|
# common hardening block) is writable.
|
||||||
|
tmpfs:
|
||||||
|
- /tmp:rw,noexec,nosuid,nodev,size=64m
|
||||||
|
- /home/tinysearch/.crawl4ai:rw,nosuid,nodev,size=256m,mode=1777
|
||||||
shm_size: 1gb
|
shm_size: 1gb
|
||||||
volumes:
|
volumes:
|
||||||
- tinysearch-models:/data/models
|
- tinysearch-models:/data/models
|
||||||
|
|||||||
@@ -4,7 +4,12 @@ set -Eeuo pipefail
|
|||||||
[[ $EUID -eq 0 ]] || { echo "Bitte als root ausführen." >&2; exit 1; }
|
[[ $EUID -eq 0 ]] || { echo "Bitte als root ausführen." >&2; exit 1; }
|
||||||
|
|
||||||
MCP_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
MCP_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||||
COMPOSE=(docker compose -f "$MCP_DIR/compose.yaml")
|
STACK_ENV=${STACK_ENV:-/etc/mike-ai/stack.env}
|
||||||
|
COMPOSE=(docker compose)
|
||||||
|
if [[ -s $STACK_ENV ]]; then
|
||||||
|
COMPOSE+=(--env-file "$STACK_ENV")
|
||||||
|
fi
|
||||||
|
COMPOSE+=(-f "$MCP_DIR/compose.yaml")
|
||||||
export SEARXNG_SETTINGS_FILE="${SEARXNG_SETTINGS_FILE:-$MCP_DIR/../web-search/searxng-settings.yml}"
|
export SEARXNG_SETTINGS_FILE="${SEARXNG_SETTINGS_FILE:-$MCP_DIR/../web-search/searxng-settings.yml}"
|
||||||
|
|
||||||
[[ -s $SEARXNG_SETTINGS_FILE ]] || {
|
[[ -s $SEARXNG_SETTINGS_FILE ]] || {
|
||||||
|
|||||||
Reference in new issue
Block a user