Fix web MCP DNS and crawler runtime
This commit is contained in:
@@ -16,6 +16,18 @@ Prompts heraus, verhindert den früher beobachteten Kontextverbrauch von über
|
||||
| `mcp-unraid-official` | `http://mike-ai-mcp-unraid-official:8000/mcp` | offizieller, read-only begrenzter Unraid-Zugang | Profil `unraid` |
|
||||
| `mcp-unraid-ssh` | `http://mike-ai-mcp-unraid-ssh:8000/mcp` | erweiterte Diagnose über einen erzwungenen SSH-Befehl | optional (`extended`) |
|
||||
|
||||
Die drei Websuch-Container verwenden `AI_DNS` aus
|
||||
`/etc/mike-ai/stack.env`. Der Web-MCP hängt zusätzlich am getrennten
|
||||
`mike-ai-tools-egress`-Netz, weil er gefundene öffentliche Seiten nach der
|
||||
SSRF-Prüfung selbst abrufen muss. Ohne diese beiden Einstellungen kann die
|
||||
Werkzeugauswahl korrekt wirken, während alle Suchmaschinen und Seitenabrufe
|
||||
gleichzeitig fehlschlagen.
|
||||
|
||||
TinySearch bleibt als Ganzes read-only. Nur das flüchtige tmpfs-Verzeichnis
|
||||
`/home/tinysearch/.crawl4ai` ist beschreibbar, weil Crawl4AI dort seinen
|
||||
temporären Browser- und Sitzungszustand erzeugt. Es wird bei jedem
|
||||
Container-Neustart vollständig verworfen.
|
||||
|
||||
TinySearch und SearXNG sind interne Abhängigkeiten des Web-MCPs und werden
|
||||
nicht direkt als allgemeine Werkzeuge angeboten.
|
||||
|
||||
|
||||
@@ -21,6 +21,12 @@ services:
|
||||
dockerfile: mcp/Dockerfile.web
|
||||
image: mike-ai/mcp-web:local
|
||||
container_name: mike-ai-mcp-web
|
||||
# The relay fetches and validates public result pages itself. It therefore
|
||||
# needs both the private tool network and the explicitly separated egress
|
||||
# network; keeping it on `tools` only makes search discovery work while
|
||||
# every page fetch fails.
|
||||
networks: [tools, egress]
|
||||
dns: ["${AI_DNS:-1.1.1.1}"]
|
||||
environment:
|
||||
TINYSEARCH_MCP_URL: http://tinysearch:8000/mcp
|
||||
SEARXNG_URL: http://searxng:8080
|
||||
@@ -33,6 +39,7 @@ services:
|
||||
<<: *tool-common
|
||||
image: searxng/searxng@sha256:e45d5894bfaa0bf8773b9f283795ae57f1c15ddb29c8cecb70b3665b0ce9ec60
|
||||
container_name: mike-ai-tools-searxng
|
||||
dns: ["${AI_DNS:-1.1.1.1}"]
|
||||
volumes:
|
||||
- ${SEARXNG_SETTINGS_FILE:-../web-search/searxng-settings.example.yml}:/etc/searxng/settings.yml:ro
|
||||
networks: [tools, egress]
|
||||
@@ -41,6 +48,13 @@ services:
|
||||
<<: *tool-common
|
||||
image: marcellm01/tinysearch@sha256:5a03d5a1f1b0fabe48f2a26e05db4a84bcb611106a57ec51e42db4549976aa9c
|
||||
container_name: mike-ai-tools-tinysearch
|
||||
dns: ["${AI_DNS:-1.1.1.1}"]
|
||||
# Crawl4AI keeps transient browser/session state here. The container stays
|
||||
# read-only; only this disposable runtime directory (and /tmp from the
|
||||
# common hardening block) is writable.
|
||||
tmpfs:
|
||||
- /tmp:rw,noexec,nosuid,nodev,size=64m
|
||||
- /home/tinysearch/.crawl4ai:rw,nosuid,nodev,size=256m,mode=1777
|
||||
shm_size: 1gb
|
||||
volumes:
|
||||
- tinysearch-models:/data/models
|
||||
|
||||
@@ -4,7 +4,12 @@ set -Eeuo pipefail
|
||||
[[ $EUID -eq 0 ]] || { echo "Bitte als root ausführen." >&2; exit 1; }
|
||||
|
||||
MCP_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
COMPOSE=(docker compose -f "$MCP_DIR/compose.yaml")
|
||||
STACK_ENV=${STACK_ENV:-/etc/mike-ai/stack.env}
|
||||
COMPOSE=(docker compose)
|
||||
if [[ -s $STACK_ENV ]]; then
|
||||
COMPOSE+=(--env-file "$STACK_ENV")
|
||||
fi
|
||||
COMPOSE+=(-f "$MCP_DIR/compose.yaml")
|
||||
export SEARXNG_SETTINGS_FILE="${SEARXNG_SETTINGS_FILE:-$MCP_DIR/../web-search/searxng-settings.yml}"
|
||||
|
||||
[[ -s $SEARXNG_SETTINGS_FILE ]] || {
|
||||
|
||||
Reference in New Issue
Block a user