Pass GitHub PAT to MCP subprocess

This commit is contained in:
Mikei386
2026-08-23 18:44:14 +02:00
parent a9847c43eb
commit ddde433224
6 changed files with 35 additions and 1 deletions
+5 -1
View File
@@ -17,5 +17,9 @@ EXPOSE 8000
# This is the same OpenWebUI-compatible stateless transport used by Athena's
# other Python/stdio MCP adapters. The official GitHub binary remains the only
# component implementing GitHub operations.
ENTRYPOINT ["mcp-proxy", "--host", "0.0.0.0", "--port", "8000", "--stateless", "--"]
# mcp-proxy intentionally starts stdio children with a minimal environment.
# Explicit pass-through is required so the GitHub subprocess receives the PAT
# already injected into this container by Docker. The value is never placed on
# the command line, image, logs or Open WebUI connection record.
ENTRYPOINT ["mcp-proxy", "--host", "0.0.0.0", "--port", "8000", "--stateless", "--pass-environment", "--"]
CMD ["/usr/local/bin/github-mcp-server", "stdio", "--read-only", "--tools", "search_repositories,get_repository_tree,get_file_contents,search_code"]
+7
View File
@@ -169,6 +169,13 @@ führte trotz gesundem GitHub-Server und gültigem Token zu
ist derselbe Transport, der sich bereits beim Athena Platform Context MCP
bewährt hat.
Die Brücke wird mit `--pass-environment` gestartet. Ohne diese ausdrückliche
Option sieht zwar der Proxy-Prozess den per Docker-Envfile injizierten PAT, der
von ihm gestartete GitHub-stdio-Unterprozess jedoch nicht; der offizielle
Server fällt dann irreführend auf die interaktive GitHub-Geräteanmeldung
zurück. Der Token bleibt dabei eine Umgebungsvariable und erscheint weder in
Kommandozeile noch Image, Log oder Open-WebUI-Konfiguration.
Dem Modell werden ausschließlich `search_repositories`, `get_repository_tree`,
`get_file_contents` und `search_code` angeboten. Der offizielle Server wird
zusätzlich explizit mit `--read-only` gestartet; die Umgebungsvariablen im