Pass GitHub PAT to MCP subprocess
This commit is contained in:
@@ -17,5 +17,9 @@ EXPOSE 8000
|
||||
# This is the same OpenWebUI-compatible stateless transport used by Athena's
|
||||
# other Python/stdio MCP adapters. The official GitHub binary remains the only
|
||||
# component implementing GitHub operations.
|
||||
ENTRYPOINT ["mcp-proxy", "--host", "0.0.0.0", "--port", "8000", "--stateless", "--"]
|
||||
# mcp-proxy intentionally starts stdio children with a minimal environment.
|
||||
# Explicit pass-through is required so the GitHub subprocess receives the PAT
|
||||
# already injected into this container by Docker. The value is never placed on
|
||||
# the command line, image, logs or Open WebUI connection record.
|
||||
ENTRYPOINT ["mcp-proxy", "--host", "0.0.0.0", "--port", "8000", "--stateless", "--pass-environment", "--"]
|
||||
CMD ["/usr/local/bin/github-mcp-server", "stdio", "--read-only", "--tools", "search_repositories,get_repository_tree,get_file_contents,search_code"]
|
||||
|
||||
@@ -169,6 +169,13 @@ führte trotz gesundem GitHub-Server und gültigem Token zu
|
||||
ist derselbe Transport, der sich bereits beim Athena Platform Context MCP
|
||||
bewährt hat.
|
||||
|
||||
Die Brücke wird mit `--pass-environment` gestartet. Ohne diese ausdrückliche
|
||||
Option sieht zwar der Proxy-Prozess den per Docker-Envfile injizierten PAT, der
|
||||
von ihm gestartete GitHub-stdio-Unterprozess jedoch nicht; der offizielle
|
||||
Server fällt dann irreführend auf die interaktive GitHub-Geräteanmeldung
|
||||
zurück. Der Token bleibt dabei eine Umgebungsvariable und erscheint weder in
|
||||
Kommandozeile noch Image, Log oder Open-WebUI-Konfiguration.
|
||||
|
||||
Dem Modell werden ausschließlich `search_repositories`, `get_repository_tree`,
|
||||
`get_file_contents` und `search_code` angeboten. Der offizielle Server wird
|
||||
zusätzlich explizit mit `--read-only` gestartet; die Umgebungsvariablen im
|
||||
|
||||
Reference in New Issue
Block a user