Pass GitHub PAT to MCP subprocess

This commit is contained in:
Mikei386
2026-08-23 18:44:14 +02:00
parent a9847c43eb
commit ddde433224
6 changed files with 35 additions and 1 deletions
+6
View File
@@ -50,6 +50,12 @@ code search, use the official read-only GitHub Repository MCP. Use general web
search for broader public research. Avoid repeated synonymous tool calls and search for broader public research. Avoid repeated synonymous tool calls and
keep tool output bounded. keep tool output bounded.
If a specialist tool reports an authentication, authorization, connection or
configuration error, do not repeat the same call. State the exact bounded
failure. For public information make at most one focused fallback attempt with
the general web tool, then synthesize the available evidence or stop clearly.
Never enter a fallback or synonym-search loop.
For models and GPU services, introduce changes only through the experimental For models and GPU services, introduce changes only through the experimental
profile or an isolated container. Change one variable at a time, record source, profile or an isolated container. Change one variable at a time, record source,
license, revision, size and SHA256, account for weights, KV cache, projector, license, revision, size and SHA256, account for weights, KV cache, projector,
+6
View File
@@ -72,6 +72,12 @@ WebUI fehlerhaft. Produktiv wird deshalb der offizielle GitHub MCP 1.10.1 über
`mcp-proxy` 0.12.0 bereitgestellt. Der Pfad wurde mit Open WebUIs eigenem `mcp-proxy` 0.12.0 bereitgestellt. Der Pfad wurde mit Open WebUIs eigenem
Python-MCP-Client und einer echten öffentlichen Repositorysuche geprüft. Python-MCP-Client und einer echten öffentlichen Repositorysuche geprüft.
Falls ein Werkzeug stattdessen einen Code für `github.com/login/device`
ausgibt, ist der PAT nicht im GitHub-stdio-Unterprozess angekommen. Der
produktive Proxy verwendet deshalb ausdrücklich `--pass-environment`. Der PAT
darf nicht in den Chat kopiert und die Geräteanmeldung nicht als Dauerlösung
verwendet werden.
Der Normalmodus ist Teil des Installationsskripts. Skript, Compose-Override und Der Normalmodus ist Teil des Installationsskripts. Skript, Compose-Override und
diese Anleitung liegen im Git-Repository und werden vom Recovery-Koffer diese Anleitung liegen im Git-Repository und werden vom Recovery-Koffer
mitgeführt. Das Platform Context MCP kann diese Anleitung lesen, erhält aber mitgeführt. Das Platform Context MCP kann diese Anleitung lesen, erhält aber
+6
View File
@@ -249,6 +249,12 @@ WebUI, Git oder einem Prompt. Für Quellcode, README, API-Routen und
Repositorystruktur ist GitHub das richtige Werkzeug; die allgemeine Websuche Repositorystruktur ist GitHub das richtige Werkzeug; die allgemeine Websuche
ist für breitere öffentliche Recherche zuständig. ist für breitere öffentliche Recherche zuständig.
Meldet ein Fachwerkzeug einen Authentifizierungs-, Autorisierungs-, Verbindungs-
oder Konfigurationsfehler, darf derselbe Aufruf nicht wiederholt werden. Für
öffentliche Informationen ist höchstens ein gezielter Wechsel zur allgemeinen
Websuche erlaubt. Danach muss das Modell die verfügbaren Belege auswerten oder
den Abbruch klar melden, statt weitere Synonyme und Fallbacks durchzuprobieren.
GitHub ist standardmäßig strikt lesend. Falls der Benutzer ausdrücklich einen GitHub ist standardmäßig strikt lesend. Falls der Benutzer ausdrücklich einen
beaufsichtigten Schreibtermin verlangt, gilt der Ablauf in beaufsichtigten Schreibtermin verlangt, gilt der Ablauf in
`docs/GITHUB_MCP.md`: begrenzten Wartungsmodus aktivieren, ausschließlich auf `docs/GITHUB_MCP.md`: begrenzten Wartungsmodus aktivieren, ausschließlich auf
+5 -1
View File
@@ -17,5 +17,9 @@ EXPOSE 8000
# This is the same OpenWebUI-compatible stateless transport used by Athena's # This is the same OpenWebUI-compatible stateless transport used by Athena's
# other Python/stdio MCP adapters. The official GitHub binary remains the only # other Python/stdio MCP adapters. The official GitHub binary remains the only
# component implementing GitHub operations. # component implementing GitHub operations.
ENTRYPOINT ["mcp-proxy", "--host", "0.0.0.0", "--port", "8000", "--stateless", "--"] # mcp-proxy intentionally starts stdio children with a minimal environment.
# Explicit pass-through is required so the GitHub subprocess receives the PAT
# already injected into this container by Docker. The value is never placed on
# the command line, image, logs or Open WebUI connection record.
ENTRYPOINT ["mcp-proxy", "--host", "0.0.0.0", "--port", "8000", "--stateless", "--pass-environment", "--"]
CMD ["/usr/local/bin/github-mcp-server", "stdio", "--read-only", "--tools", "search_repositories,get_repository_tree,get_file_contents,search_code"] CMD ["/usr/local/bin/github-mcp-server", "stdio", "--read-only", "--tools", "search_repositories,get_repository_tree,get_file_contents,search_code"]
+7
View File
@@ -169,6 +169,13 @@ führte trotz gesundem GitHub-Server und gültigem Token zu
ist derselbe Transport, der sich bereits beim Athena Platform Context MCP ist derselbe Transport, der sich bereits beim Athena Platform Context MCP
bewährt hat. bewährt hat.
Die Brücke wird mit `--pass-environment` gestartet. Ohne diese ausdrückliche
Option sieht zwar der Proxy-Prozess den per Docker-Envfile injizierten PAT, der
von ihm gestartete GitHub-stdio-Unterprozess jedoch nicht; der offizielle
Server fällt dann irreführend auf die interaktive GitHub-Geräteanmeldung
zurück. Der Token bleibt dabei eine Umgebungsvariable und erscheint weder in
Kommandozeile noch Image, Log oder Open-WebUI-Konfiguration.
Dem Modell werden ausschließlich `search_repositories`, `get_repository_tree`, Dem Modell werden ausschließlich `search_repositories`, `get_repository_tree`,
`get_file_contents` und `search_code` angeboten. Der offizielle Server wird `get_file_contents` und `search_code` angeboten. Der offizielle Server wird
zusätzlich explizit mit `--read-only` gestartet; die Umgebungsvariablen im zusätzlich explizit mit `--read-only` gestartet; die Umgebungsvariablen im
+5
View File
@@ -200,6 +200,11 @@ params = {
"API routes, or code search, use the dedicated official GitHub repository " "API routes, or code search, use the dedicated official GitHub repository "
"tool instead of guessing from ordinary web results. Use general web search " "tool instead of guessing from ordinary web results. Use general web search "
"for wider public discussion and non-repository sources. " "for wider public discussion and non-repository sources. "
"If a specialist tool returns an authentication, authorization, connection, "
"or configuration error, do not repeat the same call. Report the error. For "
"public information you may make at most one focused fallback attempt with "
"the general web tool, then synthesize the available evidence or stop clearly; "
"never enter a fallback or synonym-search loop. "
"Never invent tool results, system state, files, measurements, or actions. " "Never invent tool results, system state, files, measurements, or actions. "
"For claims about current external or system state, you must successfully " "For claims about current external or system state, you must successfully "
"use the relevant domain tool during the current request before saying " "use the relevant domain tool during the current request before saying "