Pass GitHub PAT to MCP subprocess
This commit is contained in:
@@ -50,6 +50,12 @@ code search, use the official read-only GitHub Repository MCP. Use general web
|
||||
search for broader public research. Avoid repeated synonymous tool calls and
|
||||
keep tool output bounded.
|
||||
|
||||
If a specialist tool reports an authentication, authorization, connection or
|
||||
configuration error, do not repeat the same call. State the exact bounded
|
||||
failure. For public information make at most one focused fallback attempt with
|
||||
the general web tool, then synthesize the available evidence or stop clearly.
|
||||
Never enter a fallback or synonym-search loop.
|
||||
|
||||
For models and GPU services, introduce changes only through the experimental
|
||||
profile or an isolated container. Change one variable at a time, record source,
|
||||
license, revision, size and SHA256, account for weights, KV cache, projector,
|
||||
|
||||
@@ -72,6 +72,12 @@ WebUI fehlerhaft. Produktiv wird deshalb der offizielle GitHub MCP 1.10.1 über
|
||||
`mcp-proxy` 0.12.0 bereitgestellt. Der Pfad wurde mit Open WebUIs eigenem
|
||||
Python-MCP-Client und einer echten öffentlichen Repositorysuche geprüft.
|
||||
|
||||
Falls ein Werkzeug stattdessen einen Code für `github.com/login/device`
|
||||
ausgibt, ist der PAT nicht im GitHub-stdio-Unterprozess angekommen. Der
|
||||
produktive Proxy verwendet deshalb ausdrücklich `--pass-environment`. Der PAT
|
||||
darf nicht in den Chat kopiert und die Geräteanmeldung nicht als Dauerlösung
|
||||
verwendet werden.
|
||||
|
||||
Der Normalmodus ist Teil des Installationsskripts. Skript, Compose-Override und
|
||||
diese Anleitung liegen im Git-Repository und werden vom Recovery-Koffer
|
||||
mitgeführt. Das Platform Context MCP kann diese Anleitung lesen, erhält aber
|
||||
|
||||
@@ -249,6 +249,12 @@ WebUI, Git oder einem Prompt. Für Quellcode, README, API-Routen und
|
||||
Repositorystruktur ist GitHub das richtige Werkzeug; die allgemeine Websuche
|
||||
ist für breitere öffentliche Recherche zuständig.
|
||||
|
||||
Meldet ein Fachwerkzeug einen Authentifizierungs-, Autorisierungs-, Verbindungs-
|
||||
oder Konfigurationsfehler, darf derselbe Aufruf nicht wiederholt werden. Für
|
||||
öffentliche Informationen ist höchstens ein gezielter Wechsel zur allgemeinen
|
||||
Websuche erlaubt. Danach muss das Modell die verfügbaren Belege auswerten oder
|
||||
den Abbruch klar melden, statt weitere Synonyme und Fallbacks durchzuprobieren.
|
||||
|
||||
GitHub ist standardmäßig strikt lesend. Falls der Benutzer ausdrücklich einen
|
||||
beaufsichtigten Schreibtermin verlangt, gilt der Ablauf in
|
||||
`docs/GITHUB_MCP.md`: begrenzten Wartungsmodus aktivieren, ausschließlich auf
|
||||
|
||||
@@ -17,5 +17,9 @@ EXPOSE 8000
|
||||
# This is the same OpenWebUI-compatible stateless transport used by Athena's
|
||||
# other Python/stdio MCP adapters. The official GitHub binary remains the only
|
||||
# component implementing GitHub operations.
|
||||
ENTRYPOINT ["mcp-proxy", "--host", "0.0.0.0", "--port", "8000", "--stateless", "--"]
|
||||
# mcp-proxy intentionally starts stdio children with a minimal environment.
|
||||
# Explicit pass-through is required so the GitHub subprocess receives the PAT
|
||||
# already injected into this container by Docker. The value is never placed on
|
||||
# the command line, image, logs or Open WebUI connection record.
|
||||
ENTRYPOINT ["mcp-proxy", "--host", "0.0.0.0", "--port", "8000", "--stateless", "--pass-environment", "--"]
|
||||
CMD ["/usr/local/bin/github-mcp-server", "stdio", "--read-only", "--tools", "search_repositories,get_repository_tree,get_file_contents,search_code"]
|
||||
|
||||
@@ -169,6 +169,13 @@ führte trotz gesundem GitHub-Server und gültigem Token zu
|
||||
ist derselbe Transport, der sich bereits beim Athena Platform Context MCP
|
||||
bewährt hat.
|
||||
|
||||
Die Brücke wird mit `--pass-environment` gestartet. Ohne diese ausdrückliche
|
||||
Option sieht zwar der Proxy-Prozess den per Docker-Envfile injizierten PAT, der
|
||||
von ihm gestartete GitHub-stdio-Unterprozess jedoch nicht; der offizielle
|
||||
Server fällt dann irreführend auf die interaktive GitHub-Geräteanmeldung
|
||||
zurück. Der Token bleibt dabei eine Umgebungsvariable und erscheint weder in
|
||||
Kommandozeile noch Image, Log oder Open-WebUI-Konfiguration.
|
||||
|
||||
Dem Modell werden ausschließlich `search_repositories`, `get_repository_tree`,
|
||||
`get_file_contents` und `search_code` angeboten. Der offizielle Server wird
|
||||
zusätzlich explizit mit `--read-only` gestartet; die Umgebungsvariablen im
|
||||
|
||||
@@ -200,6 +200,11 @@ params = {
|
||||
"API routes, or code search, use the dedicated official GitHub repository "
|
||||
"tool instead of guessing from ordinary web results. Use general web search "
|
||||
"for wider public discussion and non-repository sources. "
|
||||
"If a specialist tool returns an authentication, authorization, connection, "
|
||||
"or configuration error, do not repeat the same call. Report the error. For "
|
||||
"public information you may make at most one focused fallback attempt with "
|
||||
"the general web tool, then synthesize the available evidence or stop clearly; "
|
||||
"never enter a fallback or synonym-search loop. "
|
||||
"Never invent tool results, system state, files, measurements, or actions. "
|
||||
"For claims about current external or system state, you must successfully "
|
||||
"use the relevant domain tool during the current request before saying "
|
||||
|
||||
Reference in New Issue
Block a user