fix(tools): harden OpenWebUI tool workflows
This commit is contained in:
@@ -94,6 +94,12 @@ services:
|
||||
image: mike-ai/mcp-homeassistant-relay:local
|
||||
container_name: mike-ai-mcp-homeassistant
|
||||
profiles: [homeassistant]
|
||||
# Keep the public TLS hostname for SNI/certificate validation, but route it
|
||||
# to the private reverse proxy through WireGuard. Public DNS may otherwise
|
||||
# resolve to the Fritzbox WAN address, which is unreachable/hairpinned from
|
||||
# Athena's remote-site containers.
|
||||
extra_hosts:
|
||||
- "ha.casaderoll.de:${HOME_LAN_PROXY_IP:-192.168.1.2}"
|
||||
volumes:
|
||||
- ${HA_ENV_FILE:-/etc/mike-ai/homeassistant-admin-mcp.env}:/run/secrets/homeassistant.env:ro
|
||||
cap_add: [CHOWN, SETUID, SETGID]
|
||||
@@ -210,7 +216,7 @@ services:
|
||||
environment:
|
||||
# These server-side limits remain authoritative even if a client asks
|
||||
# for broader toolsets. The token itself must also remain read-only.
|
||||
GITHUB_TOOLS: search_repositories,get_repository_tree,get_file_contents,search_code
|
||||
GITHUB_TOOLS: search_repositories,get_file_contents,search_code
|
||||
GITHUB_READ_ONLY: "1"
|
||||
networks: [tools, egress]
|
||||
healthcheck:
|
||||
|
||||
Reference in New Issue
Block a user