name: mike-ai-tools x-tool-common: &tool-common restart: unless-stopped read_only: true tmpfs: - /tmp:rw,noexec,nosuid,nodev,size=64m security_opt: ["no-new-privileges:true"] cap_drop: [ALL] networks: [tools] logging: options: max-size: 10m max-file: "3" services: mcp-web: <<: *tool-common build: context: .. dockerfile: mcp/Dockerfile.web image: mike-ai/mcp-web:local container_name: mike-ai-mcp-web environment: TINYSEARCH_MCP_URL: http://tinysearch:8000/mcp SEARXNG_URL: http://searxng:8080 WEB_SEARCH_BUDGET_MAX_RELATED: "6" depends_on: tinysearch: condition: service_started searxng: <<: *tool-common image: searxng/searxng@sha256:e45d5894bfaa0bf8773b9f283795ae57f1c15ddb29c8cecb70b3665b0ce9ec60 container_name: mike-ai-tools-searxng volumes: - ${SEARXNG_SETTINGS_FILE:-../web-search/searxng-settings.example.yml}:/etc/searxng/settings.yml:ro networks: [tools, egress] tinysearch: <<: *tool-common image: marcellm01/tinysearch@sha256:5a03d5a1f1b0fabe48f2a26e05db4a84bcb611106a57ec51e42db4549976aa9c container_name: mike-ai-tools-tinysearch shm_size: 1gb volumes: - tinysearch-models:/data/models - ../web-search/tinysearch_config.json:/config/tinysearch_config.json:ro environment: MCP_TRANSPORT: streamable-http MCP_HOST: 0.0.0.0 MCP_PORT: "8000" TINYSEARCH_CONFIG_PATH: /config/tinysearch_config.json TINYSEARCH_SEARCH_BACKEND: searxng SEARXNG_URL: http://searxng:8080/search depends_on: [searxng] cap_add: [SETUID, SETGID, CHOWN] networks: [tools, egress] # The image's built-in `tinysearch doctor` also requires a writable # configuration directory, although normal server operation does not. # Check the service socket instead so read-only hardening remains intact. healthcheck: test: ["CMD", "python", "-c", "import socket; s=socket.create_connection(('127.0.0.1', 8000), 2); s.close()"] interval: 30s timeout: 5s retries: 5 start_period: 20s mcp-homeassistant: <<: *tool-common build: context: ../.. dockerfile: platform/mcp/Dockerfile.homeassistant-relay image: mike-ai/mcp-homeassistant-relay:local container_name: mike-ai-mcp-homeassistant profiles: [homeassistant] volumes: - ${HA_ENV_FILE:-/etc/mike-ai/homeassistant-admin-mcp.env}:/run/secrets/homeassistant.env:ro cap_add: [CHOWN, SETUID, SETGID] networks: [tools, egress] mcp-arr: <<: *tool-common build: context: . dockerfile: Dockerfile.arr image: mike-ai/mcp-arr:1.0.1-patched container_name: mike-ai-mcp-arr profiles: [arr] env_file: - ${ARR_ENV_FILE:-/etc/mike-ai/arr-mcp.env} volumes: # The local fork adds bounded read-only Sonarr pseudo-actions. Keep the # patch explicit until upstream publishes a self-contained 2.x image. - ${ARR_SONARR_PATCH:-./patches/mcp_sonarr.py}:/usr/local/lib/python3.13/site-packages/arr_mcp/mcp/mcp_sonarr.py:ro networks: [tools, egress] mcp-unraid-official: <<: *tool-common image: debian:13-slim container_name: mike-ai-mcp-unraid-official profiles: [unraid] env_file: - ${RUNRAID_ENV_FILE:-/etc/mike-ai/runraid/.env} environment: UNRAID_RMCP_HOST: 0.0.0.0 UNRAID_RMCP_PORT: "8000" UNRAID_RMCP_DISABLE_HTTP_AUTH: "true" UNRAID_NOAUTH: "true" UNRAID_RMCP_ALLOWED_HOSTS: "mike-ai-mcp-unraid-official:8000,mike-ai-mcp-unraid-official,localhost:8000,127.0.0.1:8000" volumes: - ${RUNRAID_BINARY:-/usr/local/bin/runraid}:/usr/local/bin/unraid:ro entrypoint: ["/usr/local/bin/unraid"] command: ["serve"] networks: [tools, egress] mcp-unraid-ssh: <<: *tool-common profiles: [extended] build: context: . dockerfile: Dockerfile.unraid-ssh image: mike-ai/mcp-unraid-ssh:local container_name: mike-ai-mcp-unraid-ssh environment: UNRAID_MCP_CONFIG: /run/config/unraid-mcp.json volumes: - ${UNRAID_MCP_SOURCE:-/opt/mike-ai/unraid-agent/unraid_mcp.py}:/app/unraid_mcp.py:ro - ${UNRAID_MCP_CONFIG:-/etc/mike-ai/unraid-mcp.json}:/run/config/unraid-mcp.json:ro - ${UNRAID_SSH_KEY:-/etc/mike-ai/keys/unraid_root}:/etc/mike-ai/keys/unraid_root:ro - ${UNRAID_KNOWN_HOSTS:-/etc/mike-ai/ssh/known_hosts_unraid_ai}:/etc/mike-ai/ssh/known_hosts_unraid_ai:ro - unraid-audit:/var/log/mike-ai networks: [tools, egress] networks: tools: name: mike-ai-tools internal: true ipam: config: [{subnet: 172.30.40.0/24}] egress: name: mike-ai-tools-egress ipam: config: [{subnet: 172.30.50.0/24}] volumes: tinysearch-models: unraid-audit: