#!/bin/sh set -eu data_dir=${MCPHUB_SETTING_PATH:-/app/data/} case "$data_dir" in */) state_dir=${data_dir%/} ;; *) state_dir=$(dirname "$data_dir") ;; esac mkdir -p "$state_dir" # A stable signing key prevents every container recreation from invalidating # all logged-in browser sessions. It lives only in persistent appdata. jwt_file="$state_dir/jwt-secret" if [ ! -s "$jwt_file" ]; then umask 077 python3 -c 'import secrets; print(secrets.token_urlsafe(64))' > "$jwt_file" fi JWT_SECRET=$(cat "$jwt_file") export JWT_SECRET # Reconcile the persistent MCPHub state with the versioned registry on every # start. Existing users, bearer tokens and per-server enabled flags survive. # This makes image upgrades reproducible instead of relying on manual edits in # MCPHub's database/UI. settings_file="$state_dir/mcp_settings.json" registry_dir="$state_dir/config" registry_file="$registry_dir/mcp-registry.json" mkdir -p "$registry_dir" "$state_dir/extensions" "$state_dir/work" if [ ! -s "$registry_file" ]; then cp /opt/casaderoll/config/mcp-registry.json "$registry_file" chmod 0600 "$registry_file" fi # MCPHub's own persistent settings and official API are the runtime source of # truth. Render the declarative registry only for a fresh recovery (or an # explicitly requested migration), never on every image update: otherwise an # MCP installed through the dashboard/API would disappear on restart. if [ ! -s "$settings_file" ] || [ "${MCPHUB_RECONCILE:-0}" = "1" ]; then python3 /opt/casaderoll/configure-settings.py \ "$settings_file" /run/secrets/mcphub \ --registry "$registry_file" fi exec "$@"