x-tool-common: &tool-common restart: unless-stopped read_only: true tmpfs: - /tmp:rw,noexec,nosuid,nodev,size=64m security_opt: ["no-new-privileges:true"] cap_drop: [ALL] networks: [tools] logging: options: max-size: 10m max-file: "3" services: # Einziger MCP auf Athena: die schmale Fassade zum root-eigenen Operator. # Alle portablen Fach-MCPs laufen als eigene Container auf Unraid. mcp-athena-operator: <<: *tool-common build: context: . dockerfile: Dockerfile.athena-operator image: mike-ai/mcp-athena-operator:3.1.0 container_name: mike-ai-mcp-athena-operator environment: ATHENA_OPERATOR_SOCKET: /operator/operator.sock volumes: - /run/mike-ai-operator:/operator:ro healthcheck: test: [CMD, python, -c, "import socket; s=socket.create_connection(('127.0.0.1',8000),2); s.close()"] interval: 30s timeout: 5s retries: 5 start_period: 10s