97 lines
4.0 KiB
Bash
97 lines
4.0 KiB
Bash
#!/usr/bin/env bash
|
|
set -Eeuo pipefail
|
|
|
|
[[ $EUID -eq 0 ]] || { echo "Bitte als root ausführen." >&2; exit 1; }
|
|
|
|
MCP_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
STACK_ENV=${STACK_ENV:-/etc/mike-ai/stack.env}
|
|
COMPOSE=(docker compose)
|
|
if [[ -s $STACK_ENV ]]; then
|
|
COMPOSE+=(--env-file "$STACK_ENV")
|
|
fi
|
|
COMPOSE+=(-f "$MCP_DIR/compose.yaml")
|
|
export SEARXNG_SETTINGS_FILE="${SEARXNG_SETTINGS_FILE:-$MCP_DIR/../web-search/searxng-settings.yml}"
|
|
|
|
[[ -s $SEARXNG_SETTINGS_FILE ]] || {
|
|
echo "SearXNG-Konfiguration fehlt: $SEARXNG_SETTINGS_FILE" >&2
|
|
exit 1
|
|
}
|
|
|
|
# The platform context MCP never receives the Docker socket. A root-owned
|
|
# timer writes a bounded metadata snapshot instead. Only documentation files
|
|
# and the dedicated state directory are writable by the unprivileged MCP uid.
|
|
install -d -m 0755 /usr/local/libexec /var/lib/mike-ai-platform-context
|
|
install -d -o 10001 -g 10001 -m 0750 /data/mike-ai-platform-context
|
|
install -m 0755 "$MCP_DIR/platform-context-snapshot.py" \
|
|
/usr/local/libexec/mike-ai-platform-context-snapshot
|
|
install -m 0644 "$MCP_DIR/../systemd/mike-ai-platform-context-snapshot.service" \
|
|
/etc/systemd/system/mike-ai-platform-context-snapshot.service
|
|
install -m 0644 "$MCP_DIR/../systemd/mike-ai-platform-context-snapshot.timer" \
|
|
/etc/systemd/system/mike-ai-platform-context-snapshot.timer
|
|
find /opt/mike-ai/stack/docs -type d -exec chown root:10001 {} + -exec chmod 0775 {} +
|
|
find /opt/mike-ai/stack/docs -type f -name '*.md' -exec chown root:10001 {} + -exec chmod 0664 {} +
|
|
systemctl daemon-reload
|
|
systemctl enable --now mike-ai-platform-context-snapshot.timer
|
|
systemctl start mike-ai-platform-context-snapshot.service
|
|
|
|
# One user-facing Athena Operator MCP controls the complete local AI platform
|
|
# through a root-side structured executor. It is intentionally not a general
|
|
# shell and exposes no raw Docker socket or host paths to the MCP container.
|
|
"$MCP_DIR/../operator/install-operator.sh"
|
|
|
|
profiles=()
|
|
if [[ -s /etc/mike-ai/homeassistant-admin-mcp.env ]]; then
|
|
profiles+=(--profile homeassistant)
|
|
else
|
|
echo "Home Assistant bleibt aus: Secret-Datei fehlt."
|
|
fi
|
|
if [[ -s /etc/mike-ai/arr-mcp.env ]]; then
|
|
profiles+=(--profile arr)
|
|
else
|
|
echo "ARR bleibt aus: Secret-Datei fehlt."
|
|
fi
|
|
if [[ -s /etc/mike-ai/navidrome-mcp.env ]]; then
|
|
profiles+=(--profile navidrome)
|
|
else
|
|
echo "Navidrome bleibt aus: Secret-Datei fehlt."
|
|
fi
|
|
if [[ -s /etc/mike-ai/deemix-mcp.env ]]; then
|
|
profiles+=(--profile deemix)
|
|
else
|
|
echo "Deemix MCP bleibt aus: Konfigurationsdatei fehlt."
|
|
fi
|
|
if [[ -s /etc/mike-ai/github-mcp.env ]] && \
|
|
grep -Eq '^GITHUB_PERSONAL_ACCESS_TOKEN=.+$' /etc/mike-ai/github-mcp.env; then
|
|
profiles+=(--profile github)
|
|
else
|
|
echo "GitHub bleibt aus: dedizierter Read-only-Token fehlt."
|
|
fi
|
|
# TinySearch keeps the embedding bundle outside the container. Download it
|
|
# once on a fresh host; subsequent rebuilds reuse the named volume.
|
|
#
|
|
# Do not call `tinysearch setup` here. The pinned container image already
|
|
# contains a complete Playwright/Chromium installation, while that command
|
|
# unconditionally tries to install Chromium again. On IPv4-only hosts this
|
|
# redundant download can hang indefinitely. Prepare only the persistent ONNX
|
|
# bundle that is actually absent on a fresh installation.
|
|
docker volume create mike-ai-tools_tinysearch-models >/dev/null
|
|
tiny_image="marcellm01/tinysearch@sha256:7a7d0585f5000f462e699e42b97409715826a9e2edcd09a166afa93a4b7cba31"
|
|
if ! docker run --rm --entrypoint test \
|
|
-v mike-ai-tools_tinysearch-models:/data/models "$tiny_image" \
|
|
-f /data/models/all-minilm-l6-v2-onnx/model.onnx; then
|
|
echo "TinySearch-Modell wird einmalig geladen."
|
|
docker run --rm --entrypoint python \
|
|
-v mike-ai-tools_tinysearch-models:/data/models "$tiny_image" \
|
|
-c 'from tinysearch.services.onnx_bundle_service import ensure_onnx_bundle_sync; ensure_onnx_bundle_sync("fast")'
|
|
fi
|
|
|
|
"${COMPOSE[@]}" "${profiles[@]}" up -d --build
|
|
|
|
for webui in mike-ai-open-webui Open-WebUI; do
|
|
if docker container inspect "$webui" >/dev/null 2>&1; then
|
|
docker network connect mike-ai-tools "$webui" 2>/dev/null || true
|
|
fi
|
|
done
|
|
|
|
"${COMPOSE[@]}" "${profiles[@]}" ps
|