45 lines
1.6 KiB
Bash
45 lines
1.6 KiB
Bash
#!/bin/sh
|
|
set -eu
|
|
|
|
data_dir=${MCPHUB_SETTING_PATH:-/app/data/}
|
|
case "$data_dir" in
|
|
*/) state_dir=${data_dir%/} ;;
|
|
*) state_dir=$(dirname "$data_dir") ;;
|
|
esac
|
|
mkdir -p "$state_dir"
|
|
|
|
# A stable signing key prevents every container recreation from invalidating
|
|
# all logged-in browser sessions. It lives only in persistent appdata.
|
|
jwt_file="$state_dir/jwt-secret"
|
|
if [ ! -s "$jwt_file" ]; then
|
|
umask 077
|
|
python3 -c 'import secrets; print(secrets.token_urlsafe(64))' > "$jwt_file"
|
|
fi
|
|
JWT_SECRET=$(cat "$jwt_file")
|
|
export JWT_SECRET
|
|
|
|
# Reconcile the persistent MCPHub state with the versioned registry on every
|
|
# start. Existing users, bearer tokens and per-server enabled flags survive.
|
|
# This makes image upgrades reproducible instead of relying on manual edits in
|
|
# MCPHub's database/UI.
|
|
settings_file="$state_dir/mcp_settings.json"
|
|
registry_dir="$state_dir/config"
|
|
registry_file="$registry_dir/mcp-registry.json"
|
|
mkdir -p "$registry_dir" "$state_dir/extensions" "$state_dir/work"
|
|
if [ ! -s "$registry_file" ]; then
|
|
cp /opt/casaderoll/config/mcp-registry.json "$registry_file"
|
|
chmod 0600 "$registry_file"
|
|
fi
|
|
|
|
# MCPHub's own persistent settings and official API are the runtime source of
|
|
# truth. Render the declarative registry only for a fresh recovery (or an
|
|
# explicitly requested migration), never on every image update: otherwise an
|
|
# MCP installed through the dashboard/API would disappear on restart.
|
|
if [ ! -s "$settings_file" ] || [ "${MCPHUB_RECONCILE:-0}" = "1" ]; then
|
|
python3 /opt/casaderoll/configure-settings.py \
|
|
"$settings_file" /run/secrets/mcphub \
|
|
--registry "$registry_file"
|
|
fi
|
|
|
|
exec "$@"
|