26 lines
1.4 KiB
Docker
26 lines
1.4 KiB
Docker
FROM ghcr.io/github/github-mcp-server@sha256:1817b57d43916532dc002bdc5f344d639bd9fb54a9148d42168458f7c3280567 AS github
|
|
|
|
FROM python:3.13-slim@sha256:ffb752e139c0a19692a43af8d8523b274222dd68eebad5d583b45c2201c6e30a
|
|
|
|
ARG MCP_PROXY_VERSION=0.12.0
|
|
RUN pip install --no-cache-dir "mcp-proxy==${MCP_PROXY_VERSION}" "mcp==1.29.0"
|
|
|
|
# GitHub publishes a minimal image containing only the official Go binary.
|
|
# mcp-proxy contributes transport conversion only; GitHub API behavior and
|
|
# every exposed tool remain implemented by GitHub's official MCP server.
|
|
COPY --from=github /server/github-mcp-server /usr/local/bin/github-mcp-server
|
|
|
|
RUN useradd --system --uid 10001 --create-home --home-dir /app mcp
|
|
USER 10001:10001
|
|
WORKDIR /app
|
|
EXPOSE 8000
|
|
# This is the same OpenWebUI-compatible stateless transport used by Athena's
|
|
# other Python/stdio MCP adapters. The official GitHub binary remains the only
|
|
# component implementing GitHub operations.
|
|
# mcp-proxy intentionally starts stdio children with a minimal environment.
|
|
# Explicit pass-through is required so the GitHub subprocess receives the PAT
|
|
# already injected into this container by Docker. The value is never placed on
|
|
# the command line, image, logs or Open WebUI connection record.
|
|
ENTRYPOINT ["mcp-proxy", "--host", "0.0.0.0", "--port", "8000", "--stateless", "--pass-environment", "--"]
|
|
CMD ["/usr/local/bin/github-mcp-server", "stdio", "--read-only", "--tools", "search_repositories,get_file_contents,search_code"]
|