From 5d2550668a5ac536299958dbc35816c18cba0bc9 Mon Sep 17 00:00:00 2001 From: Mikei386 <44135113+Mikei386@users.noreply.github.com> Date: Sat, 29 Aug 2026 19:48:15 +0200 Subject: [PATCH] Sanitize public installation metadata --- .gitignore | 12 ++++++++++++ README.md | 28 ++++++++++++++-------------- docs/HERMES.md | 6 +++--- plugin/mua.plg | 8 ++++---- 4 files changed, 33 insertions(+), 21 deletions(-) diff --git a/.gitignore b/.gitignore index cf73a00..2c83625 100644 --- a/.gitignore +++ b/.gitignore @@ -20,6 +20,18 @@ Thumbs.db /tmp/ *.tmp +# Local configuration and secrets +.env +.env.* +!.env.example +mua.conf +credentials* +secrets* +*.key +*.pem +*.p12 +*.pfx + # Build artifacts node_modules/ build/ diff --git a/README.md b/README.md index ce7625c..99584e0 100644 --- a/README.md +++ b/README.md @@ -3,8 +3,8 @@ MCP-Server für Unraid: Docker-Container, Netzwerk und System-Tools. Kompiliertes Bun-Binary (TypeScript), läuft als SysVinit-Service auf Unraid. -- **MCP-Endpunkt:** `http://:3002/mcp` (Streamable HTTP, POST-only, JSON-RPC 2.0) -- **Health-Check:** `http://:3002/health` (offen, ohne Auth) +- **MCP-Endpunkt:** `http://UNRAID-IP:3002/mcp` (Streamable HTTP, POST-only, JSON-RPC 2.0) +- **Health-Check:** `http://UNRAID-IP:3002/health` (offen, ohne Auth) - **Config-Server:** `http://127.0.0.1:3013/config` (localhost + separater Admin-Token) - **Auth:** API-Key (Bearer-Token) für `/mcp` - **Tools:** 35 (Docker, Community Applications, Netzwerk, Unraid-System und optionale Toolbox) @@ -22,7 +22,7 @@ Kurzform für Hermes: ```bash hermes mcp add unraid \ - --url http://192.168.1.2:3002/mcp \ + --url http://UNRAID-IP:3002/mcp \ --auth header \ --connect-timeout 30 hermes mcp test unraid @@ -38,7 +38,7 @@ erneute MUA-Installation nötig. ``` ┌─────────────────────────────────────────────────────────┐ -│ Unraid (192.168.1.2) │ +│ Unraid (UNRAID-IP) │ │ │ │ /usr/local/bin/mua (kompiliertes Bun-Binary) │ │ ├── MCP-Server 0.0.0.0:3002 (Bearer-Auth) │ @@ -99,10 +99,10 @@ Oder manuell: ```bash # .txz von Gitea laden -curl -O http://192.168.1.2:4000/michael/MUA-Mikes-Unraid-Agent/raw/branch/main/dist/mua-2026.08.24.r022-x86_64-1.txz +curl -O https://git.casaderoll.de/michael/MUA-Mikes-Unraid-Agent/raw/branch/main/dist/mua-2026.08.29.r027-x86_64-1.txz # Installieren -upgradepkg --install-new mua-2026.08.24.r022-x86_64-1.txz +upgradepkg --install-new mua-2026.08.29.r027-x86_64-1.txz ``` ### 2. Service starten @@ -116,7 +116,7 @@ Der Service startet automatisch bei jedem Boot (SysVinit). ### 3. Health-Check ```bash -curl http://192.168.1.2:3002/health +curl http://UNRAID-IP:3002/health # → {"status":"ok","version":"2026.08.24.r022","auth":"required"} ``` @@ -141,7 +141,7 @@ MUA ist ein **Standard-MCP-Server** (Streamable HTTP, POST-only, JSON-RPC 2.0). Jeder MCP-Client kann es nutzen — URL + Bearer-Token reichen: ``` -URL: http://192.168.1.2:3002/mcp +URL: http://UNRAID-IP:3002/mcp Auth: Authorization: Bearer ``` @@ -159,7 +159,7 @@ direkt mit diesem MUA-Endpunkt. # Direkte Anbindung ohne MCPHub mcp_servers: unraid: - url: http://192.168.1.2:3002/mcp + url: http://UNRAID-IP:3002/mcp headers: Authorization: Bearer timeout: 1800 @@ -175,24 +175,24 @@ keine eigene SSH- oder MUA-Konfiguration. ```bash # Health-Check (ohne Auth) -curl http://192.168.1.2:3002/health +curl http://UNRAID-IP:3002/health # MCP-Initialisierung (mit Auth) -curl -X POST http://192.168.1.2:3002/mcp \ +curl -X POST http://UNRAID-IP:3002/mcp \ -H "Authorization: Bearer " \ -H "Content-Type: application/json" \ -H "Accept: application/json, text/event-stream" \ -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"test","version":"1.0"}}}' # Tool-Liste -curl -X POST http://192.168.1.2:3002/mcp \ +curl -X POST http://UNRAID-IP:3002/mcp \ -H "Authorization: Bearer " \ -H "Content-Type: application/json" \ -H "Accept: application/json, text/event-stream" \ -d '{"jsonrpc":"2.0","id":2,"method":"tools/list","params":{}}' # Tool aufrufen -curl -X POST http://192.168.1.2:3002/mcp \ +curl -X POST http://UNRAID-IP:3002/mcp \ -H "Authorization: Bearer " \ -H "Content-Type: application/json" \ -H "Accept: application/json, text/event-stream" \ @@ -202,7 +202,7 @@ curl -X POST http://192.168.1.2:3002/mcp \ ### Ohne API-Key → 401 ```bash -curl -X POST http://192.168.1.2:3002/mcp \ +curl -X POST http://UNRAID-IP:3002/mcp \ -H "Content-Type: application/json" \ -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{}}' # → 401 Unauthorized diff --git a/docs/HERMES.md b/docs/HERMES.md index d97d218..c488282 100644 --- a/docs/HERMES.md +++ b/docs/HERMES.md @@ -30,7 +30,7 @@ Ein geeigneter kurzer Auftrag lautet: Der offene Health-Endpunkt benötigt keinen API-Key: ```bash -curl -fsS http://192.168.1.2:3002/health +curl -fsS http://UNRAID-IP:3002/health ``` Erwartet wird JSON mit `"status":"ok"` und `"auth":"required"`. Dann läuft @@ -63,7 +63,7 @@ Im Hermes-Container liegt die CLI in dieser Installation unter ```bash hermes mcp add unraid \ - --url http://192.168.1.2:3002/mcp \ + --url http://UNRAID-IP:3002/mcp \ --auth header \ --connect-timeout 30 ``` @@ -84,7 +84,7 @@ HTTP-Server angelegt werden: | Feld | Wert | |---|---| | Name | `unraid` | -| URL | `http://192.168.1.2:3002/mcp` | +| URL | `http://UNRAID-IP:3002/mcp` | | Authentifizierung | Header/Bearer | | Token | MUA-API-Key ohne `Bearer ` | | Connect timeout | `30` Sekunden | diff --git a/plugin/mua.plg b/plugin/mua.plg index d4228b2..7211687 100644 --- a/plugin/mua.plg +++ b/plugin/mua.plg @@ -4,10 +4,10 @@ - + - + ]> @@ -18,8 +18,8 @@ pluginURL="&pluginURL;" icon="cubes" min="7.0.0" - support="http://192.168.1.2:4000/michael/MUA-Mikes-Unraid-Agent" - project="http://192.168.1.2:4000/michael/MUA-Mikes-Unraid-Agent" + support="https://git.casaderoll.de/michael/MUA-Mikes-Unraid-Agent" + project="https://git.casaderoll.de/michael/MUA-Mikes-Unraid-Agent" >