23f7624596
ADR-166 MCP Bridge Security Lock / Static-source security lock (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / Compose default binds loopback + Mongo has auth (push) Failing after 2s
CodeQL Advanced / Analyze (rust) (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / plugin-agent-federation bindHost default (push) Failing after 1s
ADR-166 MCP Bridge Security Lock / Runtime behavior — 401 + terminal gate + fail-closed (push) Failing after 4s
business-pods-smoke / smoke (push) Failing after 1s
all-plugins-smoke / smoke-all (push) Failing after 2s
CI/CD Pipeline / Security & Code Quality (push) Failing after 1s
CI/CD Pipeline / Test Suite (ubuntu-latest) (push) Failing after 1s
CI/CD Pipeline / Build & Package (macos-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (ubuntu-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (windows-latest) (push) Has been skipped
CI/CD Pipeline / Documentation & Examples (push) Failing after 1s
Clone Tracker (14-day rolling) / Snapshot clones for ruflo ecosystem (push) Failing after 1s
CodeQL Advanced / Analyze (actions) (push) Failing after 1s
CodeQL Advanced / Analyze (javascript-typescript) (push) Failing after 1s
federation-peer-rust / stable-noop (push) Failing after 1s
metaharness-ci / score (push) Failing after 1s
metaharness-ci / router-compat (push) Failing after 0s
metaharness-ci / similarity-tests (push) Failing after 0s
no-agentbbs-smoke / smoke-without-agentbbs (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (windows-latest) (push) Has been skipped
codex-integration-audit / Codex integration audit (push) Failing after 1s
helpers-manifest-guard / guard (push) Failing after 1s
🔗 Cross-Agent Integration Tests / 🤝 Agent Coordination Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🧠 Memory Sharing Integration (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🛡️ Fault Tolerance Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / ⚡ Performance Integration Tests (push) Has been skipped
metaharness-ci / mcp-scan (push) Failing after 1s
metaharness-ci / eject-dryrun (push) Failing after 1s
metaharness-ci / metaharness-real-data (push) Failing after 0s
no-cli-optdep-bloat-2561 / guard (push) Failing after 1s
no-metaharness-smoke / smoke-without-metaharness (push) Failing after 1s
no-phantom-agentic-flow-subpath / guard (push) Failing after 1s
🔄 Automated Rollback Manager / 🚨 Failure Detection (push) Failing after 1s
V3 CI/CD Pipeline / Plugin hooks smoke / ubuntu-latest / Node 22 (push) Failing after 1s
V3 CI/CD Pipeline / ruflo-graph-intelligence build + test smoke (#2044, ADR-123) (push) Failing after 1s
CVE Audit Gate / Audit root (critical-blocking) (push) Failing after 2s
cost-tracker-smoke / smoke (push) Failing after 3s
oia-audit-weekly / audit (push) Failing after 2s
ruflo-agent-smoke / ruflo-agent structural smoke (push) Failing after 1s
📊 Status Badges Update / 📊 Update Status Badges (push) Failing after 1s
V3 CI/CD Pipeline / Static regression guards (#2267 YAML + (push) Failing after 1s
V3 CI/CD Pipeline / Test V3 Packages (push) Failing after 0s
V3 CI/CD Pipeline / agent_execute provider routing smoke (#2042) (push) Failing after 0s
CVE Audit Gate / Audit v3 (critical-blocking) (push) Failing after 1s
federation-peer-rust / stable-native (push) Failing after 2s
🔗 Cross-Agent Integration Tests / 🚀 Integration Test Setup (push) Failing after 2s
neural-trader-smoke / runtime-smoke (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (macos-latest) (push) Has been skipped
V3 CI/CD Pipeline / Build V3 (ubuntu-latest) (push) Has been skipped
V3 CI/CD Pipeline / Type Check V3 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 24 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 22 (push) Failing after 2s
V3 CI/CD Pipeline / browser rvf create flag smoke (#2015) (push) Failing after 0s
V3 CI/CD Pipeline / Dependency review (#2046) (push) Has been skipped
V3 CI/CD Pipeline / Supply-chain audit (#2046) (push) Failing after 0s
V3 CI/CD Pipeline / witness marker drift smoke (#2021) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader portfolio CG smoke (#2068, ADR-126 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader backtest signing smoke (#2068, ADR-126 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / kg-extract type-import classification smoke (#2049) (push) Failing after 0s
V3 CI/CD Pipeline / witness verify precondition smoke (#1880) (push) Failing after 2s
V3 CI/CD Pipeline / neural-trader pipeline risk-gate smoke (#2068, ADR-126 Phase 5) (push) Failing after 0s
V3 CI/CD Pipeline / neural-trader feature attribution smoke (#2068, ADR-126 Phase 6) (push) Failing after 0s
V3 CI/CD Pipeline / plugin-registry signature verification smoke (#1922, CWE-347) (push) Failing after 4s
V3 CI/CD Pipeline / memory stats legacy-DB smoke (#2120) (push) Failing after 4s
V3 CI/CD Pipeline / github deprecated actions smoke (#2089, ADR-127 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / graph query + pathfinder smoke (ADR-130 P2+P5) (push) Has been skipped
V3 CI/CD Pipeline / graph trajectory hooks smoke (ADR-130 P3) (push) Has been skipped
V3 CI/CD Pipeline / graph plugin adapter smoke (ADR-130 P4) (push) Has been skipped
V3 CI/CD Pipeline / graph benchmark (ADR-130 P6) (push) Has been skipped
V3 CI/CD Pipeline / statusline generator delegation smoke (#2195) (push) Failing after 1s
V3 CI/CD Pipeline / wizard init regression guard (#2206 (push) Failing after 1s
V3 CI/CD Pipeline / memory no-stray-db smoke (ADR-125 P7) (push) Failing after 1s
V3 CI/CD Pipeline / github-safe injection smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github actions pin smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github attribution opt-in smoke (#2089, ADR-127 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / pre-bash hook safety smoke (#2017) (push) Failing after 1s
V3 CI/CD Pipeline / Memory import smoke / ubuntu-latest (push) Failing after 0s
V3 CI/CD Pipeline / MCP protocol smoke / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / ruvllm WASM auto-init smoke (#2086) (push) Failing after 4s
V3 CI/CD Pipeline / MCP paired-tool round-trip smoke (#1889) (push) Failing after 1s
V3 CI/CD Pipeline / Plugin package install-safety (#1902/#1903/#1904) (push) Failing after 1s
V3 CI/CD Pipeline / Tool description discoverability (ADR-112) (push) Failing after 3s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (22) (push) Failing after 1s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (24) (push) Failing after 1s
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Vector-index dimension audit (#1947) (push) Failing after 0s
V3 CI/CD Pipeline / Hook-command install safety (#1921) (push) Failing after 1s
V3 CI/CD Pipeline / ToolOutputGuardrail smoke (ADR-131, (push) Failing after 1s
V3 CI/CD Pipeline / init-bundle invariants smoke (#2095, ADR-128 Phase 5) (push) Failing after 1s
V3 CI/CD Pipeline / wasm provider bridge smoke (ADR-129 P1) (push) Failing after 2s
V3 CI/CD Pipeline / wasm gallery CRUD smoke (ADR-129 P3) (push) Failing after 1s
V3 CI/CD Pipeline / wasm plugin bridge smoke (ADR-129 P4) (push) Failing after 0s
V3 CI/CD Pipeline / wasm compose smoke (ADR-129 P2) (push) Failing after 4s
V3 CI/CD Pipeline / graph schema smoke (ADR-130 P1) (push) Failing after 0s
Validate Marketplace / validate (push) Failing after 1s
🔍 Verification Pipeline / 🚀 Setup Verification (push) Failing after 1s
🔍 Verification Pipeline / 🛡️ Security Verification (push) Has been skipped
🔍 Verification Pipeline / 📝 Code Quality (push) Has been skipped
🔍 Verification Pipeline / 🧪 Test Verification (${{ matrix.os }}, Node ${{ matrix.node }}) (push) Has been skipped
🔍 Verification Pipeline / 🏗️ Build Verification (push) Has been skipped
🔍 Verification Pipeline / 📚 Documentation Verification (push) Has been skipped
CVE Audit Gate / High-severity report (warn only) (push) Has been cancelled
🔄 Automated Rollback Manager / 🔄 Execute Rollback (push) Has been cancelled
🔄 Automated Rollback Manager / ✅ Post-Rollback Verification (push) Has been cancelled
🔄 Automated Rollback Manager / 📊 Rollback Monitoring (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / windows-latest (push) Has been cancelled
🔄 Automated Rollback Manager / ⏳ Manual Rollback Approval (push) Has been cancelled
V3 CI/CD Pipeline / MCP protocol smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Memory import smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / ubuntu-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Publish to npm (alpha) (push) Has been cancelled
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / macos-latest / Node 22 (push) Has been cancelled
V3 CI/CD Pipeline / Plugin hooks smoke / macos-latest / Node 22 (push) Has been cancelled
CI/CD Pipeline / Deploy & Release (push) Has been cancelled
CI/CD Pipeline / CI Status (push) Has been cancelled
🔗 Cross-Agent Integration Tests / 📊 Integration Test Report (push) Has been cancelled
🔄 Automated Rollback Manager / 🔍 Pre-Rollback Validation (push) Has been cancelled
🔍 Verification Pipeline / ⚡ Performance Verification (push) Has been cancelled
🔍 Verification Pipeline / 📊 Verification Report (push) Has been cancelled
193 lines
5.0 KiB
Markdown
193 lines
5.0 KiB
Markdown
# Docker Deployment Guide
|
|
|
|
## Quick Start (Local / Self-Hosted)
|
|
|
|
```bash
|
|
# 1. Configure
|
|
cp .env.example .env
|
|
# Edit .env with your API keys
|
|
|
|
# 2. Generate config (for Cloud Run builds)
|
|
cp config/config.example.json config/config.json
|
|
# Edit config/config.json with your brand/model settings
|
|
node scripts/generate-config.js
|
|
|
|
# 3. Start
|
|
docker compose up -d
|
|
```
|
|
|
|
Open http://localhost:3000
|
|
|
|
## Architecture
|
|
|
|
```
|
|
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
|
|
│ Chat UI │────▶│ MCP Bridge │────▶│ MongoDB │
|
|
│ :3000 │ │ :3001 │ │ :27017 │
|
|
│ │ │ │ │ │
|
|
│ SvelteKit │ │ Express.js │ │ mongo:7 │
|
|
│ HF Chat UI │ │ Proxy + MCP │ │ Persistence │
|
|
└──────────────┘ └──────────────┘ └──────────────┘
|
|
│ │
|
|
│ ├──▶ OpenAI API
|
|
│ ├──▶ Google Gemini API
|
|
│ └──▶ OpenRouter API
|
|
│
|
|
└── OPENAI_BASE_URL=http://mcp-bridge:3001
|
|
```
|
|
|
|
All model requests from Chat UI go through the MCP Bridge, which:
|
|
1. Resolves the correct upstream provider from the model name
|
|
2. Injects the server-side API key (never exposed to the client)
|
|
3. Proxies the OpenAI-compatible request to the upstream provider
|
|
|
|
## Services
|
|
|
|
### MongoDB (`mongodb`)
|
|
- Image: `mongo:7`
|
|
- Port: 27017
|
|
- Volume: `mongo-data` (persistent)
|
|
- Stores: conversations, user sessions, settings
|
|
|
|
### MCP Bridge (`mcp-bridge`)
|
|
- Build: `./mcp-bridge/Dockerfile`
|
|
- Port: 3001
|
|
- Healthcheck: `/health`
|
|
- Provides:
|
|
- `/chat/completions` — OpenAI-compatible proxy (routes to Gemini/OpenAI/OpenRouter)
|
|
- `/mcp` — MCP JSON-RPC endpoint for tool calls
|
|
- `/health` — Health check
|
|
|
|
### Chat UI (`chat-ui`)
|
|
- Build: `./chat-ui/Dockerfile` (extends `ghcr.io/huggingface/chat-ui-db:latest`)
|
|
- Port: 3000
|
|
- Depends on: mongodb, mcp-bridge
|
|
- Config baked in via `dotenv-local.txt` → `.env.local`
|
|
|
|
## Environment Variables
|
|
|
|
### Required (at least one AI provider key)
|
|
|
|
| Variable | Description |
|
|
|----------|-------------|
|
|
| `GOOGLE_API_KEY` | Google Gemini API key |
|
|
| `OPENAI_API_KEY` | OpenAI API key |
|
|
| `OPENROUTER_API_KEY` | OpenRouter API key |
|
|
|
|
### Optional — Branding
|
|
|
|
| Variable | Default | Description |
|
|
|----------|---------|-------------|
|
|
| `BRAND_NAME` | AI Assistant | App title |
|
|
| `BRAND_DESCRIPTION` | AI-powered assistant | App subtitle |
|
|
| `PUBLIC_ORIGIN` | http://localhost:3000 | Public URL |
|
|
| `MONGODB_DB_NAME` | chat-db | MongoDB database name |
|
|
|
|
### Optional — Authentication (OIDC)
|
|
|
|
| Variable | Description |
|
|
|----------|-------------|
|
|
| `OPENID_PROVIDER_URL` | e.g., `https://accounts.google.com` |
|
|
| `OPENID_CLIENT_ID` | OAuth client ID |
|
|
| `OPENID_CLIENT_SECRET` | OAuth client secret |
|
|
| `OPENID_SCOPES` | Default: `openid profile email` |
|
|
| `OPENID_NAME_CLAIM` | Default: `name` |
|
|
| `COOKIE_SECURE` | `true` for HTTPS |
|
|
| `COOKIE_SAMESITE` | Default: `lax` |
|
|
|
|
### Optional — Backend Services
|
|
|
|
| Variable | Description |
|
|
|----------|-------------|
|
|
| `SEARCH_API_URL` | Your search/knowledge base endpoint |
|
|
| `RESEARCH_API_URL` | Your research/grounding endpoint |
|
|
|
|
## Common Operations
|
|
|
|
```bash
|
|
# Start all services
|
|
docker compose up -d
|
|
|
|
# View logs
|
|
docker compose logs -f
|
|
docker compose logs -f mcp-bridge # specific service
|
|
|
|
# Restart after .env changes
|
|
docker compose up -d --force-recreate
|
|
|
|
# Rebuild after code changes
|
|
docker compose build --no-cache
|
|
docker compose up -d
|
|
|
|
# Stop
|
|
docker compose down
|
|
|
|
# Stop and remove data
|
|
docker compose down -v
|
|
```
|
|
|
|
## Adding Models
|
|
|
|
Edit `config/config.example.json` → `models` array:
|
|
|
|
```json
|
|
{
|
|
"name": "gemini-2.5-pro",
|
|
"displayName": "Gemini 2.5 Pro",
|
|
"description": "Google's most capable model",
|
|
"provider": "gemini",
|
|
"supportsTools": true
|
|
}
|
|
```
|
|
|
|
Provider is resolved from the model name prefix:
|
|
- `gemini-*` → Google Generative Language API
|
|
- `gpt-*` → OpenAI API
|
|
- Everything else → OpenRouter API
|
|
|
|
Then regenerate and rebuild:
|
|
```bash
|
|
node scripts/generate-config.js
|
|
docker compose build chat-ui
|
|
docker compose up -d
|
|
```
|
|
|
|
## Adding MCP Tools
|
|
|
|
Edit `mcp-bridge/index.js`:
|
|
|
|
1. Add your tool to the `tools` array
|
|
2. Add a handler in the `tools/call` switch
|
|
3. Rebuild: `docker compose build mcp-bridge && docker compose up -d`
|
|
|
|
## Production (HTTPS + Domain)
|
|
|
|
For production, put a reverse proxy (nginx, Caddy, Traefik) in front:
|
|
|
|
```yaml
|
|
# Add to docker-compose.yml
|
|
services:
|
|
caddy:
|
|
image: caddy:2
|
|
ports:
|
|
- "80:80"
|
|
- "443:443"
|
|
volumes:
|
|
- ./Caddyfile:/etc/caddy/Caddyfile
|
|
- caddy-data:/data
|
|
depends_on:
|
|
- chat-ui
|
|
|
|
volumes:
|
|
caddy-data:
|
|
```
|
|
|
|
```
|
|
# Caddyfile
|
|
yourdomain.com {
|
|
reverse_proxy chat-ui:3000
|
|
}
|
|
```
|
|
|
|
Set `PUBLIC_ORIGIN=https://yourdomain.com` and `COOKIE_SECURE=true` in `.env`.
|