chore(docker): enable files_mcp service in container image

- Dockerfile: COPY files_mcp package, mkdir -p /app/data/files at build
  time, set ENV FILES_MCP_ROOT=/app/data/files as the default sandbox
  root (overridable at runtime).
- docker-compose.yml: surface FILES_MCP_ROOT in the env block with the
  same default, so operators can override it via .env or -e.

FILES_MCP_ROOT must exist at process start (path_guard._init_root
checks is_dir()), so the directory is created during build rather than
deferred to entrypoint — fail-fast at image build beats a runtime
RuntimeError on every container start.

Default lives under /app/data so it rides the existing data volume
(./data:/app/data) and persists across container restarts alongside
connections.json / pending_jobs.json / logs/.

Verified locally: docker compose config --quiet passes; FILES_MCP_ROOT
resolves to /app/data/files in the rendered config. Full image build
not run (docker daemon unavailable in this environment); please run
`docker compose up -d --build` to confirm in your environment.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Claude
2026-06-30 19:34:06 +08:00
co-authored by Claude Fable 5
parent 398caa87a1
commit e518c669e4
2 changed files with 17 additions and 0 deletions
+7
View File
@@ -56,6 +56,13 @@ services:
# 'spark2-submit' on mixed-version hosts, or to a wrapper path.
SPARK_EXECUTOR_SPARK_SUBMIT_BIN: ${SPARK_EXECUTOR_SPARK_SUBMIT_BIN:-spark-submit}
# --- files_mcp sandbox ---
# The only directory the files_mcp tools can read or write. Lives
# under the data volume so it persists across restarts. Override
# at deploy time to mount a separate host directory for stricter
# isolation from connections / pending_jobs / logs.
FILES_MCP_ROOT: ${FILES_MCP_ROOT:-/app/data/files}
# --- Runtime paths (consumed by docker-entrypoint.sh, not common/config.py) ---
# Override to point at a different JDK install or pre-mounted Spark
# distribution. The entrypoint re-derives PATH from these at every