chore(docker): enable files_mcp service in container image
- Dockerfile: COPY files_mcp package, mkdir -p /app/data/files at build time, set ENV FILES_MCP_ROOT=/app/data/files as the default sandbox root (overridable at runtime). - docker-compose.yml: surface FILES_MCP_ROOT in the env block with the same default, so operators can override it via .env or -e. FILES_MCP_ROOT must exist at process start (path_guard._init_root checks is_dir()), so the directory is created during build rather than deferred to entrypoint — fail-fast at image build beats a runtime RuntimeError on every container start. Default lives under /app/data so it rides the existing data volume (./data:/app/data) and persists across container restarts alongside connections.json / pending_jobs.json / logs/. Verified locally: docker compose config --quiet passes; FILES_MCP_ROOT resolves to /app/data/files in the rendered config. Full image build not run (docker daemon unavailable in this environment); please run `docker compose up -d --build` to confirm in your environment. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
+10
@@ -59,10 +59,20 @@ RUN uv sync --index-url=https://pypi.tuna.tsinghua.edu.cn/simple/ --frozen --no-
|
|||||||
# Now copy the source and let uv wire it in.
|
# Now copy the source and let uv wire it in.
|
||||||
COPY main.py ./
|
COPY main.py ./
|
||||||
COPY spark_executor ./spark_executor
|
COPY spark_executor ./spark_executor
|
||||||
|
COPY files_mcp ./files_mcp
|
||||||
COPY common ./common
|
COPY common ./common
|
||||||
COPY gunicorn.conf.py ./
|
COPY gunicorn.conf.py ./
|
||||||
RUN uv sync --index-url=https://pypi.tuna.tsinghua.edu.cn/simple/ --frozen --no-dev
|
RUN uv sync --index-url=https://pypi.tuna.tsinghua.edu.cn/simple/ --frozen --no-dev
|
||||||
|
|
||||||
|
# --- files_mcp sandbox ---
|
||||||
|
# FILES_MCP_ROOT is the only directory the files_mcp tools can touch. It
|
||||||
|
# must exist at process start (path_guard._init_root checks is_dir()) and
|
||||||
|
# persist across container restarts, so it lives under the data volume.
|
||||||
|
# Operators can override FILES_MCP_ROOT at `docker run` / compose to point
|
||||||
|
# at a separate host mount if they want strict isolation from /app/data.
|
||||||
|
RUN mkdir -p /app/data/files
|
||||||
|
ENV FILES_MCP_ROOT=/app/data/files
|
||||||
|
|
||||||
# Put the venv on PATH so `python` / `gunicorn` / `uvicorn` resolve to the project env.
|
# Put the venv on PATH so `python` / `gunicorn` / `uvicorn` resolve to the project env.
|
||||||
ENV PATH=/app/.venv/bin:$PATH
|
ENV PATH=/app/.venv/bin:$PATH
|
||||||
ENV PYTHONUNBUFFERED=1
|
ENV PYTHONUNBUFFERED=1
|
||||||
|
|||||||
@@ -56,6 +56,13 @@ services:
|
|||||||
# 'spark2-submit' on mixed-version hosts, or to a wrapper path.
|
# 'spark2-submit' on mixed-version hosts, or to a wrapper path.
|
||||||
SPARK_EXECUTOR_SPARK_SUBMIT_BIN: ${SPARK_EXECUTOR_SPARK_SUBMIT_BIN:-spark-submit}
|
SPARK_EXECUTOR_SPARK_SUBMIT_BIN: ${SPARK_EXECUTOR_SPARK_SUBMIT_BIN:-spark-submit}
|
||||||
|
|
||||||
|
# --- files_mcp sandbox ---
|
||||||
|
# The only directory the files_mcp tools can read or write. Lives
|
||||||
|
# under the data volume so it persists across restarts. Override
|
||||||
|
# at deploy time to mount a separate host directory for stricter
|
||||||
|
# isolation from connections / pending_jobs / logs.
|
||||||
|
FILES_MCP_ROOT: ${FILES_MCP_ROOT:-/app/data/files}
|
||||||
|
|
||||||
# --- Runtime paths (consumed by docker-entrypoint.sh, not common/config.py) ---
|
# --- Runtime paths (consumed by docker-entrypoint.sh, not common/config.py) ---
|
||||||
# Override to point at a different JDK install or pre-mounted Spark
|
# Override to point at a different JDK install or pre-mounted Spark
|
||||||
# distribution. The entrypoint re-derives PATH from these at every
|
# distribution. The entrypoint re-derives PATH from these at every
|
||||||
|
|||||||
Reference in New Issue
Block a user