chore(docker): enable files_mcp service in container image

- Dockerfile: COPY files_mcp package, mkdir -p /app/data/files at build
  time, set ENV FILES_MCP_ROOT=/app/data/files as the default sandbox
  root (overridable at runtime).
- docker-compose.yml: surface FILES_MCP_ROOT in the env block with the
  same default, so operators can override it via .env or -e.

FILES_MCP_ROOT must exist at process start (path_guard._init_root
checks is_dir()), so the directory is created during build rather than
deferred to entrypoint — fail-fast at image build beats a runtime
RuntimeError on every container start.

Default lives under /app/data so it rides the existing data volume
(./data:/app/data) and persists across container restarts alongside
connections.json / pending_jobs.json / logs/.

Verified locally: docker compose config --quiet passes; FILES_MCP_ROOT
resolves to /app/data/files in the rendered config. Full image build
not run (docker daemon unavailable in this environment); please run
`docker compose up -d --build` to confirm in your environment.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Claude
2026-06-30 19:34:06 +08:00
co-authored by Claude Fable 5
parent 398caa87a1
commit e518c669e4
2 changed files with 17 additions and 0 deletions
+10
View File
@@ -59,10 +59,20 @@ RUN uv sync --index-url=https://pypi.tuna.tsinghua.edu.cn/simple/ --frozen --no-
# Now copy the source and let uv wire it in.
COPY main.py ./
COPY spark_executor ./spark_executor
COPY files_mcp ./files_mcp
COPY common ./common
COPY gunicorn.conf.py ./
RUN uv sync --index-url=https://pypi.tuna.tsinghua.edu.cn/simple/ --frozen --no-dev
# --- files_mcp sandbox ---
# FILES_MCP_ROOT is the only directory the files_mcp tools can touch. It
# must exist at process start (path_guard._init_root checks is_dir()) and
# persist across container restarts, so it lives under the data volume.
# Operators can override FILES_MCP_ROOT at `docker run` / compose to point
# at a separate host mount if they want strict isolation from /app/data.
RUN mkdir -p /app/data/files
ENV FILES_MCP_ROOT=/app/data/files
# Put the venv on PATH so `python` / `gunicorn` / `uvicorn` resolve to the project env.
ENV PATH=/app/.venv/bin:$PATH
ENV PYTHONUNBUFFERED=1
+7
View File
@@ -56,6 +56,13 @@ services:
# 'spark2-submit' on mixed-version hosts, or to a wrapper path.
SPARK_EXECUTOR_SPARK_SUBMIT_BIN: ${SPARK_EXECUTOR_SPARK_SUBMIT_BIN:-spark-submit}
# --- files_mcp sandbox ---
# The only directory the files_mcp tools can read or write. Lives
# under the data volume so it persists across restarts. Override
# at deploy time to mount a separate host directory for stricter
# isolation from connections / pending_jobs / logs.
FILES_MCP_ROOT: ${FILES_MCP_ROOT:-/app/data/files}
# --- Runtime paths (consumed by docker-entrypoint.sh, not common/config.py) ---
# Override to point at a different JDK install or pre-mounted Spark
# distribution. The entrypoint re-derives PATH from these at every