ADR: the forgejo-mcp Service's shape and credential-less endpoint #21
Labels
No labels
needs-info
needs-triage
ready-for-agent
ready-for-human
wontfix
needs-info
needs-triage
ready-for-agent
ready-for-human
review/merge-ready
review/needs-fix
review/needs-human
review/needs-review
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
#22 Install forgejo-mcp as a Service on the forgejo Guest
olympus/infra-forge
Reference
olympus/infra-forge#21
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Parent
#17 — Install forgejo-mcp on the Guest as a LAN-reachable Service
What to build
The decision record that has to be Accepted before any implementation starts: the shape of the forgejo-mcp Service and the identity of its endpoint.
It fixes, in prose, the choices that everything after it depends on: a dedicated Ansible role for forgejo-mcp as a third Service on the
forgejoGuest, separate from theforgejorole, with its own play; Streamable HTTP at the MCP path; a credential-less endpoint inpassthroughauth mode, with the operator-token fallback deliberately off, so the Service holds no Forgejo credential of its own; a bind on the Guest interface behind a host allowlist (fail-closed: refuses to start on a non-loopback bind with no allowlist); an upstream to Forgejo over the Guest's own loopback, not through the Edge; and no Edge entry, certificate, DNS record or router rule — LAN-reachable, not WAN-published.The ADR takes the next free number in
docs/adr/at the moment it is written (the address is not reserved ahead of time), and gets a row in the ADR index. (The publish manifest publishesdocs/adr/*as a glob, so no manifest edit is needed.)This ticket is done when the Operator merges it. Implementation does not begin before that.
Acceptance criteria
docs/adr/*as a glob, so a new ADR needs no manifest edit.)pit referenced this issue2026-10-06 12:34:35 +00:00
Implemented on branch
hermes/21-forgejo-mcp-adr; PR #43 (pit/infra-forge#43).docs/adr/0003-forgejo-mcp-service-shape-and-endpoint.md, the next free number (0001 and 0002 are taken), with a row added todocs/adr/index.md. No manifest edit:docs/adr/*is already a published glob./mcp; credential-lesspassthroughwith the operator-token fallback off; bind0.0.0.0behind a10.12.0.141host allowlist, fail-closed; loopback upstream; no Edge entry) and says why for each. The rejected alternatives — signed OCI image, SSE/stdio, a configured Service token, the operator-token fallback — are each recorded once.403/401behaviour, the fallback warning) and the pinned archive's sha256, re-verified by download-and-hash.make fmtclean; relative links resolve in-repo.Two-axis review (Standards + Spec) run on the diff; the one substantive finding — the first draft called the host allowlist a LAN-only guarantee "by construction rather than a filter", when it is a
Host-header check — is fixed in the second commit.Left open: this ticket is done when you merge, per its own text.