Install forgejo-mcp as a Service on the forgejo Guest #22

Closed
opened 2026-10-06 12:34:35 +00:00 by pit · 0 comments
Owner

Parent

#17 — Install forgejo-mcp on the Guest as a LAN-reachable Service

What to build

The Service itself, running. A new Ansible role and its own play in the site playbook install the pinned forgejo-mcp release as a third Service on the forgejo Guest: the binary fetched checksum-first against a literal pinned sha256, under a dedicated service user, managed by systemd, listening on the MCP path behind a host allowlist, with no Forgejo token configured on it.

Observable from another host on the LAN: the MCP path answers 401 to a request carrying no credentials; a second playbook run reports 0 changed; the unit restarts when the pin changes and comes back after a reboot; and the server refuses to start if it is bound to a non-loopback address with no allowlist.

The role is rehearsed on the PRE Guest before it touches Prod. The PRE bind address and allowlist are inventory-scoped, not hardcoded, and the PRE overrides are parked on the forgejo-pre branch alongside the existing rehearsal rig — not on main.

Acceptance criteria

  • A new role with its own play in the site playbook; the existing forgejo role is untouched, so its handler-order contract stays intact.
  • Version, port and the archive's sha256 pinned in the role's defaults; the fetch is checksum-first against the literal hash, not a remote checksum URL.
  • The Service runs under a dedicated service user under systemd, enabled at boot and restarted on config change.
  • No Forgejo credential is configured on the Service; a credential-less request to the MCP path is refused 401.
  • The Service binds the Guest's interface with a host allowlist; a non-loopback bind with no allowlist refuses to start; a request whose Host is not declared is refused 403.
  • Reachable from another host on 10.12.0.0/24 at the pinned port; no Edge entry, certificate, DNS record or router rule added.
  • A second run of the playbook reports 0 changed.
  • Rehearsed on the PRE Guest; the PRE overrides park on the forgejo-pre branch.
## Parent #17 — Install forgejo-mcp on the Guest as a LAN-reachable Service ## What to build The Service itself, running. A new Ansible role and its own play in the site playbook install the pinned forgejo-mcp release as a third Service on the `forgejo` Guest: the binary fetched checksum-first against a literal pinned sha256, under a dedicated service user, managed by systemd, listening on the MCP path behind a host allowlist, with **no Forgejo token configured** on it. Observable from another host on the LAN: the MCP path answers `401` to a request carrying no credentials; a second playbook run reports `0 changed`; the unit restarts when the pin changes and comes back after a reboot; and the server refuses to start if it is bound to a non-loopback address with no allowlist. The role is rehearsed on the PRE Guest before it touches Prod. The PRE bind address and allowlist are inventory-scoped, not hardcoded, and the PRE overrides are parked on the `forgejo-pre` branch alongside the existing rehearsal rig — not on `main`. ## Acceptance criteria - [ ] A new role with its own play in the site playbook; the existing `forgejo` role is untouched, so its handler-order contract stays intact. - [ ] Version, port and the archive's sha256 pinned in the role's defaults; the fetch is checksum-first against the literal hash, not a remote checksum URL. - [ ] The Service runs under a dedicated service user under systemd, enabled at boot and restarted on config change. - [ ] No Forgejo credential is configured on the Service; a credential-less request to the MCP path is refused `401`. - [ ] The Service binds the Guest's interface with a host allowlist; a non-loopback bind with no allowlist refuses to start; a request whose `Host` is not declared is refused `403`. - [ ] Reachable from another host on `10.12.0.0/24` at the pinned port; no Edge entry, certificate, DNS record or router rule added. - [ ] A second run of the playbook reports `0 changed`. - [ ] Rehearsed on the PRE Guest; the PRE overrides park on the `forgejo-pre` branch.
pit closed this issue 2026-10-07 06:48:16 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
olympus/infra-forge#22
No description provided.