An Agent round-trips through the MCP endpoint #23
Labels
No labels
needs-info
needs-triage
ready-for-agent
ready-for-human
wontfix
needs-info
needs-triage
ready-for-agent
ready-for-human
review/merge-ready
review/needs-fix
review/needs-human
review/needs-review
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
Depends on
#24 Agent token scope: the capability boundary, and its ADR
olympus/infra-forge
#22 Install forgejo-mcp as a Service on the forgejo Guest
olympus/infra-forge
Reference
olympus/infra-forge#23
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Parent
#17 — Install forgejo-mcp on the Guest as a LAN-reachable Service
What to build
The endpoint used by a real Agent. From a workstation on the LAN, an MCP client over Streamable HTTP initialises against the endpoint, lists the tools, and lists and reads issues in
pit/infra-forge— carrying its own Forgejo token, since the Service holds none.This is also the proof that the upstream is the Guest's loopback: the round-trip keeps working while the Edge is down.
The client half — installing the client package with its Streamable HTTP extra, adding the MCP client config entry, and restarting the Agent (there is no hot reload) — is written down as a runbook section. It is documented, not provisioned: it edits a workstation config, which is outside this repo's IaC.
Acceptance criteria
mcp.client.streamable_httpclient on a LAN host completesinitializeandtools/listagainst the endpoint with a valid token.pit/infra-forge.pit referenced this issue2026-10-06 12:34:35 +00:00
Branch
hermes/17-forgejo-mcp, commiteff474b.Client half — new runbook subsection
#### The Agent side: the MCP clientindocs/runbooks/0001-deploy-and-rollback.md(:328), right after#### The forgejo-mcp Service. Covers themcppackage +mcp.client.streamable_httpimport path, the~/.hermes/config.yamlmcp_serversentry (url: http://10.12.0.141:8089/mcp,Authorization: token <caller's own>), the restart with no hot reload, and that the Service holds no token.Round-trip (LAN, PROD endpoint, Edge UP) —
mcp.client.streamable_httpclient:Loopback upstream — the Edge was up (
https://forgejo.thepit.space→ 200), so it was not taken down. Evidence is PRE (no Edge entry at all) plus the static unit:http://10.12.0.142:8089/mcp: initialize 3.2.0, 156 tools,list_repo_issues(pit/mcp-probe)isError=False.systemctl cat forgejo-mcp→--url http://127.0.0.1:3080/ --allowed-hosts 10.12.0.141.ss -tnpon the Guest during a held LAN session:127.0.0.1:3080 ↔ 127.0.0.1:52552(loopback), while the client sits on the LAN:8089.Manifest — no new document; the runbook is already published (
docs/wiki-pages.yml:23), so no manifest change.