An Agent round-trips through the MCP endpoint #23

Closed
opened 2026-10-06 12:34:35 +00:00 by pit · 1 comment
Owner

Parent

#17 — Install forgejo-mcp on the Guest as a LAN-reachable Service

What to build

The endpoint used by a real Agent. From a workstation on the LAN, an MCP client over Streamable HTTP initialises against the endpoint, lists the tools, and lists and reads issues in pit/infra-forge — carrying its own Forgejo token, since the Service holds none.

This is also the proof that the upstream is the Guest's loopback: the round-trip keeps working while the Edge is down.

The client half — installing the client package with its Streamable HTTP extra, adding the MCP client config entry, and restarting the Agent (there is no hot reload) — is written down as a runbook section. It is documented, not provisioned: it edits a workstation config, which is outside this repo's IaC.

Acceptance criteria

  • An mcp.client.streamable_http client on a LAN host completes initialize and tools/list against the endpoint with a valid token.
  • Issue list/read tools return real issues from pit/infra-forge.
  • The round-trip is demonstrated with the Edge down, confirming the loopback upstream.
  • A runbook section covers the client half: the client package and extra, the config entry, the restart, and that there is no hot reload.
  • Any document added here is listed in the publish manifest.
## Parent #17 — Install forgejo-mcp on the Guest as a LAN-reachable Service ## What to build The endpoint used by a real Agent. From a workstation on the LAN, an MCP client over Streamable HTTP initialises against the endpoint, lists the tools, and lists and reads issues in `pit/infra-forge` — carrying its own Forgejo token, since the Service holds none. This is also the proof that the upstream is the Guest's loopback: the round-trip keeps working while the Edge is down. The client half — installing the client package with its Streamable HTTP extra, adding the MCP client config entry, and restarting the Agent (there is no hot reload) — is written down as a runbook section. It is **documented, not provisioned**: it edits a workstation config, which is outside this repo's IaC. ## Acceptance criteria - [ ] An `mcp.client.streamable_http` client on a LAN host completes `initialize` and `tools/list` against the endpoint with a valid token. - [ ] Issue list/read tools return real issues from `pit/infra-forge`. - [ ] The round-trip is demonstrated with the Edge down, confirming the loopback upstream. - [ ] A runbook section covers the client half: the client package and extra, the config entry, the restart, and that there is no hot reload. - [ ] Any document added here is listed in the publish manifest.
Author
Owner

Branch hermes/17-forgejo-mcp, commit eff474b.

Client half — new runbook subsection #### The Agent side: the MCP client in docs/runbooks/0001-deploy-and-rollback.md (:328), right after #### The forgejo-mcp Service. Covers the mcp package + mcp.client.streamable_http import path, the ~/.hermes/config.yaml mcp_servers entry (url: http://10.12.0.141:8089/mcp, Authorization: token <caller's own>), the restart with no hot reload, and that the Service holds no token.

Round-trip (LAN, PROD endpoint, Edge UP) — mcp.client.streamable_http client:

initialize -> Forgejo MCP Server 3.2.0
tools/list -> 156 tools
list_repo_issues -> isError=False, 5 issues
  #49 [pit/infra-forge] When plan returns `No changes` do not ask for env word and apply
  #24 [pit/infra-forge] Agent token scope: the capability boundary, and its ADR
  #23 [pit/infra-forge] An Agent round-trips through the MCP endpoint
get_issue_by_index(23) -> isError=False, #23 An Agent round-trips through the MCP endpoint

Loopback upstream — the Edge was up (https://forgejo.thepit.space → 200), so it was not taken down. Evidence is PRE (no Edge entry at all) plus the static unit:

  • PRE round-trip http://10.12.0.142:8089/mcp: initialize 3.2.0, 156 tools, list_repo_issues(pit/mcp-probe) isError=False.
  • systemctl cat forgejo-mcp → --url http://127.0.0.1:3080/ --allowed-hosts 10.12.0.141.
  • Live ss -tnp on the Guest during a held LAN session: 127.0.0.1:3080 ↔ 127.0.0.1:52552 (loopback), while the client sits on the LAN :8089.

Manifest — no new document; the runbook is already published (docs/wiki-pages.yml:23), so no manifest change.

Branch `hermes/17-forgejo-mcp`, commit eff474b. **Client half** — new runbook subsection `#### The Agent side: the MCP client` in `docs/runbooks/0001-deploy-and-rollback.md` (`:328`), right after `#### The forgejo-mcp Service`. Covers the `mcp` package + `mcp.client.streamable_http` import path, the `~/.hermes/config.yaml` `mcp_servers` entry (`url: http://10.12.0.141:8089/mcp`, `Authorization: token <caller's own>`), the restart with no hot reload, and that the Service holds no token. **Round-trip (LAN, PROD endpoint, Edge UP)** — `mcp.client.streamable_http` client: ``` initialize -> Forgejo MCP Server 3.2.0 tools/list -> 156 tools list_repo_issues -> isError=False, 5 issues #49 [pit/infra-forge] When plan returns `No changes` do not ask for env word and apply #24 [pit/infra-forge] Agent token scope: the capability boundary, and its ADR #23 [pit/infra-forge] An Agent round-trips through the MCP endpoint get_issue_by_index(23) -> isError=False, #23 An Agent round-trips through the MCP endpoint ``` **Loopback upstream** — the Edge was *up* (`https://forgejo.thepit.space` → 200), so it was not taken down. Evidence is PRE (no Edge entry at all) plus the static unit: - PRE round-trip `http://10.12.0.142:8089/mcp`: initialize 3.2.0, 156 tools, `list_repo_issues(pit/mcp-probe)` isError=False. - `systemctl cat forgejo-mcp` → `--url http://127.0.0.1:3080/ --allowed-hosts 10.12.0.141`. - Live `ss -tnp` on the Guest during a held LAN session: `127.0.0.1:3080 ↔ 127.0.0.1:52552` (loopback), while the client sits on the LAN `:8089`. **Manifest** — no new document; the runbook is already published (`docs/wiki-pages.yml:23`), so no manifest change.
pit closed this issue 2026-10-07 20:14:13 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
olympus/infra-forge#23
No description provided.