Files
GitManager/docker-compose.yml
T
TBNilles f23f2f2b30 Serve MCP over HTTPS for the Claude Desktop connector
Claude Desktop's custom connector only accepts https URLs. Added an optional TLS listener (HTTPS_ADDR + TLS_CERT_FILE/TLS_KEY_FILE) alongside HTTP; docker-compose publishes 127.0.0.1:8443 and mounts a local mkcert cert from certs/ (git-ignored). Best-effort: a missing cert logs a warning and stays HTTP-only. Verified the Windows store trusts the mkcert cert and MCP initialize succeeds over https://127.0.0.1:8443/mcp.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-20 07:40:21 -04:00

46 lines
1.7 KiB
YAML

# Dev environment: `docker compose up` builds the app with hot reload (air) and
# mounts your host repositories in (AGENT.md §1.6). Because the app operates on
# repos that live on the host, the roots are mounted read-write.
services:
app:
build:
context: .
target: dev
env_file: .env
environment:
# Bind all interfaces INSIDE the container so the published port reaches
# it; the `ports` mapping below still keeps it localhost-only on the HOST.
- LISTEN_ADDR=0.0.0.0:8080
# HTTPS for the MCP connector (Claude Desktop only accepts https URLs).
# Certs are generated on the host with mkcert (see README/.env.example)
# and mounted read-only below.
- HTTPS_ADDR=0.0.0.0:8443
- TLS_CERT_FILE=/app/certs/localhost.pem
- TLS_KEY_FILE=/app/certs/localhost-key.pem
# The scanner looks here; matches the volume mount below.
- GIT_REPO_ROOTS=/repos
ports:
- "127.0.0.1:8080:8080"
- "127.0.0.1:8443:8443"
volumes:
# Source, for hot reload.
- .:/app
# Cache the Go module + build cache across restarts.
- gomod:/go/pkg/mod
# Your repositories. Set REPOS_HOST_PATH in .env (or your shell) to the
# host folder that holds them; defaults to ./repos next to this file.
- "${REPOS_HOST_PATH:-./repos}:/repos"
# --- Optional: let git authenticate to remotes from inside the container.
# Uncomment ONE approach and adjust for your host (AGENT.md §1.6, §11):
# SSH agent socket (Linux/macOS):
# - "${SSH_AUTH_SOCK}:/ssh-agent"
# or mounted keys (read-only):
# - "${HOME}/.ssh:/root/.ssh:ro"
# environment for the SSH-agent option:
# environment:
# - SSH_AUTH_SOCK=/ssh-agent
volumes:
gomod: