mcp connection
Some checks failed
CI / fixture (push) Has been cancelled
CI / test (push) Has been cancelled

This commit is contained in:
2026-09-22 10:58:02 +05:30
parent 4e1f746b22
commit f2aa3b3ad8
53 changed files with 12515 additions and 37 deletions

View File

@@ -42,6 +42,41 @@ HTTP_CORS_ORIGINS=https://platform.krowforce.com,https://mcp.krowforce.com
# anonymous.
HTTP_COOKIE_SAMESITE=lax
# Networks whose X-Forwarded-For header may be believed. Comma-separated CIDR
# blocks or bare addresses.
#
# THIS DEPLOYMENT NEEDS IT SET, AND THE VALUE IS NOT KNOWABLE FROM THIS REPO.
#
# The API binds loopback and something else terminates TLS in front of it, so
# Go sees the proxy's address on every request. Three limits are keyed by that
# address — failed logins (20 per 15 minutes), OAuth client registration (10
# per hour) and OAuth authorization before sign-in (20 per hour) — and while it
# is unset, all three are ONE budget for the whole deployment. The observable
# symptoms are users rate-limiting each other: a connector that refuses to
# register because somebody else already did, and sign-in refused platform-wide
# after twenty bad passwords anywhere.
#
# Set it to the address or network the ingress reaches the API from. Find it
# rather than guess it — on the API host, with the stack running:
#
# docker inspect -f '{{range .NetworkSettings.Networks}}{{.Gateway}}{{end}}' krow-api
#
# That gateway is the address a proxy on the host arrives as. If the proxy runs
# in a container on a shared Docker network, use that network's subnet instead:
#
# docker network inspect -f '{{range .IPAM.Config}}{{.Subnet}}{{end}}' <network>
#
# Confirm before committing to it: with LOG_LEVEL=debug, one request's logged
# address should be the real client's, not the proxy's.
#
# NEVER 0.0.0.0/0. That trusts every caller's own header — not a weaker limit
# but no limit at all, since anyone could then mint a budget per request.
#
# Left unset here deliberately. An operator supplying a wrong value gets the
# shared bucket back; an operator supplying 0.0.0.0/0 gets no protection at all,
# so this file ships no value rather than a plausible-looking one to copy.
HTTP_TRUSTED_PROXIES=
# ── Database ────────────────────────────────────────────────────────────────
# Point at a managed PostgreSQL. With docker-compose.local-db.yml layered on
# top, set DATABASE_HOST=postgres instead.

View File

@@ -152,6 +152,17 @@ services:
# Unset, the server derives it from HTTP_CORS_ORIGINS. The default below
# is deliberate: a compose deployment keeps Lax unless told otherwise.
HTTP_COOKIE_SAMESITE: ${HTTP_COOKIE_SAMESITE:-lax}
# Networks whose X-Forwarded-For may be believed. Empty means none, and
# empty is what this file defaults to on purpose: a value invented here
# would be trusted by every deployment that copies it.
#
# It MUST be set for this topology. The api container publishes on
# loopback with a reverse proxy in front, so without it Go sees the
# proxy's address on every request and the three address-keyed limits —
# failed logins, OAuth registration, OAuth authorization before sign-in —
# become one budget shared by every user. See .env.docker.example for how
# to find the right value.
HTTP_TRUSTED_PROXIES: ${HTTP_TRUSTED_PROXIES:-}
DATABASE_MAX_OPEN_CONNS: ${DATABASE_MAX_OPEN_CONNS:-25}
DATABASE_MIN_IDLE_CONNS: ${DATABASE_MIN_IDLE_CONNS:-2}
DATABASE_CONN_MAX_LIFETIME: ${DATABASE_CONN_MAX_LIFETIME:-30m}