feat: Phase 1 — Authentik auth, MCP endpoint, persistent memory
End-to-end Phase 1 of shared-memory: a logged-in Authentik user can sign into the Web UI (/me debug page), and an MCP client with an Authentik- issued bearer token can call memory.write / memory.list / memory.get / memory.delete plus project.identify against /api/mcp. Stack: - Next.js 15 (App Router) + React 19 + TypeScript, pnpm workspaces - Drizzle ORM + Postgres 16 + pgvector + pg_trgm - Auth.js v5 with Authentik provider (Web UI) - jose + Authentik JWKS for MCP bearer-token validation - JSON-RPC 2.0 dispatcher implementing the MCP wire protocol over plain HTTP POST (hand-rolled to fit Next.js App Router; switches to SSE in a later phase if server-initiated events are needed) - bge-small embeddings sidecar deferred to Phase 2; the schema already reserves the vector(384) column + IVFFlat index, FTS via a STORED tsvector column, and the visibility enum (private/shared/team) so cross-user memory sharing can be added without a future migration Deployment supports two modes (set in .env, never committed): - Behind an external reverse proxy (HAProxy / nginx / Cloudflare Tunnel / Traefik) — DEFAULT; the app exposes APP_PORT on the host with X-Forwarded-* trusted, no in-container TLS - Built-in TLS via Caddy — opt-in with `docker compose --profile tls up` Discovery endpoint at /.well-known/oauth-protected-resource (RFC 9728) points MCP clients at the Authentik authorization server after a 401. README walks through both Authentik providers (Web UI + MCP resource server), the audience scope mapping, redirect URIs, and includes a worked HAProxy config snippet. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
+28
-8
@@ -5,14 +5,30 @@
|
||||
|
||||
# -----------------------------------------------------------------------------
|
||||
# Public URL the app is reached at.
|
||||
# Used for OIDC redirect URIs, MCP discovery metadata, and the Caddy site name.
|
||||
# Used for OIDC redirect URIs, MCP discovery metadata, and Auth.js callbacks.
|
||||
# -----------------------------------------------------------------------------
|
||||
PUBLIC_URL=https://memory.example.com
|
||||
|
||||
# -----------------------------------------------------------------------------
|
||||
# Deployment mode
|
||||
# -----------------------------------------------------------------------------
|
||||
# By default the app exposes a plain HTTP port to the host for use behind an
|
||||
# external reverse proxy (HAProxy, nginx, Traefik, Cloudflare Tunnel, etc.).
|
||||
APP_PORT=3000
|
||||
# Bind interface for the exposed port. Use 127.0.0.1 to only accept traffic
|
||||
# from a proxy on the same host. Default 0.0.0.0 accepts from anywhere.
|
||||
APP_BIND=0.0.0.0
|
||||
|
||||
# The two settings below are ONLY consumed by the optional `caddy` service,
|
||||
# which is started with: `docker compose --profile tls up -d`.
|
||||
# Leave them as-is if you terminate TLS upstream (HAProxy, etc.).
|
||||
APP_HOSTNAME=memory.example.com
|
||||
ACME_EMAIL=you@example.com
|
||||
|
||||
# -----------------------------------------------------------------------------
|
||||
# Authentik OIDC
|
||||
# Create two Applications in Authentik (one for the Web UI, one for the MCP
|
||||
# resource server). See README.md for the exact provider settings.
|
||||
# resource server). See README.md for exact provider settings.
|
||||
# -----------------------------------------------------------------------------
|
||||
OIDC_ISSUER=https://auth.example.com/application/o/shared-memory/
|
||||
OIDC_CLIENT_ID_WEB=replace-me
|
||||
@@ -21,18 +37,20 @@ OIDC_CLIENT_ID_MCP=replace-me
|
||||
OIDC_AUDIENCE=shared-memory
|
||||
|
||||
# -----------------------------------------------------------------------------
|
||||
# Database (Postgres 16 + pgvector)
|
||||
# Default values match the docker-compose `db` service.
|
||||
# Database (Postgres 16 + pgvector — pgvector/pgvector:pg16 image)
|
||||
# -----------------------------------------------------------------------------
|
||||
POSTGRES_USER=memory
|
||||
POSTGRES_PASSWORD=replace-me-with-a-strong-password
|
||||
POSTGRES_DB=memory
|
||||
DATABASE_URL=postgres://memory:replace-me-with-a-strong-password@db:5432/memory
|
||||
|
||||
# Built automatically by docker-compose from the values above. Override only
|
||||
# if you point at an external Postgres.
|
||||
# DATABASE_URL=postgres://memory:...@db:5432/memory
|
||||
|
||||
# -----------------------------------------------------------------------------
|
||||
# Embedder sidecar (added in Phase 2)
|
||||
# Embedder sidecar (added in Phase 2; leave EMBEDDER_URL empty in Phase 1)
|
||||
# -----------------------------------------------------------------------------
|
||||
EMBEDDER_URL=http://embedder:8080
|
||||
EMBEDDER_URL=
|
||||
EMBEDDING_MODEL=Xenova/bge-small-en-v1.5
|
||||
EMBEDDING_DIM=384
|
||||
|
||||
@@ -45,4 +63,6 @@ NEXTAUTH_SECRET=replace-me-with-32-bytes-of-random
|
||||
# App
|
||||
# -----------------------------------------------------------------------------
|
||||
LOG_LEVEL=info
|
||||
NODE_ENV=production
|
||||
|
||||
# Optional: pin to a specific built image (e.g. for a registry-pushed build).
|
||||
# IMAGE_REF=registry.example.com/shared-memory-web:0.1.0
|
||||
|
||||
Reference in New Issue
Block a user