Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions src/oci-javascript-mcp-server/.dockerignore
Original file line number Diff line number Diff line change
@@ -1,9 +1,10 @@
*
!package.json
!package-lock.json
!buf.gen.yaml
!proto/
!proto/runner.proto
!runner/
!runner/package.json
!runner/package-lock.json
!src/
!src/grpc.ts
!src/protocol.ts
Expand Down
6 changes: 5 additions & 1 deletion src/oci-javascript-mcp-server/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,13 @@
# Changelog

## Unreleased
## 0.2.0

### Fixed

- Select OCI session-token authentication using SDK profile inheritance and
keep profile diagnostics off MCP stdout.
- Keep `isolated-vm` out of host runtime dependencies and install the runner's
dependencies from a separate manifest, pruning code generators from the image.
- Preserve OCI status codes, service codes, operation details, and request IDs in
uncaught `run_javascript` errors so callers can assess failures and retry decisions.

Expand Down
24 changes: 6 additions & 18 deletions src/oci-javascript-mcp-server/Containerfile
Original file line number Diff line number Diff line change
Expand Up @@ -10,33 +10,21 @@ RUN apt-get update \
&& apt-get install -y --no-install-recommends g++ make python3 \
&& rm -rf /var/lib/apt/lists/*

COPY package.json package-lock.json ./
RUN npm ci --include=dev \
&& npm cache clean --force
COPY runner/package.json runner/package-lock.json ./
RUN npm ci --include=dev

COPY buf.gen.yaml ./
COPY proto/ ./proto/
RUN npx --no-install buf generate
RUN npx --no-install buf generate \
&& npm prune --omit=dev \
&& npm cache clean --force

FROM node:26-bookworm-slim@sha256:cd565714d4da3e84bfd341e31448f81d47c6362198f152345297c9c1154e6341

WORKDIR /app

COPY --from=dependencies --chown=65532:65532 \
/app/node_modules/isolated-vm \
./node_modules/isolated-vm
COPY --from=dependencies --chown=65532:65532 \
/app/node_modules/node-gyp-build \
./node_modules/node-gyp-build
COPY --from=dependencies --chown=65532:65532 \
/app/node_modules/@grpc/grpc-js \
./node_modules/@grpc/grpc-js
COPY --from=dependencies --chown=65532:65532 \
/app/node_modules/@js-sdsl/ordered-map \
./node_modules/@js-sdsl/ordered-map
COPY --from=dependencies --chown=65532:65532 \
/app/node_modules/@bufbuild/protobuf \
./node_modules/@bufbuild/protobuf
/app/node_modules ./node_modules
COPY --from=dependencies --chown=65532:65532 /app/src/generated/runner.ts ./src/generated/runner.ts
COPY --chown=65532:65532 \
src/grpc.ts \
Expand Down
23 changes: 21 additions & 2 deletions src/oci-javascript-mcp-server/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,8 +13,10 @@ access, environment variables, or a network API.

## Quick start

Requires Node.js 26 or newer, rootless Podman, and an OCI SDK configuration. A
native build toolchain is also needed when installing `isolated-vm` on the host.
Requires Node.js 26 or newer, rootless Podman, and an OCI SDK configuration.
Production host installs omit `isolated-vm`; the container build installs it for
the runner. Building and testing from source also installs the addon and may
require a native build toolchain.

From this directory:

Expand Down Expand Up @@ -155,6 +157,23 @@ conservative mounts and network policy.

## Development

Run `npm ci --include=dev` to install test and development dependencies, including
`isolated-vm`. This requires a native build toolchain when no prebuilt addon is
available. The container build supplies its own build toolchain.

The root manifest includes host runtime dependencies and development dependencies
for the combined host and runner tests. `runner/package.json` and its lockfile
define the container's runtime dependencies and development dependencies for
protobuf generation. The Containerfile installs both, generates the bindings,
and prunes development dependencies before copying modules into the final image.
Both runner build files are included in the published package so the image can
also be built from the package contents.

When updating dependencies shared by the root and runner manifests, update both
declarations and regenerate both lockfiles. Keep the resolved versions aligned
so local tests exercise the same addon, gRPC libraries, and generators as the
container.

```bash
moon run oci-javascript-mcp-server:compile # generate bindings and compile the npm entry point
moon run oci-javascript-mcp-server:test # unit and MCP stdio integration tests; 90% line minimum
Expand Down
2 changes: 2 additions & 0 deletions src/oci-javascript-mcp-server/moon.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,7 @@ tasks:
- 'test/**/*'
- 'package.json'
- 'package-lock.json'
- 'runner/*.json'

check:
description: 'Checks TypeScript types'
Expand Down Expand Up @@ -61,6 +62,7 @@ tasks:
- '.dockerignore'
- 'package.json'
- 'package-lock.json'
- 'runner/*.json'
outputs:
- 'dist/*.tgz'
options:
Expand Down
8 changes: 5 additions & 3 deletions src/oci-javascript-mcp-server/package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

6 changes: 4 additions & 2 deletions src/oci-javascript-mcp-server/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "oci-javascript-mcp-server",
"version": "0.1.1",
"version": "0.2.0",
"description": "Podman-isolated OCI JavaScript code execution MCP server",
"type": "module",
"keywords": [
Expand All @@ -25,6 +25,8 @@
"src/generated/runner.ts",
"proto/",
"buf.gen.yaml",
"runner/package.json",
"runner/package-lock.json",
".dockerignore",
"Containerfile",
"CHANGELOG.md",
Expand All @@ -41,7 +43,6 @@
"@bufbuild/protobuf": "2.15.0",
"@grpc/grpc-js": "^1.14.4",
"@modelcontextprotocol/sdk": "^1.29.0",
"isolated-vm": "^7.0.0",
"oci-common": "^2.132.0",
"oci-sdk": "^2.132.0",
"selfsigned": "^3.0.1",
Expand All @@ -54,6 +55,7 @@
"@bufbuild/buf": "1.73.0",
"@types/node": "^25.9.1",
"c8": "^12.0.0",
"isolated-vm": "^7.0.0",
"ts-proto": "2.12.4",
"typescript": "^5.9.3"
},
Expand Down
Loading
Loading