feat(v3.12.0): media pipeline, AI image generation, capability probe, companion v2.9.0
Some checks failed
Release / Test before release (push) Has been cancelled
Release / Publish to PyPI (push) Has been cancelled
Release / Publish to Docker Hub (push) Has been cancelled
Release / Create GitHub Release (push) Has been cancelled

Three-month batch sync from internal repo (~80 commits) covering Tracks F.5a, F.7e, F.8, F.17, F.18, F.X.

WordPress media pipeline
- Pillow-based optimization, AI image generation (OpenAI / Stability / Replicate / Google Nano Banana / OpenRouter), chunked + resumable uploads, bulk delete/reassign, idempotent retries.

Capability discovery (F.7e)
- Per-site credential probe + adapters for WordPress / WooCommerce / Gitea, tier-fit unions granted ∪ roles, capability badge UI with HTMX partial re-check, install hint in every companion-unreachable error.

Companion plugin overhaul
- Renamed wordpress-plugin/airano-mcp-seo-bridge → wordpress-plugin/airano-mcp-bridge.
- Eight new endpoints: /capabilities, /bulk-meta, /export, /cache-purge, /transient-flush, /site-health, /audit-hook, /upload-and-attach.
- wp.org Plugin Check pass: i18n, WP_Filesystem, scheme allowlist on audit-hook URL.

Other
- Gitea ergonomics (F.17): batch files, tree, search, compare, releases, fork.
- Opportunistic bcrypt upgrade for legacy SHA-256 admin keys (F.8).
- n8n refactor: structured errors, capability probe, missing tools backfilled.
- Idempotency-Key dedup for AI media upload retries; WP client fast-fails on unreachable sites.

Docs
- README + CLAUDE.md drop the fixed "633 tools" claim. The total grows with each release; per-plugin approximations + dashboard-surfaced counts replace it.
- Tools/Tests badges removed in favour of "Plugins: 10".

Deployment
- PyPI mirror chain, optional BUILD_HTTP_PROXY, Alpine→Yandex apk mirror, Debian-slim Plan-B Dockerfile, mirror.gcr.io variant.

CI
- Black + Ruff clean on Python 3.12; pytest tests/ green.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-04-25 16:25:58 +02:00
parent 788439e377
commit f203ca88de
140 changed files with 23802 additions and 2253 deletions

113
Dockerfile.slim Normal file
View File

@@ -0,0 +1,113 @@
# ===================================
# MCP Hub — Dockerfile (Debian slim, restrictive-network variant)
# ===================================
# Plan B fallback when both registry-1.docker.io AND
# dl-cdn.alpinelinux.org are unreachable from the build host.
#
# Switches the base from python:3.12-alpine (musl + apk) to
# python:3.12-slim-bookworm (Debian + apt). Debian's package mirrors
# are CDN-fronted (Cloudflare/Fastly) and are usually reachable from
# networks that block Alpine's CDN. Image is pulled from mirror.gcr.io
# to also bypass Docker Hub TLS issues.
#
# Tradeoffs vs Dockerfile.mirror (Alpine):
# - Image size: ~120 MB (slim) vs ~60 MB (alpine) — acceptable
# - Compatibility: ALL Python wheels work (no musl rebuild needed)
# - Security baseline: equivalent (slim is minimal Debian, no shell extras)
#
# Switch back to Dockerfile.mirror once dl-cdn.alpinelinux.org reachable
# OR back to Dockerfile once registry-1.docker.io is reachable.
# ===================================
# Stage 1: Build stage
FROM mirror.gcr.io/library/python:3.12-slim-bookworm AS builder
# Optional HTTP proxy for restricted networks. ARG values are NOT baked
# into the final image, so the runtime container never carries the proxy.
ARG BUILD_HTTP_PROXY=""
ARG BUILD_HTTPS_PROXY=""
ARG BUILD_NO_PROXY=""
# Install build dependencies via apt (proxy honoured if BUILD_HTTP_PROXY set)
RUN export HTTP_PROXY="${BUILD_HTTP_PROXY}" \
HTTPS_PROXY="${BUILD_HTTPS_PROXY}" \
NO_PROXY="${BUILD_NO_PROXY}" \
&& apt-get update && apt-get install -y --no-install-recommends \
build-essential \
libffi-dev \
libssl-dev \
&& rm -rf /var/lib/apt/lists/*
# Create build directory
WORKDIR /build
# Copy requirements and install Python dependencies (proxy honoured)
COPY requirements.txt .
RUN export HTTP_PROXY="${BUILD_HTTP_PROXY}" \
HTTPS_PROXY="${BUILD_HTTPS_PROXY}" \
NO_PROXY="${BUILD_NO_PROXY}" \
&& pip install --no-cache-dir --user -r requirements.txt
# Stage 2: Production stage
FROM mirror.gcr.io/library/python:3.12-slim-bookworm AS production
# Re-declare proxy ARGs in this stage (ARGs don't cross stage boundaries).
ARG BUILD_HTTP_PROXY=""
ARG BUILD_HTTPS_PROXY=""
ARG BUILD_NO_PROXY=""
# CRITICAL: Install wget for health checks + docker-cli for WP-CLI tools
# libmagic1 is required by python-magic (F.5a media upload MIME sniffing)
RUN export HTTP_PROXY="${BUILD_HTTP_PROXY}" \
HTTPS_PROXY="${BUILD_HTTPS_PROXY}" \
NO_PROXY="${BUILD_NO_PROXY}" \
&& apt-get update && apt-get install -y --no-install-recommends \
wget \
curl \
docker.io \
libmagic1 \
&& rm -rf /var/lib/apt/lists/*
# Create non-root user for security and grant Docker socket access
# Docker group (GID 999) allows access to /var/run/docker.sock
RUN groupadd -g 1001 appgroup && \
useradd -u 1001 -g appgroup -s /bin/sh -m appuser && \
(groupadd -g 999 docker 2>/dev/null || true) && \
(usermod -aG docker appuser 2>/dev/null || true)
# Set working directory
WORKDIR /app
# Copy Python packages from builder
COPY --from=builder /root/.local /home/appuser/.local
# Copy application code
COPY --chown=appuser:appgroup . .
# Create data directories for API keys and logs with correct ownership
# This must be done before switching to non-root user
RUN mkdir -p /app/data /app/logs && \
chown -R appuser:appgroup /app/data /app/logs && \
chmod 755 /app/data /app/logs
# Make server.py executable
RUN chmod +x server.py
# Switch to non-root user
USER appuser
# Add local packages to PATH
ENV PATH=/home/appuser/.local/bin:$PATH
ENV PYTHONUNBUFFERED=1
# CRITICAL: EXPOSE port for Coolify
EXPOSE 8000
# CRITICAL: Health check
HEALTHCHECK --interval=30s --timeout=10s --start-period=40s --retries=3 \
CMD wget --no-verbose --tries=1 --spider http://localhost:8000/health || exit 1
# CRITICAL: Listen on 0.0.0.0 (not localhost!)
# Run server with streamable-http transport on port 8000
CMD ["python", "server.py", "--transport", "streamable-http", "--port", "8000", "--host", "0.0.0.0"]