docs: README for Consumers of the Image (#9) #30
No reviewers
Labels
No labels
bug
enhancement
needs-info
needs-triage
ready-for-agent
ready-for-human
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
vicoli-oss/docker-forgejo-mcp!30
Loading…
Reference in a new issue
No description provided.
Delete branch "piscis/forgejo-issue-9-implement"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes #9
Summary
Replaces the empty README with documentation for Consumers, one section per item in the ticket:
Tokens only ever come from the environment:
-e NAMEpass-through for stdio, and"Authorization": "token ${FORGEJO_ACCESS_TOKEN}"(expanded by Claude Code, single-quoted forclaude mcp add) for HTTP. In HTTP mode the server gets no token at all; Upstream's default passthrough auth uses the caller's header.Evidence
Every Consumer snippet was pulled out of README.md and run verbatim against
code.vicoli.de/vicoli-oss/forgejo-mcp:3, with a clean emptyDOCKER_CONFIG(nodocker login) and the local Image removed first so it was pulled anonymously.FORGEJO_URL=https://code.vicoli.de;FORGEJO_ACCESS_TOKENwas mapped from the environment and never written anywhere.docker run -i --rm -e FORGEJO_URL -e FORGEJO_ACCESS_TOKEN …:3Connection verification successful,MCP server ready for stdio communicationinitializecheck{"jsonrpc":"2.0","id":1,"result":{…,"serverInfo":{"name":"Forgejo MCP Server","version":"3.2.0"}}}.mcp.jsonclaude -p --strict-mcp-config --mcp-config <snippet>calledmcp__forgejo__get_my_user_infoand got the right loginclaude mcp add --scope project forgejo -- docker run ….mcp.jsonsnippet, with 0 token occurrences in the file;claude mcp listshows it as Pending approval (the README says so). Without--scope projectit shows✔ Connecteddocker run -d … --transport http --host 0.0.0.0 --allowed-hosts localhost[::]:8080. curlinitializetohttp://localhost:8080/mcpwith the header → 200. Without the header → 401. Via127.0.0.1→ 403 (the README says to uselocalhost).mcp.jsonclaude -pcalledget_my_user_infoand got the right login. The same config withFORGEJO_ACCESS_TOKENunset fails ("token is not configured"), so the header comes from the environmentclaude mcp add --scope project --transport http … --header 'Authorization: token ${FORGEJO_ACCESS_TOKEN}'.mcp.jsonequals the README's HTTP snippet (jq diff), with 0 token occurrences. Local scope:✔ Connecteddocker rm -f forgejo-mcpMaintainer snippet:
make verify-pin build smoke-test PLATFORMS=linux/arm64→smoke-test [linux/arm64]: PASS: 156 tools listed.I also checked the glossary terms (Upstream, Upstream Version, Image, Rebuild, Consumer, Pin): they're capitalised as defined, "pin" is never used as a verb, and "MCP client" is only used for the software that connects to the server.
Merge Danger
Door: two-way
Docs only; no build, CI or Image change.
Blast Radius: none
Merging touches no Pin values, so CI builds and smoke-tests but publishes nothing.