Repository navigation
feat(images): provide MDN MCP server via managed settings - #153
Merged
Merged
Conversation
Mozilla's MDN MCP server (mcp.mdn.mozilla.net) gives Claude current web platform docs and browser compatibility data instead of whatever was in its training set. Ship it from the image so consumers get it without per-project setup. managedMcpServers in /etc/claude-code/managed-settings.json is the only seam that works here. init-plugins.sh is a template consumers copy into their own repos, so editing it would reach new consumers only; the image flows to existing ones through the Renovate rebuild + image-pull channel. A user-scope config baked at build time would be shadowed by the volume mounted at /home/node/.claude, and a `claude mcp add` in postCreateCommand would race the extension's OAuth flow, which devcontainer.json warns against. claude-code already had the managed settings file for the Playwright SessionStart hook, so it gains the key only. ralphex-fe gains the file plus mkdir/COPY; it runs as root throughout and drops privileges via gosu, so it needs no USER guarding. Managed settings are read at session start, so ralphex's non-interactive `claude -p` runs get the server too. Both send X-Moz-1st-Party-Data-Opt-Out: 1, Mozilla's documented opt-out from the query logging they do while the server is experimental. Developers can still turn it off per-user in /mcp under Managed MCPs. The sandbox firewall is default-DROP, and the settings file is read locally, so without an allowlist entry the server would look configured and healthy while every tool call was dropped. Adds mcp.mdn.mozilla.net to the reference firewall script the claude-code README points at. CI asserts the URL in both images, following the jq | grep -qx idiom already used for the Playwright hook. Also refreshes ralphex-fe's tool table, which had drifted from its Dockerfile across several Renovate bumps (Bun, Hugo, Claude Code, rtk, ralphex). Requires Claude Code >= 2.1.259; both images pin 2.1.276.
…fe tools The previous commit added the MDN assertion only to the publish-time verify commands in build-claude-code.yml and build-ralphex-fe.yml. ci.yml runs its own verify at PR time and already carried the sibling managed-settings assertion for the Playwright hook, so a regression that dropped managedMcpServers would have gone green on the PR and failed only after merge. Adds the assertion to all three ci.yml entries. ralphex-fe's tool table listed wget, which the final image does not contain — the apt block installs curl but not wget, and the wget calls live in the alpine download stages. Verified against the published image. procps in the claude-code table was checked the same way and is present, so that row stands.
# Conflicts: # .github/workflows/build-claude-code.yml # .github/workflows/ci.yml
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Provides Mozilla's MDN MCP server to every Claude Code session in the
claude-codeandralphex-feimages, throughmanagedMcpServersin/etc/claude-code/managed-settings.json.Why
MDN's server serves current web platform documentation and browser compatibility data, so Claude checks the DOM/CSS surface instead of recalling whatever was in its training set. Shipping it from the image means consumers get it with no per-project setup, and existing consumers pick it up through the Renovate rebuild + image-pull channel they already use.
managedMcpServersis the only seam that works here:init-plugins.sh— it's a template consumers copy into their own repos, so editing it reaches new consumers only./home/node/.claudeis a volume mount, which would shadow it.claude mcp addinpostCreateCommand—devcontainer.jsonexplicitly warns thatclaudeCLI calls there race the extension's OAuth flow and can corrupt auth state.Changes
claude-code— adds themanagedMcpServerskey to the existingmanaged-settings.json(already COPYed for the PlaywrightSessionStarthook), so no Dockerfile change beyond the comment.ralphex-fe— newmanaged-settings.jsonplusmkdir/COPY. It runs as root throughout and drops privileges viagosu, so it needs none of theUSER root/USER nodeguardingclaude-codehas.mcp.mdn.mozilla.netto.devcontainer/claude-sandbox/init-firewall.sh, the reference script theclaude-codeREADME points consumers at.jq … | grep -qxidiom already used for the Playwright hook;build-ralphex-fe.ymlgains apaths:trigger for the new file.ralphex-fe's tool table, which had drifted from its Dockerfile across several Renovate bumps (Bun 1.3.9→1.4.2, Hugo 0.156.0→0.166.0, Claude Code 2.1.216→2.1.276, rtk 0.43.0→0.49.0, ralphex 1.6.0→1.7.0).Notes
X-Moz-1st-Party-Data-Opt-Out: 1, Mozilla's documented opt-out from the query logging they do while the server is experimental.claude mcp removerefuses a provided server, but each developer can turn it off for themselves in/mcpunder Managed MCPs, or block it viadeniedMcpServers.COPY, resulting file modes (644, dir755), and both workflows' verify pipelines — including a negative control — against a scratch image.actionlint,shellcheck, andhadolintall clean;hadolintreports the same 11 pre-existingDL3066infos as master, none new.