You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[RUN-5039] Support docker --env-file; bake release version into image User-Agent - #105
The Docker image already worked with --env-file (it only reads process.env), but docker run --env-file is stricter than dotenv: it keeps surrounding quotes and CRLF verbatim. src/config.ts now cleans env values (trim, strip one pair of surrounding quotes, empty → unset, trailing / dropped from URLs) so a dotenv-style file doesn't silently break requests.
Runlayer (internal) only supports --env-file. Docs now describe that flow: the connector reads ~/.rundeck-mcp/.env, so internal users just create the file there. Customers can still use -e variables or --env-file.
Docs: --env-file usage and format rules (SETUP.md, README, TECHNICAL-CAPABILITIES.md, CLAUDE.md, skills), .env.example rewritten as the shared template, .gitignore ignores .env.* except .env.example.
CI/Dockerfile: RUNDECK_MCP_VERSION build-arg bakes the release version into the image's User-Agent (the docker-build job does its own fresh checkout, so it can't rely on the build job's patch).
Kind of Change
Bug Fix
Enhancement/New Feature/Behavior
Maintenance/Refactor
Other... docs, CI
Development Checklist
npm run validate passes locally (build + test + integration validations)
Unit tests added/updated for modified code
New/changed tools, resources, or prompts documented in CLAUDE.md if applicable
New environment variables documented in CLAUDE.md's Environment Variables table (no new variables)
Docs download / RUNDECK_DOCS_PATH behavior unaffected, or changes called out below
npm test passes (28 suites, 394 tests); npm run validate was not run.
Testing
Testing setup:
npm test
docker build -t rundeck-mcp:envtest . then sh ci/docker-smoke-test.sh rundeck-mcp:envtest (new section 6 covers --env-file with a quoted URL and CRLF).
docker run -d -i --env-file ~/.rundeck-mcp/.env rundeck-mcp:envtest, then docker exec <container> env | grep RUNDECK_.
Acceptance Criteria:
Container started with --env-file has the variables in its environment and reports healthy
Quoted/CRLF/trailing-slash values are normalized (unit tests)
Smoke test passes, including the new --env-file section
Runlayer connector reading ~/.rundeck-mcp/.env verified end to end (not tested from here)
Runlayer (internal) only supports --env-file, configured to read the
standard ~/.rundeck-mcp/.env, so users just create the file there.
Customers can still use -e variables or --env-file.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
smartinellibenedetti
changed the title
Support docker --env-file; bake release version into image User-Agent
[RUN-5039] Support docker --env-file; bake release version into image User-Agent
Oct 1, 2026
Tested the image built from this branch locally (docker run -i --rm --env-file ~/.rundeck-mcp/.env):
initialize and tools/list work (9 tools); docs are fetched on startup.
docs_search returns results.
api_call works with the env-file config against a Rundeck 6.3 instance (read-only GETs: system/info, projects, project/{p}/jobs, runnerManagement/runners), including the upstream 403 returned as a normal tool response.
Not covered: write/destructive calls and the Runlayer connector (it currently fails before reaching the container because $HOME isn't expanded in its --env-file path, which is a connector config issue, not this PR).
CI does not verify build argument updates USER_AGENT
.circleci/config.yml:167
No CI check verifies that this build argument actually changed the compiled USER_AGENT. Because sed exits successfully when its search text is absent, a later edit to the constant can make tagged builds silently publish rundeck-mcp/SNAPSHOT while every current smoke test passes. Import USER_AGENT from the built image and compare it with RUNDECK_MCP_VERSION after at least one local image build.
Smoke test omits normalized URL and token configuration
ci/docker-smoke-test.sh:127
This assertion only proves that the server can initialize; initialization does not consume RUNDECK_URL or RUNDECK_TOKEN, and the earlier log check only exercises RUNDECK_DOCS_PATH. Consequently, this new smoke section still passes if URL quote/CR/trailing-slash normalization is broken in the compiled image. Read configManager.getConfig() inside the built container and assert the normalized URL and token before the protocol check.
Smoke tests do not verify the compiled image User-Agent version
Dockerfile:36
The new image-version behavior is not asserted by the smoke tests: the unit test only compares the header with the source constant, and branch builds legitimately use SNAPSHOT. If this sed target drifts or the build arg stops propagating, tagged images still build successfully with the wrong User-Agent. Add a smoke assertion that reads USER_AGENT from the compiled image and compares it with RUNDECK_MCP_VERSION.
Restart diagnostic is misleading for intentionally empty environment values
src/config.ts:37
Quoted-empty and whitespace-only values are intentionally treated as unset here, but src/tools/api.ts:75-79 still checks the raw process.env strings. For values such as RUNDECK_TOKEN='""', API calls now report that the variable “exists ... but wasn't loaded” and suggest restarting, even though restarting cannot fix an intentionally empty value. Base that diagnostic on the normalized value, or omit the restart note for values normalized to unset.
External env file location is overstated as an access boundary
Keeping the env file outside the project does not ensure that an agent never sees it: this skill itself instructs the agent to write the file, and an agent with filesystem or shell access may read files under the user's home directory. Since the file contains a live token, describe this location as reducing accidental repository-context and Git exposure rather than as an access boundary.
Fail release build when User-Agent replacement is missing
Dockerfile:36
This replacement can silently stop working: sed exits successfully when the placeholder is absent, so a later refactor of USER_AGENT would still publish a release image labeled SNAPSHOT. Guard the expected source text before replacing it (or assert the compiled value afterward) so the release build fails instead of shipping the wrong User-Agent.
Do not claim repository storage prevents agent token access
The claim that the agent never sees this token is incorrect: this skill asks the user for the token in Step 4 and then instructs the agent to write it here. Keeping the file outside the repository prevents accidental commits, but it does not create an agent-access boundary; avoid promising otherwise so users understand the credential exposure.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
About this change
Jira Ticket: RUN-5039
Purpose of the Changes
--env-file(it only readsprocess.env), butdocker run --env-fileis stricter than dotenv: it keeps surrounding quotes and CRLF verbatim.src/config.tsnow cleans env values (trim, strip one pair of surrounding quotes, empty → unset, trailing/dropped from URLs) so a dotenv-style file doesn't silently break requests.--env-file. Docs now describe that flow: the connector reads~/.rundeck-mcp/.env, so internal users just create the file there. Customers can still use-evariables or--env-file.--env-fileusage and format rules (SETUP.md, README, TECHNICAL-CAPABILITIES.md, CLAUDE.md, skills),.env.examplerewritten as the shared template,.gitignoreignores.env.*except.env.example.RUNDECK_MCP_VERSIONbuild-arg bakes the release version into the image's User-Agent (the docker-build job does its own fresh checkout, so it can't rely on the build job's patch).Kind of Change
Development Checklist
npm run validatepasses locally (build + test + integration validations)RUNDECK_DOCS_PATHbehavior unaffected, or changes called out belownpm testpasses (28 suites, 394 tests);npm run validatewas not run.Testing
Testing setup:
npm testdocker build -t rundeck-mcp:envtest .thensh ci/docker-smoke-test.sh rundeck-mcp:envtest(new section 6 covers--env-filewith a quoted URL and CRLF).docker run -d -i --env-file ~/.rundeck-mcp/.env rundeck-mcp:envtest, thendocker exec <container> env | grep RUNDECK_.Acceptance Criteria:
--env-filehas the variables in its environment and reports healthy--env-filesection~/.rundeck-mcp/.envverified end to end (not tested from here)🤖 Generated with Claude Code