Skip to content

Commit 3d5ea2a

Browse files
committed
feat(glyph): add basic-memory mcp
1 parent d8241d2 commit 3d5ea2a

2 files changed

Lines changed: 44 additions & 0 deletions

File tree

Lines changed: 43 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
1+
{pkgs, ...}: {
2+
users.users.basic-memory = {
3+
isSystemUser = true;
4+
group = "basic-memory";
5+
home = "/var/lib/basic-memory";
6+
};
7+
users.groups.basic-memory = {};
8+
9+
systemd.services.basic-memory = {
10+
description = "basic-memory MCP Server";
11+
after = ["network-online.target"];
12+
wants = ["network-online.target"];
13+
wantedBy = ["multi-user.target"];
14+
15+
environment = {
16+
HOME = "/var/lib/basic-memory";
17+
BASIC_MEMORY_CONFIG_DIR = "/var/lib/basic-memory";
18+
UV_CACHE_DIR = "/var/lib/basic-memory/.cache/uv";
19+
};
20+
21+
serviceConfig = {
22+
ExecStart = "${pkgs.uv}/bin/uvx basic-memory mcp --transport streamable-http --port 8091 --host 127.0.0.1";
23+
User = "basic-memory";
24+
Group = "basic-memory";
25+
WorkingDirectory = "/var/lib/basic-memory";
26+
StateDirectory = "basic-memory";
27+
Restart = "on-failure";
28+
RestartSec = 5;
29+
30+
# Hardening
31+
NoNewPrivileges = true;
32+
PrivateDevices = true;
33+
PrivateTmp = true;
34+
ProtectHome = true;
35+
ProtectSystem = "strict";
36+
ReadWritePaths = ["/var/lib/basic-memory"];
37+
ProtectKernelTunables = true;
38+
ProtectKernelModules = true;
39+
ProtectControlGroups = true;
40+
RestrictSUIDSGID = true;
41+
};
42+
};
43+
}

‎hosts/glyph/services/default.nix‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@
55
}: {
66
imports = [
77
./avahi.nix
8+
./basic-memory.nix
89
./dns.nix
910
./filebrowser.nix
1011
./jellyfin.nix

0 commit comments

Comments
 (0)