Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions hosts/glyph/services/default.nix
Original file line number Diff line number Diff line change
Expand Up @@ -59,4 +59,6 @@
enable = true;
extraUpFlags = ["--ssh"];
};

services.mcpjungle.enable = true;
}
1 change: 1 addition & 0 deletions modules/home/development.nix
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,7 @@ in {
"Bash(git show *)"
"Bash(git add *)"
"Bash(git branch *)"
"Bash(gh api:*)"
"Bash(mkdir *)"
"Bash(* --version)"
"Bash(* --help *)"
Expand Down
1 change: 1 addition & 0 deletions modules/nixos/default.nix
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# NixOS-specific configuration modules
{
imports = [
./llm
./web
./filebrowser-quantum.nix
./users.nix
Expand Down
5 changes: 5 additions & 0 deletions modules/nixos/llm/default.nix
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
{
imports = [
./mcpjungle.nix
];
}
60 changes: 60 additions & 0 deletions modules/nixos/llm/mcpjungle.nix
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
{
config,
pkgs,
lib,
...
}: let
cfg = config.services.mcpjungle;
in {
options.services.mcpjungle = {
enable = lib.mkEnableOption "MCPJungle MCP Gateway";

package = lib.mkPackageOption pkgs "mcpjungle" {};

port = lib.mkOption {
type = lib.types.port;
default = 8090;
description = "Port for the HTTP server to listen on.";
};

openFirewall = lib.mkEnableOption "opening firewall ports for MCPJungle";
};

config = lib.mkIf cfg.enable {
users.users.mcpjungle = {
isSystemUser = true;
group = "mcpjungle";
};
users.groups.mcpjungle = {};

systemd.services.mcpjungle = {
description = "MCPJungle MCP Gateway";
after = ["network.target"];
wantedBy = ["multi-user.target"];

serviceConfig = {
ExecStart = "${lib.getExe cfg.package} start --port ${toString cfg.port}";
User = "mcpjungle";
Group = "mcpjungle";
WorkingDirectory = "/var/lib/mcpjungle";
StateDirectory = "mcpjungle";
Restart = "on-failure";
RestartSec = 5;

# Hardening
NoNewPrivileges = true;
PrivateDevices = true;
PrivateTmp = true;
ProtectHome = true;
ProtectSystem = "strict";
ReadWritePaths = ["/var/lib/mcpjungle"];
ProtectKernelTunables = true;
ProtectKernelModules = true;
ProtectControlGroups = true;
RestrictSUIDSGID = true;
};
};

networking.firewall.allowedTCPPorts = lib.mkIf cfg.openFirewall [cfg.port];
};
}
3 changes: 3 additions & 0 deletions overlays/custom-packages.nix
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,9 @@ self: super: {
# FileBrowser quantum fork
filebrowser-quantum = super.callPackage ./../packages/filebrowser-quantum/package.nix {};

# MCP Gateway
mcpjungle = super.callPackage ./../packages/mcpjungle/package.nix {};

# Mochi spaced repetition software
mochi = super.callPackage ./../packages/mochi/package.nix {};

Expand Down
36 changes: 36 additions & 0 deletions packages/mcpjungle/package.nix
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
{
lib,
fetchFromGitHub,
buildGoModule,
}:
buildGoModule rec {
pname = "mcpjungle";
version = "0.3.5";

src = fetchFromGitHub {
owner = "mcpjungle";
repo = "mcpjungle";
rev = version;
hash = "sha256-Q/ASyI6DygmYa284wk2pmYgVtPKRummnyh60v+Ri7bU=";
};

vendorHash = "sha256-pvCDf7Y+LiIOiZ0O/bJMzkf75o7HQbYpF01yFY4J9Yg=";

# Tests require HOME to exist (tilde expansion); skip in sandbox
doCheck = false;

env.CGO_ENABLED = 0;

ldflags = [
"-s"
"-w"
"-X github.com/mcpjungle/mcpjungle/pkg/version.Version=${version}"
];

meta = with lib; {
description = "Self-hosted MCP Gateway";
homepage = "https://github.com/mcpjungle/mcpjungle";
license = licenses.mit;
mainProgram = "mcpjungle";
};
}