Skip to content

Publish Docker image + one-click Claude Desktop extension (.mcpb) - #2

Merged
twiesing merged 1 commit into
mainfrom
feat/mcpb-extension-and-docker-fix
Jun 29, 2026
Merged

twiesing merged 1 commit into
mainfrom
feat/mcpb-extension-and-docker-fix

Conversation

@twiesing

Copy link
Copy Markdown
Member

Why

Two things were blocking easy distribution:

  1. The Docker image was never published. The Docker workflow failed on every push to main because pnpm install exits non-zero on unapproved build scripts (esbuild, via vite/vitest) and the approval was never copied into the image. So neither :latest nor 0.1.0 exist on ghcr.io despite the README.
  2. No frictionless install for end users — every client required hand-editing config to pass the X-ET-Token header.

What

9613506 fix(docker) — install with --ignore-scripts in both stages. The build stage only compiles via tsc; the runtime needs only zod + the MCP SDK, so no dependency build scripts are required. Verified: image builds, /health → {"ok":true,...}.

0ac3628 feat(mcpb) — a Claude Desktop extension (.mcpb): install by double-click, enter the access token in a form field, no config editing.

  • mcp-remote is bundled and runs on Claude Desktop's own Node runtime — no npx, no system Node, no network fetch, no shell. Works identically on macOS, Windows and Linux; the token is passed as args, never through a shell.
  • Server URL is a pre-filled, overridable user_config field.
  • scripts/build-mcpb.mjs (+ pnpm pack:mcpb) syncs the version, bundles deps in an isolated temp dir, and bakes ETRACKER_MCP_URL into the default when set.
  • release.yml builds and attaches the .mcpb to GitHub Releases on v*.*.* tags.
  • README documents the one-click install; the manual mcp-remote path stays as a fallback.

Verification

  • pnpm typecheck + pnpm test green
  • Full docker build succeeds; container serves /health
  • .mcpb builds (1.4 MB, mcp-remote/dist/proxy.js present); launcher starts mcp-remote and injects the X-ET-Token header

Follow-ups (not in this PR)

  • Set the central server URL — repo variable ETRACKER_MCP_URL (used by the release build) or the manifest.json default. Currently a placeholder https://etracker-mcp.mittwald.de/mcp.
  • The Docker workflow only runs on main, so the image publishes on merge. Tag v0.1.0 afterwards to produce the semver image and the first .mcpb release.

… build approval

Follow-up corrections to the merged mcpb extension:

- Bundle mcp-remote and run it on Claude Desktop's own Node runtime instead of
  shelling out to npx. spawning npx.cmd needs shell:true on Windows (Node
  CVE-2024-27980), and shell:true would pass the token through a shell. The
  bundled launcher uses process.execPath + an args array, so install works
  identically on macOS, Windows and Linux with no system Node or network fetch.
- build-mcpb.mjs installs the bundle's deps in an isolated temp dir (outside
  the repo) so pnpm doesn't pull in the project's workspace deps.
- release.yml runs the build script via node directly, bypassing the pnpm
  script runner's project deps-status check.
- pnpm-workspace.yaml: restore allowBuilds: esbuild: true. It is the only key
  that suppresses pnpm's unapproved-build error here; onlyBuiltDependencies
  (set in the merged PR) breaks every local 'pnpm <script>' invocation.
- README: the extension no longer needs system Node or npx.
@twiesing
twiesing force-pushed the feat/mcpb-extension-and-docker-fix branch from 0ac3628 to 3cc0235 Compare June 29, 2026 12:59
@twiesing
twiesing merged commit 05c5a05 into main Jun 29, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant