feat: add MCP_ALLOWED_HOSTS support for reverse proxy configuration

This commit is contained in:
sha
2026-03-21 00:00:43 +02:00
parent a4180cc6f6
commit 3f67f7b0da
4 changed files with 14 additions and 0 deletions
+1
View File
@@ -10,4 +10,5 @@ services:
MCP_HOST: 0.0.0.0 MCP_HOST: 0.0.0.0
MCP_PORT: 8000 MCP_PORT: 8000
MCP_AUTH_TOKEN: ${MCP_AUTH_TOKEN:-} MCP_AUTH_TOKEN: ${MCP_AUTH_TOKEN:-}
MCP_ALLOWED_HOSTS: ${MCP_ALLOWED_HOSTS:-}
restart: on-failure restart: on-failure
+3
View File
@@ -12,4 +12,7 @@ stringData:
{{- if .Values.auth.token }} {{- if .Values.auth.token }}
MCP_AUTH_TOKEN: {{ .Values.auth.token | quote }} MCP_AUTH_TOKEN: {{ .Values.auth.token | quote }}
{{- end }} {{- end }}
{{- if .Values.auth.allowedHosts }}
MCP_ALLOWED_HOSTS: {{ .Values.auth.allowedHosts | quote }}
{{- end }}
{{- end }} {{- end }}
+3
View File
@@ -15,6 +15,9 @@ redmine:
auth: auth:
# Bearer token for HTTP transport (leave empty to disable auth) # Bearer token for HTTP transport (leave empty to disable auth)
token: "" token: ""
# Comma-separated list of additional allowed Host headers (e.g. your public domain)
# FastMCP allows only localhost by default — set this when running behind a reverse proxy
allowedHosts: ""
service: service:
type: ClusterIP type: ClusterIP
+7
View File
@@ -9,6 +9,8 @@ Environment variables:
MCP_HOST — bind host for HTTP transport (default: 0.0.0.0) MCP_HOST — bind host for HTTP transport (default: 0.0.0.0)
MCP_PORT — bind port for HTTP transport (default: 8000) MCP_PORT — bind port for HTTP transport (default: 8000)
MCP_AUTH_TOKEN — Bearer token for HTTP transport auth (optional) MCP_AUTH_TOKEN — Bearer token for HTTP transport auth (optional)
MCP_ALLOWED_HOSTS — Comma-separated extra allowed Host headers, e.g. redmine.mcp.example.com
(FastMCP only allows localhost by default — required when behind a reverse proxy)
""" """
import os import os
@@ -24,6 +26,11 @@ if __name__ == "__main__":
port = int(os.environ.get("MCP_PORT", "8000")) port = int(os.environ.get("MCP_PORT", "8000"))
token = os.environ.get("MCP_AUTH_TOKEN", "") token = os.environ.get("MCP_AUTH_TOKEN", "")
allowed_hosts = os.environ.get("MCP_ALLOWED_HOSTS", "")
if allowed_hosts:
for h in (h.strip() for h in allowed_hosts.split(",")):
mcp.settings.transport_security.allowed_hosts.append(h)
app = mcp.streamable_http_app() app = mcp.streamable_http_app()
if token: if token: