Add FlowAgent MCP image (Dockerfile + entrypoint) — build only, not wired to any stack yet
Part 1/3 of FlowAgent (Power Automate MCP) integration into the mcpo service
(NOT mcpo-critical). This PR only adds the image build artifacts; it does not
modify ai.yaml, mcpo/config.json, or the Woodpecker deploy pipeline, so no live
service is affected by merging this alone.
Background: mcpo/config.json previously had a dead/abandoned "powerautomate"
entry (npm package powerautomate-mcp, never onboarded to the secrets pipeline)
that will be replaced by this in a follow-up PR. This build produces a
self-contained image with:
- azure-cli, for non-interactive `az login --service-principal` at container
start (see entrypoint.sh)
- FlowAgent's self-contained MCP engine (server/mcp.mjs from
microsoft/power-platform-skills — official MIT-licensed Microsoft repo),
pinned via FLOWAGENT_REF build arg rather than tracking `main`, so builds
stay reproducible until deliberately bumped.
Requires (added in follow-up PRs, not yet live):
- Woodpecker secrets: flowagent_azure_client_id, flowagent_azure_tenant_id,
flowagent_azure_client_secret (Pattern C, Docker secrets via _FILE)
- Azure AD App Registration with Power Automate + Dataverse permissions,
admin-consented (manual, outside GitOps — see secrets/flowagent.secrets.example)
This commit is contained in:
@@ -0,0 +1,21 @@
|
||||
FROM ghcr.io/open-webui/mcpo:main
|
||||
|
||||
# Azure CLI — required for non-interactive service-principal auth
|
||||
# (`az login --service-principal`) performed by entrypoint.sh at container
|
||||
# start. FlowAgent's auth model is Azure CLI + MSAL; see
|
||||
# https://github.com/microsoft/power-platform-skills/blob/main/plugins/power-automate/references/connection-patterns.md
|
||||
RUN apk add --no-cache py3-pip curl \
|
||||
&& pip install --no-cache-dir --break-system-packages azure-cli
|
||||
|
||||
# FlowAgent self-contained MCP bundle (stdio transport, all tools inlined,
|
||||
# Node 18+ only — no npm install / remote host needed at runtime).
|
||||
# Pinned to a ref (commit SHA or tag), NOT `main`, for reproducible builds.
|
||||
# Bump deliberately via PR when upstream ships updates:
|
||||
# https://github.com/microsoft/power-platform-skills/tree/main/plugins/power-automate/server
|
||||
ARG FLOWAGENT_REF=main
|
||||
RUN mkdir -p /app/flowagent \
|
||||
&& curl -fsSL "https://raw.githubusercontent.com/microsoft/power-platform-skills/${FLOWAGENT_REF}/plugins/power-automate/server/mcp.mjs" \
|
||||
-o /app/flowagent/mcp.mjs
|
||||
|
||||
COPY entrypoint.sh /app/flowagent/entrypoint.sh
|
||||
RUN chmod +x /app/flowagent/entrypoint.sh
|
||||
Reference in New Issue
Block a user