[SUPERSEDED — see homelab/mcp-config] FlowAgent MCP (Power Automate) — PR 1/3 #12

Closed
admin wants to merge 3 commits from flowagent-mcp-setup into main
3 Commits
Author SHA1 Message Date
admin f7c8ebc05e Add flowagent secrets reference doc (placeholders only, no real values)
Documents the Pattern C secrets needed once mcpo/config.json + ai.yaml are
updated in a follow-up PR to actually wire FlowAgent into the mcpo service.
2026-08-29 20:31:11 -07:00
admin 2ca0643439 Add FlowAgent entrypoint: non-interactive az login via Pattern C secrets
Reads the three _FILE-convention secrets (mounted by Swarm from Docker secrets
provisioned by Woodpecker — see secrets/flowagent.secrets.example), performs
`az login --service-principal`, then execs into whatever command mcpo invokes
(node /app/flowagent/mcp.mjs). No secret value is ever written to disk outside
the ephemeral Docker secret mount, logged, or baked into the image.
2026-08-29 20:31:10 -07:00
admin 5ae478272f Add FlowAgent MCP image (Dockerfile + entrypoint) — build only, not wired to any stack yet
Part 1/3 of FlowAgent (Power Automate MCP) integration into the mcpo service
(NOT mcpo-critical). This PR only adds the image build artifacts; it does not
modify ai.yaml, mcpo/config.json, or the Woodpecker deploy pipeline, so no live
service is affected by merging this alone.

Background: mcpo/config.json previously had a dead/abandoned "powerautomate"
entry (npm package powerautomate-mcp, never onboarded to the secrets pipeline)
that will be replaced by this in a follow-up PR. This build produces a
self-contained image with:
  - azure-cli, for non-interactive `az login --service-principal` at container
    start (see entrypoint.sh)
  - FlowAgent's self-contained MCP engine (server/mcp.mjs from
    microsoft/power-platform-skills — official MIT-licensed Microsoft repo),
    pinned via FLOWAGENT_REF build arg rather than tracking `main`, so builds
    stay reproducible until deliberately bumped.

Requires (added in follow-up PRs, not yet live):
  - Woodpecker secrets: flowagent_azure_client_id, flowagent_azure_tenant_id,
    flowagent_azure_client_secret (Pattern C, Docker secrets via _FILE)
  - Azure AD App Registration with Power Automate + Dataverse permissions,
    admin-consented (manual, outside GitOps — see secrets/flowagent.secrets.example)
2026-08-29 20:31:09 -07:00