Skip to content

Releases: grammy-jiang/binnacle

Binnacle v1.0.1 — MIT + PyPI preparation

Choose a tag to compare

@grammy-jiang grammy-jiang released this 09 Oct 10:49
v1.0.1
02f4bab

Binnacle v1.0.1 — Initial MIT / PyPI publication

This release packages the existing FastMCP 4.1.0 Binnacle server for PyPI
without redesigning its eight public MCP tools, durable Job Manager, auth,
visibility policy or Linux systemd deployment process.

Changes since v1.0.0

  • Added an explicit MIT LICENSE and SPDX PEP 639 project metadata.
  • Added Python 3.10–3.14 classifiers, maintainer attribution, package keywords,
    homepage, repository, issue tracker and GitHub Release links.
  • Added the complete Markdown README to the Wheel and source-distribution
    metadata, with Linux prerequisite instructions and prominent security scope.
  • Added rigorous package archive checks for license, long description,
    metadata links, exact dependency baseline and isolated install.
  • Added a dedicated PyPI workflow with exact-SHA, previously deployed tag and
    required CI checks; only the separate approved publish job can request OIDC.
  • Explicitly pinned FastMCP 4.1.0, MCP 2.3.0 and MCP-types 2.3.0 as
    distribution dependencies, so public PyPI installs use the tested protocol
    baseline rather than silently selecting an untested newer MCP SDK.

Security and compatibility

This MCP server can read/write files and execute commands. It is a trusted
development-host tool, not a hardened multi-tenant service. Bearer tokens
and command/root security must be managed by the installing administrator.
The client-announced tool visibility label is not a verified authorization
identity. Do not expose the HTTP service publicly without a secure gateway.

The managed job service remains independently deployed and must not be
restarted just because the package or MCP server version changes.

PyPI publication requires the authorized PyPI account to establish a Trusted
Publisher for grammy-jiang/binnacle, workflow publish-pypi.yml, GitHub
environment pypi, then explicit GitHub deployment-environment approval.
No PyPI Token or password is included in source or GitHub secrets.

Deployed release verification

Source commit: 02f4bab9bc7562668ffc41d622c4274449933768.
The exact commit was deployed on Raspberry Pi with successful guarded
Live Smoke (12/12 journal correlations), the required seven GitHub CI
checks passed, and the MCP service runs FastMCP 4.1.0, MCP SDK 2.3.0,
and MCP Types 2.3.0.

Package publication

The GitHub Release triggers a separate PyPI Trusted Publishing workflow.
Package publication is not established by this GitHub Release alone;
the package is available on PyPI only after the protected pypi GitHub
environment and the PyPI OIDC exchange both succeed.

Binnacle v1.0.0

Choose a tag to compare

@grammy-jiang grammy-jiang released this 09 Oct 08:41
v1.0.0
7ed2eb8

Binnacle v1.0.0

First explicitly versioned GitHub-only release of Binnacle, a Linux/Raspberry
Pi MCP development server.

Highlights

  • FastMCP upgraded from 4.0.10 to 4.1.0, retaining the reviewed MCP and
    MCP-types 2.1.1 protocol baseline.
  • Native root composition of Files, Search and Commands. The eight public MCP
    tools retain their input/output schemas, errors, ordering, client visibility
    and authentication behavior.
  • Privacy-protecting MCP journal telemetry: command strings, file contents,
    search patterns, stdin, raw paths and arbitrary errors no longer enter the
    Binnacle request/tool/job journal instrumentation.
  • Compatible Live Smoke using opaque, validated per-call request metadata to
    correlate tool calls with exactly their own results after parameter redaction.
  • Durable Job Manager, systemd units, Linux platform seams and watchdog/tunnel
    companions preserve their prior behavior and ownership.
  • Maintainer first-party import configuration was preserved while retaining
    PyYAML, types-PyYAML and zizmor quality/security dependencies.

Release assurance

The released Git Tag identifies the exact source snapshot verified by
code-quality, Python 3.10–3.14 compatibility, coverage, packaging and guarded
production deployment checks. Distribution files attached to the GitHub
release, if present, can be checked against the SHA-256 manifest.

Operational and security boundaries

  • The existing bearer token and advertised-client visibility are not
    identity-based authorization or an operating system security sandbox.
  • The durable job store, command output, stdin spools, historical journal
    entries and separate tunnel logs retain their own privacy boundaries;
    this release only changes the Binnacle journal instrumentation.
  • No PyPI publishing or automated release system has been introduced.
  • Roll back a deployment with the existing guarded process. Never rewrite
    the published Git Tag; publish corrections under a later version.

Current Raspberry Pi deployment note

The Binnacle MCP service has been restarted on the exact v1.0.0 commit, and
FastMCP 4.1.0 plus authenticated Live Smoke are confirmed running. The stable
binnacle-jobs service remains on its prior process revision by design; it
was not restarted as part of the MCP rollout, to protect durable job
ownership. Its existing process-level journal behavior is not retroactively
changed until a separately controlled idle-time restart. Old job metadata,
outputs, and historical journals are not erased. The Doctor's sole warning
reports this expected independent revision difference.