Repository navigation
Releases: grammy-jiang/binnacle
Release list
Binnacle v1.0.1 — MIT + PyPI preparation
Binnacle v1.0.1 — Initial MIT / PyPI publication
This release packages the existing FastMCP 4.1.0 Binnacle server for PyPI
without redesigning its eight public MCP tools, durable Job Manager, auth,
visibility policy or Linux systemd deployment process.
Changes since v1.0.0
- Added an explicit MIT LICENSE and SPDX PEP 639 project metadata.
- Added Python 3.10–3.14 classifiers, maintainer attribution, package keywords,
homepage, repository, issue tracker and GitHub Release links. - Added the complete Markdown README to the Wheel and source-distribution
metadata, with Linux prerequisite instructions and prominent security scope. - Added rigorous package archive checks for license, long description,
metadata links, exact dependency baseline and isolated install. - Added a dedicated PyPI workflow with exact-SHA, previously deployed tag and
required CI checks; only the separate approved publish job can request OIDC. - Explicitly pinned FastMCP 4.1.0, MCP 2.3.0 and MCP-types 2.3.0 as
distribution dependencies, so public PyPI installs use the tested protocol
baseline rather than silently selecting an untested newer MCP SDK.
Security and compatibility
This MCP server can read/write files and execute commands. It is a trusted
development-host tool, not a hardened multi-tenant service. Bearer tokens
and command/root security must be managed by the installing administrator.
The client-announced tool visibility label is not a verified authorization
identity. Do not expose the HTTP service publicly without a secure gateway.
The managed job service remains independently deployed and must not be
restarted just because the package or MCP server version changes.
PyPI publication requires the authorized PyPI account to establish a Trusted
Publisher for grammy-jiang/binnacle, workflow publish-pypi.yml, GitHub
environment pypi, then explicit GitHub deployment-environment approval.
No PyPI Token or password is included in source or GitHub secrets.
Deployed release verification
Source commit: 02f4bab9bc7562668ffc41d622c4274449933768.
The exact commit was deployed on Raspberry Pi with successful guarded
Live Smoke (12/12 journal correlations), the required seven GitHub CI
checks passed, and the MCP service runs FastMCP 4.1.0, MCP SDK 2.3.0,
and MCP Types 2.3.0.
Package publication
The GitHub Release triggers a separate PyPI Trusted Publishing workflow.
Package publication is not established by this GitHub Release alone;
the package is available on PyPI only after the protected pypi GitHub
environment and the PyPI OIDC exchange both succeed.
Binnacle v1.0.0
Binnacle v1.0.0
First explicitly versioned GitHub-only release of Binnacle, a Linux/Raspberry
Pi MCP development server.
Highlights
- FastMCP upgraded from 4.0.10 to 4.1.0, retaining the reviewed MCP and
MCP-types 2.1.1 protocol baseline. - Native root composition of Files, Search and Commands. The eight public MCP
tools retain their input/output schemas, errors, ordering, client visibility
and authentication behavior. - Privacy-protecting MCP journal telemetry: command strings, file contents,
search patterns, stdin, raw paths and arbitrary errors no longer enter the
Binnacle request/tool/job journal instrumentation. - Compatible Live Smoke using opaque, validated per-call request metadata to
correlate tool calls with exactly their own results after parameter redaction. - Durable Job Manager, systemd units, Linux platform seams and watchdog/tunnel
companions preserve their prior behavior and ownership. - Maintainer first-party import configuration was preserved while retaining
PyYAML, types-PyYAML and zizmor quality/security dependencies.
Release assurance
The released Git Tag identifies the exact source snapshot verified by
code-quality, Python 3.10–3.14 compatibility, coverage, packaging and guarded
production deployment checks. Distribution files attached to the GitHub
release, if present, can be checked against the SHA-256 manifest.
Operational and security boundaries
- The existing bearer token and advertised-client visibility are not
identity-based authorization or an operating system security sandbox. - The durable job store, command output, stdin spools, historical journal
entries and separate tunnel logs retain their own privacy boundaries;
this release only changes the Binnacle journal instrumentation. - No PyPI publishing or automated release system has been introduced.
- Roll back a deployment with the existing guarded process. Never rewrite
the published Git Tag; publish corrections under a later version.
Current Raspberry Pi deployment note
The Binnacle MCP service has been restarted on the exact v1.0.0 commit, and
FastMCP 4.1.0 plus authenticated Live Smoke are confirmed running. The stable
binnacle-jobs service remains on its prior process revision by design; it
was not restarted as part of the MCP rollout, to protect durable job
ownership. Its existing process-level journal behavior is not retroactively
changed until a separately controlled idle-time restart. Old job metadata,
outputs, and historical journals are not erased. The Doctor's sole warning
reports this expected independent revision difference.