-
Notifications
You must be signed in to change notification settings - Fork 0
Docker
The image shibbirweb/mcp-db-read-only runs the same server with nothing else installed. It's built for Intel and Apple Silicon (linux/amd64 and linux/arm64).
| Tag | Gets |
|---|---|
latest |
The newest release |
1 |
The newest 1.x release (recommended: new features and fixes, never a breaking change) |
1.1 |
The newest 1.1.x release |
1.1.0 |
Exactly that version |
{
"mcpServers": {
"databases": {
"command": "docker",
"args": [
"run", "-i", "--rm",
"--add-host", "host.docker.internal:host-gateway",
"-e", "DB_URL=postgres://readonly:secret@host.docker.internal:5432/myapp",
"shibbirweb/mcp-db-read-only:1"
]
}
}
}-
-iis required: the client talks to the server through its input and output. -
--rmremoves the container when the client closes it. - Pass every setting with its own
-e NAME=value.
Inside a container, localhost means the container itself. Use host.docker.internal instead, and keep the --add-host host.docker.internal:host-gateway line (Docker Desktop has it built in, Linux needs the flag).
flowchart LR
subgraph computer["Your computer"]
DB[("Your database<br/>port 5432")]
subgraph container["Docker container"]
S["mcp-db-read-only"]
L["localhost<br/>(the container itself)"]
end
end
S -->|"host.docker.internal:5432<br/>reaches it"| DB
S -.->|"localhost:5432<br/>finds nothing"| L
A database in another container? Put both on one Docker network and use the container's name as the host.
Mount the folder, read-only, and use the path inside the container:
"-v", "/Users/me/data:/data:ro",
"-e", "DB_URL=sqlite:///data/app.db"Mount a folder for DB_LOG_DIR, so the logs outlive the container:
"-v", "/Users/me/Library/Logs/mcp-db-read-only:/logs",
"-e", "DB_LOG_DIR=/logs"And view them, from Docker or with npx, as described on Logging and Viewer:
docker run --rm -p 127.0.0.1:4800:4800 -v /Users/me/Library/Logs/mcp-db-read-only:/logs:ro \
shibbirweb/mcp-db-read-only node dist/index.js viewer --dir /logs --port 4800-p 127.0.0.1:4800:4800 makes the page reachable from your computer only.
Both run the same code. npm (npx) starts a little faster and needs Node 22.13+. Docker needs nothing but Docker and keeps the server walled off from the rest of your computer: it can only reach what you pass in.
User guide
Developer guide
- Architecture
- Design Patterns
- Domain and Configuration
- Drivers
- Read Only Enforcement
- Tools internals
- Call Logging internals
- Server Lifecycle
- Testing
- Release Process
Links