import net from 'node:net'; import { createDb, eq, isNotNull, mcpServers } from '@bmm/db'; import { config } from '../config.js'; /** * Container hardening flags applied on every runner deployment on Linux * production hosts. Skipped only when explicitly disabled (dev/Windows * Docker Desktop, which doesn't fully honour --read-only on bind mounts). * * Without these, a tenant container runs as root with full capabilities on * the shared host — combined with the LLM static-check being a regex * blacklist (Z2-001), this would let a malicious tenant execute arbitrary * code on the host. With them, the blast radius collapses to "within the * container", which holds only that tenant's own decrypted secrets. */ const HARDENING_FLAGS = [ '--read-only', '--cap-drop=ALL', '--security-opt=no-new-privileges:true', '--pids-limit=100', '--memory=512m', '--memory-swap=512m', '--cpus=0.5', // /tmp needs writable space — runner-template uses it for build/cache. '--tmpfs=/tmp:rw,nosuid,nodev,size=64m', ]; function shouldHarden(): boolean { // Explicit opt-out for local dev on Windows where --read-only conflicts // with how Docker Desktop binds volumes. Production must always harden. if (process.env.RUNNER_DISABLE_HARDENING === '1') return false; const env = process.env.NODE_ENV; return env === 'production' || env === 'staging'; } const db = createDb(); async function portFree(port: number, host = '127.0.0.1'): Promise { return new Promise((resolve) => { const tester = net .createServer() .once('error', () => resolve(false)) .once('listening', () => tester.close(() => resolve(true))) .listen(port, host); }); } export async function allocatePort(): Promise { const used = new Set( ( await db .select({ port: mcpServers.hostPort }) .from(mcpServers) .where(isNotNull(mcpServers.hostPort)) ) .map((r) => r.port) .filter((p): p is number => typeof p === 'number'), ); for (let port = config.RUNNER_PORT_RANGE_START; port <= config.RUNNER_PORT_RANGE_END; port++) { if (used.has(port)) continue; if (await portFree(port)) return port; } throw new Error('no_free_port'); } export interface DeployHandle { containerId: string; publicUrl: string; hostPort: number; } export interface DeployInput { serverId: string; slug: string; hostPort: number; imageTag: string; envVars: Record; } export async function deployContainer(input: DeployInput): Promise { // Docker CLI is portable across linux/mac/win — sufficient for now; future // iteration will switch to the engine API via UNIX socket. const { spawn } = await import('node:child_process'); const containerName = `bmm-mcp-${input.slug}-${Date.now().toString(36)}`; const args = [ 'run', '-d', '--name', containerName, '-p', `${input.hostPort}:3000`, ]; if (shouldHarden()) { args.push(...HARDENING_FLAGS); } for (const [k, v] of Object.entries(input.envVars)) { args.push('-e', `${k}=${v}`); } args.push('--restart=unless-stopped', input.imageTag); return await new Promise((resolve, reject) => { const child = spawn('docker', args, { stdio: ['ignore', 'pipe', 'pipe'] }); let out = ''; let err = ''; child.stdout.on('data', (d) => { out += d.toString(); }); child.stderr.on('data', (d) => { err += d.toString(); }); child.on('error', (e) => reject(e)); child.on('close', async (code) => { if (code !== 0) { reject(new Error(`docker_run_failed (exit ${code}): ${err.trim() || out.trim()}`)); return; } const containerId = out.trim().slice(0, 64); const publicUrl = `http://${config.RUNNER_HOST}:${input.hostPort}`; await db .update(mcpServers) .set({ containerId, hostPort: input.hostPort, publicUrl, status: 'live', updatedAt: new Date(), }) .where(eq(mcpServers.id, input.serverId)); resolve({ containerId, publicUrl, hostPort: input.hostPort }); }); }); } export async function stopContainer( containerId: string, ): Promise<{ ok: boolean; detail: string }> { if (!containerId || containerId.length < 4) { return { ok: false, detail: 'invalid_container_id' }; } const { spawn } = await import('node:child_process'); return await new Promise<{ ok: boolean; detail: string }>((resolve) => { const child = spawn('docker', ['rm', '-f', containerId], { stdio: ['ignore', 'pipe', 'pipe'], }); let err = ''; child.stderr?.on('data', (d: Buffer) => { err += d.toString(); }); child.on('error', () => resolve({ ok: false, detail: 'spawn_failed' })); child.on('close', (code) => resolve(code === 0 ? { ok: true, detail: '' } : { ok: false, detail: err.trim() || `exit ${code}` }), ); }); } export async function dockerAvailable(): Promise { const { spawn } = await import('node:child_process'); return await new Promise((resolve) => { const child = spawn('docker', ['version'], { stdio: 'ignore' }); child.on('error', () => resolve(false)); child.on('close', (code) => resolve(code === 0)); }); }