-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathserver.json
More file actions
59 lines (59 loc) · 5.32 KB
/
Copy pathserver.json
File metadata and controls
59 lines (59 loc) · 5.32 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.agentic-research/notme",
"title": "notme",
"description": "Self-hostable identity authority — passkeys, bridge certs, DPoP-bound tokens, and APAS.",
"version": "0.2.0",
"repository": {
"url": "https://github.com/agentic-research/notme",
"source": "github"
},
"websiteUrl": "https://github.com/agentic-research/notme/blob/main/README.md",
"_meta": {
"io.modelcontextprotocol.registry/publisher-provided": {
"artifacts": [
{
"registryType": "oci",
"identifier": "ghcr.io/agentic-research/notme",
"version": "0.2.0"
},
{
"registryType": "oci",
"identifier": "ghcr.io/agentic-research/notme-proxy",
"version": "0.2.0"
}
]
},
"io.github.agentic-research.notme/surface": {
"note": "There is no `packages` key and no `remotes`, deliberately. notme is an identity authority (OAuth/OIDC endpoints, cert mint), not an MCP server — `worker/` registers no MCP tools and `proxy/` parses no JSON-RPC, it moves bytes. Cloister derives MCP session behaviour from `remotes[].type` or `packages[].transport.type`; with neither present it falls through cleanly, which is the correct outcome for a non-MCP producer. Declaring an MCP surface here would be worse than omitting it: cloister would generate backends for tools that do not exist.",
"whyArtifactsNotPackages": "The registry schema puts `transport` in `Package.required`, so a producer that publishes images and serves no MCP cannot use `packages[]` without either a placeholder transport (a runtime lie — see above) or a document that fails the schema its own `$schema` key names. notme shipped the second from 2026-07-28 until this file moved to `artifacts` (notme-6e5330). `_meta.\"io.modelcontextprotocol.registry/publisher-provided\"` is the schema's own open extension slot (`additionalProperties: true`), and is where ley-line-open's `leyline-mcp-descriptor` renders artifact-only producers (ley-line-open-0135fa; the shape was adopted from v0.13.0, and LLO is at 0.17.0 as of 2026-08-05 — this file is hand-maintained, so the version is a provenance note, not a pin). The `artifacts` array below matches that emitter's rendered output for notme, which is also cloister's contract fixture on cloister-02dd65.",
"purpose": "This file exists for the ADR-0041 image-publish contract — it is the package-identity manifest consumers read to derive `<identifier>:<version>`, not an MCP registry entry."
},
"io.github.agentic-research.notme/packages": {
"note": "Two OCI images, versioned and published together from a single `v*` tag. `version` is the tag the publish job actually pushes (ADR-0041 §2), asserted per-entry by `task version:check` before anything is pushed. notme strips the `v` — a `v0.1.0` tag publishes `:0.1.0` — because cloister's cluster.toml already names `notme:0.1.0`, so registry-qualifying it is a pure prefix addition with no version rewrite.",
"ghcr.io/agentic-research/notme": "workerd + the worker bundle. The identity authority itself: mints lease certs against the master CA, serves the OAuth/OIDC endpoints. Listens on 8788.",
"ghcr.io/agentic-research/notme-proxy": "The mTLS forward proxy / cloister-companion. Holds the bridge cert + private key in process memory and presents them on outbound TLS, so no Worker ever holds a credential."
},
"art.cloister/v1": {
"note": "Both images are hypervisor-tier bundles in a cloister cluster, declared separately (`notme-identity` and `notme-proxy`) and derived separately per ADR-0038. They are not interchangeable and do not share a lifecycle beyond the release tag. This block is notme's own topology and is not derivable from the image addresses — note that leyline-mcp-descriptor puts tool-group claims under this same `art.cloister/v1` key, a different occupant of one namespace. notme has no tool groups, so there is nothing to collide with; a generated descriptor would simply omit the key and lose this content, which is why the file stays hand-maintained (notme-450c3c).",
"bundles": [
{
"name": "notme-identity",
"tier": "hypervisor",
"kind": "external",
"package": "ghcr.io/agentic-research/notme",
"httpPort": 8788,
"rationale": "Identity authority: mints lease certs against the master CA. Mediates trust — every authenticated request transits a lease this bundle minted. Compromise blast radius is cluster-wide (forge any peer's identity). Singleton per cluster: one master CA. Three-criterion test per ADR-0011, expanded in ADR-0018."
},
{
"name": "notme-proxy",
"tier": "hypervisor",
"kind": "external",
"package": "ghcr.io/agentic-research/notme-proxy",
"ipcSocket": "/run/cloister-uds/companion.sock",
"rationale": "Holds the bridge cert + private key in process memory and presents them on outbound TLS, so no Worker ever holds a credential (two-plane model). Every attested egress and every UDS dial from workerd transits this bundle, so it mediates trust and its compromise blast radius is every upstream the cluster reaches. Singleton per host: one socket, one cert. Companion role per ADR-0005."
}
]
}
}
}