deploy/docker-compose.yml was unedited docs-mcp-template boilerplate —
untouched since the scaffold commit, still carrying <product>,
<registry> and <owner> placeholders — describing a standalone stack
that has never existed. crop-chem-docs runs as the `chem-mcp` service
inside Drawbar's parent compose.
It also set MCP_ALLOWED_HOSTS, which no code in this repo reads. The
knob is MCP_DISABLE_DNS_REBINDING_PROTECTION. Anyone who trusted the
old file and set an allowlist would have gotten a 421 on every request
with nothing in the logs to explain it.
- deploy/docker-compose.yml: replaced with the real chem-mcp block, a
copy of what runs in Drawbar/drawbar-backend. Verified structurally
identical to the parent (image, environment, expose, extra_hosts,
restart, labels all equal). Carries the why for each setting: the
:latest-vs-corpus-tag Watchtower trap (#339), the rebind-protection
rationale, and that the OLLAMA_URL override is load-bearing because
Drawbar's own ollama service is commented out — the image default
http://ollama:11434 does not resolve in that stack, so without the
override every search_docs call fails to embed its query.
- deploy/drawbar-compose-snippet.md: deleted. It was a second,
differently-wrong copy (service name `crop-chem-docs`, ports
8001:8000, and "No environment block needed — the image's defaults
handle it", which is false on both the rebind and Ollama counts).
Its still-true content (verification commands) moved into the compose
file; the tag scheme and deploy chain were already in the README.
- deploy/rerank-docker.md: RERANK_URL said http://10.10.1.65:8082. In
production the MCP reaches the sidecar by compose service name
(http://llama-rerank:8080, baked into the image). Documents the
network-attach gotcha that makes rerank fail silently, and keeps the
host-IP form for local dev.
- README.md: file tree updated for the deleted file; Watchtower poll
interval corrected 5 min -> 60s (WATCHTOWER_POLL_INTERVAL=60, as
configured on trashpanda).
Verified: no <product>/<registry>/<owner> placeholders remain in
deploy/ or README, and all six env vars set in the block are ones the
server actually reads.
Closes#5
Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01FFBDnRWHispovmJVK9rXc9