Kyle Isom 47ec4e60ad unikernel: isolated host-only bridge networking (Phase 2)
When the mcp-br0 bridge exists, the agent runs unikernels on it instead
of QEMU user-mode networking: each VM gets a TAP device on the bridge
and a static 10.99.0.0/24 IP (baked into the Nanos image via ops
RunConfig). With the host firewall dropping off-bridge VM traffic and no
NAT, a VM can reach only the gateway -- making mc-proxy mediation
mandatory by topology rather than convention.

- runtime/qemu.go: bridge mode (createTAP/destroyTAP, IP allocator,
  deterministic MAC, static-IP ops config, VMAddr for proxy backends).
- agent auto-enables bridge mode when /sys/class/net/mcp-br0 exists.

Verified on straylight: uktest unikernel boots on mcp-br0 at 10.99.0.2,
serves via the gateway, TAP enslaved to the bridge; bridge has no uplink
and off-bridge forwarding is dropped.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-11 01:07:49 -07:00
2026-03-26 22:46:36 -07:00
2026-03-30 17:46:12 -07:00

MCP — Metacircular Control Plane

MCP is the orchestrator for the Metacircular platform. It manages container lifecycle, tracks what services run where, and transfers files between the operator's workstation and managed nodes.

Architecture

CLI (mcp) — thin client on the operator's workstation. Reads local service definition files, pushes intent to agents, queries status.

Agent (mcp-agent) — per-node daemon. Manages containers via rootless podman, stores a SQLite registry of desired/observed state, monitors for drift, and alerts the operator.

Quick Start

Build

make all          # vet, lint, test, build
make mcp          # CLI only
make mcp-agent    # agent only

Install the CLI

cp mcp ~/.local/bin/
mkdir -p ~/.config/mcp/services

Create ~/.config/mcp/mcp.toml:

[services]
dir = "/home/<user>/.config/mcp/services"

[mcias]
server_url   = "https://mcias.metacircular.net:8443"
service_name = "mcp"

[auth]
token_path = "/home/<user>/.config/mcp/token"

[[nodes]]
name = "rift"
address = "100.95.252.120:9444"

Authenticate

mcp login

Check status

mcp status    # full picture: services, drift, events
mcp ps        # live container check with uptime
mcp list      # quick registry query

Deploy a service

Write a service definition in ~/.config/mcp/services/<name>.toml:

name = "myservice"
node = "rift"
active = true

[[components]]
name = "api"
image = "mcr.svc.mcp.metacircular.net:8443/myservice:v1.0.0"
network = "mcpnet"
user = "0:0"
restart = "unless-stopped"
ports = ["127.0.0.1:8443:8443"]
volumes = ["/srv/myservice:/srv/myservice"]
cmd = ["server", "--config", "/srv/myservice/myservice.toml"]

Then deploy:

mcp deploy myservice

Commands

Command Description
mcp login Authenticate to MCIAS
mcp deploy <service>[/<component>] Deploy from service definition
mcp stop <service> Stop all components
mcp start <service> Start all components
mcp restart <service> Restart all components
mcp list List services (registry)
mcp ps Live container check
mcp status [service] Full status with drift and events
mcp sync Push all service definitions
mcp adopt <service> Adopt running containers
mcp service show <service> Print spec from agent
mcp service edit <service> Edit definition in $EDITOR
mcp service export <service> Export agent spec to file
mcp push <file> <service> [path] Push file to node
mcp pull <service> <path> [file] Pull file from node
mcp node list List nodes
mcp node add <name> <addr> Add a node
mcp node remove <name> Remove a node

Documentation

Description
No description provided
Readme 43 MiB
2026-03-27 08:34:37 +00:00
Languages
Go 98.8%
Shell 0.7%
Nix 0.3%
Makefile 0.2%