Skip to content

Latest commit

 

History

History
13 lines (11 loc) · 2.79 KB

File metadata and controls

13 lines (11 loc) · 2.79 KB

1Panel implementation contract

The package is Greenfield. This document is its implementation acceptance source. No spec-tool initialization or client-cache modification occurs; the source Git repository is created for the user-authorized GitHub publication.

  1. Agent Plugins 1.0.0 root plugin.json and standard mcp.json, name 1panel, English display name 1Panel; native Codex/Claude compatibility metadata must agree.
  2. Create a reusable 1panel-skills source suite covering routing, setup, system inspection, websites, certificates, databases, applications and scoped security review. Derive actual capability and parameter guidance from the pinned official MCP source and 1Panel documentation, with attribution. Do not invent backup, firewall, delete, shell or arbitrary application tools.
  3. Integrate the official MCP server at release v1.0.0 / commit a12b2d4ddae90f6b210b73b89ba2bc4b572dcd0c, externally built/installed by the user. Do not copy its GPL source into an Apache plugin or silently install tools. The tag reports an older internal server version; verify configured binary SHA256, not a fabricated version flag.
  4. The standard stdio entry uses only package code and the explicit ${PLUGIN_DATA} location. Read private configuration there; no reliance on inherited PANEL variables, APPDATA/HOME or interpolated secrets in visible MCP JSON. Pass credentials to the official process environment, never arguments or logs.
  5. Enforce readonly by default in executable policy: filter discovery and reject direct write calls. Explicit local configuration supports readwrite (three create tools) and full (two application install tools). Unknown tools are denied even if upstream adds them. Per-operation authorization and target verification remain skill responsibilities, not an invented approval proof in the transport.
  6. Use actual upstream JSON-RPC protocol, preserve request identities, forward supported lifecycle/cancellation, bound input and in-flight requests, detect child exit, and never automatically retry writes. For a timeout, report unknown outcome and reconcile before resubmission.
  7. Connection/setup errors must be visible without revealing keys. Preserve other plugin skills when MCP cannot start. Avoid implicit remote connections, installation or live changes.
  8. Tests must use the actual pinned official server, initialized through the shipped proxy, against a loopback simulated 1Panel API: discovery, permission denial, read responses, mutation forwarding after explicit configured access, authentication headers, errors and unknown outcomes. Mock API tests do not prove a real production panel or user client installation.
  9. Deliver source provenance, credentials/setup instructions, architecture, regression tests, CI and a package archive. Never auto-roll back by deleting a newly created resource.