Add JoomEngine MCP for Joomla to PHP images - #5
Merged
Conversation
Contributor
Author
|
Final source-level validation status
The PR intentionally remains a draft until the |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
Makes the PHP and full OpenCode images able to consume the public JoomEngine MCP for Joomla package through a local, bounded stdio integration.
What changed
joomla-mcpas a manifest-owned composable capability for thephpandfullimages only;@joomengine/joomla-mcp@0.7.0, with the JoomEngine repository and inspected commit recorded in the source lock;occtl joomla-configurefor one fixed HTTPS Joomla origin with explicitreadonly,content,admin, andfullprofiles;fullprofile;occtl joomla-test, which runs the upstream non-mutatingreadprofile over Joomla API + local stdio and retains redacted evidence in the workspace;0.3.0-rc.2and replaces the stale deferred-repository documentation with the operational deployment and security model.Security boundaries
The normal image path opens no inbound MCP port and requires no MCP HTTP bearer token or JWKS service. It accepts only a fixed HTTPS Joomla origin and a configured alias. Joomla Web Services plugins, the dedicated API user's permissions, Joomla ACL, enabled toolsets, bounded grants, plans, and one-time apply tokens remain independent controls.
The ready
connectedpolicy supports public HTTPS Joomla origins while rejecting private, management, metadata, link-local, and carrier-grade NAT ranges. Private Joomla sites require an approved brokered/restricted path or an explicitly acknowledged lab environment; this change does not weaken the shared ACL.Validation completed
The GitHub validation workflow remains the authoritative ShellCheck/yamllint run.
Deliberate promotion gates
This change does not claim that static tests produce a certified VM image or that every upstream Joomla action family is production-certified. Promotion still requires:
phpandfullbuilds on the trusted KVM/Incus builder;