Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

4) Deployment Topology (Docker Compose)

From cognokratos/sophos-agent · docs/architecture/4-deployment-topology-docker-compose.md · pinned revision 8d9fe52182d8

Learn: 08 — Local-first and runtime ownership (what the topology enforces, and what it doesn't).

Defined in infra/compose.yml; started with make start (or make inspector).

Services

ServiceImage / buildPublished to hostReached by the app atVolumes
webinfra/app/Dockerfile (SvelteKit + agent)127.0.0.1:5173—infra/app/config (ro), data/db/
mcp-memoryinfra/mcp/memory/Dockerfilenot publishedhttp://mcp-memory:8080/mcpdata/memory/ → /data/memory
mcp-fetchinfra/mcp/fetch/Dockerfilenot publishedhttp://mcp-fetch:8080/mcp—
mcp-inspectorghcr.io/modelcontextprotocol/inspector:2.9.0127.0.0.1:6274 (opt-in)——
  • Ollama is not a Compose service. The app reaches the host's Ollama through OLLAMA_HOST (default http://host.docker.internal:11434 in infra/.env.example).
  • Each MCP server is a stdio server wrapped by mcp-proxy, which serves Streamable HTTP on /mcp (and legacy SSE on /sse) inside the container.
  • The Memory server writes to MEMORY_FILE_PATH=/data/memory/memory.jsonl, set in compose.yml next to the volume, so the knowledge graph persists in the repository's data/memory/.
  • web reads CONFIG_DIR=config and DATABASE_PATH=data/db/sophos.db from compose.yml and mounts the repository's data/db/ (a directory, because SQLite writes -wal/-shm files next to the database); infra/.env holds only Ollama and agent settings.

Profiles

  • (default) — web, mcp-memory, mcp-fetch.
  • inspector — adds the MCP Inspector (make inspector). Its backend runs on the Compose network, so in its UI connect to http://mcp-memory:8080/mcp or http://mcp-fetch:8080/mcp; the MCP ports never need to be published. The API token is printed in the container logs.

To debug an MCP server from the host without the Inspector, add a temporary port mapping that keeps the loopback prefix (e.g. 127.0.0.1:8081:8080).

Healthchecks

ServiceProbe (inside the container)
webwget → /api/healthz
mcp-memorywget → mcp-proxy /ping
mcp-fetchPython urllib → mcp-proxy /status

web starts only after both MCP services are healthy. make start and scripts/test.sh use docker compose up --wait. /api/readyz (Ollama + model) is checked by scripts/test.sh, not by a Compose healthcheck, so the stack starts even while the model is still being pulled.

Version pinning

ComponentPinned in
JS dependencies (app)pnpm-lock.yaml (authoritative), installed with --frozen-lockfile
pnpmpackage.json#packageManager, activated with Corepack
Memory MCP containerinfra/mcp/memory/package.json + package-lock.json (npm ci)
Fetch MCP containerinfra/mcp/fetch/requirements.in → locked requirements.txt (uv pip compile)
MCP Inspectorimage tag 2.9.0
Local stdio serversexact versions in config/mcp.json (npx …@2026.8.31, uvx …@2026.8.18)
Base imagesmajor-version tags (node:24-alpine, python:3.12-slim), not digests

This chapter is maintained in cognokratos/sophos-agent beside the code it teaches. The book shows docs/architecture/4-deployment-topology-docker-compose.md at revision 8d9fe52182d8441454916ec8a6ab13c0773228e2 (branch main). View source at this revision · Report a correction.

Corrections are made upstream against the current main branch and appear here when the book's pin for this source is updated.