deploy
deploy ¶
Concrete wiring of the multi-tenant datacrew resolver for deployment.
Builds a DatacrewResolver with production dependency impls
- verify_token: validate the dc_ JWT against datacrew.space JWKS (RS256)
- check_entitlement: GET /api/internal/entitlements/check (X-Webui-Secret)
- fetch_cred: GET /api/internal/domo-cred/{email}/{slug} (X-Webui-Secret)
- decrypt: envelope.decrypt with the VPS RSA private key (the real wiring)
The network deps are overridable so the wiring is unit-testable; defaults make real HTTP/JWKS calls and are exercised at deploy time (integration), not here.
build_datacrew_resolver ¶
build_datacrew_resolver(
*,
rsa_private_key_pem: str,
jwks_url: str = "https://datacrew.space/.well-known/jwks.json",
issuer: str = "https://datacrew.space",
audience: str = "https://domo.datacrew.space",
internal_base_url: str = "https://datacrew.space",
internal_secret: str = "",
entitlement_resource: str = "crew-dcs",
verify_token: Callable[[str | None], str] | None = None,
check_entitlement: (
Callable[[str], Awaitable[bool]] | None
) = None,
fetch_cred: (
Callable[[str, str], Awaitable[dict]] | None
) = None,
validate: Callable[[Any], Awaitable[bool]] | None = None
) -> DatacrewResolver
Wire a production DatacrewResolver. Network deps default to real impls; pass overrides (verify_token/check_entitlement/fetch_cred) to unit-test.
Source code in src/crew_dcs/mcp_server/deploy.py
211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 | |
build_jwt_verifier ¶
build_jwt_verifier(
*, jwks_url: str, issuer: str, audience: str
)
A FastMCP JWTVerifier that tolerates the dc_ wire prefix.
MCP clients send Authorization: Bearer dc_<jwt>. The stock JWTVerifier would
try to parse the literal dc_<jwt> (not a valid JWT) and 401 every request, so
we strip the prefix before delegating to the real verification.
Source code in src/crew_dcs/mcp_server/deploy.py
40 41 42 43 44 45 46 47 48 49 50 51 52 53 | |
build_validate_handler ¶
build_validate_handler(
*,
rsa_private_key_pem: str,
internal_base_url: str,
internal_secret: str,
fetch_cred: (
Callable[[str, str], Awaitable[dict | None]] | None
) = None,
who_am_i: (
Callable[[str, str], Awaitable[Any]] | None
) = None
)
Build the async Starlette handler for POST /internal/validate.
Server-to-server: validates an ALREADY-STORED, envelope-encrypted Domo
credential the website cannot decrypt (only this VPS holds the RSA private
key). Auth is the shared X-Webui-Secret header — this route is NOT behind
the dc_ JWTVerifier. The token is never returned, only a boolean verdict.
Network deps (fetch_cred/who_am_i) default to the real httpx impls
and are injectable for unit tests.
Source code in src/crew_dcs/mcp_server/deploy.py
159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 | |
strip_dc_prefix ¶
strip_dc_prefix(token: str | None) -> str | None
Return the bare JWT, dropping a leading dc_ if present. None stays None.
Source code in src/crew_dcs/mcp_server/deploy.py
33 34 35 36 37 | |