ai: migrate LLM backbone from Kimi CLI to Codex CLI
Retires the Moonshot/Kimi subscription in favour of the already-paid ChatGPT plan. Both CLI wrappers now run `codex exec`; the kimi-agent container is gone. adolf-llm + hindsight-llm: - runKimi -> runCodex (`codex exec --json --skip-git-repo-check`), resume via `codex exec resume <thread_id>`. - MCP moves from a per-session .mcp.json (a workaround for Kimi having no --mcp-config-file flag) to a $CODEX_HOME/config.toml generated once at startup from shared-mcp.json. Field translation is load-bearing: bearerTokenEnvVar -> bearer_token_env_var, enabledTools -> enabled_tools. - approval_policy="never" + sandbox_mode required, or unattended turns block on an approval prompt nobody can answer. kimi-agent removed. It was the ONLY large-tier deployment behind LiteLLM, so deleting it outright would have silently degraded every large-tier request to the local 4B model via the existing fallbacks. tier-large, the auto_router complex-reasoning route and their fallbacks now point at the codex-backed adolf-llm wrapper (model_name: codex-agent). Three environment blockers fixed along the way: - OpenAI geo-blocks this host (403 unsupported_country_region_territory). Both containers now egress via the host xray proxy, with NO_PROXY keeping MCP and *.alogins.net traffic off the tunnel. - node:22-slim ships no system CA store; the Rust codex binary validates TLS against it, so every HTTPS call failed with a generic transport error while Node's own fetch worked. ca-certificates added to both images. - `codex exec resume` rejects -C/--cd (plain `codex exec` accepts it), which broke follow-up turns while first turns succeeded. Known regression: Kimi's managed-usage API has no Codex equivalent, so the /usage route returns 501 and there is no quota probe for the codex model. The two quota plugins degrade quietly to no output. Also: stop tracking cognee.env (live LLM + JWT secrets) and gitignore it. The secrets remain in earlier history and should be rotated. Verified live: plain turn, SSE streaming, session resume, MCP tool call, bearer-token MCP call, and completions through both LiteLLM routes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014Y5QPagv4iun1ghpwM96Ff
This commit is contained in:
23
ai/cognee-mcp/Dockerfile
Normal file
23
ai/cognee-mcp/Dockerfile
Normal file
@@ -0,0 +1,23 @@
|
||||
# Adolf kb#70 — cognee-mcp deletion fix.
|
||||
#
|
||||
# Base: official upstream image (do not hand-roll cognee-mcp itself).
|
||||
# Patches exactly two files to fix a real bug: the `forget` MCP tool (the
|
||||
# only deletion-capable tool actually exposed to agents — `delete`,
|
||||
# `delete_dataset`, and `prune` exist in src/server.py but are never
|
||||
# registered with @mcp.tool(), so they're unreachable dead code) never
|
||||
# exposed a `data_id` parameter, and its cognee_client.forget() wrapper
|
||||
# never forwarded one either — even though cognee's own /api/v1/forget
|
||||
# endpoint has always supported single-item deletion via dataset+data_id.
|
||||
# Net effect: agents could delete an entire dataset but never a single
|
||||
# entry/fact. Verified 2026-07-07 by calling the live /api/v1/forget
|
||||
# endpoint directly with data_id — entry-level delete works fine
|
||||
# server-side; the MCP bridge was just never wired up to use it.
|
||||
#
|
||||
# See src/cognee_client.py forget() and src/server.py forget() for the
|
||||
# fix. Both files are full copies of the upstream 0.5.4 source with only
|
||||
# the forget-related code changed (diff against the base image at
|
||||
# /app/src/{cognee_client,server}.py to see the exact delta).
|
||||
FROM cognee/cognee-mcp:1.2.2
|
||||
|
||||
COPY src/cognee_client.py /app/src/cognee_client.py
|
||||
COPY src/server.py /app/src/server.py
|
||||
Reference in New Issue
Block a user