Commit cd94774
feat: Add read-only mode for security (enabled by default)
Implements read-only mode to protect against accidental or malicious
deployment creation when using AI assistants. Server runs in read-only
mode by default with explicit opt-out required.
Features:
- Read-only mode enabled by default (secure by default)
- Configuration via DEPLOYHQ_READ_ONLY env var or --read-only CLI flag
- CLI flag takes precedence over environment variable
- Blocks create_deployment tool with clear, actionable error message
- All read operations (list/get) work normally in read-only mode
- Comprehensive logging of read-only status at startup
Configuration:
- Default: read-only enabled (true)
- Disable via: DEPLOYHQ_READ_ONLY=false or --read-only=false
- Accepts: "true", "false", "1", "0", "yes", "no" (case-insensitive)
- Precedence: CLI flag > Environment variable > Default
Documentation:
- Updated README.md with security section and examples
- Updated USER_GUIDE.md with detailed instructions
- Added troubleshooting for read-only mode errors
Tests:
- 48 new tests covering configuration parsing and enforcement
- 100% test pass rate (160 tests total)
- Tests for all input formats, precedence rules, and edge cases
- Integration tests for read-only enforcement and read operations
Inspired by Octopus Deploy's MCP server security model.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <[email protected]>1 parent 9e39900 commit cd94774
File tree
11 files changed
+1209
-10
lines changed- docs
- src
- __tests__
- transports
11 files changed
+1209
-10
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
244 | 244 | | |
245 | 245 | | |
246 | 246 | | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
247 | 257 | | |
248 | 258 | | |
249 | 259 | | |
| |||
395 | 405 | | |
396 | 406 | | |
397 | 407 | | |
| 408 | + | |
| 409 | + | |
| 410 | + | |
| 411 | + | |
| 412 | + | |
| 413 | + | |
| 414 | + | |
| 415 | + | |
| 416 | + | |
| 417 | + | |
| 418 | + | |
| 419 | + | |
| 420 | + | |
| 421 | + | |
| 422 | + | |
| 423 | + | |
| 424 | + | |
| 425 | + | |
| 426 | + | |
| 427 | + | |
| 428 | + | |
| 429 | + | |
| 430 | + | |
| 431 | + | |
| 432 | + | |
| 433 | + | |
| 434 | + | |
| 435 | + | |
| 436 | + | |
| 437 | + | |
| 438 | + | |
| 439 | + | |
| 440 | + | |
| 441 | + | |
| 442 | + | |
| 443 | + | |
| 444 | + | |
| 445 | + | |
| 446 | + | |
| 447 | + | |
| 448 | + | |
| 449 | + | |
| 450 | + | |
| 451 | + | |
| 452 | + | |
| 453 | + | |
| 454 | + | |
| 455 | + | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
| 464 | + | |
| 465 | + | |
| 466 | + | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
| 471 | + | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
398 | 476 | | |
| 477 | + | |
399 | 478 | | |
| 479 | + | |
400 | 480 | | |
401 | | - | |
402 | 481 | | |
403 | 482 | | |
404 | 483 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
583 | 583 | | |
584 | 584 | | |
585 | 585 | | |
| 586 | + | |
| 587 | + | |
| 588 | + | |
| 589 | + | |
| 590 | + | |
| 591 | + | |
| 592 | + | |
| 593 | + | |
| 594 | + | |
| 595 | + | |
| 596 | + | |
| 597 | + | |
| 598 | + | |
| 599 | + | |
| 600 | + | |
| 601 | + | |
| 602 | + | |
| 603 | + | |
| 604 | + | |
| 605 | + | |
| 606 | + | |
| 607 | + | |
| 608 | + | |
| 609 | + | |
| 610 | + | |
| 611 | + | |
| 612 | + | |
| 613 | + | |
| 614 | + | |
| 615 | + | |
| 616 | + | |
| 617 | + | |
| 618 | + | |
| 619 | + | |
| 620 | + | |
| 621 | + | |
| 622 | + | |
| 623 | + | |
| 624 | + | |
| 625 | + | |
| 626 | + | |
| 627 | + | |
| 628 | + | |
| 629 | + | |
| 630 | + | |
| 631 | + | |
| 632 | + | |
| 633 | + | |
| 634 | + | |
| 635 | + | |
| 636 | + | |
| 637 | + | |
| 638 | + | |
| 639 | + | |
| 640 | + | |
| 641 | + | |
| 642 | + | |
| 643 | + | |
| 644 | + | |
| 645 | + | |
| 646 | + | |
| 647 | + | |
| 648 | + | |
| 649 | + | |
| 650 | + | |
| 651 | + | |
| 652 | + | |
| 653 | + | |
| 654 | + | |
| 655 | + | |
| 656 | + | |
| 657 | + | |
| 658 | + | |
586 | 659 | | |
587 | 660 | | |
588 | 661 | | |
| |||
0 commit comments