This experimental service is designed for trusted application-to-service traffic on a private network. Do not expose the example routes or Python server directly to the internet.
- Generate a service token of at least 32 non-whitespace ASCII characters. Never commit it. A token grants access to every job in that service instance.
- Enforce end-user authentication and per-job ownership in the PHP application. The example deliberately omits those application-specific policies and publishes no ports.
- Only trusted task implementations are allowed. Python child processes inherit the service environment; they are not suitable for arbitrary user-provided scripts.
- Container configuration uses a non-root user, read-only filesystem, dropped capabilities, no-new-privileges, CPU/memory/PID bounds, and an internal-only network for execution. It mounts only this checkout and the optional dependency/model cache, never a Docker socket or home directory.
- Dependency acquisition is separate and internet-enabled. Execution installs hash-checked wheels from the local cache without internet access. The model downloader retrieves fixed files at a pinned revision and checks their hashes; it does not execute model-repository code.
- CI may run on a self-hosted runner, which executes a workflow's code with that runner's network access, and the lab's runs a privileged Docker-in-Docker daemon. The workflows as written send a fork's pull request to GitHub's disposable runners, but a fork can edit them in its own pull request and name the self-hosted runner, and GitHub runs a pull request's workflows as the pull request has them. The boundary is therefore the repository's fork pull request approval policy: with a self-hosted runner configured, require approval for all outside contributors, not only first-time ones, and review a fork's workflow changes before approving its run. The runner installs Docker Compose from a pinned release checked by SHA-256 when its image lacks it.
- Model files, native libraries and runtime dependencies still carry supply-chain risk. Review upgrades, regenerate locks deliberately and rerun tests before changing pins.
- Requests and results may contain sensitive documents. They live in RAM, may be present in process/core dumps, and are not encrypted by this service. Minimize retention and use appropriate host/storage policies. Embedding vectors are derived from their input text and can reveal much of it; store and transmit them with the same care as the text.
- Redaction is assistive, not a compliance control. The rules find only the structured identifiers they recognise, and the optional named-entity models were trained on English news, so their recall on names from other domains or languages is lower and unmeasured here; review redacted output before treating it as free of personal data. The model files are third-party ONNX conversions of the original weights, pinned by revision and hash but not signed by the original author.
- The MCP server is a client of this service for an AI agent over stdio, where there is no authentication: the host that launches it inherits its trust, and it holds the token from its environment and never returns it. Running it over HTTP or SSE would be a new authorisation surface that the bearer token does not cover; it is out of scope. An agent can be prompt-injected and can then fill a worker's capacity, so point the MCP server at a dedicated worker, never at one serving a production application; compose's
mcpandmcp-modeleach have their own. It reads files only underBRIDGE_MCP_ROOTand writes none; snippets it returns are the agent's own file content and enter the agent's context like any file it reads. Index files built forbridge_searchare derived data:index.jsonholds every chunk's text verbatim andvectors.f32holds vectors that can reveal it, so keep them with the same care as their sources. The builder runs with the service token like the PHP client and is the only component that writes, into the directory the operator names. - Access logs are disabled to avoid accidentally recording identifiers and inputs. Internal exceptions become generic task errors. This is not a full observability or compliance solution.
- Cancel/timeout terminates the task process, but cannot roll back previously completed external effects. No task in the prototype modifies an external system.
- The default health endpoint proves HTTP service availability, not model integrity, ability to spawn processes or successful inference. An ONNX worker checks before it starts that each model directory holds its tokenizer and model files and refuses to start otherwise; that proves presence, not integrity, which the fetcher's hashes establish. Use a controlled model smoke test for readiness validation.
The FrankenPHP executable is copied from its pinned image into a task-only executable tmpfs. This removes upstream file capabilities without granting the container capabilities. Other temporary storage is non-executable; the optional Python dependency tmpfs must permit native library mappings.