Sign inSign up

pirlruc/gitlab-mcp

By pirlruc

•Updated 2 months ago

GitLab MCP server

Image
Developer tools
0

248

pirlruc/gitlab-mcp repository overview

⁠Docker Hub — gitlab-mcp

gitlab-mcp is a stdio MCP⁠ server for self-hosted GitLab. It exposes merge-request tools (list, search, diffs, discussions, pipelines, and allowlisted updates) to MCP clients such as Cursor.

The image speaks MCP over stdin/stdout only.

⁠Quick start

Minimum run (interactive stdio — how MCP clients launch the server):

docker run --rm -i \
  -e GITLAB_URL=https://gitlab.example.com \
  -e GITLAB_TOKEN=glpat-xxxxxxxx \
  pirlruc/gitlab-mcp:0.1.0

Recommended hardened run:

docker run --rm -i \
  --read-only \
  --cap-drop ALL \
  --security-opt no-new-privileges \
  --tmpfs /tmp:rw,noexec,nosuid,size=64m \
  -e GITLAB_URL=https://gitlab.example.com \
  -e GITLAB_TOKEN \
  -e GITLAB_READ_ONLY=1 \
  pirlruc/gitlab-mcp:0.1.0

Pass secrets with -e VAR (from the host environment) or --env-file. Never bake tokens into the image.

⁠Token scopes
ModeSuggested GitLab token scopes
Read-only (GITLAB_READ_ONLY=1)read_api
Writes enabledapi

⁠Environment variables

All configuration is via environment variables (no CLI flags for secrets).

VariableRequiredDefaultDescription
GITLAB_URLyes—GitLab base URL, e.g. https://gitlab.example.com
GITLAB_TOKENyes—Personal or project access token
GITLAB_READ_ONLYnofalseWhen true / 1, write tools are not registered
GITLAB_DEFAULT_PROJECTno—Default project id or group/project path
GITLAB_TIMEOUT_SECONDSno30HTTP timeout in seconds
GITLAB_PER_PAGEno50Page size for list endpoints (1–100)
GITLAB_MAX_PAGESno20Max pages per paginated call
GITLAB_CA_BUNDLEno—Path to a CA bundle file inside the container for private CAs
GITLAB_VERIFY_SSLnotrueSet false / 0 to disable TLS verification (not recommended)
⁠Private CA certificates

Mount a host CA bundle and point GITLAB_CA_BUNDLE at the mount path:

docker run --rm -i \
  -v /etc/ssl/certs/ca-certificates.crt:/certs/ca.crt:ro \
  -e GITLAB_CA_BUNDLE=/certs/ca.crt \
  -e GITLAB_URL \
  -e GITLAB_TOKEN \
  pirlruc/gitlab-mcp:0.1.0

⁠Cursor MCP config

Add to your Cursor MCP settings (adjust the image tag and env values):

{
  "mcpServers": {
    "gitlab": {
      "command": "docker",
      "args": [
        "run", "--rm", "-i",
        "--read-only",
        "--cap-drop", "ALL",
        "--security-opt", "no-new-privileges",
        "--tmpfs", "/tmp:rw,noexec,nosuid,size=64m",
        "-e", "GITLAB_URL",
        "-e", "GITLAB_TOKEN",
        "-e", "GITLAB_READ_ONLY",
        "-e", "GITLAB_DEFAULT_PROJECT",
        "pirlruc/gitlab-mcp:0.1.0"
      ],
      "env": {
        "GITLAB_URL": "https://gitlab.example.com",
        "GITLAB_TOKEN": "<token>",
        "GITLAB_READ_ONLY": "1",
        "GITLAB_DEFAULT_PROJECT": "group/project"
      }
    }
  }
}

Docker must be available on the host PATH. The client starts the container and talks MCP over the attached stdio streams.

⁠Compose sketch

# For local smoke tests only — MCP clients usually invoke `docker run` directly.
services:
  gitlab-mcp:
    image: pirlruc/gitlab-mcp:0.1.0
    stdin_open: true
    tty: false
    read_only: true
    cap_drop: [ALL]
    security_opt: [no-new-privileges:true]
    tmpfs:
      - /tmp:rw,noexec,nosuid,size=64m
    environment:
      GITLAB_URL: ${GITLAB_URL}
      GITLAB_TOKEN: ${GITLAB_TOKEN}
      GITLAB_READ_ONLY: "1"

Tag summary

Content type

Image

Digest

sha256:9df623d53…

Size

38.4 MB

Last updated

2 months ago

docker pull pirlruc/gitlab-mcp