Run the gitaiflow MCP server in Docker for an isolated or shared deployment.
gitaiflow is a private repository, so this path is for repo collaborators, not a general public install. If you don’t have access, use the AI-Native Binary or Claude Desktop Extension instead — or request access.
The container packages the MCP layer and runs the gitaiflow native binary. Requires access to the private gitaiflow repository.
git clone https://gitlab.com/codefleet-labs/gitaiflow.gitcd gitaiflow
export MCP_HOST_WORKSPACE="/Users/<user>/projects"
docker build --no-cache -f Dockerfile.mcp -t gitaiflow-mcp:local .
docker rm -f gitaiflow-mcp 2>/dev/null || truedocker run --rm \--name gitaiflow-mcp \-p 8080:8080 \--env-file .mcp.env \-e MCP_TRANSPORT=streamable-http \-e MCP_WORKSPACE=/workspace \-e MCP_ALLOWED_WORKSPACES=/workspace \-e GITAIFLOW_BINARY=/app/bin/gitaiflow \-v "$HOME/.gitaiflow:/root/.gitaiflow" \-v "$MCP_HOST_WORKSPACE:/workspace" \-v "/path/to/gitaiflow-linux-arm64:/app/bin/gitaiflow:ro" \gitaiflow-mcp:local
curl -i http://localhost:8080/health
Docker packages the MCP integration while the gitaiflow AOT executable remains the execution engine. Pass MCP settings with --env-file .mcp.env or -e flags; explicit -e values win, so .mcp.env can keep native host paths.
AI settings still come from ~/.gitaiflow/config.env — mount $HOME/.gitaiflow at /root/.gitaiflow (writable) so gitaiflow can read them and persist local state.
streamable-http (default) serves /mcp and /health on port 8080; stdio talks over stdin/stdout for local desktop clients and starts no HTTP listener.Authorization: Bearer <token>. Keep it out of logs and screenshots./workspace.MCP_WORKSPACE (native: same absolute path; Docker: /workspace). The request path then selects a Git repository beneath it.| Name | Default | Notes |
|---|---|---|
| MCP_TRANSPORT | streamable-http | streamable-http (default) serves /mcp and /health on port 8080; stdio talks over stdin/stdout for local desktop clients and starts no HTTP listener. |
| MCP_API_TOKEN | Optional | Bearer token for the streamable HTTP endpoint. Clients send it as Authorization: Bearer <token>. Keep it out of logs and screenshots. |
| MCP_WORKSPACE | Set explicitly | Working parent workspace. Native: an absolute host path. In Docker: /workspace. |
| MCP_ALLOWED_WORKSPACES | Set explicitly | Allow-list that authorizes repository roots. Set it alongside MCP_WORKSPACE (native: same absolute path; Docker: /workspace). The request path then selects a Git repository beneath it. |
| GITAIFLOW_BINARY | Auto-resolved | Path to the gitaiflow executable the MCP server runs. In Docker set it to /app/bin/gitaiflow and mount a matching Linux binary there. |
| Host | Container | Notes |
|---|---|---|
| $HOME/.gitaiflow | /root/.gitaiflow | Holds config.env with your AI settings. Must be writable — gitaiflow stores local state such as usage.jsonl there. |
| Parent workspace containing your repositories | /workspace | Not required to be a Git repository itself; each repository beneath it must have its own .git. |
| Matching Linux gitaiflow binary | /app/bin/gitaiflow (read-only) | Mount it explicitly — do not assume it exists just because the container starts. |
If $PWD is your gitaiflow checkout, -v "$PWD:/workspace" mounts only that one repository and sibling repositories disappear. Define the parent workspace explicitly: export MCP_HOST_WORKSPACE="/Users/<user>/projects".
The Docker mount at /workspace, together with MCP_ALLOWED_WORKSPACES, identifies the parent workspace. The tool path argument selects one Git repository inside it, and the selected directory must itself be a Git repository root.
/workspace — one -v flag, not one per repository. For example, -v "/Users/<user>/projects:/workspace" if projects/ holds paperclip/, VoiceStudio/, and issuetracker/, each with its own .git.paperclip resolves to /workspace/paperclip.curl -i http://localhost:8080/health