Sign inSign up

mekayelanik/valkey-mcp-server

By mekayelanik

β€’Updated 12 days ago

Image
Machine learning & AI
Developer tools
Data science
0

3.8K

mekayelanik/valkey-mcp-server repository overview

Valkey Logo

⁠Valkey MCP Server

Docker Pulls Docker Stars GHCR License: GPL-3.0 Platforms GitHub Stars GitHub Forks GitHub Issues Last Commit

⁠Multi-Architecture Docker Image for Valkey Data Management

⁠😎 Buy Me a Coffee β˜•οΈŽ

Your support encourages me to keep creating/supporting my open-source projects. If you found value in this project, you can buy me a coffee to keep me inspired.

Buy Me A Coffee ⁠

⁠Table of Contents


⁠Overview

Valkey MCP Server is a Model Context Protocol server that provides tools for managing and interacting with Valkey databases. Built on Alpine Linux for minimal footprint and maximum security, wrapped with mcp-proxy⁠ (replacing supergateway) for StreamableHTTP/SSE transport. Valkey is an open-source, high-performance key/value datastore that is fully compatible with the Redis protocol.

⁠Key Features
  • Multi-Architecture Support - Native support for x86-64 and ARM64
  • Multiple Transport Protocols - StreamableHTTP and SSE via mcp-proxy (exposed simultaneously)
  • Secure by Design - Alpine-based with minimal attack surface
  • High Performance - ZSTD compression for faster deployments
  • Production Ready - Stable releases with comprehensive testing
  • Easy Configuration - Simple environment variable setup

⁠Supported Architectures

ArchitectureTag PrefixStatus
x86-64amd64-<version>Stable
ARM64arm64v8-<version>Stable

Multi-arch images automatically select the correct architecture for your system.


⁠Available Tags

TagStabilityDescriptionUse Case
stableHighMost stable releaseRecommended for production
latestHighLatest stable releaseStay current with stable features
1.1.1HighSpecific versionVersion pinning for consistency
0.1.0-08042026HighVersion + build dateExact build reproducibility
betaLowBeta releasesTesting only
⁠System Requirements
  • Docker Engine: 23.0+
  • RAM: Minimum 512MB
  • CPU: Single core sufficient

CRITICAL: Do NOT expose this container directly to the internet without proper security measures (reverse proxy, SSL/TLS, authentication, firewall rules).


⁠Quick Start

services:
  valkey-mcp-server:
    image: mekayelanik/valkey-mcp-server:stable
    container_name: valkey-mcp-server
    restart: unless-stopped
    ports:
      - "8040:8040"
    environment:
      - PORT=8040
      - INTERNAL_PORT=38011
      - PUID=1000
      - PGID=1000
      - TZ=Asia/Dhaka
      - PROTOCOL=SHTTP
      # ENABLE_HTTPS=false is plaintext over the wire. Safe ONLY for loopback
      # / trusted internal networks. Set to "true" for any public, multi-host,
      # or untrusted deployment β€” HAProxy auto-generates a self-signed cert
      # if none is mounted under /etc/haproxy/certs/.
      - ENABLE_HTTPS=false
      - HTTP_VERSION_MODE=auto
      # mcp-proxy session model. Stateful by default β€” one stdio child shared
      # across all sessions (multiplexed via JSON-RPC ids). Set to true only
      # if full per-request isolation is required (memory-hostile).
      - MCP_PROXY_STATELESS=false
      # Cap virtual memory of the valkey-mcp stdio child (MiB; 0 disables)
      - VALKEY_MAX_MEM_MB=1024
      # HAProxy concurrency caps (0 disables)
      - HAPROXY_FRONTEND_MAXCONN=64
      - HAPROXY_SERVER_MAXCONN=16
      # Valkey connection settings
      # - VALKEY_URL=valkey://localhost:6379
      # - VALKEY_HOST=localhost
      # - VALKEY_PORT=6379
      # - VALKEY_USERNAME=
      # - VALKEY_PWD=
      # - VALKEY_USE_SSL=false
      # - VALKEY_SSL_CA_PATH=
      # - VALKEY_SSL_KEYFILE=
      # - VALKEY_SSL_CERTFILE=
      # - VALKEY_SSL_CERT_REQS=required
      # - VALKEY_SSL_CA_CERTS=
      # - VALKEY_CLUSTER_MODE=false
      # Optional: require Bearer token auth at HAProxy layer
      # - API_KEY=replace-with-strong-secret
    hostname: valkey-mcp-server
    domainname: local

Deploy:

docker compose up -d
docker compose logs -f valkey-mcp-server
⁠Docker CLI
docker run -d \
  --name=valkey-mcp-server \
  --restart=unless-stopped \
  -p 8040:8040 \
  -e PORT=8040 \
  -e INTERNAL_PORT=38011 \
  -e PUID=1000 \
  -e PGID=1000 \
  -e TZ=Asia/Dhaka \
  -e PROTOCOL=SHTTP \
  -e ENABLE_HTTPS=false \
  -e HTTP_VERSION_MODE=auto \
  mekayelanik/valkey-mcp-server:stable
⁠Access Endpoints
ProtocolEndpointDescription
SHTTPhttp://host-ip:8040/mcpStreamable HTTP (default; exposed simultaneously)
SSEhttp://host-ip:8040/sseServer-Sent Events (exposed simultaneously)
Healthhttp://host-ip:8040/healthzHealth check (answered by HAProxy, sub-millisecond)

When HTTPS is enabled (ENABLE_HTTPS=true), use TLS endpoints:

ProtocolEndpoint
SHTTPhttps://host-ip:8040/mcp
SSEhttps://host-ip:8040/sse

WebSocket transport was dropped in the migration to mcp-proxy. Setting PROTOCOL=WS will now fail at startup with a clear message. Use SHTTP or SSE instead.

Security Warning: The container now defaults to HTTP (ENABLE_HTTPS=false) for easier local setup. Use ENABLE_HTTPS=true for production, public networks, or any untrusted environment.

ARM Devices: Allow 30-60 seconds for initialization before accessing endpoints.


⁠Configuration

⁠Environment Variables
VariableDefaultDescription
PORT8040External HAProxy port
INTERNAL_PORT38011Internal mcp-proxy port (loopback)
MCP_PROXY_STATELESSfalseShare one stdio child across sessions; flip to true for per-request isolation
MCP_BRIDGEmcp-proxystdio↔HTTP bridge: mcp-proxy or fastmcp (FastMCP-based, tracks the mcp 2.x SDK)
MCP_LOG_FILE/tmp/valkey-mcp-server.logServer log file; the upstream default writes to an unwritable directory
VALKEY_MAX_MEM_MB0Virtual memory cap on valkey-mcp child (0 disables)
HAPROXY_FRONTEND_MAXCONN(unset)Cap concurrent connections at HAProxy frontend
HAPROXY_SERVER_MAXCONN(unset)Cap concurrent connections to mcp-proxy backend
PUID1000User ID for file permissions
PGID1000Group ID for file permissions
TZUTCContainer timezone (TZ database⁠)
PROTOCOLSHTTPDefault transport protocol
VALKEY_URL(empty)Full Valkey connection URL (e.g. valkey://user:pass@host:6379)
VALKEY_HOST127.0.0.1Valkey server hostname
VALKEY_PORT6379Valkey server port
VALKEY_USERNAME(empty)Valkey authentication username
VALKEY_PWD(empty)Valkey authentication password
VALKEY_USE_SSLfalseEnable SSL for Valkey connection (true/false)
VALKEY_SSL_CA_PATH(empty)Path to SSL CA file
VALKEY_SSL_KEYFILE(empty)Path to SSL key file
VALKEY_SSL_CERTFILE(empty)Path to SSL certificate file
VALKEY_SSL_CERT_REQSrequiredSSL certificate requirements
VALKEY_SSL_CA_CERTS(empty)Path to SSL CA certificates
VALKEY_CLUSTER_MODEfalseEnable Valkey Cluster mode (true/false)
VALKEY_READONLY(unset)true β†’ --readonly, false β†’ --no-readonly, unset β†’ upstream default (read-write)
API_KEY(empty)Enables Bearer token auth (Authorization: Bearer <API_KEY>)
CORS(empty)Comma-separated CORS origins, supports *
ENABLE_HTTPSfalseEnables TLS termination in HAProxy
TLS_CERT_PATH/etc/haproxy/certs/server.crtTLS cert path
TLS_KEY_PATH/etc/haproxy/certs/server.keyTLS private key path
TLS_PEM_PATH/etc/haproxy/certs/server.pemCombined PEM file used by HAProxy
TLS_CNlocalhostCN for auto-generated certificate
TLS_SANDNS:<TLS_CN>SAN for auto-generated certificate
TLS_DAYS365Auto-generated cert validity period
TLS_MIN_VERSIONTLSv1.3Minimum TLS protocol (TLSv1.2 or TLSv1.3)
HTTP_VERSION_MODEautoauto, all, h1, h2, h3, h1+h2
RATE_LIMIT0Max requests per RATE_LIMIT_PERIOD per IP (0 = disabled)
RATE_LIMIT_PERIOD10sSliding window for rate limiting (e.g., 10s, 1m, 1h)
MAX_CONNECTIONS_PER_IP0Max concurrent connections per IP (0 = disabled)
IP_ALLOWLIST(empty)Comma-separated IPs/CIDRs to allow (all others blocked)
IP_BLOCKLIST(empty)Comma-separated IPs/CIDRs to block
⁠HTTPS and HTTP Version Notes
  • If ENABLE_HTTPS=true and cert files are missing, the container auto-generates a self-signed certificate.
  • If TLS_CERT_PATH and TLS_KEY_PATH exist, they are merged into TLS_PEM_PATH and used directly.
  • HTTP_VERSION_MODE=h3 (or auto) enables HTTP/3 only when HAProxy build includes QUIC; otherwise it safely falls back.
⁠API Key Authentication Notes
  • Set API_KEY to enforce authentication at reverse proxy level.
  • Expected header format: Authorization: Bearer <API_KEY>.
  • Localhost health checks remain accessible for liveness/readiness.
⁠Rate Limiting and IP Access Control
  • Rate limiting: Set RATE_LIMIT=100 to allow 100 requests per RATE_LIMIT_PERIOD (default 10s) per IP. Exceeding the limit returns HTTP 429 with a Retry-After header.
  • Connection limiting: Set MAX_CONNECTIONS_PER_IP=50 to cap concurrent connections per IP. Exceeding returns HTTP 429.
  • IP blocklist: Set IP_BLOCKLIST=192.0.2.0/24,198.51.100.5 to block specific IPs/CIDRs. Blocked IPs receive HTTP 403.
  • IP allowlist: Set IP_ALLOWLIST=10.0.0.0/8,192.168.1.0/24 to allow only listed IPs/CIDRs. All others receive HTTP 403. Localhost is always allowed.
  • All features default to disabled. Combine as needed β€” blocklist is checked before allowlist.
⁠Memory & Concurrency Tuning

mcp-proxy runs the Valkey MCP backend as a single long-lived stdio child and multiplexes all client sessions through it via JSON-RPC ids. This caps the expected memory footprint; the knobs below cap the worst case:

  • MCP_PROXY_STATELESS=false (default) β€” share one backend child across all sessions. Recommended for almost every deployment. Flip to true only when you genuinely need per-request isolation.
  • VALKEY_MAX_MEM_MB=1024 β€” caps the virtual-memory size of the valkey-mcp child via prlimit --as. A runaway backend gets OOM-killed by the kernel before it exhausts the host.
  • HAPROXY_FRONTEND_MAXCONN=64 + HAPROXY_SERVER_MAXCONN=16 β€” bound concurrent connections at the HAProxy layer so a burst cannot saturate the upstream stdio bridge.
  • /healthz is answered directly by HAProxy with a local 200 β€” Docker's container healthcheck no longer depends on upstream MCP readiness.
⁠User & Group IDs

Find your IDs and set them to avoid permission issues:

id username
# uid=1000(user) gid=1000(group)
⁠Timezone Examples
- TZ=Asia/Dhaka        # Bangladesh
- TZ=America/New_York  # US Eastern
- TZ=Europe/London     # UK
- TZ=UTC               # Universal Time

⁠MCP Client Configuration

⁠Transport Support
ClientSHTTPSSERecommended
VS Code (Cline/Roo-Cline)YesYesSHTTP
Claude DesktopYesYesSHTTP
Claude CLIYesYesSHTTP
Codex CLIYesYesSHTTP
Codeium (Windsurf)YesYesSHTTP
CursorYesYesSHTTP

WebSocket transport was dropped in the migration to mcp-proxy.


⁠VS Code (Cline/Roo-Cline)

Configure in .vscode/settings.json:

{
  "mcp.servers": {
    "valkey-mcp": {
      "url": "http://host-ip:8040/mcp",
      "transport": "http"
    }
  }
}

⁠Claude Desktop App/Claude Code

With API_KEY:

claude mcp add-json valkey-mcp '{"type":"http","url":"http://localhost:8040/mcp","headers":{"Authorization":"Bearer <YOUR_API_KEY>"}}'

Without API_KEY:

claude mcp add-json valkey-mcp '{"type":"http","url":"http://localhost:8040/mcp"}'

⁠Codex CLI

Configure in ~/.codex/config.json:

{
  "mcpServers": {
    "valkey-mcp": {
      "transport": "http",
      "url": "http://host-ip:8040/mcp"
    }
  }
}

⁠Codeium (Windsurf)

Configure in .codeium/mcp_settings.json:

{
  "mcpServers": {
    "valkey-mcp": {
      "transport": "http",
      "url": "http://host-ip:8040/mcp"
    }
  }
}

⁠Cursor

Configure in ~/.cursor/mcp.json:

{
  "mcpServers": {
    "valkey-mcp": {
      "transport": "http",
      "url": "http://host-ip:8040/mcp"
    }
  }
}

⁠Testing Configuration

Verify with MCP Inspector⁠:

npm install -g @modelcontextprotocol/inspector
mcp-inspector http://host-ip:8040/mcp

⁠Network Configuration

⁠Comparison
Network ModeComplexityPerformanceUse Case
BridgeEasyGoodDefault, isolated
HostModerateExcellentDirect host access
MACVLANAdvancedExcellentDedicated IP

⁠Bridge Network (Default)
services:
  valkey-mcp-server:
    image: mekayelanik/valkey-mcp-server:stable
    ports:
      - "8040:8040"

Benefits: Container isolation, easy setup, works everywhere Access: http://localhost:8040/mcp


⁠Host Network (Linux Only)
services:
  valkey-mcp-server:
    image: mekayelanik/valkey-mcp-server:stable
    network_mode: host

Benefits: Maximum performance, no NAT overhead, no port mapping needed Considerations: Linux only, shares host network namespace Access: http://localhost:8040/mcp


⁠MACVLAN Network (Advanced)
services:
  valkey-mcp-server:
    image: mekayelanik/valkey-mcp-server:stable
    mac_address: "AB:BC:CD:DE:EF:01"
    networks:
      macvlan-net:
        ipv4_address: 192.168.1.100

networks:
  macvlan-net:
    driver: macvlan
    driver_opts:
      parent: eth0
    ipam:
      config:
        - subnet: 192.168.1.0/24
          gateway: 192.168.1.1

Benefits: Dedicated IP, direct LAN access Considerations: Linux only, requires additional setup Access: http://192.168.1.100:8040/mcp


⁠Updating

⁠Docker Compose
docker compose pull
docker compose up -d
docker image prune -f
⁠Docker CLI
docker pull mekayelanik/valkey-mcp-server:stable
docker stop valkey-mcp-server && docker rm valkey-mcp-server
# Run your original docker run command
docker image prune -f
⁠One-Time Update with Watchtower
docker run --rm \
  -v /var/run/docker.sock:/var/run/docker.sock \
  containrrr/watchtower \
  --run-once \
  valkey-mcp-server

⁠Troubleshooting

⁠Pre-Flight Checklist
  • Docker Engine 23.0+
  • Port 8040 available
  • Sufficient startup time (ARM devices)
  • Latest stable image
  • Correct configuration
⁠Common Issues
⁠Container Won't Start
# Check Docker version
docker --version

# Verify port availability
sudo netstat -tulpn | grep 8040

# Check logs
docker logs valkey-mcp-server
⁠Permission Errors
# Get your IDs
id $USER

# Update configuration with correct PUID/PGID
# Fix volume permissions if needed
sudo chown -R 1000:1000 /path/to/volume
⁠Client Cannot Connect
# Test connectivity
curl http://localhost:8040/mcp
curl http://host-ip:8040/mcp
curl -k https://localhost:8040/mcp
curl -k https://host-ip:8040/mcp

# Check firewall
sudo ufw status

# Verify container
docker inspect valkey-mcp-server | grep IPAddress
⁠Slow ARM Performance
  • Wait 30-60 seconds after start
  • Monitor: docker logs -f valkey-mcp-server
  • Check resources: docker stats valkey-mcp-server
  • Use faster storage (SSD vs SD card)
⁠Debug Information

When reporting issues, include:

# System info
docker --version && uname -a

# Container logs
docker logs valkey-mcp-server --tail 200 > logs.txt

# Container config
docker inspect valkey-mcp-server > inspect.json

⁠Additional Resources

⁠Documentation
⁠Docker Resources
⁠Monitoring

⁠😎 Buy Me a Coffee β˜•οΈŽ

Your support encourages me to keep creating/supporting my open-source projects. If you found value in this project, you can buy me a coffee to keep me inspired.

Buy Me A Coffee ⁠

⁠Support & License

⁠Getting Help

Docker Image Issues:

Valkey MCP Issues:

⁠Contributing

We welcome contributions:

  1. Report bugs via GitHub Issues
  2. Suggest features
  3. Improve documentation
  4. Test beta releases
⁠License

GPL License. See LICENSE⁠ for details.

Valkey MCP server has its own license - see upstream repository⁠.


Tag summary

Content type

Image

Digest

sha256:36b4dab6c…

Size

134 MB

Last updated

13 days ago

docker pull mekayelanik/valkey-mcp-server