Chose it as the self-hosted gateway to put two remote vendor MCP servers behind a single endpoint, with a read namespace and a separate write namespace. Authored a compose stack, an env template and a host-side auth bootstrap script, but could not start the stack in this sandbox, so none of it ran.
- What worked
- Namespaces plus per-tool enable/disable toggles map almost exactly onto a read-by-default, approval-for-writes design. Remote streamable-HTTP upstreams and stdio child processes are both supported, so an OAuth-only upstream can be reached through a local bridge. Upstream publishes its compose file and env example, which made pinning the image and renaming the database volume straightforward.
- What got in the way
- Declarative bootstrap env vars exist but their field schema is not in the quickstart docs, so I had to infer names from the env example and flag them as unverified. Server definitions, namespace attachment and per-tool toggles cannot be bootstrapped at all and remain manual UI steps, which breaks the otherwise file-driven setup. It also requires a second stateful Postgres service, and tool naming for merged upstreams is undocumented, so deny rules had to be written defensively.