feat(blender): agent control via mcp-for-blender (in-container, ssh stdio)

The MCP server (mcp-for-blender 2.1.1, frozen requirements) runs inside the Blender
container. Its add-on is vendored at upstream 41a18432 (MIT) and started by a
startup hook. scripts/blender-mcp carries the stdio over ssh + docker exec, so the
add-on socket, which runs arbitrary Python with no auth, stays on the container's
localhost with no published port. It also runs there because viewport screenshots
need a filesystem shared by server and Blender. Telemetry is off and safe mode is
on. The hook also defaults Cycles to OptiX on GPU 3, because safe mode forbids
agents from touching preferences.

Verified end to end from nh3-dev: 36 tools; a GPU render of an agent-built scene;
a viewport screenshot; and safe mode refusing 'import os'. Blender left down
(on demand).
This commit is contained in:
vh
2026-09-27 14:34:07 -07:00
parent 7ae7193c21
commit ac1cd29afa
8 changed files with 6442 additions and 6 deletions
+9 -1
View File
@@ -9,7 +9,7 @@
# Image: linuxserver/blender (Selkies web desktop, official Blender build with sm_120 CUDA +
# OptiX kernels). Its NVIDIA mode needs host driver >= 580 (fv-ml1: 580.65.06) and
# /dev/nvidia-modeset. HTTPS only (Selkies' WebCodecs need a secure context), self-signed cert.
# Basic auth from .env (CUSTOM_USER / PASSWORD; vault fv-ml1/blender-web). The desktop grants
# Basic auth from .env (CUSTOM_USER / PASSWORD; vault fv-ml1/blender-web-password). The desktop grants
# a shell inside the container, so never expose it beyond the LAN.
#
# Paths: /config (home: prefs, add-ons) → /opt/docker/data/blender (restic via /opt/docker).
@@ -39,8 +39,16 @@ services:
volumes:
- /opt/docker/data/blender:/config
- /tank/blender:/work
# MCP bridge (stacks/blender/conf → /opt/docker/conf/blender): the pinned add-on, plus a
# startup hook that enables it and keeps its socket serving. Read-only; update via the repo.
- /opt/docker/conf/blender/scripts/addons/blender_mcp.py:/config/.config/blender/5.2/scripts/addons/blender_mcp.py:ro
- /opt/docker/conf/blender/scripts/startup/fleet_mcp.py:/config/.config/blender/5.2/scripts/startup/fleet_mcp.py:ro
ports:
- "${HTTPS_PORT:-3001}:3001"
# ⚠ NO port for the MCP add-on socket (it runs arbitrary Python, no auth). It listens on the
# container's own localhost. The MCP server runs INSIDE this container
# (/work/.mcp-venv), and agents reach it as `ssh … docker exec -i` stdio
# (scripts/blender-mcp). Never publish 9876.
shm_size: "1gb"
labels:
- homepage.group=AI - Studios