The MCP server (mcp-for-blender 2.1.1, frozen requirements) runs inside the Blender container. Its add-on is vendored at upstream 41a18432 (MIT) and started by a startup hook. scripts/blender-mcp carries the stdio over ssh + docker exec, so the add-on socket, which runs arbitrary Python with no auth, stays on the container's localhost with no published port. It also runs there because viewport screenshots need a filesystem shared by server and Blender. Telemetry is off and safe mode is on. The hook also defaults Cycles to OptiX on GPU 3, because safe mode forbids agents from touching preferences. Verified end to end from nh3-dev: 36 tools; a GPU render of an agent-built scene; a viewport screenshot; and safe mode refusing 'import os'. Blender left down (on demand).
59 lines
3.0 KiB
YAML
59 lines
3.0 KiB
YAML
# blender: Blender 5.2 LTS on fv-ml1 GPU 3, driven by agents (MCP) with a browser desktop for
|
|
# watching. Prime, 2026-09-27: "go ahead with gpu 3, both".
|
|
#
|
|
# ⚠ ON DEMAND ONLY. GPU 3 is the fleet's deliberately empty card, the reserve for a full-size
|
|
# vLLM seat (flash-next needs 93 of 96 GiB, and vLLM sizes KV against TOTAL VRAM). Blender
|
|
# borrows it: `restart: "no"`, so a reboot never brings it back, and it is stopped whenever a big
|
|
# seat needs the card. Start: `docker compose up -d`. Stop: `docker compose down`.
|
|
#
|
|
# Image: linuxserver/blender (Selkies web desktop, official Blender build with sm_120 CUDA +
|
|
# OptiX kernels). Its NVIDIA mode needs host driver >= 580 (fv-ml1: 580.65.06) and
|
|
# /dev/nvidia-modeset. HTTPS only (Selkies' WebCodecs need a secure context), self-signed cert.
|
|
# Basic auth from .env (CUSTOM_USER / PASSWORD; vault fv-ml1/blender-web-password). The desktop grants
|
|
# a shell inside the container, so never expose it beyond the LAN.
|
|
#
|
|
# Paths: /config (home: prefs, add-ons) → /opt/docker/data/blender (restic via /opt/docker).
|
|
# /work (projects, assets, renders) → /tank/blender (big, NOT backed up; renders are
|
|
# regenerable, and anything precious is copied out).
|
|
#
|
|
# .env (tunables): IMAGE, HTTPS_PORT, CUSTOM_USER, PASSWORD.
|
|
|
|
name: blender
|
|
|
|
services:
|
|
blender:
|
|
image: ${IMAGE:?set IMAGE}
|
|
container_name: blender
|
|
restart: "no"
|
|
runtime: nvidia
|
|
environment:
|
|
PUID: "1002" # infra-ops, so agents can read and write /work over ssh
|
|
PGID: "1003"
|
|
TZ: America/Los_Angeles
|
|
CUSTOM_USER: ${CUSTOM_USER:?set CUSTOM_USER}
|
|
PASSWORD: ${PASSWORD:?set PASSWORD}
|
|
NVIDIA_VISIBLE_DEVICES: "3" # GPU 3 only: never touch the serving cards
|
|
NVIDIA_DRIVER_CAPABILITIES: all # compute (Cycles), graphics (viewport), video (NVENC stream)
|
|
devices:
|
|
- /dev/nvidia-modeset:/dev/nvidia-modeset
|
|
volumes:
|
|
- /opt/docker/data/blender:/config
|
|
- /tank/blender:/work
|
|
# MCP bridge (stacks/blender/conf → /opt/docker/conf/blender): the pinned add-on, plus a
|
|
# startup hook that enables it and keeps its socket serving. Read-only; update via the repo.
|
|
- /opt/docker/conf/blender/scripts/addons/blender_mcp.py:/config/.config/blender/5.2/scripts/addons/blender_mcp.py:ro
|
|
- /opt/docker/conf/blender/scripts/startup/fleet_mcp.py:/config/.config/blender/5.2/scripts/startup/fleet_mcp.py:ro
|
|
ports:
|
|
- "${HTTPS_PORT:-3001}:3001"
|
|
# ⚠ NO port for the MCP add-on socket (it runs arbitrary Python, no auth). It listens on the
|
|
# container's own localhost. The MCP server runs INSIDE this container
|
|
# (/work/.mcp-venv), and agents reach it as `ssh … docker exec -i` stdio
|
|
# (scripts/blender-mcp). Never publish 9876.
|
|
shm_size: "1gb"
|
|
labels:
|
|
- homepage.group=AI - Studios
|
|
- homepage.name=Blender
|
|
- homepage.icon=si-blender
|
|
- homepage.description=Blender 5.2 on fv-ml1 GPU 3 (on demand)
|
|
- homepage.href=https://10.251.50.54:${HTTPS_PORT:-3001}
|