linux/amd64 and linux/arm64, so it runs on a Raspberry Pi or a small server.
Docker
The HTTP server image isghcr.io/milfordai/milford, and the MCP server image is ghcr.io/milfordai/milford-mcp. Mount a directory that holds milford.config.yaml at /config. The image reads MILFORD_CONFIG, which defaults to /config/milford.config.yaml.
./flows/triage.json resolves to /config/flows/triage.json.
Docker Compose
The repository’sdocker-compose.yml builds the images from source. Put milford.config.yaml and a flows/ directory next to docker-compose.yml, then set your keys:
./milford.config.yaml and ./flows read-only under /config and passes these variables through: MILFORD_TOKEN, ANTHROPIC_API_KEY, OPENAI_API_KEY, GROQ_API_KEY, TYPESAFE_API_KEY. Add the variables your config uses to the environment list.
The image healthcheck calls
/health on port 8080. If you change server.port, update the healthcheck.MCP server image
TheDockerfile has a second target for the MCP server. Set mcp.transport: http and mcp.auth.tokens in the config, then run it with the mcp profile:
/health there. The HTTP server image stays the default target.
Image publishing
Thedocker GitHub Actions workflow builds multi-arch images when a v* tag is pushed. It pushes the HTTP server to ghcr.io/milfordai/milford and the MCP server to ghcr.io/milfordai/milford-mcp, each tagged with the version and latest.
Running offline
Milford works without internet when its providers are local: a classifier behind thehttp provider, or a local OpenAI-compatible server. Use fallback to prefer local providers and fall back to a cloud provider.
Without Docker
Install the server from npm and run it:@milfordai/mcp. See installation for global installs and the library packages.
Reliability settings
Set these before you expose the server to other clients:- Keep
server.auth.tokensset. Without tokens the API is open. - Tune
run.timeoutMs,run.maxConcurrentRunsandserver.maxBodyBytesto your workload. The defaults are 60 seconds, 64 runs and 1 MB. - Add
circuitBreakerand afallbackto providers that can go down, andrateLimitto providers with quotas. See providers.