Skip to content

ATMOS_PROFILE environment variable set in mcp.yaml env block is not used during MCP server auth setup #2283

Description

Describe the Bug

When configuring an MCP server in .atmos.d/mcp.yaml with ATMOS_PROFILE set under the env key, the value is not picked up during the auth setup phase. The server fails to start with identity not found: core-root/terraform, which indicates the identity lookup is happening without the managers profile context. The same identity resolves correctly when ATMOS_PROFILE is exported directly in the shell.

The env block in mcp.yaml should inject environment variables into the server process, but it appears the auth setup runs before these variables are applied, causing identity resolution to fail.

Expected Behavior

Setting ATMOS_PROFILE in the env block of a server definition in mcp.yaml should make it available during the full server lifecycle, including the auth/identity resolution phase. The server should start successfully the same way it would if ATMOS_PROFILE were exported in the shell before running the command.

Steps to Reproduce

  1. Configure .atmos.d/mcp.yaml with a server that sets ATMOS_PROFILE under env:
    yaml
mcp:
  enabled: true
  servers:
    atmos:
      description: Atmos MCP server
      command: atmos
      args: ["mcp", "start"]
      env:
        ATMOS_PROFILE: managers
      identity: core-root/terraform
  1. Run the MCP test command:
atmos mcp test atmos
  1. Observe the error:
✗ Server failed to start
   Error: MCP server failed to start: atmos: auth setup failed for "atmos": identity not found:  core-root/terraform
  1. As a workaround, export the variable in the shell first:
export ATMOS_PROFILE=managers
atmos mcp test atmos

Screenshots

No response

Environment

• Atmos version: 1.214.0
• OS: macOS (darwin/arm64)

Additional Context

The env variables defined in mcp.yaml seem to be applied after the identity/auth resolution step rather than before it. The auth setup needs the profile context to locate the identity core-root/terraform, but since ATMOS_PROFILE from the env block isn't set yet at that point, the identity lookup fails against the default (empty) profile.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bug🐛 An issue with the system

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions