sort into folders
This commit is contained in:
@@ -0,0 +1,10 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
namespace: toolhive-system
|
||||
|
||||
resources:
|
||||
- mcpserver-gitea.yaml
|
||||
- mcpserver-radar.yaml
|
||||
- mcpserver-argocd.yaml
|
||||
- mcpserver-kubernetes.yaml
|
||||
@@ -0,0 +1,52 @@
|
||||
apiVersion: toolhive.stacklok.dev/v1beta1
|
||||
kind: MCPServer
|
||||
metadata:
|
||||
name: argocd-mcp
|
||||
namespace: toolhive-system
|
||||
annotations:
|
||||
toolhive.stacklok.dev/registry-export: "true"
|
||||
toolhive.stacklok.dev/registry-title: Argo CD MCP
|
||||
toolhive.stacklok.dev/registry-description: Read-only Argo CD MCP server for inspecting homelab GitOps applications and resources.
|
||||
toolhive.stacklok.dev/registry-url: http://mcp-argocd-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
|
||||
spec:
|
||||
# argoproj-labs MCP server for Argo CD. v0.7.0 starts streamable HTTP on
|
||||
# port 3000 by default; setting args: ["stdio"] makes the image try to run
|
||||
# /app/stdio and crash.
|
||||
image: ghcr.io/argoproj-labs/mcp-for-argocd:v0.7.0
|
||||
transport: streamable-http
|
||||
mcpPort: 3000
|
||||
groupRef:
|
||||
name: homelab-core
|
||||
env:
|
||||
- name: ARGOCD_BASE_URL
|
||||
value: http://argocd-server.argocd
|
||||
# argocd-server serves a self-signed cert in-cluster.
|
||||
- name: NODE_TLS_REJECT_UNAUTHORIZED
|
||||
value: "0"
|
||||
# Start read-only; drop this to enable sync/write tools later.
|
||||
- name: MCP_READ_ONLY
|
||||
value: "true"
|
||||
# ToolHive 0.28.3 does not translate spec.secrets into the workload, so inject
|
||||
# the token natively on the `mcp` container via podTemplateSpec.
|
||||
podTemplateSpec:
|
||||
spec:
|
||||
groupRef:
|
||||
name: homelab-core
|
||||
containers:
|
||||
- name: mcp
|
||||
env:
|
||||
- name: ARGOCD_API_TOKEN
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: argocd-mcp-secret
|
||||
key: token
|
||||
permissionProfile:
|
||||
type: builtin
|
||||
name: network
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 128Mi
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 512Mi
|
||||
@@ -0,0 +1,48 @@
|
||||
apiVersion: toolhive.stacklok.dev/v1beta1
|
||||
kind: MCPServer
|
||||
metadata:
|
||||
name: gitea-mcp
|
||||
namespace: toolhive-system
|
||||
annotations:
|
||||
toolhive.stacklok.dev/registry-export: "true"
|
||||
toolhive.stacklok.dev/registry-title: Gitea MCP
|
||||
toolhive.stacklok.dev/registry-description: Gitea MCP server for repository, issue, and pull request workflows in the homelab Gitea instance.
|
||||
toolhive.stacklok.dev/registry-url: http://mcp-gitea-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
|
||||
spec:
|
||||
# Upstream Gitea MCP server. Speaks stdio; ToolHive's proxy runner wraps it and
|
||||
# exposes streamable-http at http://mcp-gitea-mcp-proxy.mcp-services:8080/mcp.
|
||||
image: docker.gitea.com/gitea-mcp-server:nightly
|
||||
transport: stdio
|
||||
proxyMode: streamable-http
|
||||
proxyPort: 8080
|
||||
groupRef:
|
||||
name: homelab-core
|
||||
# No args: the image's default command already runs the binary in stdio mode.
|
||||
# (Passing "-t stdio" replaced the command and execed "-t" directly.)
|
||||
env:
|
||||
- name: GITEA_HOST
|
||||
value: http://gitea-ha-http.apps:3000
|
||||
# NOTE: ToolHive 0.28.3 does not translate spec.secrets into the workload, so
|
||||
# inject the token natively on the `mcp` container via podTemplateSpec.
|
||||
podTemplateSpec:
|
||||
spec:
|
||||
groupRef:
|
||||
name: homelab-core
|
||||
containers:
|
||||
- name: mcp
|
||||
env:
|
||||
- name: GITEA_ACCESS_TOKEN
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: gitea-mcp-secret
|
||||
key: token
|
||||
permissionProfile:
|
||||
type: builtin
|
||||
name: network
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 64Mi
|
||||
limits:
|
||||
cpu: 300m
|
||||
memory: 256Mi
|
||||
@@ -0,0 +1,41 @@
|
||||
apiVersion: toolhive.stacklok.dev/v1beta1
|
||||
kind: MCPServer
|
||||
metadata:
|
||||
name: kubernetes-mcp
|
||||
namespace: toolhive-system
|
||||
annotations:
|
||||
toolhive.stacklok.dev/registry-export: "true"
|
||||
toolhive.stacklok.dev/registry-title: Kubernetes MCP
|
||||
toolhive.stacklok.dev/registry-description: Read-only Kubernetes MCP server for safe cluster inspection and troubleshooting.
|
||||
toolhive.stacklok.dev/registry-url: http://mcp-kubernetes-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
|
||||
spec:
|
||||
# containers/kubernetes-mcp-server. Authenticates to the API in-cluster via the
|
||||
# kubernetes-mcp ServiceAccount (read-only ClusterRole, see rbac file). Speaks
|
||||
# stdio; ToolHive proxies to streamable-http at
|
||||
# http://mcp-kubernetes-mcp-proxy.mcp-services:8080/mcp.
|
||||
image: ghcr.io/containers/kubernetes-mcp-server:latest
|
||||
transport: stdio
|
||||
# The current image's default CMD starts HTTP mode with `--port 8080`.
|
||||
# Override args so ToolHive's stdio proxy talks to a stdio MCP server.
|
||||
args:
|
||||
- --log-file
|
||||
- stderr
|
||||
- --read-only
|
||||
- --disable-destructive
|
||||
proxyMode: streamable-http
|
||||
proxyPort: 8080
|
||||
groupRef:
|
||||
name: homelab-core
|
||||
# Pin the MCP server pod to our read-only ServiceAccount. The ClusterRole is
|
||||
# the real guardrail: even if a write tool is invoked, the API rejects it.
|
||||
serviceAccount: kubernetes-mcp
|
||||
permissionProfile:
|
||||
type: builtin
|
||||
name: network
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 128Mi
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 512Mi
|
||||
@@ -0,0 +1,10 @@
|
||||
apiVersion: toolhive.stacklok.dev/v1alpha1
|
||||
kind: MCPServerEntry
|
||||
metadata:
|
||||
name: radar
|
||||
namespace: toolhive-system
|
||||
spec:
|
||||
remoteUrl: http://radar.radar:9280/mcp
|
||||
transport: streamable-http
|
||||
groupRef:
|
||||
name: homelab-core
|
||||
Reference in New Issue
Block a user