From 3caeeb2997929cce3a599c41f4861d58c99c11d7 Mon Sep 17 00:00:00 2001 From: mnemonic Date: Mon, 15 Jun 2026 13:31:45 +0000 Subject: [PATCH] fix: replace invalid incomingAuth.oidc with MCPOIDCConfig + oidcConfigRef The .spec.incomingAuth.oidc inline block is not a valid field in the v0.29.3 VirtualMCPServer CRD schema, causing ArgoCD ComparisonErrors. The correct v0.29.3 API separates OIDC provider config into a dedicated MCPOIDCConfig (v1beta1) resource, referenced from the VirtualMCPServer via spec.incomingAuth.oidcConfigRef.name. - Add MCPOIDCConfig resources for state-docs-vmcp and full-vmcp (inline type, Keycloak issuer, replicated client secrets from keycloak ns) - Update state-docs-vmcp and full-vmcp VirtualMCPServer manifests to reference the new MCPOIDCConfig resources via oidcConfigRef - Register new MCPOIDCConfig files in vmcp-servers kustomization Co-Authored-By: Claude Sonnet 4.6 --- .../overlays/production/vmcp-servers/full-vmcp.yaml | 8 ++------ .../production/vmcp-servers/kustomization.yaml | 2 ++ .../vmcp-servers/oidcconfig-full-vmcp.yaml | 13 +++++++++++++ .../vmcp-servers/oidcconfig-state-docs-vmcp.yaml | 13 +++++++++++++ .../production/vmcp-servers/state-docs-vmcp.yaml | 8 ++------ 5 files changed, 32 insertions(+), 12 deletions(-) create mode 100644 manifest/overlays/production/vmcp-servers/oidcconfig-full-vmcp.yaml create mode 100644 manifest/overlays/production/vmcp-servers/oidcconfig-state-docs-vmcp.yaml diff --git a/manifest/overlays/production/vmcp-servers/full-vmcp.yaml b/manifest/overlays/production/vmcp-servers/full-vmcp.yaml index 67b0e21..9cf36fd 100644 --- a/manifest/overlays/production/vmcp-servers/full-vmcp.yaml +++ b/manifest/overlays/production/vmcp-servers/full-vmcp.yaml @@ -20,12 +20,8 @@ spec: name: homelab-embedding incomingAuth: type: oidc - oidc: - issuerUrl: https://cloak.olb42.com/realms/home-lab - clientId: toolhive-full-vmcp - clientSecretRef: - name: toolhive-full-vmcp-secret - key: client-secret + oidcConfigRef: + name: full-vmcp-oidc config: aggregation: conflictResolution: prefix diff --git a/manifest/overlays/production/vmcp-servers/kustomization.yaml b/manifest/overlays/production/vmcp-servers/kustomization.yaml index 8513129..120ee39 100644 --- a/manifest/overlays/production/vmcp-servers/kustomization.yaml +++ b/manifest/overlays/production/vmcp-servers/kustomization.yaml @@ -4,6 +4,8 @@ kind: Kustomization namespace: toolhive-system resources: + - oidcconfig-state-docs-vmcp.yaml + - oidcconfig-full-vmcp.yaml - full-vmcp.yaml - full-vmcp-ingress.yaml - dev-safe-vmcp.yaml diff --git a/manifest/overlays/production/vmcp-servers/oidcconfig-full-vmcp.yaml b/manifest/overlays/production/vmcp-servers/oidcconfig-full-vmcp.yaml new file mode 100644 index 0000000..5b8b011 --- /dev/null +++ b/manifest/overlays/production/vmcp-servers/oidcconfig-full-vmcp.yaml @@ -0,0 +1,13 @@ +apiVersion: toolhive.stacklok.dev/v1beta1 +kind: MCPOIDCConfig +metadata: + name: full-vmcp-oidc + namespace: toolhive-system +spec: + type: inline + inline: + issuer: https://cloak.olb42.com/realms/home-lab + clientId: toolhive-full-vmcp + clientSecretRef: + name: toolhive-full-vmcp-secret + key: client-secret diff --git a/manifest/overlays/production/vmcp-servers/oidcconfig-state-docs-vmcp.yaml b/manifest/overlays/production/vmcp-servers/oidcconfig-state-docs-vmcp.yaml new file mode 100644 index 0000000..57cc824 --- /dev/null +++ b/manifest/overlays/production/vmcp-servers/oidcconfig-state-docs-vmcp.yaml @@ -0,0 +1,13 @@ +apiVersion: toolhive.stacklok.dev/v1beta1 +kind: MCPOIDCConfig +metadata: + name: state-docs-vmcp-oidc + namespace: toolhive-system +spec: + type: inline + inline: + issuer: https://cloak.olb42.com/realms/home-lab + clientId: state-docs-vmcp + clientSecretRef: + name: state-docs-vmcp-secret + key: client-secret diff --git a/manifest/overlays/production/vmcp-servers/state-docs-vmcp.yaml b/manifest/overlays/production/vmcp-servers/state-docs-vmcp.yaml index 2ee87ab..4955736 100644 --- a/manifest/overlays/production/vmcp-servers/state-docs-vmcp.yaml +++ b/manifest/overlays/production/vmcp-servers/state-docs-vmcp.yaml @@ -15,12 +15,8 @@ spec: name: homelab-embedding incomingAuth: type: oidc - oidc: - issuerUrl: https://cloak.olb42.com/realms/home-lab - clientId: state-docs-vmcp - clientSecretRef: - name: state-docs-vmcp-secret - key: client-secret + oidcConfigRef: + name: state-docs-vmcp-oidc config: aggregation: conflictResolution: prefix