fix: replace invalid incomingAuth.oidc with MCPOIDCConfig + oidcConfigRef

The .spec.incomingAuth.oidc inline block is not a valid field in the
v0.29.3 VirtualMCPServer CRD schema, causing ArgoCD ComparisonErrors.

The correct v0.29.3 API separates OIDC provider config into a dedicated
MCPOIDCConfig (v1beta1) resource, referenced from the VirtualMCPServer
via spec.incomingAuth.oidcConfigRef.name.

- Add MCPOIDCConfig resources for state-docs-vmcp and full-vmcp (inline
  type, Keycloak issuer, replicated client secrets from keycloak ns)
- Update state-docs-vmcp and full-vmcp VirtualMCPServer manifests to
  reference the new MCPOIDCConfig resources via oidcConfigRef
- Register new MCPOIDCConfig files in vmcp-servers kustomization

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
This commit is contained in:
2026-06-15 13:31:45 +00:00
co-authored by Claude Sonnet 4.6
parent d09eb39701
commit 3caeeb2997
5 changed files with 32 additions and 12 deletions
@@ -20,12 +20,8 @@ spec:
name: homelab-embedding name: homelab-embedding
incomingAuth: incomingAuth:
type: oidc type: oidc
oidc: oidcConfigRef:
issuerUrl: https://cloak.olb42.com/realms/home-lab name: full-vmcp-oidc
clientId: toolhive-full-vmcp
clientSecretRef:
name: toolhive-full-vmcp-secret
key: client-secret
config: config:
aggregation: aggregation:
conflictResolution: prefix conflictResolution: prefix
@@ -4,6 +4,8 @@ kind: Kustomization
namespace: toolhive-system namespace: toolhive-system
resources: resources:
- oidcconfig-state-docs-vmcp.yaml
- oidcconfig-full-vmcp.yaml
- full-vmcp.yaml - full-vmcp.yaml
- full-vmcp-ingress.yaml - full-vmcp-ingress.yaml
- dev-safe-vmcp.yaml - dev-safe-vmcp.yaml
@@ -0,0 +1,13 @@
apiVersion: toolhive.stacklok.dev/v1beta1
kind: MCPOIDCConfig
metadata:
name: full-vmcp-oidc
namespace: toolhive-system
spec:
type: inline
inline:
issuer: https://cloak.olb42.com/realms/home-lab
clientId: toolhive-full-vmcp
clientSecretRef:
name: toolhive-full-vmcp-secret
key: client-secret
@@ -0,0 +1,13 @@
apiVersion: toolhive.stacklok.dev/v1beta1
kind: MCPOIDCConfig
metadata:
name: state-docs-vmcp-oidc
namespace: toolhive-system
spec:
type: inline
inline:
issuer: https://cloak.olb42.com/realms/home-lab
clientId: state-docs-vmcp
clientSecretRef:
name: state-docs-vmcp-secret
key: client-secret
@@ -15,12 +15,8 @@ spec:
name: homelab-embedding name: homelab-embedding
incomingAuth: incomingAuth:
type: oidc type: oidc
oidc: oidcConfigRef:
issuerUrl: https://cloak.olb42.com/realms/home-lab name: state-docs-vmcp-oidc
clientId: state-docs-vmcp
clientSecretRef:
name: state-docs-vmcp-secret
key: client-secret
config: config:
aggregation: aggregation:
conflictResolution: prefix conflictResolution: prefix