diff --git a/manifest/overlays/production/secrets/kustomization.yaml b/manifest/overlays/production/secrets/kustomization.yaml new file mode 100644 index 0000000..9af48f7 --- /dev/null +++ b/manifest/overlays/production/secrets/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +namespace: toolhive-system + +# resources: +# - state-docs-vmcp-secret.sealed.secret.yaml diff --git a/manifest/overlays/production/vmcp-servers/full-vmcp.yaml b/manifest/overlays/production/vmcp-servers/full-vmcp.yaml index da1ee07..e8dd3cd 100644 --- a/manifest/overlays/production/vmcp-servers/full-vmcp.yaml +++ b/manifest/overlays/production/vmcp-servers/full-vmcp.yaml @@ -23,6 +23,23 @@ spec: oidcConfigRef: name: full-vmcp-oidc audience: toolhive-full-vmcp + authServerConfig: + issuer: https://full-vmcp.ngorse.com + upstreamProviders: + - name: keycloak + type: oidc + oidcConfig: + issuerUrl: https://cloak.olb42.com/realms/home-lab + clientId: toolhive-full-vmcp + clientSecretFile: /var/run/secrets/toolhive/client-secret + redirectUri: https://full-vmcp.ngorse.com/oauth/callback + scopes: + - openid + - profile + - email + - offline_access + allowedAudiences: + - toolhive-full-vmcp config: aggregation: conflictResolution: prefix diff --git a/manifest/overlays/production/vmcp-servers/oidcconfig-full-vmcp.yaml b/manifest/overlays/production/vmcp-servers/oidcconfig-full-vmcp.yaml index 5b8b011..24e7c33 100644 --- a/manifest/overlays/production/vmcp-servers/oidcconfig-full-vmcp.yaml +++ b/manifest/overlays/production/vmcp-servers/oidcconfig-full-vmcp.yaml @@ -6,7 +6,7 @@ metadata: spec: type: inline inline: - issuer: https://cloak.olb42.com/realms/home-lab + issuer: https://full-vmcp.ngorse.com clientId: toolhive-full-vmcp clientSecretRef: name: toolhive-full-vmcp-secret diff --git a/manifest/overlays/production/vmcp-servers/oidcconfig-state-docs-vmcp.yaml b/manifest/overlays/production/vmcp-servers/oidcconfig-state-docs-vmcp.yaml index 57cc824..35dc1a1 100644 --- a/manifest/overlays/production/vmcp-servers/oidcconfig-state-docs-vmcp.yaml +++ b/manifest/overlays/production/vmcp-servers/oidcconfig-state-docs-vmcp.yaml @@ -6,7 +6,7 @@ metadata: spec: type: inline inline: - issuer: https://cloak.olb42.com/realms/home-lab + issuer: https://state-docs.ngorse.com clientId: state-docs-vmcp clientSecretRef: name: state-docs-vmcp-secret diff --git a/manifest/overlays/production/vmcp-servers/state-docs-vmcp.yaml b/manifest/overlays/production/vmcp-servers/state-docs-vmcp.yaml index 2dad83b..d96465c 100644 --- a/manifest/overlays/production/vmcp-servers/state-docs-vmcp.yaml +++ b/manifest/overlays/production/vmcp-servers/state-docs-vmcp.yaml @@ -18,6 +18,23 @@ spec: oidcConfigRef: name: state-docs-vmcp-oidc audience: state-docs-vmcp + authServerConfig: + issuer: https://state-docs.ngorse.com + upstreamProviders: + - name: keycloak + type: oidc + oidcConfig: + issuerUrl: https://cloak.olb42.com/realms/home-lab + clientId: state-docs-vmcp + clientSecretFile: /var/run/secrets/toolhive/client-secret + redirectUri: https://state-docs.ngorse.com/oauth/callback + scopes: + - openid + - profile + - email + - offline_access + allowedAudiences: + - state-docs-vmcp config: aggregation: conflictResolution: prefix