change auth for vmcp

This commit is contained in:
2026-06-17 14:49:54 +01:00
parent ad0e5df277
commit 4de136186f
5 changed files with 43 additions and 2 deletions
@@ -0,0 +1,7 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: toolhive-system
# resources:
# - state-docs-vmcp-secret.sealed.secret.yaml
@@ -23,6 +23,23 @@ spec:
oidcConfigRef: oidcConfigRef:
name: full-vmcp-oidc name: full-vmcp-oidc
audience: toolhive-full-vmcp audience: toolhive-full-vmcp
authServerConfig:
issuer: https://full-vmcp.ngorse.com
upstreamProviders:
- name: keycloak
type: oidc
oidcConfig:
issuerUrl: https://cloak.olb42.com/realms/home-lab
clientId: toolhive-full-vmcp
clientSecretFile: /var/run/secrets/toolhive/client-secret
redirectUri: https://full-vmcp.ngorse.com/oauth/callback
scopes:
- openid
- profile
- email
- offline_access
allowedAudiences:
- toolhive-full-vmcp
config: config:
aggregation: aggregation:
conflictResolution: prefix conflictResolution: prefix
@@ -6,7 +6,7 @@ metadata:
spec: spec:
type: inline type: inline
inline: inline:
issuer: https://cloak.olb42.com/realms/home-lab issuer: https://full-vmcp.ngorse.com
clientId: toolhive-full-vmcp clientId: toolhive-full-vmcp
clientSecretRef: clientSecretRef:
name: toolhive-full-vmcp-secret name: toolhive-full-vmcp-secret
@@ -6,7 +6,7 @@ metadata:
spec: spec:
type: inline type: inline
inline: inline:
issuer: https://cloak.olb42.com/realms/home-lab issuer: https://state-docs.ngorse.com
clientId: state-docs-vmcp clientId: state-docs-vmcp
clientSecretRef: clientSecretRef:
name: state-docs-vmcp-secret name: state-docs-vmcp-secret
@@ -18,6 +18,23 @@ spec:
oidcConfigRef: oidcConfigRef:
name: state-docs-vmcp-oidc name: state-docs-vmcp-oidc
audience: state-docs-vmcp audience: state-docs-vmcp
authServerConfig:
issuer: https://state-docs.ngorse.com
upstreamProviders:
- name: keycloak
type: oidc
oidcConfig:
issuerUrl: https://cloak.olb42.com/realms/home-lab
clientId: state-docs-vmcp
clientSecretFile: /var/run/secrets/toolhive/client-secret
redirectUri: https://state-docs.ngorse.com/oauth/callback
scopes:
- openid
- profile
- email
- offline_access
allowedAudiences:
- state-docs-vmcp
config: config:
aggregation: aggregation:
conflictResolution: prefix conflictResolution: prefix