diff --git a/manifest/overlays/production/vmcp-servers/full-vmcp-ingress.yaml b/manifest/overlays/production/vmcp-servers/full-vmcp-ingress.yaml index d48a0b0..e5e7a3d 100644 --- a/manifest/overlays/production/vmcp-servers/full-vmcp-ingress.yaml +++ b/manifest/overlays/production/vmcp-servers/full-vmcp-ingress.yaml @@ -13,6 +13,12 @@ spec: entryPoints: - websecure routes: + - kind: Rule + match: Host(`mcp.ngorse.com`) + services: + - name: vmcp-full-vmcp + namespace: toolhive-system + port: 4483 - kind: Rule match: Host(`full-vmcp.olb42.com`) services: diff --git a/manifest/overlays/production/vmcp-servers/full-vmcp.yaml b/manifest/overlays/production/vmcp-servers/full-vmcp.yaml index 6e39534..3267547 100644 --- a/manifest/overlays/production/vmcp-servers/full-vmcp.yaml +++ b/manifest/overlays/production/vmcp-servers/full-vmcp.yaml @@ -21,16 +21,15 @@ spec: incomingAuth: type: oidc oidcConfigRef: - name: full-vmcp-oidc - audience: http://full-vmcp.toolhive-system.svc.cluster.local:4483 + name: public-mcp-oidc authServerConfig: - issuer: https://full-vmcp.ngorse.com + issuer: https://mcp.ngorse.com upstreamProviders: - name: keycloak type: oidc oidcConfig: issuerUrl: https://cloak.olb42.com/realms/home-lab - clientId: toolhive-full-vmcp + clientId: public-mcp config: aggregation: conflictResolution: prefix diff --git a/manifest/overlays/production/vmcp-servers/kustomization.yaml b/manifest/overlays/production/vmcp-servers/kustomization.yaml index f508b81..09c9e7b 100644 --- a/manifest/overlays/production/vmcp-servers/kustomization.yaml +++ b/manifest/overlays/production/vmcp-servers/kustomization.yaml @@ -4,8 +4,8 @@ kind: Kustomization namespace: toolhive-system resources: + - oidcconfig-public-mcp.yaml - oidcconfig-state-docs-vmcp.yaml - - oidcconfig-full-vmcp.yaml - full-vmcp.yaml - full-vmcp-ingress.yaml - full-vmcp-ngorse-ingress.yaml diff --git a/manifest/overlays/production/vmcp-servers/oidcconfig-full-vmcp.yaml b/manifest/overlays/production/vmcp-servers/oidcconfig-public-mcp.yaml similarity index 56% rename from manifest/overlays/production/vmcp-servers/oidcconfig-full-vmcp.yaml rename to manifest/overlays/production/vmcp-servers/oidcconfig-public-mcp.yaml index 24e7c33..0171b77 100644 --- a/manifest/overlays/production/vmcp-servers/oidcconfig-full-vmcp.yaml +++ b/manifest/overlays/production/vmcp-servers/oidcconfig-public-mcp.yaml @@ -1,13 +1,13 @@ apiVersion: toolhive.stacklok.dev/v1beta1 kind: MCPOIDCConfig metadata: - name: full-vmcp-oidc + name: public-mcp-oidc namespace: toolhive-system spec: type: inline inline: - issuer: https://full-vmcp.ngorse.com - clientId: toolhive-full-vmcp + issuer: https://mcp.ngorse.com + clientId: public-mcp clientSecretRef: - name: toolhive-full-vmcp-secret + name: public-mcp-secret key: client-secret diff --git a/manifest/overlays/production/vmcp-servers/state-docs-vmcp.yaml b/manifest/overlays/production/vmcp-servers/state-docs-vmcp.yaml index 17bb84d..5edb2b9 100644 --- a/manifest/overlays/production/vmcp-servers/state-docs-vmcp.yaml +++ b/manifest/overlays/production/vmcp-servers/state-docs-vmcp.yaml @@ -14,18 +14,7 @@ spec: embeddingServerRef: name: homelab-embedding incomingAuth: - type: oidc - oidcConfigRef: - name: state-docs-vmcp-oidc - audience: state-docs-vmcp - authServerConfig: - issuer: https://state-docs.ngorse.com - upstreamProviders: - - name: keycloak - type: oidc - oidcConfig: - issuerUrl: https://cloak.olb42.com/realms/home-lab - clientId: state-docs-vmcp + type: anonymous config: aggregation: conflictResolution: prefix