Implement shared public MCP federation gateway

- full-vmcp serves as public entry point at mcp.ngorse.com
- Single Keycloak client (public-mcp) for all external tools
- authServerConfig proxies auth to Keycloak
- state-docs-vmcp becomes internal-only (no auth required)
- Shared OIDC config for token validation
- All external clients authenticate once at gateway
This commit is contained in:
2026-06-17 16:26:48 +01:00
parent d1d8c6aa3f
commit 676bad4dd2
5 changed files with 15 additions and 21 deletions
@@ -0,0 +1,13 @@
apiVersion: toolhive.stacklok.dev/v1beta1
kind: MCPOIDCConfig
metadata:
name: public-mcp-oidc
namespace: toolhive-system
spec:
type: inline
inline:
issuer: https://mcp.ngorse.com
clientId: public-mcp
clientSecretRef:
name: public-mcp-secret
key: client-secret