Implement shared public MCP federation gateway
- full-vmcp serves as public entry point at mcp.ngorse.com - Single Keycloak client (public-mcp) for all external tools - authServerConfig proxies auth to Keycloak - state-docs-vmcp becomes internal-only (no auth required) - Shared OIDC config for token validation - All external clients authenticate once at gateway
This commit is contained in:
@@ -13,6 +13,12 @@ spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- kind: Rule
|
||||
match: Host(`mcp.ngorse.com`)
|
||||
services:
|
||||
- name: vmcp-full-vmcp
|
||||
namespace: toolhive-system
|
||||
port: 4483
|
||||
- kind: Rule
|
||||
match: Host(`full-vmcp.olb42.com`)
|
||||
services:
|
||||
|
||||
@@ -21,16 +21,15 @@ spec:
|
||||
incomingAuth:
|
||||
type: oidc
|
||||
oidcConfigRef:
|
||||
name: full-vmcp-oidc
|
||||
audience: http://full-vmcp.toolhive-system.svc.cluster.local:4483
|
||||
name: public-mcp-oidc
|
||||
authServerConfig:
|
||||
issuer: https://full-vmcp.ngorse.com
|
||||
issuer: https://mcp.ngorse.com
|
||||
upstreamProviders:
|
||||
- name: keycloak
|
||||
type: oidc
|
||||
oidcConfig:
|
||||
issuerUrl: https://cloak.olb42.com/realms/home-lab
|
||||
clientId: toolhive-full-vmcp
|
||||
clientId: public-mcp
|
||||
config:
|
||||
aggregation:
|
||||
conflictResolution: prefix
|
||||
|
||||
@@ -4,8 +4,8 @@ kind: Kustomization
|
||||
namespace: toolhive-system
|
||||
|
||||
resources:
|
||||
- oidcconfig-public-mcp.yaml
|
||||
- oidcconfig-state-docs-vmcp.yaml
|
||||
- oidcconfig-full-vmcp.yaml
|
||||
- full-vmcp.yaml
|
||||
- full-vmcp-ingress.yaml
|
||||
- full-vmcp-ngorse-ingress.yaml
|
||||
|
||||
+4
-4
@@ -1,13 +1,13 @@
|
||||
apiVersion: toolhive.stacklok.dev/v1beta1
|
||||
kind: MCPOIDCConfig
|
||||
metadata:
|
||||
name: full-vmcp-oidc
|
||||
name: public-mcp-oidc
|
||||
namespace: toolhive-system
|
||||
spec:
|
||||
type: inline
|
||||
inline:
|
||||
issuer: https://full-vmcp.ngorse.com
|
||||
clientId: toolhive-full-vmcp
|
||||
issuer: https://mcp.ngorse.com
|
||||
clientId: public-mcp
|
||||
clientSecretRef:
|
||||
name: toolhive-full-vmcp-secret
|
||||
name: public-mcp-secret
|
||||
key: client-secret
|
||||
@@ -14,18 +14,7 @@ spec:
|
||||
embeddingServerRef:
|
||||
name: homelab-embedding
|
||||
incomingAuth:
|
||||
type: oidc
|
||||
oidcConfigRef:
|
||||
name: state-docs-vmcp-oidc
|
||||
audience: state-docs-vmcp
|
||||
authServerConfig:
|
||||
issuer: https://state-docs.ngorse.com
|
||||
upstreamProviders:
|
||||
- name: keycloak
|
||||
type: oidc
|
||||
oidcConfig:
|
||||
issuerUrl: https://cloak.olb42.com/realms/home-lab
|
||||
clientId: state-docs-vmcp
|
||||
type: anonymous
|
||||
config:
|
||||
aggregation:
|
||||
conflictResolution: prefix
|
||||
|
||||
Reference in New Issue
Block a user