Implement shared public MCP federation gateway

- full-vmcp serves as public entry point at mcp.ngorse.com
- Single Keycloak client (public-mcp) for all external tools
- authServerConfig proxies auth to Keycloak
- state-docs-vmcp becomes internal-only (no auth required)
- Shared OIDC config for token validation
- All external clients authenticate once at gateway
This commit is contained in:
2026-06-17 16:26:48 +01:00
parent d1d8c6aa3f
commit 676bad4dd2
5 changed files with 15 additions and 21 deletions
@@ -13,6 +13,12 @@ spec:
entryPoints:
- websecure
routes:
- kind: Rule
match: Host(`mcp.ngorse.com`)
services:
- name: vmcp-full-vmcp
namespace: toolhive-system
port: 4483
- kind: Rule
match: Host(`full-vmcp.olb42.com`)
services:
@@ -21,16 +21,15 @@ spec:
incomingAuth:
type: oidc
oidcConfigRef:
name: full-vmcp-oidc
audience: http://full-vmcp.toolhive-system.svc.cluster.local:4483
name: public-mcp-oidc
authServerConfig:
issuer: https://full-vmcp.ngorse.com
issuer: https://mcp.ngorse.com
upstreamProviders:
- name: keycloak
type: oidc
oidcConfig:
issuerUrl: https://cloak.olb42.com/realms/home-lab
clientId: toolhive-full-vmcp
clientId: public-mcp
config:
aggregation:
conflictResolution: prefix
@@ -4,8 +4,8 @@ kind: Kustomization
namespace: toolhive-system
resources:
- oidcconfig-public-mcp.yaml
- oidcconfig-state-docs-vmcp.yaml
- oidcconfig-full-vmcp.yaml
- full-vmcp.yaml
- full-vmcp-ingress.yaml
- full-vmcp-ngorse-ingress.yaml
@@ -1,13 +1,13 @@
apiVersion: toolhive.stacklok.dev/v1beta1
kind: MCPOIDCConfig
metadata:
name: full-vmcp-oidc
name: public-mcp-oidc
namespace: toolhive-system
spec:
type: inline
inline:
issuer: https://full-vmcp.ngorse.com
clientId: toolhive-full-vmcp
issuer: https://mcp.ngorse.com
clientId: public-mcp
clientSecretRef:
name: toolhive-full-vmcp-secret
name: public-mcp-secret
key: client-secret
@@ -14,18 +14,7 @@ spec:
embeddingServerRef:
name: homelab-embedding
incomingAuth:
type: oidc
oidcConfigRef:
name: state-docs-vmcp-oidc
audience: state-docs-vmcp
authServerConfig:
issuer: https://state-docs.ngorse.com
upstreamProviders:
- name: keycloak
type: oidc
oidcConfig:
issuerUrl: https://cloak.olb42.com/realms/home-lab
clientId: state-docs-vmcp
type: anonymous
config:
aggregation:
conflictResolution: prefix