From a777bd26bb4c7665e873f7b1043831b466f510dd Mon Sep 17 00:00:00 2001 From: nick-gorse Date: Sat, 30 May 2026 19:28:21 +0100 Subject: [PATCH] add rbac --- .../overlays/production/kustomization.yaml | 1 + .../overlays/production/mcp-kube-rbac.yaml | 56 +++++++++++++++++++ 2 files changed, 57 insertions(+) create mode 100644 manifest/overlays/production/mcp-kube-rbac.yaml diff --git a/manifest/overlays/production/kustomization.yaml b/manifest/overlays/production/kustomization.yaml index 79d6494..fe09d58 100644 --- a/manifest/overlays/production/kustomization.yaml +++ b/manifest/overlays/production/kustomization.yaml @@ -9,3 +9,4 @@ resources: - mcpserver-argocd.yaml - mcpserver-kubernetes.yaml - mcp-group-homelab-core.yaml + - mcp-kube-rbac.yaml diff --git a/manifest/overlays/production/mcp-kube-rbac.yaml b/manifest/overlays/production/mcp-kube-rbac.yaml new file mode 100644 index 0000000..5e4fae0 --- /dev/null +++ b/manifest/overlays/production/mcp-kube-rbac.yaml @@ -0,0 +1,56 @@ +apiVersion: v1 +kind: ServiceAccount +metadata: + name: kubernetes-mcp + namespace: toolhive-system +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: mcp-kubernetes-readonly + namespace: toolhive-system +rules: + - apiGroups: [""] + resources: + - pods + - pods/log + - pods/status + - services + - endpoints + - events + - namespaces + - nodes + - configmaps + - persistentvolumeclaims + - replicationcontrollers + verbs: ["get", "list", "watch"] + - apiGroups: ["apps"] + resources: ["deployments", "replicasets", "statefulsets", "daemonsets"] + verbs: ["get", "list", "watch"] + - apiGroups: ["batch"] + resources: ["jobs", "cronjobs"] + verbs: ["get", "list", "watch"] + - apiGroups: ["networking.k8s.io"] + resources: ["ingresses", "networkpolicies"] + verbs: ["get", "list", "watch"] + - apiGroups: ["argoproj.io"] + resources: ["applications", "applicationsets", "appprojects"] + verbs: ["get", "list", "watch"] + - apiGroups: ["metrics.k8s.io"] + resources: ["pods", "nodes"] + verbs: ["get", "list"] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: mcp-kubernetes-readonly + namespace: toolhive-system +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: mcp-kubernetes-readonly +subjects: + - kind: ServiceAccount + name: kubernetes-mcp + # namespace is set by the overlay's kustomize namespace transformer. + namespace: toolhive-system