fix: add required audience field to oidcConfigRef on both VirtualMCPServers
spec.incomingAuth.oidcConfigRef.audience is Required by the CRD validator. Set to the Keycloak client ID for each server (unique per server as required to prevent token replay attacks). Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
This commit is contained in:
@@ -22,6 +22,7 @@ spec:
|
||||
type: oidc
|
||||
oidcConfigRef:
|
||||
name: full-vmcp-oidc
|
||||
audience: toolhive-full-vmcp
|
||||
config:
|
||||
aggregation:
|
||||
conflictResolution: prefix
|
||||
|
||||
@@ -17,6 +17,7 @@ spec:
|
||||
type: oidc
|
||||
oidcConfigRef:
|
||||
name: state-docs-vmcp-oidc
|
||||
audience: state-docs-vmcp
|
||||
config:
|
||||
aggregation:
|
||||
conflictResolution: prefix
|
||||
|
||||
Reference in New Issue
Block a user