diff --git a/manifest/overlays/production/dev-safe-vmcp.yaml b/manifest/overlays/production/dev-safe-vmcp.yaml index 02c0af2..e9253e0 100644 --- a/manifest/overlays/production/dev-safe-vmcp.yaml +++ b/manifest/overlays/production/dev-safe-vmcp.yaml @@ -3,6 +3,11 @@ kind: VirtualMCPServer metadata: name: dev-safe-vmcp namespace: toolhive-system + annotations: + toolhive.stacklok.dev/registry-export: "true" + toolhive.stacklok.dev/registry-title: Dev Safe Virtual MCP + toolhive.stacklok.dev/registry-description: Development-focused virtual MCP combining safe Gitea and AutoMem tools. + toolhive.stacklok.dev/registry-url: http://vmcp-dev-safe-vmcp.toolhive-system.svc.cluster.local:4483 spec: groupRef: name: homelab-core @@ -25,4 +30,4 @@ spec: - workload: kubernetes-mcp excludeAll: true optimizer: - maxToolsToReturn: 5 \ No newline at end of file + maxToolsToReturn: 5 diff --git a/manifest/overlays/production/full-vmcp.yaml b/manifest/overlays/production/full-vmcp.yaml index 7d6e83e..57aaf28 100644 --- a/manifest/overlays/production/full-vmcp.yaml +++ b/manifest/overlays/production/full-vmcp.yaml @@ -3,6 +3,11 @@ kind: VirtualMCPServer metadata: name: full-vmcp namespace: toolhive-system + annotations: + toolhive.stacklok.dev/registry-export: "true" + toolhive.stacklok.dev/registry-title: Full Homelab Virtual MCP + toolhive.stacklok.dev/registry-description: Full virtual MCP exposing the homelab MCP tool group through ToolHive aggregation. + toolhive.stacklok.dev/registry-url: http://vmcp-full-vmcp.toolhive-system.svc.cluster.local:4483 spec: groupRef: name: homelab-core @@ -14,4 +19,4 @@ spec: aggregation: conflictResolution: prefix optimizer: - maxToolsToReturn: 8 \ No newline at end of file + maxToolsToReturn: 8 diff --git a/manifest/overlays/production/k8s-registry-rbac.yaml b/manifest/overlays/production/k8s-registry-rbac.yaml new file mode 100644 index 0000000..8435e23 --- /dev/null +++ b/manifest/overlays/production/k8s-registry-rbac.yaml @@ -0,0 +1,73 @@ +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: k8s-registry-api-discovery +rules: + - apiGroups: + - toolhive.stacklok.dev + resources: + - mcpservers + - mcpremoteproxies + - virtualmcpservers + verbs: + - get + - list + - watch + - apiGroups: + - "" + resources: + - services + verbs: + - get + - list + - watch + - apiGroups: + - gateway.networking.k8s.io + resources: + - httproutes + - gateways + verbs: + - get + - list + - watch +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: k8s-registry-api-discovery +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: k8s-registry-api-discovery +subjects: + - kind: ServiceAccount + name: k8s-registry-registry-api + namespace: toolhive-system +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: k8s-registry-api-events + namespace: toolhive-system +rules: + - apiGroups: + - "" + resources: + - events + verbs: + - create + - patch +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: k8s-registry-api-events + namespace: toolhive-system +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: k8s-registry-api-events +subjects: + - kind: ServiceAccount + name: k8s-registry-registry-api + namespace: toolhive-system diff --git a/manifest/overlays/production/kustomization.yaml b/manifest/overlays/production/kustomization.yaml index e876935..c5c66ba 100644 --- a/manifest/overlays/production/kustomization.yaml +++ b/manifest/overlays/production/kustomization.yaml @@ -24,5 +24,6 @@ resources: - ops-safe-vmcp.yaml - ops-safe-vmcp-ingress.yaml - k8s-registry.yaml + - k8s-registry-rbac.yaml - toolhive-registry-backup.yaml - toolhive-registry-postgres.yaml diff --git a/manifest/overlays/production/mcpserver-argocd.yaml b/manifest/overlays/production/mcpserver-argocd.yaml index 91072a8..c565e73 100644 --- a/manifest/overlays/production/mcpserver-argocd.yaml +++ b/manifest/overlays/production/mcpserver-argocd.yaml @@ -3,6 +3,11 @@ kind: MCPServer metadata: name: argocd-mcp namespace: toolhive-system + annotations: + toolhive.stacklok.dev/registry-export: "true" + toolhive.stacklok.dev/registry-title: Argo CD MCP + toolhive.stacklok.dev/registry-description: Read-only Argo CD MCP server for inspecting homelab GitOps applications and resources. + toolhive.stacklok.dev/registry-url: http://mcp-argocd-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp spec: # argoproj-labs MCP server for Argo CD. v0.7.0 starts streamable HTTP on # port 3000 by default; setting args: ["stdio"] makes the image try to run diff --git a/manifest/overlays/production/mcpserver-gitea.yaml b/manifest/overlays/production/mcpserver-gitea.yaml index f20613f..315a1fa 100644 --- a/manifest/overlays/production/mcpserver-gitea.yaml +++ b/manifest/overlays/production/mcpserver-gitea.yaml @@ -3,6 +3,11 @@ kind: MCPServer metadata: name: gitea-mcp namespace: toolhive-system + annotations: + toolhive.stacklok.dev/registry-export: "true" + toolhive.stacklok.dev/registry-title: Gitea MCP + toolhive.stacklok.dev/registry-description: Gitea MCP server for repository, issue, and pull request workflows in the homelab Gitea instance. + toolhive.stacklok.dev/registry-url: http://mcp-gitea-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp spec: # Upstream Gitea MCP server. Speaks stdio; ToolHive's proxy runner wraps it and # exposes streamable-http at http://mcp-gitea-mcp-proxy.mcp-services:8080/mcp. diff --git a/manifest/overlays/production/mcpserver-kubernetes.yaml b/manifest/overlays/production/mcpserver-kubernetes.yaml index a1d8635..6546b79 100644 --- a/manifest/overlays/production/mcpserver-kubernetes.yaml +++ b/manifest/overlays/production/mcpserver-kubernetes.yaml @@ -3,6 +3,11 @@ kind: MCPServer metadata: name: kubernetes-mcp namespace: toolhive-system + annotations: + toolhive.stacklok.dev/registry-export: "true" + toolhive.stacklok.dev/registry-title: Kubernetes MCP + toolhive.stacklok.dev/registry-description: Read-only Kubernetes MCP server for safe cluster inspection and troubleshooting. + toolhive.stacklok.dev/registry-url: http://mcp-kubernetes-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp spec: # containers/kubernetes-mcp-server. Authenticates to the API in-cluster via the # kubernetes-mcp ServiceAccount (read-only ClusterRole, see rbac file). Speaks diff --git a/manifest/overlays/production/ops-safe-vmcp.yaml b/manifest/overlays/production/ops-safe-vmcp.yaml index 860fb52..75787da 100644 --- a/manifest/overlays/production/ops-safe-vmcp.yaml +++ b/manifest/overlays/production/ops-safe-vmcp.yaml @@ -3,6 +3,11 @@ kind: VirtualMCPServer metadata: name: ops-safe-vmcp namespace: toolhive-system + annotations: + toolhive.stacklok.dev/registry-export: "true" + toolhive.stacklok.dev/registry-title: Ops Safe Virtual MCP + toolhive.stacklok.dev/registry-description: Operations-focused virtual MCP combining safe Argo CD and Kubernetes tools. + toolhive.stacklok.dev/registry-url: http://vmcp-ops-safe-vmcp.toolhive-system.svc.cluster.local:4483 spec: groupRef: name: homelab-core @@ -25,4 +30,4 @@ spec: toolConfigRef: name: ops-tools optimizer: - maxToolsToReturn: 6 \ No newline at end of file + maxToolsToReturn: 6 diff --git a/manifest/overlays/production/toolhive-registry-postgres.yaml b/manifest/overlays/production/toolhive-registry-postgres.yaml index 2070734..15c75b4 100644 --- a/manifest/overlays/production/toolhive-registry-postgres.yaml +++ b/manifest/overlays/production/toolhive-registry-postgres.yaml @@ -22,6 +22,8 @@ spec: initdb: database: toolhive-reg-pg owner: toolhive-registry + postInitSQL: + - CREATE ROLE toolhive_registry_server; postgresql: parameters: max_connections: "200"