add OIDC auth to state-docs-vmcp VirtualMCPServer

Switch incomingAuth from anonymous to oidc, wiring Keycloak (home-lab realm
at cloak.olb42.com) as the provider with clientId state-docs-vmcp. Secret
ref (state-docs-vmcp-secret, key: client-secret) is added to kustomization
as a TODO comment pending the sealed secret creation.

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
This commit is contained in:
2026-06-14 16:55:43 +00:00
co-authored by Claude Sonnet 4.6
parent 8b9e54a924
commit b497211278
2 changed files with 8 additions and 1 deletions
@@ -11,6 +11,7 @@ resources:
- ingressroute.yaml
- secrets/gitea-mcp-secret.sealed.secret.yaml
- secrets/argocd-mcp-secret.sealed.secret.yaml
# TODO: add after sealing — secrets/state-docs-vmcp-secret.sealed.secret.yaml
- mcp-tool-config-state-docs.yaml
- mcp-tool-config-ops.yaml
- mcp-tool-config-dev.yaml