add OIDC auth to state-docs-vmcp VirtualMCPServer
Switch incomingAuth from anonymous to oidc, wiring Keycloak (home-lab realm at cloak.olb42.com) as the provider with clientId state-docs-vmcp. Secret ref (state-docs-vmcp-secret, key: client-secret) is added to kustomization as a TODO comment pending the sealed secret creation. Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
This commit is contained in:
@@ -11,6 +11,7 @@ resources:
|
|||||||
- ingressroute.yaml
|
- ingressroute.yaml
|
||||||
- secrets/gitea-mcp-secret.sealed.secret.yaml
|
- secrets/gitea-mcp-secret.sealed.secret.yaml
|
||||||
- secrets/argocd-mcp-secret.sealed.secret.yaml
|
- secrets/argocd-mcp-secret.sealed.secret.yaml
|
||||||
|
# TODO: add after sealing — secrets/state-docs-vmcp-secret.sealed.secret.yaml
|
||||||
- mcp-tool-config-state-docs.yaml
|
- mcp-tool-config-state-docs.yaml
|
||||||
- mcp-tool-config-ops.yaml
|
- mcp-tool-config-ops.yaml
|
||||||
- mcp-tool-config-dev.yaml
|
- mcp-tool-config-dev.yaml
|
||||||
|
|||||||
@@ -14,7 +14,13 @@ spec:
|
|||||||
embeddingServerRef:
|
embeddingServerRef:
|
||||||
name: homelab-embedding
|
name: homelab-embedding
|
||||||
incomingAuth:
|
incomingAuth:
|
||||||
type: anonymous
|
type: oidc
|
||||||
|
oidc:
|
||||||
|
issuerUrl: https://cloak.olb42.com/realms/home-lab
|
||||||
|
clientId: state-docs-vmcp
|
||||||
|
clientSecretRef:
|
||||||
|
name: state-docs-vmcp-secret
|
||||||
|
key: client-secret
|
||||||
config:
|
config:
|
||||||
aggregation:
|
aggregation:
|
||||||
conflictResolution: prefix
|
conflictResolution: prefix
|
||||||
|
|||||||
Reference in New Issue
Block a user