argocd and kube mcp to read-write

This commit is contained in:
2026-06-13 19:33:23 +01:00
parent 5a1f1f352b
commit bf86461753
3 changed files with 20 additions and 38 deletions
@@ -6,11 +6,11 @@ metadata:
annotations:
toolhive.stacklok.dev/registry-export: "true"
toolhive.stacklok.dev/registry-title: Kubernetes MCP
toolhive.stacklok.dev/registry-description: Read-only Kubernetes MCP server for safe cluster inspection and troubleshooting.
toolhive.stacklok.dev/registry-description: Write-capable Kubernetes MCP server for cluster inspection, troubleshooting, and GitOps maintenance actions.
toolhive.stacklok.dev/registry-url: http://mcp-kubernetes-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
spec:
# containers/kubernetes-mcp-server. Authenticates to the API in-cluster via the
# kubernetes-mcp ServiceAccount (read-only ClusterRole, see rbac file). Speaks
# kubernetes-mcp ServiceAccount (write-capable ClusterRole, see rbac file). Speaks
# stdio; ToolHive proxies to streamable-http at
# http://mcp-kubernetes-mcp-proxy.mcp-services:8080/mcp.
image: ghcr.io/containers/kubernetes-mcp-server:latest
@@ -20,14 +20,12 @@ spec:
args:
- --log-file
- stderr
- --read-only
- --disable-destructive
proxyMode: streamable-http
proxyPort: 8080
groupRef:
name: homelab-core
# Pin the MCP server pod to our read-only ServiceAccount. The ClusterRole is
# the real guardrail: even if a write tool is invoked, the API rejects it.
# Pin the MCP server pod to the ServiceAccount that carries its Kubernetes API
# write permissions.
serviceAccount: kubernetes-mcp
permissionProfile:
type: builtin