argocd and kube mcp to read-write
This commit is contained in:
@@ -7,35 +7,20 @@ metadata:
|
|||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
metadata:
|
metadata:
|
||||||
name: mcp-kubernetes-readonly
|
name: mcp-kubernetes-admin
|
||||||
namespace: toolhive-system
|
namespace: toolhive-system
|
||||||
rules:
|
rules:
|
||||||
- apiGroups: [""]
|
- apiGroups: ["*"]
|
||||||
resources:
|
resources: ["*"]
|
||||||
- pods
|
verbs:
|
||||||
- pods/log
|
- get
|
||||||
- pods/status
|
- list
|
||||||
- services
|
- watch
|
||||||
- endpoints
|
- create
|
||||||
- events
|
- update
|
||||||
- namespaces
|
- patch
|
||||||
- nodes
|
- delete
|
||||||
- configmaps
|
- deletecollection
|
||||||
- persistentvolumeclaims
|
|
||||||
- replicationcontrollers
|
|
||||||
verbs: ["get", "list", "watch"]
|
|
||||||
- apiGroups: ["apps"]
|
|
||||||
resources: ["deployments", "replicasets", "statefulsets", "daemonsets"]
|
|
||||||
verbs: ["get", "list", "watch"]
|
|
||||||
- apiGroups: ["batch"]
|
|
||||||
resources: ["jobs", "cronjobs"]
|
|
||||||
verbs: ["get", "list", "watch"]
|
|
||||||
- apiGroups: ["networking.k8s.io"]
|
|
||||||
resources: ["ingresses", "networkpolicies"]
|
|
||||||
verbs: ["get", "list", "watch"]
|
|
||||||
- apiGroups: ["argoproj.io"]
|
|
||||||
resources: ["applications", "applicationsets", "appprojects"]
|
|
||||||
verbs: ["get", "list", "watch"]
|
|
||||||
- apiGroups: ["metrics.k8s.io"]
|
- apiGroups: ["metrics.k8s.io"]
|
||||||
resources: ["pods", "nodes"]
|
resources: ["pods", "nodes"]
|
||||||
verbs: ["get", "list"]
|
verbs: ["get", "list"]
|
||||||
@@ -43,12 +28,12 @@ rules:
|
|||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
metadata:
|
metadata:
|
||||||
name: mcp-kubernetes-readonly
|
name: mcp-kubernetes-admin
|
||||||
namespace: toolhive-system
|
namespace: toolhive-system
|
||||||
roleRef:
|
roleRef:
|
||||||
apiGroup: rbac.authorization.k8s.io
|
apiGroup: rbac.authorization.k8s.io
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
name: mcp-kubernetes-readonly
|
name: mcp-kubernetes-admin
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: kubernetes-mcp
|
name: kubernetes-mcp
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ metadata:
|
|||||||
annotations:
|
annotations:
|
||||||
toolhive.stacklok.dev/registry-export: "true"
|
toolhive.stacklok.dev/registry-export: "true"
|
||||||
toolhive.stacklok.dev/registry-title: Argo CD MCP
|
toolhive.stacklok.dev/registry-title: Argo CD MCP
|
||||||
toolhive.stacklok.dev/registry-description: Read-only Argo CD MCP server for inspecting homelab GitOps applications and resources.
|
toolhive.stacklok.dev/registry-description: Write-capable Argo CD MCP server for inspecting and operating homelab GitOps applications and resources.
|
||||||
toolhive.stacklok.dev/registry-url: http://mcp-argocd-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
|
toolhive.stacklok.dev/registry-url: http://mcp-argocd-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
|
||||||
glance/parent: argocd
|
glance/parent: argocd
|
||||||
spec:
|
spec:
|
||||||
@@ -24,9 +24,8 @@ spec:
|
|||||||
# argocd-server serves a self-signed cert in-cluster.
|
# argocd-server serves a self-signed cert in-cluster.
|
||||||
- name: NODE_TLS_REJECT_UNAUTHORIZED
|
- name: NODE_TLS_REJECT_UNAUTHORIZED
|
||||||
value: "0"
|
value: "0"
|
||||||
# Start read-only; drop this to enable sync/write tools later.
|
|
||||||
- name: MCP_READ_ONLY
|
- name: MCP_READ_ONLY
|
||||||
value: "true"
|
value: "false"
|
||||||
# ToolHive 0.28.3 does not translate spec.secrets into the workload, so inject
|
# ToolHive 0.28.3 does not translate spec.secrets into the workload, so inject
|
||||||
# the token natively on the `mcp` container via podTemplateSpec.
|
# the token natively on the `mcp` container via podTemplateSpec.
|
||||||
resourceOverrides:
|
resourceOverrides:
|
||||||
|
|||||||
@@ -6,11 +6,11 @@ metadata:
|
|||||||
annotations:
|
annotations:
|
||||||
toolhive.stacklok.dev/registry-export: "true"
|
toolhive.stacklok.dev/registry-export: "true"
|
||||||
toolhive.stacklok.dev/registry-title: Kubernetes MCP
|
toolhive.stacklok.dev/registry-title: Kubernetes MCP
|
||||||
toolhive.stacklok.dev/registry-description: Read-only Kubernetes MCP server for safe cluster inspection and troubleshooting.
|
toolhive.stacklok.dev/registry-description: Write-capable Kubernetes MCP server for cluster inspection, troubleshooting, and GitOps maintenance actions.
|
||||||
toolhive.stacklok.dev/registry-url: http://mcp-kubernetes-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
|
toolhive.stacklok.dev/registry-url: http://mcp-kubernetes-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
|
||||||
spec:
|
spec:
|
||||||
# containers/kubernetes-mcp-server. Authenticates to the API in-cluster via the
|
# containers/kubernetes-mcp-server. Authenticates to the API in-cluster via the
|
||||||
# kubernetes-mcp ServiceAccount (read-only ClusterRole, see rbac file). Speaks
|
# kubernetes-mcp ServiceAccount (write-capable ClusterRole, see rbac file). Speaks
|
||||||
# stdio; ToolHive proxies to streamable-http at
|
# stdio; ToolHive proxies to streamable-http at
|
||||||
# http://mcp-kubernetes-mcp-proxy.mcp-services:8080/mcp.
|
# http://mcp-kubernetes-mcp-proxy.mcp-services:8080/mcp.
|
||||||
image: ghcr.io/containers/kubernetes-mcp-server:latest
|
image: ghcr.io/containers/kubernetes-mcp-server:latest
|
||||||
@@ -20,14 +20,12 @@ spec:
|
|||||||
args:
|
args:
|
||||||
- --log-file
|
- --log-file
|
||||||
- stderr
|
- stderr
|
||||||
- --read-only
|
|
||||||
- --disable-destructive
|
|
||||||
proxyMode: streamable-http
|
proxyMode: streamable-http
|
||||||
proxyPort: 8080
|
proxyPort: 8080
|
||||||
groupRef:
|
groupRef:
|
||||||
name: homelab-core
|
name: homelab-core
|
||||||
# Pin the MCP server pod to our read-only ServiceAccount. The ClusterRole is
|
# Pin the MCP server pod to the ServiceAccount that carries its Kubernetes API
|
||||||
# the real guardrail: even if a write tool is invoked, the API rejects it.
|
# write permissions.
|
||||||
serviceAccount: kubernetes-mcp
|
serviceAccount: kubernetes-mcp
|
||||||
permissionProfile:
|
permissionProfile:
|
||||||
type: builtin
|
type: builtin
|
||||||
|
|||||||
Reference in New Issue
Block a user