argocd and kube mcp to read-write

This commit is contained in:
2026-06-13 19:33:23 +01:00
parent 5a1f1f352b
commit bf86461753
3 changed files with 20 additions and 38 deletions
+14 -29
View File
@@ -7,35 +7,20 @@ metadata:
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole kind: ClusterRole
metadata: metadata:
name: mcp-kubernetes-readonly name: mcp-kubernetes-admin
namespace: toolhive-system namespace: toolhive-system
rules: rules:
- apiGroups: [""] - apiGroups: ["*"]
resources: resources: ["*"]
- pods verbs:
- pods/log - get
- pods/status - list
- services - watch
- endpoints - create
- events - update
- namespaces - patch
- nodes - delete
- configmaps - deletecollection
- persistentvolumeclaims
- replicationcontrollers
verbs: ["get", "list", "watch"]
- apiGroups: ["apps"]
resources: ["deployments", "replicasets", "statefulsets", "daemonsets"]
verbs: ["get", "list", "watch"]
- apiGroups: ["batch"]
resources: ["jobs", "cronjobs"]
verbs: ["get", "list", "watch"]
- apiGroups: ["networking.k8s.io"]
resources: ["ingresses", "networkpolicies"]
verbs: ["get", "list", "watch"]
- apiGroups: ["argoproj.io"]
resources: ["applications", "applicationsets", "appprojects"]
verbs: ["get", "list", "watch"]
- apiGroups: ["metrics.k8s.io"] - apiGroups: ["metrics.k8s.io"]
resources: ["pods", "nodes"] resources: ["pods", "nodes"]
verbs: ["get", "list"] verbs: ["get", "list"]
@@ -43,12 +28,12 @@ rules:
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
metadata: metadata:
name: mcp-kubernetes-readonly name: mcp-kubernetes-admin
namespace: toolhive-system namespace: toolhive-system
roleRef: roleRef:
apiGroup: rbac.authorization.k8s.io apiGroup: rbac.authorization.k8s.io
kind: ClusterRole kind: ClusterRole
name: mcp-kubernetes-readonly name: mcp-kubernetes-admin
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: kubernetes-mcp name: kubernetes-mcp
@@ -6,7 +6,7 @@ metadata:
annotations: annotations:
toolhive.stacklok.dev/registry-export: "true" toolhive.stacklok.dev/registry-export: "true"
toolhive.stacklok.dev/registry-title: Argo CD MCP toolhive.stacklok.dev/registry-title: Argo CD MCP
toolhive.stacklok.dev/registry-description: Read-only Argo CD MCP server for inspecting homelab GitOps applications and resources. toolhive.stacklok.dev/registry-description: Write-capable Argo CD MCP server for inspecting and operating homelab GitOps applications and resources.
toolhive.stacklok.dev/registry-url: http://mcp-argocd-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp toolhive.stacklok.dev/registry-url: http://mcp-argocd-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
glance/parent: argocd glance/parent: argocd
spec: spec:
@@ -24,9 +24,8 @@ spec:
# argocd-server serves a self-signed cert in-cluster. # argocd-server serves a self-signed cert in-cluster.
- name: NODE_TLS_REJECT_UNAUTHORIZED - name: NODE_TLS_REJECT_UNAUTHORIZED
value: "0" value: "0"
# Start read-only; drop this to enable sync/write tools later.
- name: MCP_READ_ONLY - name: MCP_READ_ONLY
value: "true" value: "false"
# ToolHive 0.28.3 does not translate spec.secrets into the workload, so inject # ToolHive 0.28.3 does not translate spec.secrets into the workload, so inject
# the token natively on the `mcp` container via podTemplateSpec. # the token natively on the `mcp` container via podTemplateSpec.
resourceOverrides: resourceOverrides:
@@ -6,11 +6,11 @@ metadata:
annotations: annotations:
toolhive.stacklok.dev/registry-export: "true" toolhive.stacklok.dev/registry-export: "true"
toolhive.stacklok.dev/registry-title: Kubernetes MCP toolhive.stacklok.dev/registry-title: Kubernetes MCP
toolhive.stacklok.dev/registry-description: Read-only Kubernetes MCP server for safe cluster inspection and troubleshooting. toolhive.stacklok.dev/registry-description: Write-capable Kubernetes MCP server for cluster inspection, troubleshooting, and GitOps maintenance actions.
toolhive.stacklok.dev/registry-url: http://mcp-kubernetes-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp toolhive.stacklok.dev/registry-url: http://mcp-kubernetes-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
spec: spec:
# containers/kubernetes-mcp-server. Authenticates to the API in-cluster via the # containers/kubernetes-mcp-server. Authenticates to the API in-cluster via the
# kubernetes-mcp ServiceAccount (read-only ClusterRole, see rbac file). Speaks # kubernetes-mcp ServiceAccount (write-capable ClusterRole, see rbac file). Speaks
# stdio; ToolHive proxies to streamable-http at # stdio; ToolHive proxies to streamable-http at
# http://mcp-kubernetes-mcp-proxy.mcp-services:8080/mcp. # http://mcp-kubernetes-mcp-proxy.mcp-services:8080/mcp.
image: ghcr.io/containers/kubernetes-mcp-server:latest image: ghcr.io/containers/kubernetes-mcp-server:latest
@@ -20,14 +20,12 @@ spec:
args: args:
- --log-file - --log-file
- stderr - stderr
- --read-only
- --disable-destructive
proxyMode: streamable-http proxyMode: streamable-http
proxyPort: 8080 proxyPort: 8080
groupRef: groupRef:
name: homelab-core name: homelab-core
# Pin the MCP server pod to our read-only ServiceAccount. The ClusterRole is # Pin the MCP server pod to the ServiceAccount that carries its Kubernetes API
# the real guardrail: even if a write tool is invoked, the API rejects it. # write permissions.
serviceAccount: kubernetes-mcp serviceAccount: kubernetes-mcp
permissionProfile: permissionProfile:
type: builtin type: builtin