94 Commits
Author SHA1 Message Date
olb042 78b1119710 Fix full VMCP redirect URI 2026-06-23 19:15:35 +01:00
olb042 48476c7dac Fix full VMCP audience 2026-06-23 19:12:19 +01:00
olb042 d393f66d47 add back ingress 2026-06-17 17:37:24 +01:00
olb042 de8f55c253 move to public-mcp 2026-06-17 17:25:52 +01:00
olb042 a72a2055af move to public-mcp 2026-06-17 16:48:38 +01:00
olb042 676bad4dd2 Implement shared public MCP federation gateway
- full-vmcp serves as public entry point at mcp.ngorse.com
- Single Keycloak client (public-mcp) for all external tools
- authServerConfig proxies auth to Keycloak
- state-docs-vmcp becomes internal-only (no auth required)
- Shared OIDC config for token validation
- All external clients authenticate once at gateway
2026-06-17 16:26:48 +01:00
olb042 d1d8c6aa3f change audidence 2026-06-17 15:35:15 +01:00
olb042 a7f069bdd7 add ngorse ingress 2026-06-17 15:28:57 +01:00
olb042 95fcbb5441 seperate ingress 2026-06-17 15:27:40 +01:00
olb042 841bb8e6c8 Simplify authServerConfig to only required CRD fields 2026-06-17 15:02:35 +01:00
olb042 d402c1726e test toolhive.stacklok.dev/v1beta1 2026-06-17 14:59:12 +01:00
olb042 919888aba6 test toolhive.stacklok.dev/v1beta1 2026-06-17 14:57:49 +01:00
olb042 b6f6c3ebe4 Configure OIDC auth servers for VMCP servers to proxy through Keycloak 2026-06-17 14:52:02 +01:00
olb042 4de136186f change auth for vmcp 2026-06-17 14:49:54 +01:00
olb042andClaude Sonnet 4.6 ad0e5df277 fix: add required audience field to oidcConfigRef on both VirtualMCPServers
spec.incomingAuth.oidcConfigRef.audience is Required by the CRD validator.
Set to the Keycloak client ID for each server (unique per server as required
to prevent token replay attacks).

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
2026-06-15 13:34:33 +00:00
olb042andClaude Sonnet 4.6 3caeeb2997 fix: replace invalid incomingAuth.oidc with MCPOIDCConfig + oidcConfigRef
The .spec.incomingAuth.oidc inline block is not a valid field in the
v0.29.3 VirtualMCPServer CRD schema, causing ArgoCD ComparisonErrors.

The correct v0.29.3 API separates OIDC provider config into a dedicated
MCPOIDCConfig (v1beta1) resource, referenced from the VirtualMCPServer
via spec.incomingAuth.oidcConfigRef.name.

- Add MCPOIDCConfig resources for state-docs-vmcp and full-vmcp (inline
  type, Keycloak issuer, replicated client secrets from keycloak ns)
- Update state-docs-vmcp and full-vmcp VirtualMCPServer manifests to
  reference the new MCPOIDCConfig resources via oidcConfigRef
- Register new MCPOIDCConfig files in vmcp-servers kustomization

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
2026-06-15 13:31:45 +00:00
olb042andClaude Sonnet 4.6 d09eb39701 narrow ignoreApplicationDifferences to /automated/enabled only
Previously ignoring the entire /spec/syncPolicy prevented the ApplicationSet
controller from propagating syncOption changes (like ServerSideDiff=true) to
the live Application. Now only /automated/enabled is ignored, preserving
manual auto-sync control while allowing syncOptions to reconcile normally.

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
2026-06-15 13:04:59 +00:00
olb042andClaude Sonnet 4.6 50fdec56cb add ServerSideDiff=true to bypass incomingAuth.oidc schema error
ArgoCD's client-side structured merge diff fails on VirtualMCPServer
resources that use spec.incomingAuth.oidc because the CRD schema does
not declare that subfield. ServerSideDiff=true switches diff computation
to a server-side dry-run which handles preserved-unknown-fields correctly.

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
2026-06-15 13:03:54 +00:00
olb042 457d042569 add vmcp 2026-06-15 13:54:03 +01:00
olb042andClaude Sonnet 4.6 f82d0b449b remove stale TODO for state-docs-vmcp sealed secret
Secret is replicated from Keycloak into toolhive-system; no sealed secret needed.

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
2026-06-15 12:10:25 +00:00
olb042 9f162958bf oidc auth 2026-06-15 12:59:34 +01:00
olb042 f74bf9e50f temp oidc auth 2026-06-15 12:58:50 +01:00
olb042 adc06573cc update version 2026-06-15 12:49:25 +01:00
olb042andClaude Sonnet 4.6 b497211278 add OIDC auth to state-docs-vmcp VirtualMCPServer
Switch incomingAuth from anonymous to oidc, wiring Keycloak (home-lab realm
at cloak.olb42.com) as the provider with clientId state-docs-vmcp. Secret
ref (state-docs-vmcp-secret, key: client-secret) is added to kustomization
as a TODO comment pending the sealed secret creation.

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
2026-06-14 16:55:43 +00:00
olb042 8b9e54a924 update ingress 2026-06-14 02:40:20 +01:00
olb042 4da61242df update ssl 2026-06-14 02:29:04 +01:00
olb042 6ff5eaafa2 add second ingressroute 2026-06-14 02:11:42 +01:00
olb042 6da4451697 add internal dns 2026-06-14 02:05:02 +01:00
olb042 b58c369d11 embedding 2026-06-13 20:47:48 +01:00
olb042 cc1bb128e1 enable tools 2026-06-13 20:45:37 +01:00
olb042 62b1214926 add incoming auth 2026-06-13 20:19:53 +01:00
olb042 ab95db2782 add state doc 2026-06-13 20:16:18 +01:00
olb042 ccd0093f00 add state docs 2026-06-13 20:09:43 +01:00
olb042 3e78b15f19 add registry visible remote mcp proxies 2026-06-13 19:59:04 +01:00
olb042 13d58831b4 fix registry discovery rbac for mcp entries 2026-06-13 19:55:57 +01:00
olb042 bf86461753 argocd and kube mcp to read-write 2026-06-13 19:33:23 +01:00
olb042 5a1f1f352b pangolin ingress 2026-06-13 19:29:32 +01:00
olb042 596c464754 glance reg 2026-06-06 00:21:16 +01:00
olb042 5106b5e73c vmcp glance 2026-06-06 00:16:30 +01:00
olb042 6a8328ec88 radar 2026-06-06 00:13:34 +01:00
olb042 d9dda8fef8 pod glance 2026-06-05 23:57:31 +01:00
olb042 6a15fbe49f argocd mcp podtemplate/metadata/annotations/glances.parent 2026-06-05 23:56:49 +01:00
olb042 1bbb463bfe glances changes 2026-06-05 16:25:10 +01:00
olb042 0df4a6b461 glance for gitea mcp 2026-06-05 15:49:20 +01:00
olb042 353ba6a250 change resourceoverides 2026-06-04 23:46:16 +01:00
olb042 7aa4ae4dd6 icon mcp 2026-06-04 20:35:09 +01:00
olb042 a9f3cf86d2 icon fix 2026-06-04 20:33:17 +01:00
olb042 37695d8f40 glances 2026-06-04 19:21:53 +01:00
olb042 cae8eabac1 update services and rbac 2026-06-03 18:09:23 +01:00
olb042 0a03987dae sort into folders 2026-06-03 14:09:28 +01:00