15 Commits
Author SHA1 Message Date
olb042 78b1119710 Fix full VMCP redirect URI 2026-06-23 19:15:35 +01:00
olb042 48476c7dac Fix full VMCP audience 2026-06-23 19:12:19 +01:00
olb042 de8f55c253 move to public-mcp 2026-06-17 17:25:52 +01:00
olb042 676bad4dd2 Implement shared public MCP federation gateway
- full-vmcp serves as public entry point at mcp.ngorse.com
- Single Keycloak client (public-mcp) for all external tools
- authServerConfig proxies auth to Keycloak
- state-docs-vmcp becomes internal-only (no auth required)
- Shared OIDC config for token validation
- All external clients authenticate once at gateway
2026-06-17 16:26:48 +01:00
olb042 d1d8c6aa3f change audidence 2026-06-17 15:35:15 +01:00
olb042 841bb8e6c8 Simplify authServerConfig to only required CRD fields 2026-06-17 15:02:35 +01:00
olb042 919888aba6 test toolhive.stacklok.dev/v1beta1 2026-06-17 14:57:49 +01:00
olb042 b6f6c3ebe4 Configure OIDC auth servers for VMCP servers to proxy through Keycloak 2026-06-17 14:52:02 +01:00
olb042 4de136186f change auth for vmcp 2026-06-17 14:49:54 +01:00
olb042andClaude Sonnet 4.6 ad0e5df277 fix: add required audience field to oidcConfigRef on both VirtualMCPServers
spec.incomingAuth.oidcConfigRef.audience is Required by the CRD validator.
Set to the Keycloak client ID for each server (unique per server as required
to prevent token replay attacks).

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
2026-06-15 13:34:33 +00:00
olb042andClaude Sonnet 4.6 3caeeb2997 fix: replace invalid incomingAuth.oidc with MCPOIDCConfig + oidcConfigRef
The .spec.incomingAuth.oidc inline block is not a valid field in the
v0.29.3 VirtualMCPServer CRD schema, causing ArgoCD ComparisonErrors.

The correct v0.29.3 API separates OIDC provider config into a dedicated
MCPOIDCConfig (v1beta1) resource, referenced from the VirtualMCPServer
via spec.incomingAuth.oidcConfigRef.name.

- Add MCPOIDCConfig resources for state-docs-vmcp and full-vmcp (inline
  type, Keycloak issuer, replicated client secrets from keycloak ns)
- Update state-docs-vmcp and full-vmcp VirtualMCPServer manifests to
  reference the new MCPOIDCConfig resources via oidcConfigRef
- Register new MCPOIDCConfig files in vmcp-servers kustomization

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
2026-06-15 13:31:45 +00:00
olb042 457d042569 add vmcp 2026-06-15 13:54:03 +01:00
olb042 5a1f1f352b pangolin ingress 2026-06-13 19:29:32 +01:00
olb042 5106b5e73c vmcp glance 2026-06-06 00:16:30 +01:00
olb042 0a03987dae sort into folders 2026-06-03 14:09:28 +01:00