- full-vmcp serves as public entry point at mcp.ngorse.com
- Single Keycloak client (public-mcp) for all external tools
- authServerConfig proxies auth to Keycloak
- state-docs-vmcp becomes internal-only (no auth required)
- Shared OIDC config for token validation
- All external clients authenticate once at gateway
spec.incomingAuth.oidcConfigRef.audience is Required by the CRD validator.
Set to the Keycloak client ID for each server (unique per server as required
to prevent token replay attacks).
Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
The .spec.incomingAuth.oidc inline block is not a valid field in the
v0.29.3 VirtualMCPServer CRD schema, causing ArgoCD ComparisonErrors.
The correct v0.29.3 API separates OIDC provider config into a dedicated
MCPOIDCConfig (v1beta1) resource, referenced from the VirtualMCPServer
via spec.incomingAuth.oidcConfigRef.name.
- Add MCPOIDCConfig resources for state-docs-vmcp and full-vmcp (inline
type, Keycloak issuer, replicated client secrets from keycloak ns)
- Update state-docs-vmcp and full-vmcp VirtualMCPServer manifests to
reference the new MCPOIDCConfig resources via oidcConfigRef
- Register new MCPOIDCConfig files in vmcp-servers kustomization
Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
Previously ignoring the entire /spec/syncPolicy prevented the ApplicationSet
controller from propagating syncOption changes (like ServerSideDiff=true) to
the live Application. Now only /automated/enabled is ignored, preserving
manual auto-sync control while allowing syncOptions to reconcile normally.
Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
ArgoCD's client-side structured merge diff fails on VirtualMCPServer
resources that use spec.incomingAuth.oidc because the CRD schema does
not declare that subfield. ServerSideDiff=true switches diff computation
to a server-side dry-run which handles preserved-unknown-fields correctly.
Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
Switch incomingAuth from anonymous to oidc, wiring Keycloak (home-lab realm
at cloak.olb42.com) as the provider with clientId state-docs-vmcp. Secret
ref (state-docs-vmcp-secret, key: client-secret) is added to kustomization
as a TODO comment pending the sealed secret creation.
Co-Authored-By: Claude Sonnet 4.6 <[email protected]>