The .spec.incomingAuth.oidc inline block is not a valid field in the
v0.29.3 VirtualMCPServer CRD schema, causing ArgoCD ComparisonErrors.
The correct v0.29.3 API separates OIDC provider config into a dedicated
MCPOIDCConfig (v1beta1) resource, referenced from the VirtualMCPServer
via spec.incomingAuth.oidcConfigRef.name.
- Add MCPOIDCConfig resources for state-docs-vmcp and full-vmcp (inline
type, Keycloak issuer, replicated client secrets from keycloak ns)
- Update state-docs-vmcp and full-vmcp VirtualMCPServer manifests to
reference the new MCPOIDCConfig resources via oidcConfigRef
- Register new MCPOIDCConfig files in vmcp-servers kustomization
Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
Previously ignoring the entire /spec/syncPolicy prevented the ApplicationSet
controller from propagating syncOption changes (like ServerSideDiff=true) to
the live Application. Now only /automated/enabled is ignored, preserving
manual auto-sync control while allowing syncOptions to reconcile normally.
Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
ArgoCD's client-side structured merge diff fails on VirtualMCPServer
resources that use spec.incomingAuth.oidc because the CRD schema does
not declare that subfield. ServerSideDiff=true switches diff computation
to a server-side dry-run which handles preserved-unknown-fields correctly.
Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
Switch incomingAuth from anonymous to oidc, wiring Keycloak (home-lab realm
at cloak.olb42.com) as the provider with clientId state-docs-vmcp. Secret
ref (state-docs-vmcp-secret, key: client-secret) is added to kustomization
as a TODO comment pending the sealed secret creation.
Co-Authored-By: Claude Sonnet 4.6 <[email protected]>