Compare commits
43
Commits
0df4a6b461
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
78b1119710 | ||
|
|
48476c7dac | ||
|
|
d393f66d47 | ||
|
|
de8f55c253 | ||
|
|
a72a2055af | ||
|
|
676bad4dd2 | ||
|
|
d1d8c6aa3f | ||
|
|
a7f069bdd7 | ||
|
|
95fcbb5441 | ||
|
|
841bb8e6c8 | ||
|
|
d402c1726e | ||
|
|
919888aba6 | ||
|
|
b6f6c3ebe4 | ||
|
|
4de136186f | ||
|
|
ad0e5df277 | ||
|
|
3caeeb2997 | ||
|
|
d09eb39701 | ||
|
|
50fdec56cb | ||
|
|
457d042569 | ||
|
|
f82d0b449b | ||
|
|
9f162958bf | ||
|
|
f74bf9e50f | ||
|
|
adc06573cc | ||
|
|
b497211278 | ||
|
|
8b9e54a924 | ||
|
|
4da61242df | ||
|
|
6ff5eaafa2 | ||
|
|
6da4451697 | ||
|
|
b58c369d11 | ||
|
|
cc1bb128e1 | ||
|
|
62b1214926 | ||
|
|
ab95db2782 | ||
|
|
ccd0093f00 | ||
|
|
3e78b15f19 | ||
|
|
13d58831b4 | ||
|
|
bf86461753 | ||
|
|
5a1f1f352b | ||
|
|
596c464754 | ||
|
|
5106b5e73c | ||
|
|
6a8328ec88 | ||
|
|
d9dda8fef8 | ||
|
|
6a15fbe49f | ||
|
|
1bbb463bfe |
@@ -6,7 +6,7 @@ metadata:
|
|||||||
spec:
|
spec:
|
||||||
ignoreApplicationDifferences:
|
ignoreApplicationDifferences:
|
||||||
- jsonPointers:
|
- jsonPointers:
|
||||||
- /spec/syncPolicy
|
- /spec/syncPolicy/automated/enabled
|
||||||
goTemplate: true
|
goTemplate: true
|
||||||
goTemplateOptions: ["missingkey=error"]
|
goTemplateOptions: ["missingkey=error"]
|
||||||
generators:
|
generators:
|
||||||
@@ -15,7 +15,7 @@ spec:
|
|||||||
- environment: production
|
- environment: production
|
||||||
namespace: toolhive-system
|
namespace: toolhive-system
|
||||||
overlay: production
|
overlay: production
|
||||||
chartVersion: 0.28.3
|
chartVersion: 0.29.3
|
||||||
template:
|
template:
|
||||||
metadata:
|
metadata:
|
||||||
name: 'toolhive-{{ .environment }}'
|
name: 'toolhive-{{ .environment }}'
|
||||||
@@ -60,3 +60,6 @@ spec:
|
|||||||
- CreateNamespace=true
|
- CreateNamespace=true
|
||||||
# CRD schemas are large; SSA avoids the last-applied-config annotation limit.
|
# CRD schemas are large; SSA avoids the last-applied-config annotation limit.
|
||||||
- ServerSideApply=true
|
- ServerSideApply=true
|
||||||
|
# Use server-side dry-run for diff computation to bypass CRD schema
|
||||||
|
# validation errors on fields marked x-kubernetes-preserve-unknown-fields.
|
||||||
|
- ServerSideDiff=true
|
||||||
|
|||||||
@@ -7,35 +7,20 @@ metadata:
|
|||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
metadata:
|
metadata:
|
||||||
name: mcp-kubernetes-readonly
|
name: mcp-kubernetes-admin
|
||||||
namespace: toolhive-system
|
namespace: toolhive-system
|
||||||
rules:
|
rules:
|
||||||
- apiGroups: [""]
|
- apiGroups: ["*"]
|
||||||
resources:
|
resources: ["*"]
|
||||||
- pods
|
verbs:
|
||||||
- pods/log
|
- get
|
||||||
- pods/status
|
- list
|
||||||
- services
|
- watch
|
||||||
- endpoints
|
- create
|
||||||
- events
|
- update
|
||||||
- namespaces
|
- patch
|
||||||
- nodes
|
- delete
|
||||||
- configmaps
|
- deletecollection
|
||||||
- persistentvolumeclaims
|
|
||||||
- replicationcontrollers
|
|
||||||
verbs: ["get", "list", "watch"]
|
|
||||||
- apiGroups: ["apps"]
|
|
||||||
resources: ["deployments", "replicasets", "statefulsets", "daemonsets"]
|
|
||||||
verbs: ["get", "list", "watch"]
|
|
||||||
- apiGroups: ["batch"]
|
|
||||||
resources: ["jobs", "cronjobs"]
|
|
||||||
verbs: ["get", "list", "watch"]
|
|
||||||
- apiGroups: ["networking.k8s.io"]
|
|
||||||
resources: ["ingresses", "networkpolicies"]
|
|
||||||
verbs: ["get", "list", "watch"]
|
|
||||||
- apiGroups: ["argoproj.io"]
|
|
||||||
resources: ["applications", "applicationsets", "appprojects"]
|
|
||||||
verbs: ["get", "list", "watch"]
|
|
||||||
- apiGroups: ["metrics.k8s.io"]
|
- apiGroups: ["metrics.k8s.io"]
|
||||||
resources: ["pods", "nodes"]
|
resources: ["pods", "nodes"]
|
||||||
verbs: ["get", "list"]
|
verbs: ["get", "list"]
|
||||||
@@ -43,12 +28,12 @@ rules:
|
|||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: ClusterRoleBinding
|
kind: ClusterRoleBinding
|
||||||
metadata:
|
metadata:
|
||||||
name: mcp-kubernetes-readonly
|
name: mcp-kubernetes-admin
|
||||||
namespace: toolhive-system
|
namespace: toolhive-system
|
||||||
roleRef:
|
roleRef:
|
||||||
apiGroup: rbac.authorization.k8s.io
|
apiGroup: rbac.authorization.k8s.io
|
||||||
kind: ClusterRole
|
kind: ClusterRole
|
||||||
name: mcp-kubernetes-readonly
|
name: mcp-kubernetes-admin
|
||||||
subjects:
|
subjects:
|
||||||
- kind: ServiceAccount
|
- kind: ServiceAccount
|
||||||
name: kubernetes-mcp
|
name: kubernetes-mcp
|
||||||
|
|||||||
@@ -6,6 +6,8 @@ namespace: toolhive-system
|
|||||||
resources:
|
resources:
|
||||||
- mcpserver-gitea.yaml
|
- mcpserver-gitea.yaml
|
||||||
- mcpserver-radar.yaml
|
- mcpserver-radar.yaml
|
||||||
|
- mcpremoteproxy-automem.yaml
|
||||||
|
- mcpremoteproxy-radar.yaml
|
||||||
- mcpserver-argocd.yaml
|
- mcpserver-argocd.yaml
|
||||||
- mcpserver-kubernetes.yaml
|
- mcpserver-kubernetes.yaml
|
||||||
- mcp-headless-services.yaml
|
- mcp-headless-services.yaml
|
||||||
|
|||||||
@@ -0,0 +1,32 @@
|
|||||||
|
apiVersion: toolhive.stacklok.dev/v1beta1
|
||||||
|
kind: MCPRemoteProxy
|
||||||
|
metadata:
|
||||||
|
name: automem
|
||||||
|
namespace: toolhive-system
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/environment: production
|
||||||
|
app.kubernetes.io/part-of: automem
|
||||||
|
annotations:
|
||||||
|
toolhive.stacklok.dev/registry-export: "true"
|
||||||
|
toolhive.stacklok.dev/registry-title: AutoMem MCP
|
||||||
|
toolhive.stacklok.dev/registry-description: AutoMem MCP bridge for persistent cross-session memory.
|
||||||
|
toolhive.stacklok.dev/registry-url: http://mcp-automem-remote-proxy.toolhive-system.svc.cluster.local:8080
|
||||||
|
spec:
|
||||||
|
remoteUrl: http://automem-mcp-bridge.automem:8080/mcp
|
||||||
|
transport: streamable-http
|
||||||
|
proxyPort: 8080
|
||||||
|
groupRef:
|
||||||
|
name: homelab-core
|
||||||
|
headerForward:
|
||||||
|
addHeadersFromSecret:
|
||||||
|
- headerName: X-API-Key
|
||||||
|
valueSecretRef:
|
||||||
|
name: automem-mcp-client-auth
|
||||||
|
key: authorization
|
||||||
|
resourceOverrides:
|
||||||
|
proxyDeployment:
|
||||||
|
annotations:
|
||||||
|
glance/parent: automem
|
||||||
|
proxyService:
|
||||||
|
annotations:
|
||||||
|
glance/parent: automem
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
apiVersion: toolhive.stacklok.dev/v1beta1
|
||||||
|
kind: MCPRemoteProxy
|
||||||
|
metadata:
|
||||||
|
name: radar
|
||||||
|
namespace: toolhive-system
|
||||||
|
annotations:
|
||||||
|
toolhive.stacklok.dev/registry-export: "true"
|
||||||
|
toolhive.stacklok.dev/registry-title: Radar MCP
|
||||||
|
toolhive.stacklok.dev/registry-description: Radar MCP Server
|
||||||
|
toolhive.stacklok.dev/registry-url: https://radar.olb42.com/mcp
|
||||||
|
glance/parent: radar
|
||||||
|
spec:
|
||||||
|
remoteUrl: http://radar.radar:9280/mcp
|
||||||
|
transport: streamable-http
|
||||||
|
proxyPort: 8080
|
||||||
|
groupRef:
|
||||||
|
name: homelab-core
|
||||||
|
resourceOverrides:
|
||||||
|
proxyDeployment:
|
||||||
|
annotations:
|
||||||
|
glance/parent: radar
|
||||||
|
proxyService:
|
||||||
|
annotations:
|
||||||
|
glance/parent: radar
|
||||||
@@ -6,8 +6,9 @@ metadata:
|
|||||||
annotations:
|
annotations:
|
||||||
toolhive.stacklok.dev/registry-export: "true"
|
toolhive.stacklok.dev/registry-export: "true"
|
||||||
toolhive.stacklok.dev/registry-title: Argo CD MCP
|
toolhive.stacklok.dev/registry-title: Argo CD MCP
|
||||||
toolhive.stacklok.dev/registry-description: Read-only Argo CD MCP server for inspecting homelab GitOps applications and resources.
|
toolhive.stacklok.dev/registry-description: Write-capable Argo CD MCP server for inspecting and operating homelab GitOps applications and resources.
|
||||||
toolhive.stacklok.dev/registry-url: http://mcp-argocd-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
|
toolhive.stacklok.dev/registry-url: http://mcp-argocd-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
|
||||||
|
glance/parent: argocd
|
||||||
spec:
|
spec:
|
||||||
# argoproj-labs MCP server for Argo CD. v0.7.0 starts streamable HTTP on
|
# argoproj-labs MCP server for Argo CD. v0.7.0 starts streamable HTTP on
|
||||||
# port 3000 by default; setting args: ["stdio"] makes the image try to run
|
# port 3000 by default; setting args: ["stdio"] makes the image try to run
|
||||||
@@ -23,9 +24,8 @@ spec:
|
|||||||
# argocd-server serves a self-signed cert in-cluster.
|
# argocd-server serves a self-signed cert in-cluster.
|
||||||
- name: NODE_TLS_REJECT_UNAUTHORIZED
|
- name: NODE_TLS_REJECT_UNAUTHORIZED
|
||||||
value: "0"
|
value: "0"
|
||||||
# Start read-only; drop this to enable sync/write tools later.
|
|
||||||
- name: MCP_READ_ONLY
|
- name: MCP_READ_ONLY
|
||||||
value: "true"
|
value: "false"
|
||||||
# ToolHive 0.28.3 does not translate spec.secrets into the workload, so inject
|
# ToolHive 0.28.3 does not translate spec.secrets into the workload, so inject
|
||||||
# the token natively on the `mcp` container via podTemplateSpec.
|
# the token natively on the `mcp` container via podTemplateSpec.
|
||||||
resourceOverrides:
|
resourceOverrides:
|
||||||
@@ -33,6 +33,9 @@ spec:
|
|||||||
annotations:
|
annotations:
|
||||||
glance/parent: argocd
|
glance/parent: argocd
|
||||||
podTemplateSpec:
|
podTemplateSpec:
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
glance/parent: argocd
|
||||||
spec:
|
spec:
|
||||||
groupRef:
|
groupRef:
|
||||||
name: homelab-core
|
name: homelab-core
|
||||||
|
|||||||
@@ -8,6 +8,7 @@ metadata:
|
|||||||
toolhive.stacklok.dev/registry-title: Gitea MCP
|
toolhive.stacklok.dev/registry-title: Gitea MCP
|
||||||
toolhive.stacklok.dev/registry-description: Gitea MCP server for repository, issue, and pull request workflows in the homelab Gitea instance.
|
toolhive.stacklok.dev/registry-description: Gitea MCP server for repository, issue, and pull request workflows in the homelab Gitea instance.
|
||||||
toolhive.stacklok.dev/registry-url: http://mcp-gitea-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
|
toolhive.stacklok.dev/registry-url: http://mcp-gitea-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
|
||||||
|
glance/parent: gitea
|
||||||
spec:
|
spec:
|
||||||
# Upstream Gitea MCP server. Speaks stdio; ToolHive's proxy runner wraps it and
|
# Upstream Gitea MCP server. Speaks stdio; ToolHive's proxy runner wraps it and
|
||||||
# exposes streamable-http at http://mcp-gitea-mcp-proxy.mcp-services:8080/mcp.
|
# exposes streamable-http at http://mcp-gitea-mcp-proxy.mcp-services:8080/mcp.
|
||||||
@@ -29,6 +30,9 @@ spec:
|
|||||||
annotations:
|
annotations:
|
||||||
glance/parent: gitea
|
glance/parent: gitea
|
||||||
podTemplateSpec:
|
podTemplateSpec:
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
glance/parent: gitea
|
||||||
spec:
|
spec:
|
||||||
groupRef:
|
groupRef:
|
||||||
name: homelab-core
|
name: homelab-core
|
||||||
|
|||||||
@@ -6,11 +6,11 @@ metadata:
|
|||||||
annotations:
|
annotations:
|
||||||
toolhive.stacklok.dev/registry-export: "true"
|
toolhive.stacklok.dev/registry-export: "true"
|
||||||
toolhive.stacklok.dev/registry-title: Kubernetes MCP
|
toolhive.stacklok.dev/registry-title: Kubernetes MCP
|
||||||
toolhive.stacklok.dev/registry-description: Read-only Kubernetes MCP server for safe cluster inspection and troubleshooting.
|
toolhive.stacklok.dev/registry-description: Write-capable Kubernetes MCP server for cluster inspection, troubleshooting, and GitOps maintenance actions.
|
||||||
toolhive.stacklok.dev/registry-url: http://mcp-kubernetes-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
|
toolhive.stacklok.dev/registry-url: http://mcp-kubernetes-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
|
||||||
spec:
|
spec:
|
||||||
# containers/kubernetes-mcp-server. Authenticates to the API in-cluster via the
|
# containers/kubernetes-mcp-server. Authenticates to the API in-cluster via the
|
||||||
# kubernetes-mcp ServiceAccount (read-only ClusterRole, see rbac file). Speaks
|
# kubernetes-mcp ServiceAccount (write-capable ClusterRole, see rbac file). Speaks
|
||||||
# stdio; ToolHive proxies to streamable-http at
|
# stdio; ToolHive proxies to streamable-http at
|
||||||
# http://mcp-kubernetes-mcp-proxy.mcp-services:8080/mcp.
|
# http://mcp-kubernetes-mcp-proxy.mcp-services:8080/mcp.
|
||||||
image: ghcr.io/containers/kubernetes-mcp-server:latest
|
image: ghcr.io/containers/kubernetes-mcp-server:latest
|
||||||
@@ -20,14 +20,12 @@ spec:
|
|||||||
args:
|
args:
|
||||||
- --log-file
|
- --log-file
|
||||||
- stderr
|
- stderr
|
||||||
- --read-only
|
|
||||||
- --disable-destructive
|
|
||||||
proxyMode: streamable-http
|
proxyMode: streamable-http
|
||||||
proxyPort: 8080
|
proxyPort: 8080
|
||||||
groupRef:
|
groupRef:
|
||||||
name: homelab-core
|
name: homelab-core
|
||||||
# Pin the MCP server pod to our read-only ServiceAccount. The ClusterRole is
|
# Pin the MCP server pod to the ServiceAccount that carries its Kubernetes API
|
||||||
# the real guardrail: even if a write tool is invoked, the API rejects it.
|
# write permissions.
|
||||||
serviceAccount: kubernetes-mcp
|
serviceAccount: kubernetes-mcp
|
||||||
permissionProfile:
|
permissionProfile:
|
||||||
type: builtin
|
type: builtin
|
||||||
|
|||||||
@@ -3,6 +3,12 @@ kind: MCPServerEntry
|
|||||||
metadata:
|
metadata:
|
||||||
name: radar
|
name: radar
|
||||||
namespace: toolhive-system
|
namespace: toolhive-system
|
||||||
|
annotations:
|
||||||
|
toolhive.stacklok.dev/registry-export: "true"
|
||||||
|
toolhive.stacklok.dev/registry-title: Radar MCP
|
||||||
|
toolhive.stacklok.dev/registry-description: Radar MCP Server
|
||||||
|
toolhive.stacklok.dev/registry-url: https://radar.olb42.com/mcp
|
||||||
|
glance/parent: radar
|
||||||
spec:
|
spec:
|
||||||
remoteUrl: http://radar.radar:9280/mcp
|
remoteUrl: http://radar.radar:9280/mcp
|
||||||
transport: streamable-http
|
transport: streamable-http
|
||||||
|
|||||||
@@ -5,14 +5,36 @@ metadata:
|
|||||||
namespace: toolhive-system
|
namespace: toolhive-system
|
||||||
spec:
|
spec:
|
||||||
toolsFilter:
|
toolsFilter:
|
||||||
- get_application
|
- list_org_repos
|
||||||
- get_application_health
|
- search_repos
|
||||||
- get_application_history
|
- get_repository_tree
|
||||||
- get_pods
|
- get_dir_contents
|
||||||
- describe_pod
|
- get_file_contents
|
||||||
- get_events
|
- list_branches
|
||||||
- get_pod_logs
|
- list_commits
|
||||||
|
- get_commit
|
||||||
- create_or_update_file
|
- create_or_update_file
|
||||||
- get_file
|
- recall_memory
|
||||||
- memory_search
|
- store_memory
|
||||||
- upsert_memory
|
- update_memory
|
||||||
|
- associate_memories
|
||||||
|
- list_applications
|
||||||
|
- get_application
|
||||||
|
- get_application_resource_tree
|
||||||
|
- get_application_managed_resources
|
||||||
|
- get_application_workload_logs
|
||||||
|
- get_application_events
|
||||||
|
- get_resource_events
|
||||||
|
- get_resources
|
||||||
|
- configuration_view
|
||||||
|
- namespaces_list
|
||||||
|
- events_list
|
||||||
|
- pods_get
|
||||||
|
- pods_list
|
||||||
|
- pods_list_in_namespace
|
||||||
|
- pods_log
|
||||||
|
- pods_top
|
||||||
|
- nodes_top
|
||||||
|
- nodes_stats_summary
|
||||||
|
- resources_get
|
||||||
|
- resources_list
|
||||||
|
|||||||
@@ -9,7 +9,8 @@ rules:
|
|||||||
- mcpservers
|
- mcpservers
|
||||||
- mcpremoteproxies
|
- mcpremoteproxies
|
||||||
- virtualmcpservers
|
- virtualmcpservers
|
||||||
- mcpserverentry
|
- mcpserverentries
|
||||||
|
- mcpgroups
|
||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- list
|
- list
|
||||||
|
|||||||
@@ -6,6 +6,10 @@ spec:
|
|||||||
pgpassSecretRef:
|
pgpassSecretRef:
|
||||||
name: toolhive-reg-pg-app
|
name: toolhive-reg-pg-app
|
||||||
key: pgpass
|
key: pgpass
|
||||||
|
podTemplateSpec:
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
glance/parent: toolhive
|
||||||
configYAML: |
|
configYAML: |
|
||||||
database:
|
database:
|
||||||
host: toolhive-reg-pg-rw
|
host: toolhive-reg-pg-rw
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
namespace: toolhive-system
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- public-mcp-secret.sealed.secret.yaml
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
---
|
||||||
|
apiVersion: bitnami.com/v1alpha1
|
||||||
|
kind: SealedSecret
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
sealedsecrets.bitnami.com/cluster-wide: "true"
|
||||||
|
name: public-mcp-secret
|
||||||
|
namespace: keycloak
|
||||||
|
spec:
|
||||||
|
encryptedData:
|
||||||
|
client-id: AgANqLN6opyrUHiqVaUKvHwUr4chY38qb03WxUzXWll6SDh7bRvHcZ3wAMHfsmigEz2cSWVMWg0VmEcP16r6gcEiYGQ2/Ol182oXbtI/bWad/3rFFzMlLrKie8H9oGS/LgyRyhEiQ2hDzsdAJWARdHrRhbpFvJ1QeUJtcIBGKy8CcjTm8YfW7u/IqNyo0X+NIK2vImO9UdrmzIIDwQav0e30dRkmtbL5lamR563Qa1k4alEdOTF/E2fe6OVxaIqjpbzHnjmbKRA1ymhYGOasm8hTUeE/IVicAZNeQAg0ps31PSHpwjnEzyDZ1k7p5Dvc4+RhNXhOmONnI38/EbTA0dXra2ZeRxdcmErGrN2KrVZmlxyBK3462z8yWbiGU4esAdHJAdAjBkD+sDP2jYIsy7wvzArYM/hbFqDBrLs9vf29bYyUfRoRo/0BS+iO06zBjr0ssUT95FBrs1RLXDJUaomFkylz32L+jLfalKc4N1xeIwA76VOk4m3lVllmZP0YFC/mifHJ6qzuOgJqBw8fTkYhASiwyfsbbk3c8f4VlHqvXPKhJKkJvaUMMve59XpKuVX8O3phW2nJG4hl86OVkfOQRIZgPqn6t5UiHyJCPv6JoxAITs40thG06QUn263MTyZyaNGw9/PPVmSO/O5N2DIElWl75FpAEg3fqsljJiq2NGVQWLmT3C7tdyUwDEuu0r91cQmfUY7EehBD
|
||||||
|
client-secret: AgCCe5CH8xoDedXE9iM4GGEw/K7LhdXzH3lPynjlJ85OdMLuM6yYkaN37xF9FbdwhkQQnX3pjM08ILjEnpWtIx8zNmzTl+U90sSo85YqbSyZcNK7uy3oCTaRB6sdtPmdcDWEjtUcvv7+2WZcnAH8IfpT7wpesrjkO7uND0ZFX2bqhR26goq40gSiNahfCLp5QkZlsnTb6r6uw2N0utOLFDp3m233Nh268kxamlvr8E1IYDZFBC8KDIz9rfKvuMNBV6CA++FDeYybS1WNkgK3hQ+tGRVy5L7zB6x06zKzh4UIBn1t9sEga1x2ZH2Szgcb6EgBXmQ3rFaJ7O52dUltLV4GHX4uqRmjj+aZFQQuaJuvgp1Dc0rhFFwKveH5R0VcEarSDHeRlQmPiszKTsk8tgfCw8U64uoe6ACPq0isWVYBvUxttm/nB3MNSEl3TOquw9UtsiV1CaqC5LpI4qO1EatpARF57uqxw1Ewl8e8WrcBQ3WlI+7kjsJ2jHODx8sTlByqW7PZeJB4pk8sIq3NXA4VK/7f+852itxE0R7S67nZ4xFi75V6omyaEcniDVaPzxoC6EiFsPrUj8QpA+eRlKZRFTS4fmQRUkKVGYEnSWxDTkM1ot5dPx1MkA6MsEwq7wiuZwIbXeLK9Z3NqqsJ5LyTwidXhim5vf4iMHqH6Fj9ZL0RZTjMqfLXSjDD+Tu9qwMnXfkZx6EMsOLKc5uz73lP2VpGoUyq9ndqHsEbqYjbHQ==
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
|
||||||
|
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
|
||||||
|
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: keycloak, toolhive-system
|
||||||
|
sealedsecrets.bitnami.com/cluster-wide: "true"
|
||||||
|
sealedsecrets.bitnami.com/managed: "true"
|
||||||
|
name: public-mcp-secret
|
||||||
|
namespace: keycloak
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
apiVersion: toolhive.stacklok.dev/v1alpha1
|
apiVersion: toolhive.stacklok.dev/v1beta1
|
||||||
kind: VirtualMCPServer
|
kind: VirtualMCPServer
|
||||||
metadata:
|
metadata:
|
||||||
name: dev-safe-vmcp
|
name: dev-safe-vmcp
|
||||||
|
|||||||
@@ -5,10 +5,10 @@ metadata:
|
|||||||
namespace: toolhive-system
|
namespace: toolhive-system
|
||||||
labels:
|
labels:
|
||||||
app.kubernetes.io/name: full-vmcp
|
app.kubernetes.io/name: full-vmcp
|
||||||
annotations:
|
# annotations:
|
||||||
dns.public: 'true'
|
# dns.public: 'false'
|
||||||
dns.public.access.policy: google-ws
|
# dns.public.access.policy: google-ws
|
||||||
dns.public.hostname: full-vmcp.olb42.com
|
# dns.public.hostname: full-vmcp.olb42.com
|
||||||
spec:
|
spec:
|
||||||
entryPoints:
|
entryPoints:
|
||||||
- websecure
|
- websecure
|
||||||
|
|||||||
@@ -0,0 +1,30 @@
|
|||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: full-vmcp-ngorse-ingress
|
||||||
|
namespace: toolhive-system
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: full-vmcp
|
||||||
|
annotations:
|
||||||
|
dns.internal: 'true'
|
||||||
|
dns.internal.hostname: full-vmcp.ngorse.com
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- kind: Rule
|
||||||
|
match: Host(`mcp.ngorse.com`)
|
||||||
|
services:
|
||||||
|
- name: vmcp-full-vmcp
|
||||||
|
namespace: toolhive-system
|
||||||
|
port: 4483
|
||||||
|
- kind: Rule
|
||||||
|
match: Host(`full-vmcp.ngorse.com`)
|
||||||
|
services:
|
||||||
|
- name: vmcp-full-vmcp
|
||||||
|
namespace: toolhive-system
|
||||||
|
port: 4483
|
||||||
|
# No default TLSStore in this cluster, so reference the wildcard cert
|
||||||
|
# explicitly. olb42-wildcard-tls is auto-reflected into every namespace.
|
||||||
|
tls:
|
||||||
|
secretName: ngorse-wildcard-tls
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
apiVersion: toolhive.stacklok.dev/v1alpha1
|
apiVersion: toolhive.stacklok.dev/v1beta1
|
||||||
kind: VirtualMCPServer
|
kind: VirtualMCPServer
|
||||||
metadata:
|
metadata:
|
||||||
name: full-vmcp
|
name: full-vmcp
|
||||||
@@ -7,14 +7,31 @@ metadata:
|
|||||||
toolhive.stacklok.dev/registry-export: "true"
|
toolhive.stacklok.dev/registry-export: "true"
|
||||||
toolhive.stacklok.dev/registry-title: Full Homelab Virtual MCP
|
toolhive.stacklok.dev/registry-title: Full Homelab Virtual MCP
|
||||||
toolhive.stacklok.dev/registry-description: Full virtual MCP exposing the homelab MCP tool group through ToolHive aggregation.
|
toolhive.stacklok.dev/registry-description: Full virtual MCP exposing the homelab MCP tool group through ToolHive aggregation.
|
||||||
toolhive.stacklok.dev/registry-url: http://vmcp-full-vmcp.toolhive-system.svc.cluster.local:4483
|
toolhive.stacklok.dev/registry-url: https://mcp.ngorse.com
|
||||||
|
glance/parent: toolhive
|
||||||
spec:
|
spec:
|
||||||
groupRef:
|
groupRef:
|
||||||
name: homelab-core
|
name: homelab-core
|
||||||
|
podTemplateSpec:
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
glance/parent: toolhive
|
||||||
embeddingServerRef:
|
embeddingServerRef:
|
||||||
name: homelab-embedding
|
name: homelab-embedding
|
||||||
incomingAuth:
|
incomingAuth:
|
||||||
type: anonymous
|
type: oidc
|
||||||
|
oidcConfigRef:
|
||||||
|
name: public-mcp-oidc
|
||||||
|
audience: http://full-vmcp.toolhive-system.svc.cluster.local:4483
|
||||||
|
authServerConfig:
|
||||||
|
issuer: https://mcp.ngorse.com
|
||||||
|
upstreamProviders:
|
||||||
|
- name: keycloak
|
||||||
|
type: oidc
|
||||||
|
oidcConfig:
|
||||||
|
issuerUrl: https://cloak.olb42.com/realms/home-lab
|
||||||
|
clientId: public-mcp
|
||||||
|
redirectUri: https://mcp.ngorse.com/oauth/callback
|
||||||
config:
|
config:
|
||||||
aggregation:
|
aggregation:
|
||||||
conflictResolution: prefix
|
conflictResolution: prefix
|
||||||
|
|||||||
@@ -4,9 +4,16 @@ kind: Kustomization
|
|||||||
namespace: toolhive-system
|
namespace: toolhive-system
|
||||||
|
|
||||||
resources:
|
resources:
|
||||||
|
- oidcconfig-public-mcp.yaml
|
||||||
|
- oidcconfig-state-docs-vmcp.yaml
|
||||||
- full-vmcp.yaml
|
- full-vmcp.yaml
|
||||||
- full-vmcp-ingress.yaml
|
- full-vmcp-ingress.yaml
|
||||||
|
- full-vmcp-ngorse-ingress.yaml
|
||||||
- dev-safe-vmcp.yaml
|
- dev-safe-vmcp.yaml
|
||||||
- dev-safe-vmcp-ingress.yaml
|
- dev-safe-vmcp-ingress.yaml
|
||||||
- ops-safe-vmcp.yaml
|
- ops-safe-vmcp.yaml
|
||||||
- ops-safe-vmcp-ingress.yaml
|
- ops-safe-vmcp-ingress.yaml
|
||||||
|
- state-docs-vmcp.yaml
|
||||||
|
- state-docs-vmcp-ingress.yaml
|
||||||
|
- state-docs-ngorse-ingress.yaml
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,13 @@
|
|||||||
|
apiVersion: toolhive.stacklok.dev/v1beta1
|
||||||
|
kind: MCPOIDCConfig
|
||||||
|
metadata:
|
||||||
|
name: public-mcp-oidc
|
||||||
|
namespace: toolhive-system
|
||||||
|
spec:
|
||||||
|
type: inline
|
||||||
|
inline:
|
||||||
|
issuer: https://mcp.ngorse.com
|
||||||
|
clientId: public-mcp
|
||||||
|
clientSecretRef:
|
||||||
|
name: public-mcp-secret
|
||||||
|
key: client-secret
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
apiVersion: toolhive.stacklok.dev/v1beta1
|
||||||
|
kind: MCPOIDCConfig
|
||||||
|
metadata:
|
||||||
|
name: state-docs-vmcp-oidc
|
||||||
|
namespace: toolhive-system
|
||||||
|
spec:
|
||||||
|
type: inline
|
||||||
|
inline:
|
||||||
|
issuer: https://state-docs.ngorse.com
|
||||||
|
clientId: state-docs-vmcp
|
||||||
|
clientSecretRef:
|
||||||
|
name: state-docs-vmcp-secret
|
||||||
|
key: client-secret
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
apiVersion: toolhive.stacklok.dev/v1alpha1
|
apiVersion: toolhive.stacklok.dev/v1beta1
|
||||||
kind: VirtualMCPServer
|
kind: VirtualMCPServer
|
||||||
metadata:
|
metadata:
|
||||||
name: ops-safe-vmcp
|
name: ops-safe-vmcp
|
||||||
|
|||||||
@@ -0,0 +1,24 @@
|
|||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: state-docs-vmcp-ngorse-ingress
|
||||||
|
namespace: toolhive-system
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: state-docs-vmcp
|
||||||
|
annotations:
|
||||||
|
dns.internal: 'true'
|
||||||
|
dns.internal.hostname: state-docs.ngorse.com
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- kind: Rule
|
||||||
|
match: Host(`state-docs.ngorse.com`)
|
||||||
|
services:
|
||||||
|
- name: vmcp-state-docs-vmcp
|
||||||
|
namespace: toolhive-system
|
||||||
|
port: 4483
|
||||||
|
# No default TLSStore in this cluster, so reference the wildcard cert
|
||||||
|
# explicitly. olb42-wildcard-tls is auto-reflected into every namespace.
|
||||||
|
tls:
|
||||||
|
secretName: ngorse-wildcard-tls
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: state-docs-vmcp-ingress
|
||||||
|
namespace: toolhive-system
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: state-docs-vmcp
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- kind: Rule
|
||||||
|
match: Host(`state-docs.olb42.com`)
|
||||||
|
services:
|
||||||
|
- name: vmcp-state-docs-vmcp
|
||||||
|
namespace: toolhive-system
|
||||||
|
port: 4483
|
||||||
|
# No default TLSStore in this cluster, so reference the wildcard cert
|
||||||
|
# explicitly. olb42-wildcard-tls is auto-reflected into every namespace.
|
||||||
|
tls:
|
||||||
|
secretName: olb42-wildcard-tls
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
apiVersion: toolhive.stacklok.dev/v1beta1
|
||||||
|
kind: VirtualMCPServer
|
||||||
|
metadata:
|
||||||
|
name: state-docs-vmcp
|
||||||
|
namespace: toolhive-system
|
||||||
|
annotations:
|
||||||
|
toolhive.stacklok.dev/registry-export: "true"
|
||||||
|
toolhive.stacklok.dev/registry-title: Document State Virtual MCP
|
||||||
|
toolhive.stacklok.dev/registry-description: Virtual MCP which is focused on enabling documentation of the current state
|
||||||
|
toolhive.stacklok.dev/registry-url: https://state-docs.ngorse.com
|
||||||
|
spec:
|
||||||
|
groupRef:
|
||||||
|
name: homelab-core
|
||||||
|
embeddingServerRef:
|
||||||
|
name: homelab-embedding
|
||||||
|
incomingAuth:
|
||||||
|
type: anonymous
|
||||||
|
config:
|
||||||
|
aggregation:
|
||||||
|
conflictResolution: prefix
|
||||||
|
excludeAllTools: false
|
||||||
|
tools:
|
||||||
|
- workload: gitea-mcp
|
||||||
|
toolConfigRef:
|
||||||
|
name: state-doc-tools
|
||||||
|
- workload: automem
|
||||||
|
toolConfigRef:
|
||||||
|
name: state-doc-tools
|
||||||
|
- workload: argocd-mcp
|
||||||
|
toolConfigRef:
|
||||||
|
name: state-doc-tools
|
||||||
|
- workload: kubernetes-mcp
|
||||||
|
toolConfigRef:
|
||||||
|
name: state-doc-tools
|
||||||
|
- workload: radar
|
||||||
|
excludeAll: true
|
||||||
|
compositeTools: []
|
||||||
|
operational:
|
||||||
|
failureHandling:
|
||||||
|
partialFailureMode: best_effort
|
||||||
Reference in New Issue
Block a user