apiVersion: traefik.io/v1alpha1 kind: IngressRoute metadata: name: mcp-services namespace: mcp-services labels: app.kubernetes.io/name: mcp-services spec: entryPoints: - websecure routes: # MCP is a programmatic protocol — interactive OIDC login would break the # clients, so access is gated at the network layer with the shared lan-only # ipAllowList middleware (192.168/16, 10/8, 172.16/12). For per-user token # auth, set spec.oidcConfigRef on each MCPServer instead. - kind: Rule match: Host(`gitea-mcp.olb42.com`) middlewares: - name: lan-only namespace: infra services: - name: mcp-gitea-mcp-proxy namespace: toolhive-system port: 8080 - kind: Rule match: Host(`argocd-mcp.olb42.com`) middlewares: - name: lan-only namespace: infra services: - name: mcp-argocd-mcp-proxy namespace: toolhive-system port: 8080 - kind: Rule match: Host(`kubernetes-mcp.olb42.com`) middlewares: - name: lan-only namespace: infra services: - name: mcp-kubernetes-mcp-proxy namespace: toolhive-system port: 8080 # No default TLSStore in this cluster, so reference the wildcard cert # explicitly. olb42-wildcard-tls is auto-reflected into every namespace. tls: secretName: olb42-wildcard-tls