apiVersion: toolhive.stacklok.dev/v1beta1 kind: MCPServer metadata: name: argocd-mcp namespace: toolhive-system annotations: toolhive.stacklok.dev/registry-export: "true" toolhive.stacklok.dev/registry-title: Argo CD MCP toolhive.stacklok.dev/registry-description: Read-only Argo CD MCP server for inspecting homelab GitOps applications and resources. toolhive.stacklok.dev/registry-url: http://mcp-argocd-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp glance/parent: argocd spec: # argoproj-labs MCP server for Argo CD. v0.7.0 starts streamable HTTP on # port 3000 by default; setting args: ["stdio"] makes the image try to run # /app/stdio and crash. image: ghcr.io/argoproj-labs/mcp-for-argocd:v0.7.0 transport: streamable-http mcpPort: 3000 groupRef: name: homelab-core env: - name: ARGOCD_BASE_URL value: http://argocd-server.argocd # argocd-server serves a self-signed cert in-cluster. - name: NODE_TLS_REJECT_UNAUTHORIZED value: "0" # Start read-only; drop this to enable sync/write tools later. - name: MCP_READ_ONLY value: "true" # ToolHive 0.28.3 does not translate spec.secrets into the workload, so inject # the token natively on the `mcp` container via podTemplateSpec. resourceOverrides: proxyDeployment: annotations: glance/parent: argocd podTemplateSpec: metadata: annotations: glance/parent: argocd spec: groupRef: name: homelab-core containers: - name: mcp env: - name: ARGOCD_API_TOKEN valueFrom: secretKeyRef: name: argocd-mcp-secret key: token permissionProfile: type: builtin name: network resources: requests: cpu: 100m memory: 128Mi limits: cpu: 500m memory: 512Mi