53 lines
1.6 KiB
YAML
53 lines
1.6 KiB
YAML
apiVersion: traefik.io/v1alpha1
|
|
kind: IngressRoute
|
|
metadata:
|
|
name: mcp-services
|
|
namespace: toolhive-system
|
|
labels:
|
|
app.kubernetes.io/name: mcp-services
|
|
spec:
|
|
entryPoints:
|
|
- websecure
|
|
routes:
|
|
# MCP is a programmatic protocol — interactive OIDC login would break the
|
|
# clients, so access is gated at the network layer with the shared lan-only
|
|
# ipAllowList middleware (192.168/16, 10/8, 172.16/12). For per-user token
|
|
# auth, set spec.oidcConfigRef on each MCPServer instead.
|
|
- kind: Rule
|
|
match: Host(`gitea-mcp.olb42.com`)
|
|
middlewares:
|
|
- name: lan-only
|
|
namespace: infra
|
|
services:
|
|
- name: mcp-gitea-mcp-proxy
|
|
namespace: toolhive-system
|
|
port: 8080
|
|
- kind: Rule
|
|
match: Host(`argocd-mcp.olb42.com`)
|
|
middlewares:
|
|
- name: lan-only
|
|
namespace: infra
|
|
services:
|
|
- name: mcp-argocd-mcp-proxy
|
|
namespace: toolhive-system
|
|
port: 8080
|
|
- kind: Rule
|
|
match: Host(`kubernetes-mcp.olb42.com`)
|
|
middlewares:
|
|
- name: lan-only
|
|
namespace: infra
|
|
services:
|
|
- name: mcp-kubernetes-mcp-proxy
|
|
namespace: toolhive-system
|
|
port: 8080
|
|
- kind: Rule
|
|
match: Host(`thv-registry.olb42.com`)
|
|
services:
|
|
- name: k8s-registry-api
|
|
namespace: toolhive-system
|
|
port: 8080
|
|
# No default TLSStore in this cluster, so reference the wildcard cert
|
|
# explicitly. olb42-wildcard-tls is auto-reflected into every namespace.
|
|
tls:
|
|
secretName: olb42-wildcard-tls
|