Files
2026-06-02 21:16:35 +01:00

53 lines
1.6 KiB
YAML

apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: mcp-services
namespace: toolhive-system
labels:
app.kubernetes.io/name: mcp-services
spec:
entryPoints:
- websecure
routes:
# MCP is a programmatic protocol — interactive OIDC login would break the
# clients, so access is gated at the network layer with the shared lan-only
# ipAllowList middleware (192.168/16, 10/8, 172.16/12). For per-user token
# auth, set spec.oidcConfigRef on each MCPServer instead.
- kind: Rule
match: Host(`gitea-mcp.olb42.com`)
middlewares:
- name: lan-only
namespace: infra
services:
- name: mcp-gitea-mcp-proxy
namespace: toolhive-system
port: 8080
- kind: Rule
match: Host(`argocd-mcp.olb42.com`)
middlewares:
- name: lan-only
namespace: infra
services:
- name: mcp-argocd-mcp-proxy
namespace: toolhive-system
port: 8080
- kind: Rule
match: Host(`kubernetes-mcp.olb42.com`)
middlewares:
- name: lan-only
namespace: infra
services:
- name: mcp-kubernetes-mcp-proxy
namespace: toolhive-system
port: 8080
- kind: Rule
match: Host(`thv-registry.olb42.com`)
services:
- name: k8s-registry-api
namespace: toolhive-system
port: 8080
# No default TLSStore in this cluster, so reference the wildcard cert
# explicitly. olb42-wildcard-tls is auto-reflected into every namespace.
tls:
secretName: olb42-wildcard-tls