Files
toolhive/manifest/overlays/production/mcp-servers/mcpserver-argocd.yaml
T
2026-06-05 16:25:10 +01:00

58 lines
1.8 KiB
YAML

apiVersion: toolhive.stacklok.dev/v1beta1
kind: MCPServer
metadata:
name: argocd-mcp
namespace: toolhive-system
annotations:
toolhive.stacklok.dev/registry-export: "true"
toolhive.stacklok.dev/registry-title: Argo CD MCP
toolhive.stacklok.dev/registry-description: Read-only Argo CD MCP server for inspecting homelab GitOps applications and resources.
toolhive.stacklok.dev/registry-url: http://mcp-argocd-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp
glance/parent: gitea
spec:
# argoproj-labs MCP server for Argo CD. v0.7.0 starts streamable HTTP on
# port 3000 by default; setting args: ["stdio"] makes the image try to run
# /app/stdio and crash.
image: ghcr.io/argoproj-labs/mcp-for-argocd:v0.7.0
transport: streamable-http
mcpPort: 3000
groupRef:
name: homelab-core
env:
- name: ARGOCD_BASE_URL
value: http://argocd-server.argocd
# argocd-server serves a self-signed cert in-cluster.
- name: NODE_TLS_REJECT_UNAUTHORIZED
value: "0"
# Start read-only; drop this to enable sync/write tools later.
- name: MCP_READ_ONLY
value: "true"
# ToolHive 0.28.3 does not translate spec.secrets into the workload, so inject
# the token natively on the `mcp` container via podTemplateSpec.
resourceOverrides:
proxyDeployment:
annotations:
glance/parent: argocd
podTemplateSpec:
spec:
groupRef:
name: homelab-core
containers:
- name: mcp
env:
- name: ARGOCD_API_TOKEN
valueFrom:
secretKeyRef:
name: argocd-mcp-secret
key: token
permissionProfile:
type: builtin
name: network
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 512Mi