Files
toolhive/manifest/overlays/production/mcpserver-kubernetes.yaml
T
2026-06-01 11:36:22 +01:00

37 lines
1.1 KiB
YAML

apiVersion: toolhive.stacklok.dev/v1beta1
kind: MCPServer
metadata:
name: kubernetes-mcp
namespace: toolhive-system
spec:
# containers/kubernetes-mcp-server. Authenticates to the API in-cluster via the
# kubernetes-mcp ServiceAccount (read-only ClusterRole, see rbac file). Speaks
# stdio; ToolHive proxies to streamable-http at
# http://mcp-kubernetes-mcp-proxy.mcp-services:8080/mcp.
image: ghcr.io/containers/kubernetes-mcp-server:latest
transport: stdio
# The current image's default CMD starts HTTP mode with `--port 8080`.
# Override args so ToolHive's stdio proxy talks to a stdio MCP server.
args:
- --log-file
- stderr
- --read-only
- --disable-destructive
proxyMode: streamable-http
proxyPort: 8080
groupRef:
name: homelab-core
# Pin the MCP server pod to our read-only ServiceAccount. The ClusterRole is
# the real guardrail: even if a write tool is invoked, the API rejects it.
serviceAccount: kubernetes-mcp
permissionProfile:
type: builtin
name: network
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 512Mi