3caeeb2997929cce3a599c41f4861d58c99c11d7
The .spec.incomingAuth.oidc inline block is not a valid field in the v0.29.3 VirtualMCPServer CRD schema, causing ArgoCD ComparisonErrors. The correct v0.29.3 API separates OIDC provider config into a dedicated MCPOIDCConfig (v1beta1) resource, referenced from the VirtualMCPServer via spec.incomingAuth.oidcConfigRef.name. - Add MCPOIDCConfig resources for state-docs-vmcp and full-vmcp (inline type, Keycloak issuer, replicated client secrets from keycloak ns) - Update state-docs-vmcp and full-vmcp VirtualMCPServer manifests to reference the new MCPOIDCConfig resources via oidcConfigRef - Register new MCPOIDCConfig files in vmcp-servers kustomization Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
toolhive
Installs the ToolHive Kubernetes operator
via Argo CD, so MCP servers can be declared as MCPServer custom resources
(see the mcp-services app). Runs in the toolhive-system namespace.
What it deploys
A multi-source Argo CD Application renders two OCI Helm charts plus this repo's values:
| Source | Purpose |
|---|---|
oci://ghcr.io/stacklok/toolhive/toolhive-operator-crds |
CRDs (MCPServer, MCPRegistry, …) |
oci://ghcr.io/stacklok/toolhive/toolhive-operator |
operator Deployment + RBAC |
this repo (ref: values) |
operator Helm values |
Both charts share a unified version, pinned via chartVersion in
bootstrap/applicationset.yaml (currently 0.28.3). RBAC scope is left
cluster (chart default) so the operator can reconcile MCPServers in
mcp-services.
Deploy
# validate the operator chart renders with our values
helm template toolhive-operator oci://ghcr.io/stacklok/toolhive/toolhive-operator \
--version 0.28.3 -n toolhive-system \
-f manifest/overlays/production/helm-values/values.yaml >/dev/null
# enable bootstrap/config.yaml (enabled: true), commit, push to main, then:
kubectl get pods -n toolhive-system
kubectl get crd | grep toolhive.stacklok.dev
Deploy this app before mcp-services — the MCPServer CRs depend on the CRDs
installed here.
Bumping the version
curl -s 'https://api.github.com/repos/stacklok/toolhive/releases?per_page=10' \
| grep tag_name
Update chartVersion in bootstrap/applicationset.yaml and push. (The CRDs and
operator charts are released together under the same version number.)