olb042andClaude Sonnet 4.6 3caeeb2997 fix: replace invalid incomingAuth.oidc with MCPOIDCConfig + oidcConfigRef
The .spec.incomingAuth.oidc inline block is not a valid field in the
v0.29.3 VirtualMCPServer CRD schema, causing ArgoCD ComparisonErrors.

The correct v0.29.3 API separates OIDC provider config into a dedicated
MCPOIDCConfig (v1beta1) resource, referenced from the VirtualMCPServer
via spec.incomingAuth.oidcConfigRef.name.

- Add MCPOIDCConfig resources for state-docs-vmcp and full-vmcp (inline
  type, Keycloak issuer, replicated client secrets from keycloak ns)
- Update state-docs-vmcp and full-vmcp VirtualMCPServer manifests to
  reference the new MCPOIDCConfig resources via oidcConfigRef
- Register new MCPOIDCConfig files in vmcp-servers kustomization

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
2026-06-15 13:31:45 +00:00
2026-05-30 19:52:57 +01:00
2026-05-29 14:05:41 +01:00

toolhive

Installs the ToolHive Kubernetes operator via Argo CD, so MCP servers can be declared as MCPServer custom resources (see the mcp-services app). Runs in the toolhive-system namespace.

What it deploys

A multi-source Argo CD Application renders two OCI Helm charts plus this repo's values:

Source Purpose
oci://ghcr.io/stacklok/toolhive/toolhive-operator-crds CRDs (MCPServer, MCPRegistry, …)
oci://ghcr.io/stacklok/toolhive/toolhive-operator operator Deployment + RBAC
this repo (ref: values) operator Helm values

Both charts share a unified version, pinned via chartVersion in bootstrap/applicationset.yaml (currently 0.28.3). RBAC scope is left cluster (chart default) so the operator can reconcile MCPServers in mcp-services.

Deploy

# validate the operator chart renders with our values
helm template toolhive-operator oci://ghcr.io/stacklok/toolhive/toolhive-operator \
  --version 0.28.3 -n toolhive-system \
  -f manifest/overlays/production/helm-values/values.yaml >/dev/null

# enable bootstrap/config.yaml (enabled: true), commit, push to main, then:
kubectl get pods -n toolhive-system
kubectl get crd | grep toolhive.stacklok.dev

Deploy this app before mcp-services — the MCPServer CRs depend on the CRDs installed here.

Bumping the version

curl -s 'https://api.github.com/repos/stacklok/toolhive/releases?per_page=10' \
  | grep tag_name

Update chartVersion in bootstrap/applicationset.yaml and push. (The CRDs and operator charts are released together under the same version number.)

S
Description
ToolHive operator install (GitOps, ArgoCD)
Readme
146 KiB