Files
toolhive/manifest/overlays/production/ingressroute.yaml
T
2026-05-30 19:53:10 +01:00

47 lines
1.4 KiB
YAML

apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: mcp-services
namespace: toolhive-system
labels:
app.kubernetes.io/name: mcp-services
spec:
entryPoints:
- websecure
routes:
# MCP is a programmatic protocol — interactive OIDC login would break the
# clients, so access is gated at the network layer with the shared lan-only
# ipAllowList middleware (192.168/16, 10/8, 172.16/12). For per-user token
# auth, set spec.oidcConfigRef on each MCPServer instead.
- kind: Rule
match: Host(`gitea-mcp.olb42.com`)
middlewares:
- name: lan-only
namespace: infra
services:
- name: mcp-gitea-mcp-proxy
namespace: toolhive-system
port: 8080
- kind: Rule
match: Host(`argocd-mcp.olb42.com`)
middlewares:
- name: lan-only
namespace: infra
services:
- name: mcp-argocd-mcp-proxy
namespace: toolhive-system
port: 8080
- kind: Rule
match: Host(`kubernetes-mcp.olb42.com`)
middlewares:
- name: lan-only
namespace: infra
services:
- name: mcp-kubernetes-mcp-proxy
namespace: toolhive-system
port: 8080
# No default TLSStore in this cluster, so reference the wildcard cert
# explicitly. olb42-wildcard-tls is auto-reflected into every namespace.
tls:
secretName: olb42-wildcard-tls