- full-vmcp serves as public entry point at mcp.ngorse.com - Single Keycloak client (public-mcp) for all external tools - authServerConfig proxies auth to Keycloak - state-docs-vmcp becomes internal-only (no auth required) - Shared OIDC config for token validation - All external clients authenticate once at gateway
38 lines
1.0 KiB
YAML
38 lines
1.0 KiB
YAML
apiVersion: toolhive.stacklok.dev/v1beta1
|
|
kind: VirtualMCPServer
|
|
metadata:
|
|
name: full-vmcp
|
|
namespace: toolhive-system
|
|
annotations:
|
|
toolhive.stacklok.dev/registry-export: "true"
|
|
toolhive.stacklok.dev/registry-title: Full Homelab Virtual MCP
|
|
toolhive.stacklok.dev/registry-description: Full virtual MCP exposing the homelab MCP tool group through ToolHive aggregation.
|
|
toolhive.stacklok.dev/registry-url: https://vmcp-full-vmcp.ngorse.com
|
|
glance/parent: toolhive
|
|
spec:
|
|
groupRef:
|
|
name: homelab-core
|
|
podTemplateSpec:
|
|
metadata:
|
|
annotations:
|
|
glance/parent: toolhive
|
|
embeddingServerRef:
|
|
name: homelab-embedding
|
|
incomingAuth:
|
|
type: oidc
|
|
oidcConfigRef:
|
|
name: public-mcp-oidc
|
|
authServerConfig:
|
|
issuer: https://mcp.ngorse.com
|
|
upstreamProviders:
|
|
- name: keycloak
|
|
type: oidc
|
|
oidcConfig:
|
|
issuerUrl: https://cloak.olb42.com/realms/home-lab
|
|
clientId: public-mcp
|
|
config:
|
|
aggregation:
|
|
conflictResolution: prefix
|
|
optimizer:
|
|
maxToolsToReturn: 8
|