olb042andClaude Sonnet 4.6 ad0e5df277 fix: add required audience field to oidcConfigRef on both VirtualMCPServers
spec.incomingAuth.oidcConfigRef.audience is Required by the CRD validator.
Set to the Keycloak client ID for each server (unique per server as required
to prevent token replay attacks).

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
2026-06-15 13:34:33 +00:00
2026-05-30 19:52:57 +01:00
2026-05-29 14:05:41 +01:00

toolhive

Installs the ToolHive Kubernetes operator via Argo CD, so MCP servers can be declared as MCPServer custom resources (see the mcp-services app). Runs in the toolhive-system namespace.

What it deploys

A multi-source Argo CD Application renders two OCI Helm charts plus this repo's values:

Source Purpose
oci://ghcr.io/stacklok/toolhive/toolhive-operator-crds CRDs (MCPServer, MCPRegistry, …)
oci://ghcr.io/stacklok/toolhive/toolhive-operator operator Deployment + RBAC
this repo (ref: values) operator Helm values

Both charts share a unified version, pinned via chartVersion in bootstrap/applicationset.yaml (currently 0.28.3). RBAC scope is left cluster (chart default) so the operator can reconcile MCPServers in mcp-services.

Deploy

# validate the operator chart renders with our values
helm template toolhive-operator oci://ghcr.io/stacklok/toolhive/toolhive-operator \
  --version 0.28.3 -n toolhive-system \
  -f manifest/overlays/production/helm-values/values.yaml >/dev/null

# enable bootstrap/config.yaml (enabled: true), commit, push to main, then:
kubectl get pods -n toolhive-system
kubectl get crd | grep toolhive.stacklok.dev

Deploy this app before mcp-services — the MCPServer CRs depend on the CRDs installed here.

Bumping the version

curl -s 'https://api.github.com/repos/stacklok/toolhive/releases?per_page=10' \
  | grep tag_name

Update chartVersion in bootstrap/applicationset.yaml and push. (The CRDs and operator charts are released together under the same version number.)

S
Description
ToolHive operator install (GitOps, ArgoCD)
Readme
146 KiB