The .spec.incomingAuth.oidc inline block is not a valid field in the v0.29.3 VirtualMCPServer CRD schema, causing ArgoCD ComparisonErrors. The correct v0.29.3 API separates OIDC provider config into a dedicated MCPOIDCConfig (v1beta1) resource, referenced from the VirtualMCPServer via spec.incomingAuth.oidcConfigRef.name. - Add MCPOIDCConfig resources for state-docs-vmcp and full-vmcp (inline type, Keycloak issuer, replicated client secrets from keycloak ns) - Update state-docs-vmcp and full-vmcp VirtualMCPServer manifests to reference the new MCPOIDCConfig resources via oidcConfigRef - Register new MCPOIDCConfig files in vmcp-servers kustomization Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
14 lines
324 B
YAML
14 lines
324 B
YAML
apiVersion: toolhive.stacklok.dev/v1beta1
|
|
kind: MCPOIDCConfig
|
|
metadata:
|
|
name: full-vmcp-oidc
|
|
namespace: toolhive-system
|
|
spec:
|
|
type: inline
|
|
inline:
|
|
issuer: https://cloak.olb42.com/realms/home-lab
|
|
clientId: toolhive-full-vmcp
|
|
clientSecretRef:
|
|
name: toolhive-full-vmcp-secret
|
|
key: client-secret
|