spec.incomingAuth.oidcConfigRef.audience is Required by the CRD validator. Set to the Keycloak client ID for each server (unique per server as required to prevent token replay attacks). Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
44 lines
1.3 KiB
YAML
44 lines
1.3 KiB
YAML
apiVersion: toolhive.stacklok.dev/v1alpha1
|
|
kind: VirtualMCPServer
|
|
metadata:
|
|
name: state-docs-vmcp
|
|
namespace: toolhive-system
|
|
annotations:
|
|
toolhive.stacklok.dev/registry-export: "true"
|
|
toolhive.stacklok.dev/registry-title: Document State Virtual MCP
|
|
toolhive.stacklok.dev/registry-description: Virtual MCP which is focused on enabling documentation of the current state
|
|
toolhive.stacklok.dev/registry-url: https://state-docs.ngorse.com
|
|
spec:
|
|
groupRef:
|
|
name: homelab-core
|
|
embeddingServerRef:
|
|
name: homelab-embedding
|
|
incomingAuth:
|
|
type: oidc
|
|
oidcConfigRef:
|
|
name: state-docs-vmcp-oidc
|
|
audience: state-docs-vmcp
|
|
config:
|
|
aggregation:
|
|
conflictResolution: prefix
|
|
excludeAllTools: false
|
|
tools:
|
|
- workload: gitea-mcp
|
|
toolConfigRef:
|
|
name: state-doc-tools
|
|
- workload: automem
|
|
toolConfigRef:
|
|
name: state-doc-tools
|
|
- workload: argocd-mcp
|
|
toolConfigRef:
|
|
name: state-doc-tools
|
|
- workload: kubernetes-mcp
|
|
toolConfigRef:
|
|
name: state-doc-tools
|
|
- workload: radar
|
|
excludeAll: true
|
|
compositeTools: []
|
|
operational:
|
|
failureHandling:
|
|
partialFailureMode: best_effort
|