Files
toolhive/manifest/overlays/production/vmcp-servers/state-docs-vmcp.yaml
T
olb042andClaude Sonnet 4.6 b497211278 add OIDC auth to state-docs-vmcp VirtualMCPServer
Switch incomingAuth from anonymous to oidc, wiring Keycloak (home-lab realm
at cloak.olb42.com) as the provider with clientId state-docs-vmcp. Secret
ref (state-docs-vmcp-secret, key: client-secret) is added to kustomization
as a TODO comment pending the sealed secret creation.

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
2026-06-14 16:55:43 +00:00

47 lines
1.4 KiB
YAML

apiVersion: toolhive.stacklok.dev/v1alpha1
kind: VirtualMCPServer
metadata:
name: state-docs-vmcp
namespace: toolhive-system
annotations:
toolhive.stacklok.dev/registry-export: "true"
toolhive.stacklok.dev/registry-title: Document State Virtual MCP
toolhive.stacklok.dev/registry-description: Virtual MCP which is focused on enabling documentation of the current state
toolhive.stacklok.dev/registry-url: https://state-docs.ngorse.com
spec:
groupRef:
name: homelab-core
embeddingServerRef:
name: homelab-embedding
incomingAuth:
type: oidc
oidc:
issuerUrl: https://cloak.olb42.com/realms/home-lab
clientId: state-docs-vmcp
clientSecretRef:
name: state-docs-vmcp-secret
key: client-secret
config:
aggregation:
conflictResolution: prefix
excludeAllTools: false
tools:
- workload: gitea-mcp
toolConfigRef:
name: state-doc-tools
- workload: automem
toolConfigRef:
name: state-doc-tools
- workload: argocd-mcp
toolConfigRef:
name: state-doc-tools
- workload: kubernetes-mcp
toolConfigRef:
name: state-doc-tools
- workload: radar
excludeAll: true
compositeTools: []
operational:
failureHandling:
partialFailureMode: best_effort