v1alpha1

package
v0.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 0 Imported by: 0

Documentation

Overview

Package v1alpha1 contains API Schema definitions for the MCP server resource.

Index

Constants

View Source
const (
	// Group is the Kubernetes API group for MCP Runtime resources.
	Group = "mcpruntime.org"
	// Version is the Kubernetes API version for MCP Runtime resources.
	Version = "v1alpha1"

	// MCPServerResource is the plural resource name for MCPServer objects.
	MCPServerResource = "mcpservers"
	// MCPAccessGrantResource is the plural resource name for MCPAccessGrant objects.
	MCPAccessGrantResource = "mcpaccessgrants"
	// MCPAgentSessionResource is the plural resource name for MCPAgentSession objects.
	MCPAgentSessionResource = "mcpagentsessions"
)

Variables

View Source
var (
	// GroupVersion is group version used to register these objects
	GroupVersion = schema.GroupVersion{Group: Group, Version: Version}

	// SchemeBuilder is used to add go types to the GroupVersionKind scheme
	SchemeBuilder = runtime.NewSchemeBuilder(addKnownTypes)

	// AddToScheme adds the types in this group-version to the given scheme.
	AddToScheme = SchemeBuilder.AddToScheme
)

Functions

func BoolPtr

func BoolPtr(v bool) *bool

BoolPtr returns a pointer to v for optional CRD boolean fields.

func EndpointUsesRetiredNamespace

func EndpointUsesRetiredNamespace(raw string) bool

EndpointUsesRetiredNamespace reports whether raw is a URL aimed at the removed combined platform namespace. Callers replace those values with the current service DNS. A collector outside that namespace is left unchanged.

func GatewayIsEnabled

func GatewayIsEnabled(gateway *GatewayConfig) bool

GatewayIsEnabled reports whether the MCP gateway sidecar should run. Omitted gateway, empty gateway: {}, and enabled: true all mean on. Only enabled: false opts out.

func ProtectedResourceMetadataURL

func ProtectedResourceMetadataURL(resource string) string

ProtectedResourceMetadataURL returns the RFC 9728 metadata document URL for a resource URL: the well-known prefix inserted between origin and path, the location a conforming client derives from the resource it connected to.

Types

type AnalyticsConfig

type AnalyticsConfig struct {
	// Disabled suppresses analytics emission from the gateway sidecar for this
	// server.
	Disabled bool `json:"disabled,omitempty"`

	// IngestURL is the analytics ingest endpoint. If empty, the operator may
	// supply its configured default ingest URL.
	IngestURL string `json:"ingestURL,omitempty"`

	// Source is the event source label attached to emitted analytics events.
	Source string `json:"source,omitempty"`

	// EventType is the event type label attached to emitted analytics events.
	EventType string `json:"eventType,omitempty"`

	// APIKeySecretRef points to a secret key containing the analytics API key.
	APIKeySecretRef *SecretKeyRef `json:"apiKeySecretRef,omitempty"`
}

AnalyticsConfig configures analytics emission from the gateway sidecar. +kubebuilder:object:generate=true

func (*AnalyticsConfig) DeepCopy

func (in *AnalyticsConfig) DeepCopy() *AnalyticsConfig

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AnalyticsConfig.

func (*AnalyticsConfig) DeepCopyInto

func (in *AnalyticsConfig) DeepCopyInto(out *AnalyticsConfig)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type AuthConfig

type AuthConfig struct {
	TokenHeader string `json:"tokenHeader,omitempty"`
	IssuerURL   string `json:"issuerURL,omitempty"`
	// Audience is the OAuth resource identifier tokens must be issued for and
	// that protected-resource metadata advertises. When
	// this is unset, it defaults to the public MCP URL built from the ingress
	// host (or MCP_DEFAULT_INGRESS_HOST on the operator), TLS setting, and path.
	Audience string `json:"audience,omitempty"`
}

AuthConfig configures OAuth authentication at the gateway. +kubebuilder:object:generate=true

func (*AuthConfig) DeepCopy

func (in *AuthConfig) DeepCopy() *AuthConfig

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AuthConfig.

func (*AuthConfig) DeepCopyInto

func (in *AuthConfig) DeepCopyInto(out *AuthConfig)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type EnvVar

type EnvVar struct {
	Name  string `json:"name"`
	Value string `json:"value"`
}

EnvVar represents a literal environment variable. +kubebuilder:object:generate=true

func (*EnvVar) DeepCopy

func (in *EnvVar) DeepCopy() *EnvVar

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new EnvVar.

func (*EnvVar) DeepCopyInto

func (in *EnvVar) DeepCopyInto(out *EnvVar)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type GatewayConfig

type GatewayConfig struct {
	// Enabled turns the gateway sidecar on or off. When nil/omitted the sidecar
	// is enabled (observability by default). Set to false to opt out.
	Enabled *bool `json:"enabled,omitempty"`

	// Image overrides the proxy container image for this server.
	Image string `json:"image,omitempty"`

	// Port is the port the gateway listens on inside the pod (defaults to 8091).
	Port int32 `json:"port,omitempty"`

	// UpstreamURL is the upstream URL the gateway proxies to.
	// Defaults to http://127.0.0.1:<spec.port>.
	UpstreamURL string `json:"upstreamURL,omitempty"`

	// StripPrefix removes a path prefix before forwarding to the upstream server.
	StripPrefix string `json:"stripPrefix,omitempty"`

	// Resources defines resource limits and requests for the gateway sidecar.
	Resources *ResourceRequirements `json:"resources,omitempty"`
}

GatewayConfig configures an optional MCP proxy sidecar for a server. +kubebuilder:object:generate=true

func (*GatewayConfig) DeepCopy

func (in *GatewayConfig) DeepCopy() *GatewayConfig

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new GatewayConfig.

func (*GatewayConfig) DeepCopyInto

func (in *GatewayConfig) DeepCopyInto(out *GatewayConfig)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type InventoryItem

type InventoryItem struct {
	Name        string            `json:"name"`
	Description string            `json:"description,omitempty"`
	Labels      map[string]string `json:"labels,omitempty"`
}

InventoryItem describes a named MCP prompt, resource, or task. +kubebuilder:object:generate=true

func (*InventoryItem) DeepCopy

func (in *InventoryItem) DeepCopy() *InventoryItem

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new InventoryItem.

func (*InventoryItem) DeepCopyInto

func (in *InventoryItem) DeepCopyInto(out *InventoryItem)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type MCPAccessGrant

type MCPAccessGrant struct {
	metav1.TypeMeta   `json:",inline"`
	metav1.ObjectMeta `json:"metadata,omitempty"`

	Spec   MCPAccessGrantSpec   `json:"spec,omitempty"`
	Status MCPAccessGrantStatus `json:"status,omitempty"`
}

MCPAccessGrant grants a human or agent access to an MCPServer.

func (*MCPAccessGrant) DeepCopy

func (in *MCPAccessGrant) DeepCopy() *MCPAccessGrant

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAccessGrant.

func (*MCPAccessGrant) DeepCopyInto

func (in *MCPAccessGrant) DeepCopyInto(out *MCPAccessGrant)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*MCPAccessGrant) DeepCopyObject

func (in *MCPAccessGrant) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

func (*MCPAccessGrant) SetupWebhookWithManager

func (r *MCPAccessGrant) SetupWebhookWithManager(mgr ctrl.Manager) error

func (*MCPAccessGrant) ValidateCreate

func (r *MCPAccessGrant) ValidateCreate() (admission.Warnings, error)

func (*MCPAccessGrant) ValidateDelete

func (r *MCPAccessGrant) ValidateDelete() (admission.Warnings, error)

func (*MCPAccessGrant) ValidateUpdate

func (r *MCPAccessGrant) ValidateUpdate(_ runtime.Object) (admission.Warnings, error)

type MCPAccessGrantList

type MCPAccessGrantList struct {
	metav1.TypeMeta `json:",inline"`
	metav1.ListMeta `json:"metadata,omitempty"`
	Items           []MCPAccessGrant `json:"items"`
}

MCPAccessGrantList contains a list of MCPAccessGrant.

func (*MCPAccessGrantList) DeepCopy

func (in *MCPAccessGrantList) DeepCopy() *MCPAccessGrantList

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAccessGrantList.

func (*MCPAccessGrantList) DeepCopyInto

func (in *MCPAccessGrantList) DeepCopyInto(out *MCPAccessGrantList)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*MCPAccessGrantList) DeepCopyObject

func (in *MCPAccessGrantList) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

type MCPAccessGrantSpec

type MCPAccessGrantSpec struct {
	ServerRef          ServerReference  `json:"serverRef"`
	Subject            SubjectRef       `json:"subject"`
	MaxTrust           TrustLevel       `json:"maxTrust,omitempty"`
	AllowedSideEffects []ToolSideEffect `json:"allowedSideEffects,omitempty"`
	PolicyVersion      string           `json:"policyVersion,omitempty"`
	Disabled           bool             `json:"disabled,omitempty"`
	ExpiresAt          *metav1.Time     `json:"expiresAt,omitempty"`
	ToolRules          []ToolRule       `json:"toolRules,omitempty"`
}

MCPAccessGrantSpec defines who can use which MCP server and with what trust ceiling. +kubebuilder:object:generate=true

func (*MCPAccessGrantSpec) DeepCopy

func (in *MCPAccessGrantSpec) DeepCopy() *MCPAccessGrantSpec

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAccessGrantSpec.

func (*MCPAccessGrantSpec) DeepCopyInto

func (in *MCPAccessGrantSpec) DeepCopyInto(out *MCPAccessGrantSpec)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type MCPAccessGrantStatus

type MCPAccessGrantStatus struct {
	Phase      string             `json:"phase,omitempty"`
	Message    string             `json:"message,omitempty"`
	Conditions []metav1.Condition `json:"conditions,omitempty"`
}

MCPAccessGrantStatus captures observed grant state. +kubebuilder:object:generate=true

func (*MCPAccessGrantStatus) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAccessGrantStatus.

func (*MCPAccessGrantStatus) DeepCopyInto

func (in *MCPAccessGrantStatus) DeepCopyInto(out *MCPAccessGrantStatus)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type MCPAgentSession

type MCPAgentSession struct {
	metav1.TypeMeta   `json:",inline"`
	metav1.ObjectMeta `json:"metadata,omitempty"`

	Spec   MCPAgentSessionSpec   `json:"spec,omitempty"`
	Status MCPAgentSessionStatus `json:"status,omitempty"`
}

MCPAgentSession stores consent and upstream token state for an agent session.

func (*MCPAgentSession) DeepCopy

func (in *MCPAgentSession) DeepCopy() *MCPAgentSession

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAgentSession.

func (*MCPAgentSession) DeepCopyInto

func (in *MCPAgentSession) DeepCopyInto(out *MCPAgentSession)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*MCPAgentSession) DeepCopyObject

func (in *MCPAgentSession) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

func (*MCPAgentSession) SetupWebhookWithManager

func (r *MCPAgentSession) SetupWebhookWithManager(mgr ctrl.Manager) error

func (*MCPAgentSession) ValidateCreate

func (r *MCPAgentSession) ValidateCreate() (admission.Warnings, error)

func (*MCPAgentSession) ValidateDelete

func (r *MCPAgentSession) ValidateDelete() (admission.Warnings, error)

func (*MCPAgentSession) ValidateUpdate

func (r *MCPAgentSession) ValidateUpdate(_ runtime.Object) (admission.Warnings, error)

type MCPAgentSessionList

type MCPAgentSessionList struct {
	metav1.TypeMeta `json:",inline"`
	metav1.ListMeta `json:"metadata,omitempty"`
	Items           []MCPAgentSession `json:"items"`
}

MCPAgentSessionList contains a list of MCPAgentSession.

func (*MCPAgentSessionList) DeepCopy

func (in *MCPAgentSessionList) DeepCopy() *MCPAgentSessionList

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAgentSessionList.

func (*MCPAgentSessionList) DeepCopyInto

func (in *MCPAgentSessionList) DeepCopyInto(out *MCPAgentSessionList)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*MCPAgentSessionList) DeepCopyObject

func (in *MCPAgentSessionList) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

type MCPAgentSessionSpec

type MCPAgentSessionSpec struct {
	ServerRef              ServerReference `json:"serverRef"`
	Subject                SubjectRef      `json:"subject"`
	ConsentedTrust         TrustLevel      `json:"consentedTrust,omitempty"`
	ExpiresAt              *metav1.Time    `json:"expiresAt,omitempty"`
	Revoked                bool            `json:"revoked,omitempty"`
	UpstreamTokenSecretRef *SecretKeyRef   `json:"upstreamTokenSecretRef,omitempty"`
	PolicyVersion          string          `json:"policyVersion,omitempty"`
}

MCPAgentSessionSpec defines a consented server-side agent session. +kubebuilder:object:generate=true

func (*MCPAgentSessionSpec) DeepCopy

func (in *MCPAgentSessionSpec) DeepCopy() *MCPAgentSessionSpec

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAgentSessionSpec.

func (*MCPAgentSessionSpec) DeepCopyInto

func (in *MCPAgentSessionSpec) DeepCopyInto(out *MCPAgentSessionSpec)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type MCPAgentSessionStatus

type MCPAgentSessionStatus struct {
	Phase      string             `json:"phase,omitempty"`
	Message    string             `json:"message,omitempty"`
	Conditions []metav1.Condition `json:"conditions,omitempty"`
}

MCPAgentSessionStatus captures observed session state. +kubebuilder:object:generate=true

func (*MCPAgentSessionStatus) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAgentSessionStatus.

func (*MCPAgentSessionStatus) DeepCopyInto

func (in *MCPAgentSessionStatus) DeepCopyInto(out *MCPAgentSessionStatus)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type MCPServer

type MCPServer struct {
	metav1.TypeMeta   `json:",inline"`
	metav1.ObjectMeta `json:"metadata,omitempty"`

	Spec   MCPServerSpec   `json:"spec,omitempty"`
	Status MCPServerStatus `json:"status,omitempty"`
}

MCPServer is the Schema for the mcpservers API.

func (*MCPServer) CanonicalResourceURL

func (r *MCPServer) CanonicalResourceURL(options PublicURLOptions) string

CanonicalResourceURL returns the MCP endpoint URL clients connect to, which is also the OAuth resource identifier (RFC 8707/9728) tokens must be issued for. It returns "" when the public host is unknown.

func (*MCPServer) DeepCopy

func (in *MCPServer) DeepCopy() *MCPServer

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPServer.

func (*MCPServer) DeepCopyInto

func (in *MCPServer) DeepCopyInto(out *MCPServer)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*MCPServer) DeepCopyObject

func (in *MCPServer) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

func (*MCPServer) Default

func (r *MCPServer) Default()

func (*MCPServer) DefaultWithOptions

func (r *MCPServer) DefaultWithOptions(options MCPServerDefaultOptions)

func (*MCPServer) EffectivePublicPath

func (r *MCPServer) EffectivePublicPath() string

EffectivePublicPath returns the path clients reach the MCP endpoint on: "/<publicPathPrefix>/mcp" for path-based routing, else spec.ingressPath.

func (*MCPServer) PublicBaseURL

func (r *MCPServer) PublicBaseURL(options PublicURLOptions) string

PublicBaseURL returns scheme://host for the server's public ingress, or "" when no host is known. Path-based servers leave spec.ingressHost empty (the ingress matches any host), so the operator-wide default host is used; the scheme follows the operator TLS default or the per-server Traefik TLS annotation, because the ingress, not the pod, terminates TLS.

func (*MCPServer) PublicIngressUsesTLS

func (r *MCPServer) PublicIngressUsesTLS(defaultTLS bool) bool

PublicIngressUsesTLS reports whether the server's ingress terminates TLS, either from the operator-wide default or an explicit Traefik annotation.

func (*MCPServer) ResolveDerivedAuth

func (r *MCPServer) ResolveDerivedAuth(options MCPServerDefaultOptions)

DefaultWithOptions applies MCPServer defaults, including operator-configured fallbacks when the webhook is registered by the operator manager. ResolveDerivedAuth fills an OAuth server's unset audience and issuer from platform state: the audience from the public URL the ingress serves, the issuer from the bundled authorization server. It is applied to the operator's in-memory copy on every reconcile and is never persisted by the admission webhook, so a later change to the host, path, TLS setting, or platform domain re-derives the values instead of leaving a stale copy in spec. Explicit values are kept.

func (*MCPServer) SetupWebhookWithManager

func (r *MCPServer) SetupWebhookWithManager(mgr ctrl.Manager) error

func (*MCPServer) SetupWebhookWithManagerWithOptions

func (r *MCPServer) SetupWebhookWithManagerWithOptions(mgr ctrl.Manager, options MCPServerDefaultOptions) error

func (*MCPServer) String

func (r *MCPServer) String() string

func (*MCPServer) ValidateCreate

func (r *MCPServer) ValidateCreate() (admission.Warnings, error)

func (*MCPServer) ValidateDelete

func (r *MCPServer) ValidateDelete() (admission.Warnings, error)

func (*MCPServer) ValidateResolvedAuth

func (r *MCPServer) ValidateResolvedAuth() error

ValidateResolvedAuth reports OAuth settings that are still missing after ResolveDerivedAuth. Admission cannot check this, because the values are derived later from operator state; the operator reports it on reconcile.

func (*MCPServer) ValidateUpdate

func (r *MCPServer) ValidateUpdate(_ runtime.Object) (admission.Warnings, error)

type MCPServerDefaultOptions

type MCPServerDefaultOptions struct {
	DefaultIngressHost        string
	DefaultIngressTLS         bool
	DefaultAnalyticsIngestURL string
	DefaultOAuthIssuerURL     string
}

MCPServerDefaultOptions holds operator-scoped values that the admission webhook can use while defaulting MCPServer objects.

func (*MCPServerDefaultOptions) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPServerDefaultOptions.

func (*MCPServerDefaultOptions) DeepCopyInto

func (in *MCPServerDefaultOptions) DeepCopyInto(out *MCPServerDefaultOptions)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type MCPServerList

type MCPServerList struct {
	metav1.TypeMeta `json:",inline"`
	metav1.ListMeta `json:"metadata,omitempty"`
	Items           []MCPServer `json:"items"`
}

MCPServerList contains a list of MCPServer.

func (*MCPServerList) DeepCopy

func (in *MCPServerList) DeepCopy() *MCPServerList

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPServerList.

func (*MCPServerList) DeepCopyInto

func (in *MCPServerList) DeepCopyInto(out *MCPServerList)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*MCPServerList) DeepCopyObject

func (in *MCPServerList) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

type MCPServerSpec

type MCPServerSpec struct {
	// TeamID is the stable platform team identifier that owns this server.
	// The operator renders it into gateway policy and analytics events.
	TeamID string `json:"teamID,omitempty"`

	// Description is a human-readable summary of what the MCP server provides.
	Description string `json:"description,omitempty"`

	// Image is the container image for the MCP server.
	Image string `json:"image"`

	// ImageTag is the tag of the container image (defaults to "latest").
	ImageTag string `json:"imageTag,omitempty"`

	// RegistryOverride, if set, overrides the registry portion of the image (e.g., registry.mcpruntime.com).
	RegistryOverride string `json:"registryOverride,omitempty"`

	// UseProvisionedRegistry tells the controller to use the provisioned registry (from operator env) for this server.
	UseProvisionedRegistry bool `json:"useProvisionedRegistry,omitempty"`

	// ImagePullSecrets are secrets to use for pulling the image.
	ImagePullSecrets []string `json:"imagePullSecrets,omitempty"`

	// Replicas is the number of desired replicas (defaults to 1).
	Replicas *int32 `json:"replicas,omitempty"`

	// Port is the port the container listens on (defaults to 8088).
	Port int32 `json:"port,omitempty"`

	// ServicePort is the port exposed by the service (defaults to 80).
	ServicePort int32 `json:"servicePort,omitempty"`

	// IngressPath is the path for the ingress route (defaults to /{name}/mcp).
	IngressPath string `json:"ingressPath,omitempty"`

	// IngressHost is the hostname for the ingress (required unless publicPathPrefix is set; defaults from MCP_DEFAULT_INGRESS_HOST env var if set on the operator).
	IngressHost string `json:"ingressHost,omitempty"`

	// PublicPathPrefix enables path-based public routing and is used to compute /<publicPathPrefix>/mcp.
	// When ingressHost is also set, the route is path-based under that host; otherwise it is hostless.
	PublicPathPrefix string `json:"publicPathPrefix,omitempty"`

	// IngressClass is the ingress class to use (e.g., "traefik", "nginx", "istio"). Defaults to "traefik".
	IngressClass string `json:"ingressClass,omitempty"`

	// IngressAnnotations are additional annotations for the ingress controller.
	IngressAnnotations map[string]string `json:"ingressAnnotations,omitempty"`

	// Resources defines resource limits and requests.
	Resources ResourceRequirements `json:"resources,omitempty"`

	// EnvVars are literal environment variables to pass to the container.
	EnvVars []EnvVar `json:"envVars,omitempty"`

	// SecretEnvVars are secret-backed environment variables to pass to the container.
	SecretEnvVars []SecretEnvVar `json:"secretEnvVars,omitempty"`

	// Tools describes the MCP tool inventory exposed by the server.
	Tools []ToolConfig `json:"tools,omitempty"`

	// Prompts describes the MCP prompt inventory exposed by the server.
	Prompts []InventoryItem `json:"prompts,omitempty"`

	// MCPResources describes the MCP resource inventory exposed by the server.
	MCPResources []InventoryItem `json:"mcpResources,omitempty"`

	// Tasks describes task templates or workflows exposed by the server.
	Tasks []InventoryItem `json:"tasks,omitempty"`

	// Auth enables optional OAuth authentication at the gateway when present.
	Auth *AuthConfig `json:"auth,omitempty"`

	// Policy configures gateway-side authorization behavior. When omitted, the
	// gateway runs in observe mode so metrics and analytics work without
	// grant/session enforcement. Set this field (for example allow-list + deny)
	// to require adapter identity and grants.
	Policy *PolicyConfig `json:"policy,omitempty"`

	// Session configures server-side agent session behavior.
	Session *SessionConfig `json:"session,omitempty"`

	// Gateway configures the MCP proxy sidecar in front of the server container.
	// When omitted or left empty, the sidecar is enabled so metrics, traces, and
	// analytics can run. Set gateway.enabled to false to opt out.
	Gateway *GatewayConfig `json:"gateway,omitempty"`

	// Analytics configures audit/analytics emission for the gateway sidecar.
	// When the gateway is enabled and this field is omitted, analytics emission
	// is on whenever the operator has a default ingest URL. Set
	// analytics.disabled to true to opt out. If set without an ingest URL, the
	// operator may supply its configured default ingest URL.
	Analytics *AnalyticsConfig `json:"analytics,omitempty"`

	// Rollout configures deployment rollout behavior for this server.
	Rollout *RolloutConfig `json:"rollout,omitempty"`
}

MCPServerSpec defines the desired state of MCPServer. +kubebuilder:object:generate=true

func (*MCPServerSpec) DeepCopy

func (in *MCPServerSpec) DeepCopy() *MCPServerSpec

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPServerSpec.

func (*MCPServerSpec) DeepCopyInto

func (in *MCPServerSpec) DeepCopyInto(out *MCPServerSpec)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type MCPServerStatus

type MCPServerStatus struct {
	// Phase represents the current phase of the MCPServer.
	Phase string `json:"phase,omitempty"`

	// Message provides additional information about the status.
	Message string `json:"message,omitempty"`

	// Conditions represent the latest available observations.
	Conditions []metav1.Condition `json:"conditions,omitempty"`

	// DeploymentReady indicates if the deployment is ready.
	DeploymentReady bool `json:"deploymentReady,omitempty"`

	// ServiceReady indicates if the service is ready.
	ServiceReady bool `json:"serviceReady,omitempty"`

	// IngressReady indicates if the ingress is ready.
	IngressReady bool `json:"ingressReady,omitempty"`

	// GatewayReady indicates if the gateway configuration and sidecar are ready.
	GatewayReady bool `json:"gatewayReady,omitempty"`

	// PolicyReady indicates if policy data for the gateway has been generated.
	PolicyReady bool `json:"policyReady,omitempty"`

	// CanaryReady indicates if the canary deployment, when configured, is ready.
	CanaryReady bool `json:"canaryReady,omitempty"`

	// URL is the public MCP endpoint the operator derived from the ingress
	// host, TLS setting, and public path. The platform API, CLI, and UI show
	// this value instead of rebuilding it, so every surface agrees with what
	// the ingress and gateway actually serve. Empty when no host is known.
	URL string `json:"url,omitempty"`
}

MCPServerStatus defines the observed state of MCPServer. +kubebuilder:object:generate=true

func (*MCPServerStatus) DeepCopy

func (in *MCPServerStatus) DeepCopy() *MCPServerStatus

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPServerStatus.

func (*MCPServerStatus) DeepCopyInto

func (in *MCPServerStatus) DeepCopyInto(out *MCPServerStatus)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type PolicyConfig

type PolicyConfig struct {
	Mode            PolicyMode     `json:"mode,omitempty"`
	DefaultDecision PolicyDecision `json:"defaultDecision,omitempty"`
	EnforceOn       string         `json:"enforceOn,omitempty"`
	PolicyVersion   string         `json:"policyVersion,omitempty"`
}

PolicyConfig configures authorization behavior at the gateway. +kubebuilder:object:generate=true

func (*PolicyConfig) DeepCopy

func (in *PolicyConfig) DeepCopy() *PolicyConfig

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PolicyConfig.

func (*PolicyConfig) DeepCopyInto

func (in *PolicyConfig) DeepCopyInto(out *PolicyConfig)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type PolicyDecision

type PolicyDecision string

+kubebuilder:validation:Enum=allow;deny

const (
	PolicyDecisionAllow PolicyDecision = mcpdefaults.PolicyDecisionAllow
	PolicyDecisionDeny  PolicyDecision = mcpdefaults.PolicyDecisionDeny
)

type PolicyMode

type PolicyMode string

+kubebuilder:validation:Enum=allow-list;observe

const (
	PolicyModeAllowList PolicyMode = mcpdefaults.PolicyModeAllowList
	PolicyModeObserve   PolicyMode = mcpdefaults.PolicyModeObserve
)

type PublicURLOptions

type PublicURLOptions struct {
	DefaultIngressHost string
	DefaultIngressTLS  bool
}

PublicURLOptions carries the operator-wide ingress settings that decide the public URL of an MCPServer when the spec leaves them unset.

func (*PublicURLOptions) DeepCopy

func (in *PublicURLOptions) DeepCopy() *PublicURLOptions

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PublicURLOptions.

func (*PublicURLOptions) DeepCopyInto

func (in *PublicURLOptions) DeepCopyInto(out *PublicURLOptions)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ResourceList

type ResourceList struct {
	CPU    string `json:"cpu,omitempty"`
	Memory string `json:"memory,omitempty"`
}

ResourceList defines CPU and memory resources. +kubebuilder:object:generate=true

func (*ResourceList) DeepCopy

func (in *ResourceList) DeepCopy() *ResourceList

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ResourceList.

func (*ResourceList) DeepCopyInto

func (in *ResourceList) DeepCopyInto(out *ResourceList)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ResourceRequirements

type ResourceRequirements struct {
	Limits   *ResourceList `json:"limits,omitempty"`
	Requests *ResourceList `json:"requests,omitempty"`
}

ResourceRequirements defines resource limits and requests. +kubebuilder:object:generate=true

func (*ResourceRequirements) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ResourceRequirements.

func (*ResourceRequirements) DeepCopyInto

func (in *ResourceRequirements) DeepCopyInto(out *ResourceRequirements)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type RolloutConfig

type RolloutConfig struct {
	Strategy       RolloutStrategy `json:"strategy,omitempty"`
	MaxUnavailable string          `json:"maxUnavailable,omitempty"`
	MaxSurge       string          `json:"maxSurge,omitempty"`
	CanaryReplicas *int32          `json:"canaryReplicas,omitempty"`
}

RolloutConfig configures deployment rollout behavior. +kubebuilder:object:generate=true

func (*RolloutConfig) DeepCopy

func (in *RolloutConfig) DeepCopy() *RolloutConfig

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new RolloutConfig.

func (*RolloutConfig) DeepCopyInto

func (in *RolloutConfig) DeepCopyInto(out *RolloutConfig)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type RolloutStrategy

type RolloutStrategy string

+kubebuilder:validation:Enum=RollingUpdate;Recreate;Canary

const (
	RolloutStrategyRollingUpdate RolloutStrategy = "RollingUpdate"
	RolloutStrategyRecreate      RolloutStrategy = "Recreate"
	RolloutStrategyCanary        RolloutStrategy = "Canary"
)

type SecretEnvVar

type SecretEnvVar struct {
	Name         string        `json:"name"`
	SecretKeyRef *SecretKeyRef `json:"secretKeyRef,omitempty"`
}

SecretEnvVar represents a secret-backed environment variable. +kubebuilder:object:generate=true

func (*SecretEnvVar) DeepCopy

func (in *SecretEnvVar) DeepCopy() *SecretEnvVar

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SecretEnvVar.

func (*SecretEnvVar) DeepCopyInto

func (in *SecretEnvVar) DeepCopyInto(out *SecretEnvVar)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type SecretKeyRef

type SecretKeyRef struct {
	Name string `json:"name"`
	Key  string `json:"key"`
}

SecretKeyRef points to a single key in a Kubernetes Secret. +kubebuilder:object:generate=true

func (*SecretKeyRef) DeepCopy

func (in *SecretKeyRef) DeepCopy() *SecretKeyRef

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SecretKeyRef.

func (*SecretKeyRef) DeepCopyInto

func (in *SecretKeyRef) DeepCopyInto(out *SecretKeyRef)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ServerReference

type ServerReference struct {
	Name      string `json:"name"`
	Namespace string `json:"namespace,omitempty"`
}

ServerReference identifies an MCPServer. +kubebuilder:object:generate=true

func (*ServerReference) DeepCopy

func (in *ServerReference) DeepCopy() *ServerReference

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ServerReference.

func (*ServerReference) DeepCopyInto

func (in *ServerReference) DeepCopyInto(out *ServerReference)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type SessionConfig

type SessionConfig struct {
	Required            bool   `json:"required,omitempty"`
	Store               string `json:"store,omitempty"`
	MaxLifetime         string `json:"maxLifetime,omitempty"`
	IdleTimeout         string `json:"idleTimeout,omitempty"`
	UpstreamTokenHeader string `json:"upstreamTokenHeader,omitempty"`
}

SessionConfig configures server-side agent session behavior. +kubebuilder:object:generate=true

func (*SessionConfig) DeepCopy

func (in *SessionConfig) DeepCopy() *SessionConfig

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SessionConfig.

func (*SessionConfig) DeepCopyInto

func (in *SessionConfig) DeepCopyInto(out *SessionConfig)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type SubjectRef

type SubjectRef struct {
	HumanID string `json:"humanID,omitempty"`
	AgentID string `json:"agentID,omitempty"`
	// TeamID constrains the subject to a stable platform team identifier.
	// A subject with only teamID grants or binds any authenticated principal in that team.
	TeamID string `json:"teamID,omitempty"`
}

SubjectRef identifies the human and optional agent a grant or session applies to. +kubebuilder:object:generate=true

func (*SubjectRef) DeepCopy

func (in *SubjectRef) DeepCopy() *SubjectRef

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SubjectRef.

func (*SubjectRef) DeepCopyInto

func (in *SubjectRef) DeepCopyInto(out *SubjectRef)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ToolConfig

type ToolConfig struct {
	Name          string            `json:"name"`
	Description   string            `json:"description,omitempty"`
	RequiredTrust TrustLevel        `json:"requiredTrust,omitempty"`
	SideEffect    ToolSideEffect    `json:"sideEffect"`
	RiskLevel     ToolRiskLevel     `json:"riskLevel,omitempty"`
	Labels        map[string]string `json:"labels,omitempty"`
}

ToolConfig describes one MCP tool exposed by a server. +kubebuilder:object:generate=true

func (*ToolConfig) DeepCopy

func (in *ToolConfig) DeepCopy() *ToolConfig

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ToolConfig.

func (*ToolConfig) DeepCopyInto

func (in *ToolConfig) DeepCopyInto(out *ToolConfig)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ToolRiskLevel

type ToolRiskLevel string

+kubebuilder:validation:Enum=low;medium;high

const (
	ToolRiskLevelLow    ToolRiskLevel = "low"
	ToolRiskLevelMedium ToolRiskLevel = "medium"
	ToolRiskLevelHigh   ToolRiskLevel = "high"
)

type ToolRule

type ToolRule struct {
	Name          string         `json:"name"`
	Decision      PolicyDecision `json:"decision"`
	RequiredTrust TrustLevel     `json:"requiredTrust,omitempty"`
}

ToolRule controls access to an individual MCP tool. +kubebuilder:object:generate=true

func (*ToolRule) DeepCopy

func (in *ToolRule) DeepCopy() *ToolRule

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ToolRule.

func (*ToolRule) DeepCopyInto

func (in *ToolRule) DeepCopyInto(out *ToolRule)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ToolSideEffect

type ToolSideEffect string

+kubebuilder:validation:Enum=read;write;destructive

const (
	ToolSideEffectRead        ToolSideEffect = "read"
	ToolSideEffectWrite       ToolSideEffect = "write"
	ToolSideEffectDestructive ToolSideEffect = "destructive"
)

type TrustLevel

type TrustLevel string

+kubebuilder:validation:Enum=low;medium;high

const (
	TrustLevelLow    TrustLevel = "low"
	TrustLevelMedium TrustLevel = "medium"
	TrustLevelHigh   TrustLevel = "high"
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL