Documentation
¶
Overview ¶
Package v1alpha1 contains API Schema definitions for the MCP server resource.
Index ¶
- Constants
- Variables
- func BoolPtr(v bool) *bool
- func EndpointUsesRetiredNamespace(raw string) bool
- func GatewayIsEnabled(gateway *GatewayConfig) bool
- func ProtectedResourceMetadataURL(resource string) string
- type AnalyticsConfig
- type AuthConfig
- type EnvVar
- type GatewayConfig
- type InventoryItem
- type MCPAccessGrant
- func (in *MCPAccessGrant) DeepCopy() *MCPAccessGrant
- func (in *MCPAccessGrant) DeepCopyInto(out *MCPAccessGrant)
- func (in *MCPAccessGrant) DeepCopyObject() runtime.Object
- func (r *MCPAccessGrant) SetupWebhookWithManager(mgr ctrl.Manager) error
- func (r *MCPAccessGrant) ValidateCreate() (admission.Warnings, error)
- func (r *MCPAccessGrant) ValidateDelete() (admission.Warnings, error)
- func (r *MCPAccessGrant) ValidateUpdate(_ runtime.Object) (admission.Warnings, error)
- type MCPAccessGrantList
- type MCPAccessGrantSpec
- type MCPAccessGrantStatus
- type MCPAgentSession
- func (in *MCPAgentSession) DeepCopy() *MCPAgentSession
- func (in *MCPAgentSession) DeepCopyInto(out *MCPAgentSession)
- func (in *MCPAgentSession) DeepCopyObject() runtime.Object
- func (r *MCPAgentSession) SetupWebhookWithManager(mgr ctrl.Manager) error
- func (r *MCPAgentSession) ValidateCreate() (admission.Warnings, error)
- func (r *MCPAgentSession) ValidateDelete() (admission.Warnings, error)
- func (r *MCPAgentSession) ValidateUpdate(_ runtime.Object) (admission.Warnings, error)
- type MCPAgentSessionList
- type MCPAgentSessionSpec
- type MCPAgentSessionStatus
- type MCPServer
- func (r *MCPServer) CanonicalResourceURL(options PublicURLOptions) string
- func (in *MCPServer) DeepCopy() *MCPServer
- func (in *MCPServer) DeepCopyInto(out *MCPServer)
- func (in *MCPServer) DeepCopyObject() runtime.Object
- func (r *MCPServer) Default()
- func (r *MCPServer) DefaultWithOptions(options MCPServerDefaultOptions)
- func (r *MCPServer) EffectivePublicPath() string
- func (r *MCPServer) PublicBaseURL(options PublicURLOptions) string
- func (r *MCPServer) PublicIngressUsesTLS(defaultTLS bool) bool
- func (r *MCPServer) ResolveDerivedAuth(options MCPServerDefaultOptions)
- func (r *MCPServer) SetupWebhookWithManager(mgr ctrl.Manager) error
- func (r *MCPServer) SetupWebhookWithManagerWithOptions(mgr ctrl.Manager, options MCPServerDefaultOptions) error
- func (r *MCPServer) String() string
- func (r *MCPServer) ValidateCreate() (admission.Warnings, error)
- func (r *MCPServer) ValidateDelete() (admission.Warnings, error)
- func (r *MCPServer) ValidateResolvedAuth() error
- func (r *MCPServer) ValidateUpdate(_ runtime.Object) (admission.Warnings, error)
- type MCPServerDefaultOptions
- type MCPServerList
- type MCPServerSpec
- type MCPServerStatus
- type PolicyConfig
- type PolicyDecision
- type PolicyMode
- type PublicURLOptions
- type ResourceList
- type ResourceRequirements
- type RolloutConfig
- type RolloutStrategy
- type SecretEnvVar
- type SecretKeyRef
- type ServerReference
- type SessionConfig
- type SubjectRef
- type ToolConfig
- type ToolRiskLevel
- type ToolRule
- type ToolSideEffect
- type TrustLevel
Constants ¶
const ( // Group is the Kubernetes API group for MCP Runtime resources. Group = "mcpruntime.org" // Version is the Kubernetes API version for MCP Runtime resources. Version = "v1alpha1" // MCPServerResource is the plural resource name for MCPServer objects. MCPServerResource = "mcpservers" // MCPAccessGrantResource is the plural resource name for MCPAccessGrant objects. MCPAccessGrantResource = "mcpaccessgrants" // MCPAgentSessionResource is the plural resource name for MCPAgentSession objects. MCPAgentSessionResource = "mcpagentsessions" )
Variables ¶
var ( // GroupVersion is group version used to register these objects GroupVersion = schema.GroupVersion{Group: Group, Version: Version} // SchemeBuilder is used to add go types to the GroupVersionKind scheme SchemeBuilder = runtime.NewSchemeBuilder(addKnownTypes) // AddToScheme adds the types in this group-version to the given scheme. AddToScheme = SchemeBuilder.AddToScheme )
Functions ¶
func EndpointUsesRetiredNamespace ¶
EndpointUsesRetiredNamespace reports whether raw is a URL aimed at the removed combined platform namespace. Callers replace those values with the current service DNS. A collector outside that namespace is left unchanged.
func GatewayIsEnabled ¶
func GatewayIsEnabled(gateway *GatewayConfig) bool
GatewayIsEnabled reports whether the MCP gateway sidecar should run. Omitted gateway, empty gateway: {}, and enabled: true all mean on. Only enabled: false opts out.
func ProtectedResourceMetadataURL ¶
ProtectedResourceMetadataURL returns the RFC 9728 metadata document URL for a resource URL: the well-known prefix inserted between origin and path, the location a conforming client derives from the resource it connected to.
Types ¶
type AnalyticsConfig ¶
type AnalyticsConfig struct {
// Disabled suppresses analytics emission from the gateway sidecar for this
// server.
Disabled bool `json:"disabled,omitempty"`
// IngestURL is the analytics ingest endpoint. If empty, the operator may
// supply its configured default ingest URL.
IngestURL string `json:"ingestURL,omitempty"`
// Source is the event source label attached to emitted analytics events.
Source string `json:"source,omitempty"`
// EventType is the event type label attached to emitted analytics events.
EventType string `json:"eventType,omitempty"`
// APIKeySecretRef points to a secret key containing the analytics API key.
APIKeySecretRef *SecretKeyRef `json:"apiKeySecretRef,omitempty"`
}
AnalyticsConfig configures analytics emission from the gateway sidecar. +kubebuilder:object:generate=true
func (*AnalyticsConfig) DeepCopy ¶
func (in *AnalyticsConfig) DeepCopy() *AnalyticsConfig
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AnalyticsConfig.
func (*AnalyticsConfig) DeepCopyInto ¶
func (in *AnalyticsConfig) DeepCopyInto(out *AnalyticsConfig)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type AuthConfig ¶
type AuthConfig struct {
TokenHeader string `json:"tokenHeader,omitempty"`
IssuerURL string `json:"issuerURL,omitempty"`
// Audience is the OAuth resource identifier tokens must be issued for and
// that protected-resource metadata advertises. When
// this is unset, it defaults to the public MCP URL built from the ingress
// host (or MCP_DEFAULT_INGRESS_HOST on the operator), TLS setting, and path.
Audience string `json:"audience,omitempty"`
}
AuthConfig configures OAuth authentication at the gateway. +kubebuilder:object:generate=true
func (*AuthConfig) DeepCopy ¶
func (in *AuthConfig) DeepCopy() *AuthConfig
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AuthConfig.
func (*AuthConfig) DeepCopyInto ¶
func (in *AuthConfig) DeepCopyInto(out *AuthConfig)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type EnvVar ¶
EnvVar represents a literal environment variable. +kubebuilder:object:generate=true
func (*EnvVar) DeepCopy ¶
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new EnvVar.
func (*EnvVar) DeepCopyInto ¶
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type GatewayConfig ¶
type GatewayConfig struct {
// Enabled turns the gateway sidecar on or off. When nil/omitted the sidecar
// is enabled (observability by default). Set to false to opt out.
Enabled *bool `json:"enabled,omitempty"`
// Image overrides the proxy container image for this server.
Image string `json:"image,omitempty"`
// Port is the port the gateway listens on inside the pod (defaults to 8091).
Port int32 `json:"port,omitempty"`
// UpstreamURL is the upstream URL the gateway proxies to.
// Defaults to http://127.0.0.1:<spec.port>.
UpstreamURL string `json:"upstreamURL,omitempty"`
// StripPrefix removes a path prefix before forwarding to the upstream server.
StripPrefix string `json:"stripPrefix,omitempty"`
// Resources defines resource limits and requests for the gateway sidecar.
Resources *ResourceRequirements `json:"resources,omitempty"`
}
GatewayConfig configures an optional MCP proxy sidecar for a server. +kubebuilder:object:generate=true
func (*GatewayConfig) DeepCopy ¶
func (in *GatewayConfig) DeepCopy() *GatewayConfig
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new GatewayConfig.
func (*GatewayConfig) DeepCopyInto ¶
func (in *GatewayConfig) DeepCopyInto(out *GatewayConfig)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type InventoryItem ¶
type InventoryItem struct {
Name string `json:"name"`
Description string `json:"description,omitempty"`
Labels map[string]string `json:"labels,omitempty"`
}
InventoryItem describes a named MCP prompt, resource, or task. +kubebuilder:object:generate=true
func (*InventoryItem) DeepCopy ¶
func (in *InventoryItem) DeepCopy() *InventoryItem
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new InventoryItem.
func (*InventoryItem) DeepCopyInto ¶
func (in *InventoryItem) DeepCopyInto(out *InventoryItem)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type MCPAccessGrant ¶
type MCPAccessGrant struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
Spec MCPAccessGrantSpec `json:"spec,omitempty"`
Status MCPAccessGrantStatus `json:"status,omitempty"`
}
MCPAccessGrant grants a human or agent access to an MCPServer.
func (*MCPAccessGrant) DeepCopy ¶
func (in *MCPAccessGrant) DeepCopy() *MCPAccessGrant
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAccessGrant.
func (*MCPAccessGrant) DeepCopyInto ¶
func (in *MCPAccessGrant) DeepCopyInto(out *MCPAccessGrant)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*MCPAccessGrant) DeepCopyObject ¶
func (in *MCPAccessGrant) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
func (*MCPAccessGrant) SetupWebhookWithManager ¶
func (r *MCPAccessGrant) SetupWebhookWithManager(mgr ctrl.Manager) error
func (*MCPAccessGrant) ValidateCreate ¶
func (r *MCPAccessGrant) ValidateCreate() (admission.Warnings, error)
func (*MCPAccessGrant) ValidateDelete ¶
func (r *MCPAccessGrant) ValidateDelete() (admission.Warnings, error)
func (*MCPAccessGrant) ValidateUpdate ¶
type MCPAccessGrantList ¶
type MCPAccessGrantList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []MCPAccessGrant `json:"items"`
}
MCPAccessGrantList contains a list of MCPAccessGrant.
func (*MCPAccessGrantList) DeepCopy ¶
func (in *MCPAccessGrantList) DeepCopy() *MCPAccessGrantList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAccessGrantList.
func (*MCPAccessGrantList) DeepCopyInto ¶
func (in *MCPAccessGrantList) DeepCopyInto(out *MCPAccessGrantList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*MCPAccessGrantList) DeepCopyObject ¶
func (in *MCPAccessGrantList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type MCPAccessGrantSpec ¶
type MCPAccessGrantSpec struct {
ServerRef ServerReference `json:"serverRef"`
Subject SubjectRef `json:"subject"`
MaxTrust TrustLevel `json:"maxTrust,omitempty"`
AllowedSideEffects []ToolSideEffect `json:"allowedSideEffects,omitempty"`
PolicyVersion string `json:"policyVersion,omitempty"`
Disabled bool `json:"disabled,omitempty"`
ExpiresAt *metav1.Time `json:"expiresAt,omitempty"`
ToolRules []ToolRule `json:"toolRules,omitempty"`
}
MCPAccessGrantSpec defines who can use which MCP server and with what trust ceiling. +kubebuilder:object:generate=true
func (*MCPAccessGrantSpec) DeepCopy ¶
func (in *MCPAccessGrantSpec) DeepCopy() *MCPAccessGrantSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAccessGrantSpec.
func (*MCPAccessGrantSpec) DeepCopyInto ¶
func (in *MCPAccessGrantSpec) DeepCopyInto(out *MCPAccessGrantSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type MCPAccessGrantStatus ¶
type MCPAccessGrantStatus struct {
Phase string `json:"phase,omitempty"`
Message string `json:"message,omitempty"`
Conditions []metav1.Condition `json:"conditions,omitempty"`
}
MCPAccessGrantStatus captures observed grant state. +kubebuilder:object:generate=true
func (*MCPAccessGrantStatus) DeepCopy ¶
func (in *MCPAccessGrantStatus) DeepCopy() *MCPAccessGrantStatus
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAccessGrantStatus.
func (*MCPAccessGrantStatus) DeepCopyInto ¶
func (in *MCPAccessGrantStatus) DeepCopyInto(out *MCPAccessGrantStatus)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type MCPAgentSession ¶
type MCPAgentSession struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
Spec MCPAgentSessionSpec `json:"spec,omitempty"`
Status MCPAgentSessionStatus `json:"status,omitempty"`
}
MCPAgentSession stores consent and upstream token state for an agent session.
func (*MCPAgentSession) DeepCopy ¶
func (in *MCPAgentSession) DeepCopy() *MCPAgentSession
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAgentSession.
func (*MCPAgentSession) DeepCopyInto ¶
func (in *MCPAgentSession) DeepCopyInto(out *MCPAgentSession)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*MCPAgentSession) DeepCopyObject ¶
func (in *MCPAgentSession) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
func (*MCPAgentSession) SetupWebhookWithManager ¶
func (r *MCPAgentSession) SetupWebhookWithManager(mgr ctrl.Manager) error
func (*MCPAgentSession) ValidateCreate ¶
func (r *MCPAgentSession) ValidateCreate() (admission.Warnings, error)
func (*MCPAgentSession) ValidateDelete ¶
func (r *MCPAgentSession) ValidateDelete() (admission.Warnings, error)
func (*MCPAgentSession) ValidateUpdate ¶
type MCPAgentSessionList ¶
type MCPAgentSessionList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []MCPAgentSession `json:"items"`
}
MCPAgentSessionList contains a list of MCPAgentSession.
func (*MCPAgentSessionList) DeepCopy ¶
func (in *MCPAgentSessionList) DeepCopy() *MCPAgentSessionList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAgentSessionList.
func (*MCPAgentSessionList) DeepCopyInto ¶
func (in *MCPAgentSessionList) DeepCopyInto(out *MCPAgentSessionList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*MCPAgentSessionList) DeepCopyObject ¶
func (in *MCPAgentSessionList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type MCPAgentSessionSpec ¶
type MCPAgentSessionSpec struct {
ServerRef ServerReference `json:"serverRef"`
Subject SubjectRef `json:"subject"`
ConsentedTrust TrustLevel `json:"consentedTrust,omitempty"`
ExpiresAt *metav1.Time `json:"expiresAt,omitempty"`
Revoked bool `json:"revoked,omitempty"`
UpstreamTokenSecretRef *SecretKeyRef `json:"upstreamTokenSecretRef,omitempty"`
PolicyVersion string `json:"policyVersion,omitempty"`
}
MCPAgentSessionSpec defines a consented server-side agent session. +kubebuilder:object:generate=true
func (*MCPAgentSessionSpec) DeepCopy ¶
func (in *MCPAgentSessionSpec) DeepCopy() *MCPAgentSessionSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAgentSessionSpec.
func (*MCPAgentSessionSpec) DeepCopyInto ¶
func (in *MCPAgentSessionSpec) DeepCopyInto(out *MCPAgentSessionSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type MCPAgentSessionStatus ¶
type MCPAgentSessionStatus struct {
Phase string `json:"phase,omitempty"`
Message string `json:"message,omitempty"`
Conditions []metav1.Condition `json:"conditions,omitempty"`
}
MCPAgentSessionStatus captures observed session state. +kubebuilder:object:generate=true
func (*MCPAgentSessionStatus) DeepCopy ¶
func (in *MCPAgentSessionStatus) DeepCopy() *MCPAgentSessionStatus
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPAgentSessionStatus.
func (*MCPAgentSessionStatus) DeepCopyInto ¶
func (in *MCPAgentSessionStatus) DeepCopyInto(out *MCPAgentSessionStatus)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type MCPServer ¶
type MCPServer struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
Spec MCPServerSpec `json:"spec,omitempty"`
Status MCPServerStatus `json:"status,omitempty"`
}
MCPServer is the Schema for the mcpservers API.
func (*MCPServer) CanonicalResourceURL ¶
func (r *MCPServer) CanonicalResourceURL(options PublicURLOptions) string
CanonicalResourceURL returns the MCP endpoint URL clients connect to, which is also the OAuth resource identifier (RFC 8707/9728) tokens must be issued for. It returns "" when the public host is unknown.
func (*MCPServer) DeepCopy ¶
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPServer.
func (*MCPServer) DeepCopyInto ¶
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*MCPServer) DeepCopyObject ¶
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
func (*MCPServer) DefaultWithOptions ¶
func (r *MCPServer) DefaultWithOptions(options MCPServerDefaultOptions)
func (*MCPServer) EffectivePublicPath ¶
EffectivePublicPath returns the path clients reach the MCP endpoint on: "/<publicPathPrefix>/mcp" for path-based routing, else spec.ingressPath.
func (*MCPServer) PublicBaseURL ¶
func (r *MCPServer) PublicBaseURL(options PublicURLOptions) string
PublicBaseURL returns scheme://host for the server's public ingress, or "" when no host is known. Path-based servers leave spec.ingressHost empty (the ingress matches any host), so the operator-wide default host is used; the scheme follows the operator TLS default or the per-server Traefik TLS annotation, because the ingress, not the pod, terminates TLS.
func (*MCPServer) PublicIngressUsesTLS ¶
PublicIngressUsesTLS reports whether the server's ingress terminates TLS, either from the operator-wide default or an explicit Traefik annotation.
func (*MCPServer) ResolveDerivedAuth ¶
func (r *MCPServer) ResolveDerivedAuth(options MCPServerDefaultOptions)
DefaultWithOptions applies MCPServer defaults, including operator-configured fallbacks when the webhook is registered by the operator manager. ResolveDerivedAuth fills an OAuth server's unset audience and issuer from platform state: the audience from the public URL the ingress serves, the issuer from the bundled authorization server. It is applied to the operator's in-memory copy on every reconcile and is never persisted by the admission webhook, so a later change to the host, path, TLS setting, or platform domain re-derives the values instead of leaving a stale copy in spec. Explicit values are kept.
func (*MCPServer) SetupWebhookWithManager ¶
func (*MCPServer) SetupWebhookWithManagerWithOptions ¶
func (r *MCPServer) SetupWebhookWithManagerWithOptions(mgr ctrl.Manager, options MCPServerDefaultOptions) error
func (*MCPServer) ValidateResolvedAuth ¶
ValidateResolvedAuth reports OAuth settings that are still missing after ResolveDerivedAuth. Admission cannot check this, because the values are derived later from operator state; the operator reports it on reconcile.
type MCPServerDefaultOptions ¶
type MCPServerDefaultOptions struct {
DefaultIngressHost string
DefaultIngressTLS bool
DefaultAnalyticsIngestURL string
DefaultOAuthIssuerURL string
}
MCPServerDefaultOptions holds operator-scoped values that the admission webhook can use while defaulting MCPServer objects.
func (*MCPServerDefaultOptions) DeepCopy ¶
func (in *MCPServerDefaultOptions) DeepCopy() *MCPServerDefaultOptions
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPServerDefaultOptions.
func (*MCPServerDefaultOptions) DeepCopyInto ¶
func (in *MCPServerDefaultOptions) DeepCopyInto(out *MCPServerDefaultOptions)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type MCPServerList ¶
type MCPServerList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []MCPServer `json:"items"`
}
MCPServerList contains a list of MCPServer.
func (*MCPServerList) DeepCopy ¶
func (in *MCPServerList) DeepCopy() *MCPServerList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPServerList.
func (*MCPServerList) DeepCopyInto ¶
func (in *MCPServerList) DeepCopyInto(out *MCPServerList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*MCPServerList) DeepCopyObject ¶
func (in *MCPServerList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type MCPServerSpec ¶
type MCPServerSpec struct {
// TeamID is the stable platform team identifier that owns this server.
// The operator renders it into gateway policy and analytics events.
TeamID string `json:"teamID,omitempty"`
// Description is a human-readable summary of what the MCP server provides.
Description string `json:"description,omitempty"`
// Image is the container image for the MCP server.
Image string `json:"image"`
// ImageTag is the tag of the container image (defaults to "latest").
ImageTag string `json:"imageTag,omitempty"`
// RegistryOverride, if set, overrides the registry portion of the image (e.g., registry.mcpruntime.com).
RegistryOverride string `json:"registryOverride,omitempty"`
// UseProvisionedRegistry tells the controller to use the provisioned registry (from operator env) for this server.
UseProvisionedRegistry bool `json:"useProvisionedRegistry,omitempty"`
// ImagePullSecrets are secrets to use for pulling the image.
ImagePullSecrets []string `json:"imagePullSecrets,omitempty"`
// Replicas is the number of desired replicas (defaults to 1).
Replicas *int32 `json:"replicas,omitempty"`
// Port is the port the container listens on (defaults to 8088).
Port int32 `json:"port,omitempty"`
// ServicePort is the port exposed by the service (defaults to 80).
ServicePort int32 `json:"servicePort,omitempty"`
// IngressPath is the path for the ingress route (defaults to /{name}/mcp).
IngressPath string `json:"ingressPath,omitempty"`
// IngressHost is the hostname for the ingress (required unless publicPathPrefix is set; defaults from MCP_DEFAULT_INGRESS_HOST env var if set on the operator).
IngressHost string `json:"ingressHost,omitempty"`
// PublicPathPrefix enables path-based public routing and is used to compute /<publicPathPrefix>/mcp.
// When ingressHost is also set, the route is path-based under that host; otherwise it is hostless.
PublicPathPrefix string `json:"publicPathPrefix,omitempty"`
// IngressClass is the ingress class to use (e.g., "traefik", "nginx", "istio"). Defaults to "traefik".
IngressClass string `json:"ingressClass,omitempty"`
// IngressAnnotations are additional annotations for the ingress controller.
IngressAnnotations map[string]string `json:"ingressAnnotations,omitempty"`
// Resources defines resource limits and requests.
Resources ResourceRequirements `json:"resources,omitempty"`
// EnvVars are literal environment variables to pass to the container.
EnvVars []EnvVar `json:"envVars,omitempty"`
// SecretEnvVars are secret-backed environment variables to pass to the container.
SecretEnvVars []SecretEnvVar `json:"secretEnvVars,omitempty"`
// Tools describes the MCP tool inventory exposed by the server.
Tools []ToolConfig `json:"tools,omitempty"`
// Prompts describes the MCP prompt inventory exposed by the server.
Prompts []InventoryItem `json:"prompts,omitempty"`
// MCPResources describes the MCP resource inventory exposed by the server.
MCPResources []InventoryItem `json:"mcpResources,omitempty"`
// Tasks describes task templates or workflows exposed by the server.
Tasks []InventoryItem `json:"tasks,omitempty"`
// Auth enables optional OAuth authentication at the gateway when present.
Auth *AuthConfig `json:"auth,omitempty"`
// Policy configures gateway-side authorization behavior. When omitted, the
// gateway runs in observe mode so metrics and analytics work without
// grant/session enforcement. Set this field (for example allow-list + deny)
// to require adapter identity and grants.
Policy *PolicyConfig `json:"policy,omitempty"`
// Session configures server-side agent session behavior.
Session *SessionConfig `json:"session,omitempty"`
// Gateway configures the MCP proxy sidecar in front of the server container.
// When omitted or left empty, the sidecar is enabled so metrics, traces, and
// analytics can run. Set gateway.enabled to false to opt out.
Gateway *GatewayConfig `json:"gateway,omitempty"`
// Analytics configures audit/analytics emission for the gateway sidecar.
// When the gateway is enabled and this field is omitted, analytics emission
// is on whenever the operator has a default ingest URL. Set
// analytics.disabled to true to opt out. If set without an ingest URL, the
// operator may supply its configured default ingest URL.
Analytics *AnalyticsConfig `json:"analytics,omitempty"`
// Rollout configures deployment rollout behavior for this server.
Rollout *RolloutConfig `json:"rollout,omitempty"`
}
MCPServerSpec defines the desired state of MCPServer. +kubebuilder:object:generate=true
func (*MCPServerSpec) DeepCopy ¶
func (in *MCPServerSpec) DeepCopy() *MCPServerSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPServerSpec.
func (*MCPServerSpec) DeepCopyInto ¶
func (in *MCPServerSpec) DeepCopyInto(out *MCPServerSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type MCPServerStatus ¶
type MCPServerStatus struct {
// Phase represents the current phase of the MCPServer.
Phase string `json:"phase,omitempty"`
// Message provides additional information about the status.
Message string `json:"message,omitempty"`
// Conditions represent the latest available observations.
Conditions []metav1.Condition `json:"conditions,omitempty"`
// DeploymentReady indicates if the deployment is ready.
DeploymentReady bool `json:"deploymentReady,omitempty"`
// ServiceReady indicates if the service is ready.
ServiceReady bool `json:"serviceReady,omitempty"`
// IngressReady indicates if the ingress is ready.
IngressReady bool `json:"ingressReady,omitempty"`
// GatewayReady indicates if the gateway configuration and sidecar are ready.
GatewayReady bool `json:"gatewayReady,omitempty"`
// PolicyReady indicates if policy data for the gateway has been generated.
PolicyReady bool `json:"policyReady,omitempty"`
// CanaryReady indicates if the canary deployment, when configured, is ready.
CanaryReady bool `json:"canaryReady,omitempty"`
// URL is the public MCP endpoint the operator derived from the ingress
// host, TLS setting, and public path. The platform API, CLI, and UI show
// this value instead of rebuilding it, so every surface agrees with what
// the ingress and gateway actually serve. Empty when no host is known.
URL string `json:"url,omitempty"`
}
MCPServerStatus defines the observed state of MCPServer. +kubebuilder:object:generate=true
func (*MCPServerStatus) DeepCopy ¶
func (in *MCPServerStatus) DeepCopy() *MCPServerStatus
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MCPServerStatus.
func (*MCPServerStatus) DeepCopyInto ¶
func (in *MCPServerStatus) DeepCopyInto(out *MCPServerStatus)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type PolicyConfig ¶
type PolicyConfig struct {
Mode PolicyMode `json:"mode,omitempty"`
DefaultDecision PolicyDecision `json:"defaultDecision,omitempty"`
EnforceOn string `json:"enforceOn,omitempty"`
PolicyVersion string `json:"policyVersion,omitempty"`
}
PolicyConfig configures authorization behavior at the gateway. +kubebuilder:object:generate=true
func (*PolicyConfig) DeepCopy ¶
func (in *PolicyConfig) DeepCopy() *PolicyConfig
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PolicyConfig.
func (*PolicyConfig) DeepCopyInto ¶
func (in *PolicyConfig) DeepCopyInto(out *PolicyConfig)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type PolicyDecision ¶
type PolicyDecision string
+kubebuilder:validation:Enum=allow;deny
const ( PolicyDecisionAllow PolicyDecision = mcpdefaults.PolicyDecisionAllow PolicyDecisionDeny PolicyDecision = mcpdefaults.PolicyDecisionDeny )
type PolicyMode ¶
type PolicyMode string
+kubebuilder:validation:Enum=allow-list;observe
const ( PolicyModeAllowList PolicyMode = mcpdefaults.PolicyModeAllowList PolicyModeObserve PolicyMode = mcpdefaults.PolicyModeObserve )
type PublicURLOptions ¶
PublicURLOptions carries the operator-wide ingress settings that decide the public URL of an MCPServer when the spec leaves them unset.
func (*PublicURLOptions) DeepCopy ¶
func (in *PublicURLOptions) DeepCopy() *PublicURLOptions
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PublicURLOptions.
func (*PublicURLOptions) DeepCopyInto ¶
func (in *PublicURLOptions) DeepCopyInto(out *PublicURLOptions)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ResourceList ¶
type ResourceList struct {
CPU string `json:"cpu,omitempty"`
Memory string `json:"memory,omitempty"`
}
ResourceList defines CPU and memory resources. +kubebuilder:object:generate=true
func (*ResourceList) DeepCopy ¶
func (in *ResourceList) DeepCopy() *ResourceList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ResourceList.
func (*ResourceList) DeepCopyInto ¶
func (in *ResourceList) DeepCopyInto(out *ResourceList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ResourceRequirements ¶
type ResourceRequirements struct {
Limits *ResourceList `json:"limits,omitempty"`
Requests *ResourceList `json:"requests,omitempty"`
}
ResourceRequirements defines resource limits and requests. +kubebuilder:object:generate=true
func (*ResourceRequirements) DeepCopy ¶
func (in *ResourceRequirements) DeepCopy() *ResourceRequirements
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ResourceRequirements.
func (*ResourceRequirements) DeepCopyInto ¶
func (in *ResourceRequirements) DeepCopyInto(out *ResourceRequirements)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type RolloutConfig ¶
type RolloutConfig struct {
Strategy RolloutStrategy `json:"strategy,omitempty"`
MaxSurge string `json:"maxSurge,omitempty"`
CanaryReplicas *int32 `json:"canaryReplicas,omitempty"`
}
RolloutConfig configures deployment rollout behavior. +kubebuilder:object:generate=true
func (*RolloutConfig) DeepCopy ¶
func (in *RolloutConfig) DeepCopy() *RolloutConfig
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new RolloutConfig.
func (*RolloutConfig) DeepCopyInto ¶
func (in *RolloutConfig) DeepCopyInto(out *RolloutConfig)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type RolloutStrategy ¶
type RolloutStrategy string
+kubebuilder:validation:Enum=RollingUpdate;Recreate;Canary
const ( RolloutStrategyRollingUpdate RolloutStrategy = "RollingUpdate" RolloutStrategyRecreate RolloutStrategy = "Recreate" RolloutStrategyCanary RolloutStrategy = "Canary" )
type SecretEnvVar ¶
type SecretEnvVar struct {
Name string `json:"name"`
SecretKeyRef *SecretKeyRef `json:"secretKeyRef,omitempty"`
}
SecretEnvVar represents a secret-backed environment variable. +kubebuilder:object:generate=true
func (*SecretEnvVar) DeepCopy ¶
func (in *SecretEnvVar) DeepCopy() *SecretEnvVar
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SecretEnvVar.
func (*SecretEnvVar) DeepCopyInto ¶
func (in *SecretEnvVar) DeepCopyInto(out *SecretEnvVar)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type SecretKeyRef ¶
SecretKeyRef points to a single key in a Kubernetes Secret. +kubebuilder:object:generate=true
func (*SecretKeyRef) DeepCopy ¶
func (in *SecretKeyRef) DeepCopy() *SecretKeyRef
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SecretKeyRef.
func (*SecretKeyRef) DeepCopyInto ¶
func (in *SecretKeyRef) DeepCopyInto(out *SecretKeyRef)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ServerReference ¶
type ServerReference struct {
Name string `json:"name"`
Namespace string `json:"namespace,omitempty"`
}
ServerReference identifies an MCPServer. +kubebuilder:object:generate=true
func (*ServerReference) DeepCopy ¶
func (in *ServerReference) DeepCopy() *ServerReference
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ServerReference.
func (*ServerReference) DeepCopyInto ¶
func (in *ServerReference) DeepCopyInto(out *ServerReference)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type SessionConfig ¶
type SessionConfig struct {
Required bool `json:"required,omitempty"`
Store string `json:"store,omitempty"`
MaxLifetime string `json:"maxLifetime,omitempty"`
IdleTimeout string `json:"idleTimeout,omitempty"`
UpstreamTokenHeader string `json:"upstreamTokenHeader,omitempty"`
}
SessionConfig configures server-side agent session behavior. +kubebuilder:object:generate=true
func (*SessionConfig) DeepCopy ¶
func (in *SessionConfig) DeepCopy() *SessionConfig
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SessionConfig.
func (*SessionConfig) DeepCopyInto ¶
func (in *SessionConfig) DeepCopyInto(out *SessionConfig)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type SubjectRef ¶
type SubjectRef struct {
HumanID string `json:"humanID,omitempty"`
AgentID string `json:"agentID,omitempty"`
// TeamID constrains the subject to a stable platform team identifier.
// A subject with only teamID grants or binds any authenticated principal in that team.
TeamID string `json:"teamID,omitempty"`
}
SubjectRef identifies the human and optional agent a grant or session applies to. +kubebuilder:object:generate=true
func (*SubjectRef) DeepCopy ¶
func (in *SubjectRef) DeepCopy() *SubjectRef
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SubjectRef.
func (*SubjectRef) DeepCopyInto ¶
func (in *SubjectRef) DeepCopyInto(out *SubjectRef)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ToolConfig ¶
type ToolConfig struct {
Name string `json:"name"`
Description string `json:"description,omitempty"`
RequiredTrust TrustLevel `json:"requiredTrust,omitempty"`
SideEffect ToolSideEffect `json:"sideEffect"`
RiskLevel ToolRiskLevel `json:"riskLevel,omitempty"`
Labels map[string]string `json:"labels,omitempty"`
}
ToolConfig describes one MCP tool exposed by a server. +kubebuilder:object:generate=true
func (*ToolConfig) DeepCopy ¶
func (in *ToolConfig) DeepCopy() *ToolConfig
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ToolConfig.
func (*ToolConfig) DeepCopyInto ¶
func (in *ToolConfig) DeepCopyInto(out *ToolConfig)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ToolRiskLevel ¶
type ToolRiskLevel string
+kubebuilder:validation:Enum=low;medium;high
const ( ToolRiskLevelLow ToolRiskLevel = "low" ToolRiskLevelMedium ToolRiskLevel = "medium" ToolRiskLevelHigh ToolRiskLevel = "high" )
type ToolRule ¶
type ToolRule struct {
Name string `json:"name"`
Decision PolicyDecision `json:"decision"`
RequiredTrust TrustLevel `json:"requiredTrust,omitempty"`
}
ToolRule controls access to an individual MCP tool. +kubebuilder:object:generate=true
func (*ToolRule) DeepCopy ¶
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ToolRule.
func (*ToolRule) DeepCopyInto ¶
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ToolSideEffect ¶
type ToolSideEffect string
+kubebuilder:validation:Enum=read;write;destructive
const ( ToolSideEffectRead ToolSideEffect = "read" ToolSideEffectWrite ToolSideEffect = "write" ToolSideEffectDestructive ToolSideEffect = "destructive" )
type TrustLevel ¶
type TrustLevel string
+kubebuilder:validation:Enum=low;medium;high
const ( TrustLevelLow TrustLevel = "low" TrustLevelMedium TrustLevel = "medium" TrustLevelHigh TrustLevel = "high" )