operator

package
v0.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 0 Imported by: 0

Documentation

Overview

Package operator provides the Kubernetes operator for MCPServer resources.

Index

Constants

View Source
const (
	// DefaultRequestCPU is the default CPU request for containers.
	DefaultRequestCPU = "50m"
	// DefaultRequestMemory is the default memory request for containers.
	DefaultRequestMemory = "64Mi"
	// DefaultLimitCPU is the default CPU limit for containers.
	DefaultLimitCPU = "500m"
	// DefaultLimitMemory is the default memory limit for containers.
	DefaultLimitMemory = "256Mi"
)

Resource defaults for MCPServer deployments.

View Source
const (
	// DefaultReplicas is the default number of replicas.
	DefaultReplicas = 1
	// DefaultPort is the default container port.
	DefaultPort = mcpdefaults.MCPServerPort
	// DefaultGatewayPort is the default container port for the MCP proxy sidecar.
	DefaultGatewayPort = mcpdefaults.MCPGatewayPort
	// DefaultGatewayMetricsPort is the default Prometheus scrape port for the MCP gateway sidecar.
	DefaultGatewayMetricsPort = 9103
	// DefaultServicePort is the default service port.
	DefaultServicePort = 80
)

MCPServer defaults.

View Source
const (
	// LabelApp is the standard app label key.
	LabelApp = "app"
	// LabelManagedBy is the label indicating the managing controller.
	LabelManagedBy = "app.kubernetes.io/managed-by"
	// LabelManagedByValue is the value for the managed-by label.
	LabelManagedByValue = "github.com/mcp-runtime/mcp-runtime"
)

Labels used by the operator.

View Source
const (
	// DefaultIngressClass is the default ingress class.
	DefaultIngressClass = "traefik"
	// DefaultIngressPathType is the default path type for ingress rules.
	DefaultIngressPathType = "Prefix"
	// IngressReadinessModeStrict requires Ingress.status.loadBalancer.ingress to be populated.
	IngressReadinessModeStrict = "strict"
	// IngressReadinessModePermissive treats an Ingress with rules as ready when LB status is absent.
	IngressReadinessModePermissive = "permissive"
)

Ingress configuration.

View Source
const (
	// DefaultRegistrySecretName is the default name for registry pull secrets.
	// #nosec G101 -- This is a secret name, not a credential.
	DefaultRegistrySecretName = "mcp-runtime-registry-pull"
)

Secret names.

View Source
const (
	// RequeueDelayNotReady is the delay before requeueing when resources are not ready.
	RequeueDelayNotReady = 10 // seconds
)

Requeue delays for reconciliation.

Variables

View Source
var (
	// Reconciliation errors.
	ErrReconcileDeployment = fmt.Errorf("failed to reconcile deployment")
	ErrReconcileService    = fmt.Errorf("failed to reconcile service")
	ErrReconcileIngress    = fmt.Errorf("failed to reconcile ingress")
	ErrUpdateStatus        = fmt.Errorf("failed to update status")
	ErrApplyDefaults       = fmt.Errorf("failed to apply defaults")

	// Validation errors.
	ErrMissingIngressHost = fmt.Errorf("missing ingress host")
	ErrMissingIngressPath = fmt.Errorf("missing ingress path")

	// Resource errors.
	ErrInvalidCPURequest    = fmt.Errorf("invalid CPU request")
	ErrInvalidMemoryRequest = fmt.Errorf("invalid memory request")
	ErrInvalidCPULimit      = fmt.Errorf("invalid CPU limit")
	ErrInvalidMemoryLimit   = fmt.Errorf("invalid memory limit")
)

Sentinel errors for operator operations.

View Source
var DefaultOperatorConfig = LoadOperatorConfig()

DefaultOperatorConfig is the default configuration loaded at startup.

Functions

func NormalizeIngressReadinessMode

func NormalizeIngressReadinessMode(value string) (string, bool)

NormalizeIngressReadinessMode returns a supported ingress readiness mode. Empty or invalid values fall back to strict mode.

Types

type MCPServerReconciler

type MCPServerReconciler struct {
	client.Client
	Scheme *runtime.Scheme

	// APIReader is an uncached reader for objects the operator does not watch
	// (the server's pods). Nil falls back to Client.
	APIReader client.Reader

	// DefaultIngressHost is the default ingress host if not specified in the CR.
	DefaultIngressHost string

	// DefaultIngressEntryPoints is the default Traefik entrypoint annotation for MCP server ingresses.
	DefaultIngressEntryPoints string

	// DefaultIngressTLS enables Traefik TLS routing for MCP server ingresses by default.
	DefaultIngressTLS bool

	// DefaultIngressTLSSecret is the Kubernetes TLS Secret holding the
	// caller-facing (user->Traefik) host certificate for mtls servers. Path-based
	// mtls servers share one host, so this single platform host certificate is
	// published as Traefik's default certificate via a TLSStore named "default"
	// (see reconcileDefaultTLSStore) rather than a per-IngressRoute secretName.
	// Empty falls back to Traefik's built-in default certificate.
	DefaultIngressTLSSecret string

	// DefaultIngressTLSSecretNamespace is the Traefik-watched namespace that holds
	// the DefaultIngressTLSSecret and the single "default" TLSStore. Must be one
	// of the namespaces Traefik's kubernetescrd provider watches.
	DefaultIngressTLSSecretNamespace string

	// IngressReadinessMode controls how ingress readiness is evaluated.
	IngressReadinessMode string

	// ProvisionedRegistry holds the provisioned registry configuration.
	// If nil or URL is empty, provisioned registry features are disabled.
	ProvisionedRegistry *RegistryConfig

	// GatewayProxyImage is the default image used for the optional MCP gateway sidecar.
	GatewayProxyImage string

	// GatewayOTLPEndpoint is the OTLP/HTTP endpoint injected into MCP gateway sidecars.
	GatewayOTLPEndpoint string

	// DefaultAnalyticsIngestURL is the default analytics ingest endpoint used when analytics is enabled.
	DefaultAnalyticsIngestURL string

	// ClusterName is the cluster label attached to policy and audit events.
	ClusterName string

	// OAuthInternalIssuerURL is the in-cluster URL used by gateway sidecars for
	// OAuth metadata and JWKS discovery.
	OAuthInternalIssuerURL string

	// OAuthIssuerURL enables bundled authorization-server resource reconciliation
	// and supplies the default public issuer for OAuth MCPServers.
	OAuthIssuerURL string

	// MTLSClusterIssuer is the pre-existing cert-manager ClusterIssuer used for
	// gateway and adapter workload certificates. It is platform-wide; it does
	// not depend on MCP request authentication.
	MTLSClusterIssuer string

	// AdapterCertificatesEnabled opts OAuth servers into optional adapter
	// client certificates on their route (MCP_ADAPTER_CERTIFICATES).
	AdapterCertificatesEnabled bool

	// AdapterTrustDomain is the platform-wide SPIFFE trust domain used for
	// session-bound adapter certificates and the trusted Traefik identity.
	AdapterTrustDomain              string
	IngressControllerNamespace      string
	IngressControllerServiceAccount string
	IngressControllerPodLabels      map[string]string
}

MCPServerReconciler reconciles a MCPServer object

func (*MCPServerReconciler) Reconcile

func (r *MCPServerReconciler) Reconcile(ctx context.Context, req ctrl.Request) (ctrl.Result, error)

Reconcile is part of the main kubernetes reconciliation loop

func (*MCPServerReconciler) SetupWithManager

func (r *MCPServerReconciler) SetupWithManager(mgr ctrl.Manager) error

type OperatorConfig

type OperatorConfig struct {
	// DefaultIngressHost is the default host for ingress resources.
	DefaultIngressHost string

	// DefaultIngressClass is the ingress class to use.
	DefaultIngressClass string

	// DefaultIngressEntryPoints is the default Traefik entrypoint annotation for MCP server ingresses.
	DefaultIngressEntryPoints string

	// DefaultIngressTLS enables Traefik TLS routing for MCP server ingresses by default.
	DefaultIngressTLS bool

	// IngressReadinessMode controls how ingress readiness is evaluated.
	IngressReadinessMode string

	// ProvisionedRegistryURL is the URL of the provisioned registry.
	ProvisionedRegistryURL string

	// ProvisionedRegistryUsername is the username for the provisioned registry.
	ProvisionedRegistryUsername string

	// ProvisionedRegistryPassword is the password for the provisioned registry.
	ProvisionedRegistryPassword string

	// ProvisionedRegistrySecretName is the name of the secret for registry credentials.
	ProvisionedRegistrySecretName string

	// InternalRegistryEndpoint is the internal registry endpoint to use for image refs when not using a provisioned registry.
	InternalRegistryEndpoint string

	// RegistryPullHost is the pullable registry host used in image refs when the operator
	// needs to rewrite images to the platform-managed registry.
	RegistryPullHost string

	// RequeueDelaySeconds is the delay in seconds before requeueing when resources aren't ready.
	RequeueDelaySeconds int

	// GatewayProxyImage is the default image used for the optional MCP gateway sidecar.
	GatewayProxyImage string

	// GatewayOTLPEndpoint is the OTLP/HTTP endpoint injected into MCP gateway sidecars.
	GatewayOTLPEndpoint string

	// AnalyticsIngestURL is the default analytics ingest endpoint for gateway sidecars.
	AnalyticsIngestURL string

	// OAuthInternalIssuerURL is the in-cluster URL used by gateway sidecars for
	// OAuth metadata and JWKS discovery.
	OAuthInternalIssuerURL string

	// ClusterName is the cluster label attached to emitted audit events.
	ClusterName string
}

OperatorConfig holds configuration for the operator loaded from environment variables.

func LoadOperatorConfig

func LoadOperatorConfig() *OperatorConfig

LoadOperatorConfig loads operator configuration from environment variables.

func (*OperatorConfig) HasProvisionedRegistry

func (c *OperatorConfig) HasProvisionedRegistry() bool

HasProvisionedRegistry returns true if a provisioned registry is configured.

func (*OperatorConfig) ToRegistryConfig

func (c *OperatorConfig) ToRegistryConfig() *RegistryConfig

ToRegistryConfig converts the config to a RegistryConfig if provisioned registry is enabled.

type RegistryConfig

type RegistryConfig struct {
	URL        string
	Username   string
	Password   string
	SecretName string
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL