Documentation
¶
Overview ¶
Package operator provides the Kubernetes operator for MCPServer resources.
Index ¶
Constants ¶
const ( // DefaultRequestCPU is the default CPU request for containers. DefaultRequestCPU = "50m" // DefaultRequestMemory is the default memory request for containers. DefaultRequestMemory = "64Mi" // DefaultLimitCPU is the default CPU limit for containers. DefaultLimitCPU = "500m" // DefaultLimitMemory is the default memory limit for containers. DefaultLimitMemory = "256Mi" )
Resource defaults for MCPServer deployments.
const ( // DefaultReplicas is the default number of replicas. DefaultReplicas = 1 // DefaultPort is the default container port. DefaultPort = mcpdefaults.MCPServerPort // DefaultGatewayPort is the default container port for the MCP proxy sidecar. DefaultGatewayPort = mcpdefaults.MCPGatewayPort // DefaultGatewayMetricsPort is the default Prometheus scrape port for the MCP gateway sidecar. DefaultGatewayMetricsPort = 9103 // DefaultServicePort is the default service port. DefaultServicePort = 80 )
MCPServer defaults.
const ( // LabelApp is the standard app label key. LabelApp = "app" // LabelManagedBy is the label indicating the managing controller. LabelManagedBy = "app.kubernetes.io/managed-by" // LabelManagedByValue is the value for the managed-by label. LabelManagedByValue = "github.com/mcp-runtime/mcp-runtime" )
Labels used by the operator.
const ( // DefaultIngressClass is the default ingress class. DefaultIngressClass = "traefik" // DefaultIngressPathType is the default path type for ingress rules. DefaultIngressPathType = "Prefix" // IngressReadinessModeStrict requires Ingress.status.loadBalancer.ingress to be populated. IngressReadinessModeStrict = "strict" // IngressReadinessModePermissive treats an Ingress with rules as ready when LB status is absent. IngressReadinessModePermissive = "permissive" )
Ingress configuration.
const ( // DefaultRegistrySecretName is the default name for registry pull secrets. // #nosec G101 -- This is a secret name, not a credential. DefaultRegistrySecretName = "mcp-runtime-registry-pull" )
Secret names.
const ( // RequeueDelayNotReady is the delay before requeueing when resources are not ready. RequeueDelayNotReady = 10 // seconds )
Requeue delays for reconciliation.
Variables ¶
var ( // Reconciliation errors. ErrReconcileDeployment = fmt.Errorf("failed to reconcile deployment") ErrReconcileService = fmt.Errorf("failed to reconcile service") ErrReconcileIngress = fmt.Errorf("failed to reconcile ingress") ErrUpdateStatus = fmt.Errorf("failed to update status") ErrApplyDefaults = fmt.Errorf("failed to apply defaults") // Validation errors. ErrMissingIngressHost = fmt.Errorf("missing ingress host") ErrMissingIngressPath = fmt.Errorf("missing ingress path") // Resource errors. ErrInvalidCPURequest = fmt.Errorf("invalid CPU request") ErrInvalidMemoryRequest = fmt.Errorf("invalid memory request") ErrInvalidCPULimit = fmt.Errorf("invalid CPU limit") ErrInvalidMemoryLimit = fmt.Errorf("invalid memory limit") )
Sentinel errors for operator operations.
var DefaultOperatorConfig = LoadOperatorConfig()
DefaultOperatorConfig is the default configuration loaded at startup.
Functions ¶
func NormalizeIngressReadinessMode ¶
NormalizeIngressReadinessMode returns a supported ingress readiness mode. Empty or invalid values fall back to strict mode.
Types ¶
type MCPServerReconciler ¶
type MCPServerReconciler struct {
client.Client
Scheme *runtime.Scheme
// APIReader is an uncached reader for objects the operator does not watch
// (the server's pods). Nil falls back to Client.
APIReader client.Reader
// DefaultIngressHost is the default ingress host if not specified in the CR.
DefaultIngressHost string
// DefaultIngressEntryPoints is the default Traefik entrypoint annotation for MCP server ingresses.
DefaultIngressEntryPoints string
// DefaultIngressTLS enables Traefik TLS routing for MCP server ingresses by default.
DefaultIngressTLS bool
// DefaultIngressTLSSecret is the Kubernetes TLS Secret holding the
// caller-facing (user->Traefik) host certificate for mtls servers. Path-based
// mtls servers share one host, so this single platform host certificate is
// published as Traefik's default certificate via a TLSStore named "default"
// (see reconcileDefaultTLSStore) rather than a per-IngressRoute secretName.
// Empty falls back to Traefik's built-in default certificate.
DefaultIngressTLSSecret string
// DefaultIngressTLSSecretNamespace is the Traefik-watched namespace that holds
// the DefaultIngressTLSSecret and the single "default" TLSStore. Must be one
// of the namespaces Traefik's kubernetescrd provider watches.
DefaultIngressTLSSecretNamespace string
// IngressReadinessMode controls how ingress readiness is evaluated.
IngressReadinessMode string
// ProvisionedRegistry holds the provisioned registry configuration.
// If nil or URL is empty, provisioned registry features are disabled.
ProvisionedRegistry *RegistryConfig
// GatewayProxyImage is the default image used for the optional MCP gateway sidecar.
GatewayProxyImage string
// GatewayOTLPEndpoint is the OTLP/HTTP endpoint injected into MCP gateway sidecars.
GatewayOTLPEndpoint string
// DefaultAnalyticsIngestURL is the default analytics ingest endpoint used when analytics is enabled.
DefaultAnalyticsIngestURL string
// ClusterName is the cluster label attached to policy and audit events.
ClusterName string
// OAuthInternalIssuerURL is the in-cluster URL used by gateway sidecars for
// OAuth metadata and JWKS discovery.
OAuthInternalIssuerURL string
// OAuthIssuerURL enables bundled authorization-server resource reconciliation
// and supplies the default public issuer for OAuth MCPServers.
OAuthIssuerURL string
// MTLSClusterIssuer is the pre-existing cert-manager ClusterIssuer used for
// gateway and adapter workload certificates. It is platform-wide; it does
// not depend on MCP request authentication.
MTLSClusterIssuer string
// AdapterCertificatesEnabled opts OAuth servers into optional adapter
// client certificates on their route (MCP_ADAPTER_CERTIFICATES).
AdapterCertificatesEnabled bool
// AdapterTrustDomain is the platform-wide SPIFFE trust domain used for
// session-bound adapter certificates and the trusted Traefik identity.
AdapterTrustDomain string
IngressControllerNamespace string
IngressControllerServiceAccount string
IngressControllerPodLabels map[string]string
}
MCPServerReconciler reconciles a MCPServer object
func (*MCPServerReconciler) Reconcile ¶
Reconcile is part of the main kubernetes reconciliation loop
func (*MCPServerReconciler) SetupWithManager ¶
func (r *MCPServerReconciler) SetupWithManager(mgr ctrl.Manager) error
type OperatorConfig ¶
type OperatorConfig struct {
// DefaultIngressHost is the default host for ingress resources.
DefaultIngressHost string
// DefaultIngressClass is the ingress class to use.
DefaultIngressClass string
// DefaultIngressEntryPoints is the default Traefik entrypoint annotation for MCP server ingresses.
DefaultIngressEntryPoints string
// DefaultIngressTLS enables Traefik TLS routing for MCP server ingresses by default.
DefaultIngressTLS bool
// IngressReadinessMode controls how ingress readiness is evaluated.
IngressReadinessMode string
// ProvisionedRegistryURL is the URL of the provisioned registry.
ProvisionedRegistryURL string
// ProvisionedRegistryUsername is the username for the provisioned registry.
ProvisionedRegistryUsername string
// ProvisionedRegistryPassword is the password for the provisioned registry.
ProvisionedRegistryPassword string
// ProvisionedRegistrySecretName is the name of the secret for registry credentials.
ProvisionedRegistrySecretName string
// InternalRegistryEndpoint is the internal registry endpoint to use for image refs when not using a provisioned registry.
InternalRegistryEndpoint string
// RegistryPullHost is the pullable registry host used in image refs when the operator
// needs to rewrite images to the platform-managed registry.
RegistryPullHost string
// RequeueDelaySeconds is the delay in seconds before requeueing when resources aren't ready.
RequeueDelaySeconds int
// GatewayProxyImage is the default image used for the optional MCP gateway sidecar.
GatewayProxyImage string
// GatewayOTLPEndpoint is the OTLP/HTTP endpoint injected into MCP gateway sidecars.
GatewayOTLPEndpoint string
// AnalyticsIngestURL is the default analytics ingest endpoint for gateway sidecars.
AnalyticsIngestURL string
// OAuthInternalIssuerURL is the in-cluster URL used by gateway sidecars for
// OAuth metadata and JWKS discovery.
OAuthInternalIssuerURL string
// ClusterName is the cluster label attached to emitted audit events.
ClusterName string
}
OperatorConfig holds configuration for the operator loaded from environment variables.
func LoadOperatorConfig ¶
func LoadOperatorConfig() *OperatorConfig
LoadOperatorConfig loads operator configuration from environment variables.
func (*OperatorConfig) HasProvisionedRegistry ¶
func (c *OperatorConfig) HasProvisionedRegistry() bool
HasProvisionedRegistry returns true if a provisioned registry is configured.
func (*OperatorConfig) ToRegistryConfig ¶
func (c *OperatorConfig) ToRegistryConfig() *RegistryConfig
ToRegistryConfig converts the config to a RegistryConfig if provisioned registry is enabled.