Documentation
¶
Index ¶
- Constants
- func IsMCPServerNotFoundForRef(err error) bool
- func ToJSON(obj interface{}) ([]byte, error)
- func ValidateOptionalResourceName(field, name string) error
- func ValidateResourceName(field, name string) error
- type AgentID
- type ErrMCPServerNotFound
- type GrantSummary
- type HumanID
- type MCPAccessGrant
- type MCPAccessGrantList
- type MCPAccessGrantSpec
- type MCPAccessGrantStatus
- type MCPAgentSession
- type MCPAgentSessionList
- type MCPAgentSessionSpec
- type MCPAgentSessionStatus
- type Manager
- func (m *Manager) ApplyGrant(ctx context.Context, grant *MCPAccessGrant) (*MCPAccessGrant, error)
- func (m *Manager) ApplySession(ctx context.Context, session *MCPAgentSession) (*MCPAgentSession, error)
- func (m *Manager) AssertMCPServerRef(ctx context.Context, ref ServerReference) error
- func (m *Manager) DeleteGrant(ctx context.Context, name, namespace string) error
- func (m *Manager) DeleteSession(ctx context.Context, name, namespace string) error
- func (m *Manager) DisableGrant(ctx context.Context, name, namespace string) error
- func (m *Manager) EnableGrant(ctx context.Context, name, namespace string) error
- func (m *Manager) GetGrant(ctx context.Context, name, namespace string) (*MCPAccessGrant, error)
- func (m *Manager) GetMCPServerRef(ctx context.Context, ref ServerReference) (*mcpv1alpha1.MCPServer, error)
- func (m *Manager) GetServerPolicy(ctx context.Context, namespace, serverName string) (map[string]interface{}, error)
- func (m *Manager) GetSession(ctx context.Context, name, namespace string) (*MCPAgentSession, error)
- func (m *Manager) ListGrants(ctx context.Context, namespace string) (*MCPAccessGrantList, error)
- func (m *Manager) ListMCPServers(ctx context.Context, namespace string) (*mcpv1alpha1.MCPServerList, error)
- func (m *Manager) ListSessions(ctx context.Context, namespace string) (*MCPAgentSessionList, error)
- func (m *Manager) RevokeSession(ctx context.Context, name, namespace string) error
- func (m *Manager) UnrevokeSession(ctx context.Context, name, namespace string) error
- type Namespace
- type PolicyDecision
- type SecretKeyRef
- type ServerName
- type ServerReference
- type SessionSummary
- type SubjectRef
- type TeamID
- type ToolRule
- type ToolSideEffect
- type TrustLevel
Constants ¶
const ( APIGroup = mcpv1alpha1.Group APIVersion = mcpv1alpha1.Version AccessGrantResource = mcpv1alpha1.MCPAccessGrantResource AccessSessionResource = mcpv1alpha1.MCPAgentSessionResource MCPServerResource = mcpv1alpha1.MCPServerResource // DefaultMCPResourceNamespace is used when a ServerReference or access resource omits a namespace. DefaultMCPResourceNamespace = mcpdefaults.MCPServersNamespace )
Variables ¶
This section is empty.
Functions ¶
func IsMCPServerNotFoundForRef ¶
IsMCPServerNotFoundForRef returns true if err is an *ErrMCPServerNotFound.
func ValidateOptionalResourceName ¶
ValidateOptionalResourceName is ValidateResourceName but treats empty as valid. Use for optional fields like serverRef.namespace.
func ValidateResourceName ¶
ValidateResourceName returns nil if name is a valid Kubernetes object name (DNS-1123 subdomain, <= 253 characters). The field argument is used in the error message so callers can distinguish, e.g., "name" from "serverRef.name".
Types ¶
type ErrMCPServerNotFound ¶
type ErrMCPServerNotFound struct {
Name, Namespace string
}
ErrMCPServerNotFound is returned by AssertMCPServerRef when the target MCPServer is missing.
func (*ErrMCPServerNotFound) Error ¶
func (e *ErrMCPServerNotFound) Error() string
type GrantSummary ¶
type GrantSummary struct {
Name string `json:"name"`
Namespace string `json:"namespace"`
ServerRef ServerReference `json:"serverRef"`
Subject SubjectRef `json:"subject"`
MaxTrust TrustLevel `json:"maxTrust"`
AllowedSideEffects []ToolSideEffect `json:"allowedSideEffects,omitempty"`
ExpiresAt *metav1.Time `json:"expiresAt,omitempty"`
Disabled bool `json:"disabled"`
Age string `json:"age"`
}
GrantSummary provides a simplified view of a grant for UI display.
func ToGrantSummary ¶
func ToGrantSummary(grant MCPAccessGrant) GrantSummary
ToGrantSummary converts an MCPAccessGrant to a GrantSummary.
type MCPAccessGrant ¶
type MCPAccessGrant struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
Spec MCPAccessGrantSpec `json:"spec,omitempty"`
Status MCPAccessGrantStatus `json:"status,omitempty"`
}
MCPAccessGrant grants a human or agent access to an MCPServer.
type MCPAccessGrantList ¶
type MCPAccessGrantList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []MCPAccessGrant `json:"items"`
}
MCPAccessGrantList contains a list of MCPAccessGrant.
type MCPAccessGrantSpec ¶
type MCPAccessGrantSpec struct {
ServerRef ServerReference `json:"serverRef"`
Subject SubjectRef `json:"subject"`
MaxTrust TrustLevel `json:"maxTrust,omitempty"`
AllowedSideEffects []ToolSideEffect `json:"allowedSideEffects,omitempty"`
PolicyVersion string `json:"policyVersion,omitempty"`
Disabled bool `json:"disabled,omitempty"`
ExpiresAt *metav1.Time `json:"expiresAt,omitempty"`
ToolRules []ToolRule `json:"toolRules,omitempty"`
}
MCPAccessGrantSpec defines who can use which MCP server and with what trust ceiling.
type MCPAccessGrantStatus ¶
type MCPAccessGrantStatus struct {
Phase string `json:"phase,omitempty"`
Message string `json:"message,omitempty"`
Conditions []metav1.Condition `json:"conditions,omitempty"`
}
MCPAccessGrantStatus captures observed grant state.
type MCPAgentSession ¶
type MCPAgentSession struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
Spec MCPAgentSessionSpec `json:"spec,omitempty"`
Status MCPAgentSessionStatus `json:"status,omitempty"`
}
MCPAgentSession stores consent and upstream token state for an agent session.
type MCPAgentSessionList ¶
type MCPAgentSessionList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []MCPAgentSession `json:"items"`
}
MCPAgentSessionList contains a list of MCPAgentSession.
type MCPAgentSessionSpec ¶
type MCPAgentSessionSpec struct {
ServerRef ServerReference `json:"serverRef"`
Subject SubjectRef `json:"subject"`
ConsentedTrust TrustLevel `json:"consentedTrust,omitempty"`
ExpiresAt *metav1.Time `json:"expiresAt,omitempty"`
Revoked bool `json:"revoked,omitempty"`
UpstreamTokenSecretRef *SecretKeyRef `json:"upstreamTokenSecretRef,omitempty"`
PolicyVersion string `json:"policyVersion,omitempty"`
}
MCPAgentSessionSpec defines a consented server-side agent session.
type MCPAgentSessionStatus ¶
type MCPAgentSessionStatus struct {
Phase string `json:"phase,omitempty"`
Message string `json:"message,omitempty"`
Conditions []metav1.Condition `json:"conditions,omitempty"`
}
MCPAgentSessionStatus captures observed session state.
type Manager ¶
type Manager struct {
// contains filtered or unexported fields
}
Manager provides operations for MCPAccessGrant and MCPAgentSession resources.
func NewManager ¶
func NewManager(dynamic dynamic.Interface, clientset kubernetes.Interface) *Manager
NewManager creates a new access resource manager.
func (*Manager) ApplyGrant ¶
func (m *Manager) ApplyGrant(ctx context.Context, grant *MCPAccessGrant) (*MCPAccessGrant, error)
ApplyGrant creates or updates an MCPAccessGrant resource.
func (*Manager) ApplySession ¶
func (m *Manager) ApplySession(ctx context.Context, session *MCPAgentSession) (*MCPAgentSession, error)
ApplySession creates or updates an MCPAgentSession resource.
func (*Manager) AssertMCPServerRef ¶
func (m *Manager) AssertMCPServerRef(ctx context.Context, ref ServerReference) error
AssertMCPServerRef returns an error if no MCPServer exists at the given ref. Use this before creating grants or sessions so the API can reject unknown targets early.
func (*Manager) DeleteGrant ¶
DeleteGrant removes an MCPAccessGrant.
func (*Manager) DeleteSession ¶
DeleteSession removes an MCPAgentSession.
func (*Manager) DisableGrant ¶
DisableGrant disables an MCPAccessGrant by setting spec.disabled to true.
func (*Manager) EnableGrant ¶
EnableGrant enables an MCPAccessGrant by setting spec.disabled to false.
func (*Manager) GetMCPServerRef ¶
func (m *Manager) GetMCPServerRef(ctx context.Context, ref ServerReference) (*mcpv1alpha1.MCPServer, error)
GetMCPServerRef returns the MCPServer referenced by ref.
func (*Manager) GetServerPolicy ¶
func (m *Manager) GetServerPolicy(ctx context.Context, namespace, serverName string) (map[string]interface{}, error)
GetServerPolicy returns the rendered policy for a specific server if available.
func (*Manager) GetSession ¶
GetSession returns a specific MCPAgentSession resource.
func (*Manager) ListGrants ¶
ListGrants returns all MCPAccessGrant resources, optionally filtered by namespace.
func (*Manager) ListMCPServers ¶
func (m *Manager) ListMCPServers(ctx context.Context, namespace string) (*mcpv1alpha1.MCPServerList, error)
ListMCPServers returns all MCPServer resources, optionally filtered by namespace.
func (*Manager) ListSessions ¶
ListSessions returns all MCPAgentSession resources, optionally filtered by namespace.
func (*Manager) RevokeSession ¶
RevokeSession revokes an MCPAgentSession by setting spec.revoked to true.
type Namespace ¶
type Namespace string
Namespace identifies a Kubernetes namespace that contains MCP runtime resources.
func ResolveServerRefNamespace ¶
func ResolveServerRefNamespace(ref ServerReference) Namespace
ResolveServerRefNamespace returns the namespace to resolve serverRef against. Empty or whitespace ref.Namespace defaults to DefaultMCPResourceNamespace.
type PolicyDecision ¶
type PolicyDecision string
PolicyDecision defines policy decisions for tool access.
const ( DecisionAllow PolicyDecision = "allow" DecisionDeny PolicyDecision = mcpdefaults.PolicyDecisionDeny DecisionAudit PolicyDecision = "audit" )
type SecretKeyRef ¶
SecretKeyRef references a secret key.
type ServerReference ¶
type ServerReference struct {
Name ServerName `json:"name"`
Namespace Namespace `json:"namespace,omitempty"`
}
ServerReference identifies an MCPServer.
type SessionSummary ¶
type SessionSummary struct {
Name string `json:"name"`
Namespace string `json:"namespace"`
ServerRef ServerReference `json:"serverRef"`
Subject SubjectRef `json:"subject"`
ConsentedTrust TrustLevel `json:"consentedTrust"`
Revoked bool `json:"revoked"`
ExpiresAt *metav1.Time `json:"expiresAt,omitempty"`
Age string `json:"age"`
}
SessionSummary provides a simplified view of a session for UI display.
func ToSessionSummary ¶
func ToSessionSummary(session MCPAgentSession) SessionSummary
ToSessionSummary converts an MCPAgentSession to a SessionSummary.
type SubjectRef ¶
type SubjectRef struct {
HumanID HumanID `json:"humanID,omitempty"`
AgentID AgentID `json:"agentID,omitempty"`
TeamID TeamID `json:"teamID,omitempty"`
}
SubjectRef identifies the human and optional agent a grant or session applies to.
type ToolRule ¶
type ToolRule struct {
Name string `json:"name"`
Decision PolicyDecision `json:"decision"`
RequiredTrust TrustLevel `json:"requiredTrust,omitempty"`
}
ToolRule controls access to an individual MCP tool.
type ToolSideEffect ¶
type ToolSideEffect string
ToolSideEffect classifies whether a tool reads, mutates, or destructively changes state.
const ( SideEffectRead ToolSideEffect = "read" SideEffectWrite ToolSideEffect = "write" SideEffectDestructive ToolSideEffect = "destructive" )
type TrustLevel ¶
type TrustLevel string
TrustLevel defines trust levels for access control.
const ( TrustLow TrustLevel = "low" TrustMedium TrustLevel = "medium" TrustHigh TrustLevel = "high" )