access

package
v0.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 0 Imported by: 0

Documentation

Index

Constants

View Source
const (
	APIGroup              = mcpv1alpha1.Group
	APIVersion            = mcpv1alpha1.Version
	AccessGrantResource   = mcpv1alpha1.MCPAccessGrantResource
	AccessSessionResource = mcpv1alpha1.MCPAgentSessionResource
	MCPServerResource     = mcpv1alpha1.MCPServerResource
	// DefaultMCPResourceNamespace is used when a ServerReference or access resource omits a namespace.
	DefaultMCPResourceNamespace = mcpdefaults.MCPServersNamespace
)

Variables

This section is empty.

Functions

func IsMCPServerNotFoundForRef

func IsMCPServerNotFoundForRef(err error) bool

IsMCPServerNotFoundForRef returns true if err is an *ErrMCPServerNotFound.

func ToJSON

func ToJSON(obj interface{}) ([]byte, error)

ToJSON converts a grant or session to JSON bytes.

func ValidateOptionalResourceName

func ValidateOptionalResourceName(field, name string) error

ValidateOptionalResourceName is ValidateResourceName but treats empty as valid. Use for optional fields like serverRef.namespace.

func ValidateResourceName

func ValidateResourceName(field, name string) error

ValidateResourceName returns nil if name is a valid Kubernetes object name (DNS-1123 subdomain, <= 253 characters). The field argument is used in the error message so callers can distinguish, e.g., "name" from "serverRef.name".

Types

type AgentID

type AgentID string

AgentID identifies an authenticated agent principal.

type ErrMCPServerNotFound

type ErrMCPServerNotFound struct {
	Name, Namespace string
}

ErrMCPServerNotFound is returned by AssertMCPServerRef when the target MCPServer is missing.

func (*ErrMCPServerNotFound) Error

func (e *ErrMCPServerNotFound) Error() string

type GrantSummary

type GrantSummary struct {
	Name               string           `json:"name"`
	Namespace          string           `json:"namespace"`
	ServerRef          ServerReference  `json:"serverRef"`
	Subject            SubjectRef       `json:"subject"`
	MaxTrust           TrustLevel       `json:"maxTrust"`
	AllowedSideEffects []ToolSideEffect `json:"allowedSideEffects,omitempty"`
	ExpiresAt          *metav1.Time     `json:"expiresAt,omitempty"`
	Disabled           bool             `json:"disabled"`
	Age                string           `json:"age"`
}

GrantSummary provides a simplified view of a grant for UI display.

func ToGrantSummary

func ToGrantSummary(grant MCPAccessGrant) GrantSummary

ToGrantSummary converts an MCPAccessGrant to a GrantSummary.

type HumanID

type HumanID string

HumanID identifies an authenticated human principal.

type MCPAccessGrant

type MCPAccessGrant struct {
	metav1.TypeMeta   `json:",inline"`
	metav1.ObjectMeta `json:"metadata,omitempty"`

	Spec   MCPAccessGrantSpec   `json:"spec,omitempty"`
	Status MCPAccessGrantStatus `json:"status,omitempty"`
}

MCPAccessGrant grants a human or agent access to an MCPServer.

type MCPAccessGrantList

type MCPAccessGrantList struct {
	metav1.TypeMeta `json:",inline"`
	metav1.ListMeta `json:"metadata,omitempty"`
	Items           []MCPAccessGrant `json:"items"`
}

MCPAccessGrantList contains a list of MCPAccessGrant.

type MCPAccessGrantSpec

type MCPAccessGrantSpec struct {
	ServerRef          ServerReference  `json:"serverRef"`
	Subject            SubjectRef       `json:"subject"`
	MaxTrust           TrustLevel       `json:"maxTrust,omitempty"`
	AllowedSideEffects []ToolSideEffect `json:"allowedSideEffects,omitempty"`
	PolicyVersion      string           `json:"policyVersion,omitempty"`
	Disabled           bool             `json:"disabled,omitempty"`
	ExpiresAt          *metav1.Time     `json:"expiresAt,omitempty"`
	ToolRules          []ToolRule       `json:"toolRules,omitempty"`
}

MCPAccessGrantSpec defines who can use which MCP server and with what trust ceiling.

type MCPAccessGrantStatus

type MCPAccessGrantStatus struct {
	Phase      string             `json:"phase,omitempty"`
	Message    string             `json:"message,omitempty"`
	Conditions []metav1.Condition `json:"conditions,omitempty"`
}

MCPAccessGrantStatus captures observed grant state.

type MCPAgentSession

type MCPAgentSession struct {
	metav1.TypeMeta   `json:",inline"`
	metav1.ObjectMeta `json:"metadata,omitempty"`

	Spec   MCPAgentSessionSpec   `json:"spec,omitempty"`
	Status MCPAgentSessionStatus `json:"status,omitempty"`
}

MCPAgentSession stores consent and upstream token state for an agent session.

type MCPAgentSessionList

type MCPAgentSessionList struct {
	metav1.TypeMeta `json:",inline"`
	metav1.ListMeta `json:"metadata,omitempty"`
	Items           []MCPAgentSession `json:"items"`
}

MCPAgentSessionList contains a list of MCPAgentSession.

type MCPAgentSessionSpec

type MCPAgentSessionSpec struct {
	ServerRef              ServerReference `json:"serverRef"`
	Subject                SubjectRef      `json:"subject"`
	ConsentedTrust         TrustLevel      `json:"consentedTrust,omitempty"`
	ExpiresAt              *metav1.Time    `json:"expiresAt,omitempty"`
	Revoked                bool            `json:"revoked,omitempty"`
	UpstreamTokenSecretRef *SecretKeyRef   `json:"upstreamTokenSecretRef,omitempty"`
	PolicyVersion          string          `json:"policyVersion,omitempty"`
}

MCPAgentSessionSpec defines a consented server-side agent session.

type MCPAgentSessionStatus

type MCPAgentSessionStatus struct {
	Phase      string             `json:"phase,omitempty"`
	Message    string             `json:"message,omitempty"`
	Conditions []metav1.Condition `json:"conditions,omitempty"`
}

MCPAgentSessionStatus captures observed session state.

type Manager

type Manager struct {
	// contains filtered or unexported fields
}

Manager provides operations for MCPAccessGrant and MCPAgentSession resources.

func NewManager

func NewManager(dynamic dynamic.Interface, clientset kubernetes.Interface) *Manager

NewManager creates a new access resource manager.

func (*Manager) ApplyGrant

func (m *Manager) ApplyGrant(ctx context.Context, grant *MCPAccessGrant) (*MCPAccessGrant, error)

ApplyGrant creates or updates an MCPAccessGrant resource.

func (*Manager) ApplySession

func (m *Manager) ApplySession(ctx context.Context, session *MCPAgentSession) (*MCPAgentSession, error)

ApplySession creates or updates an MCPAgentSession resource.

func (*Manager) AssertMCPServerRef

func (m *Manager) AssertMCPServerRef(ctx context.Context, ref ServerReference) error

AssertMCPServerRef returns an error if no MCPServer exists at the given ref. Use this before creating grants or sessions so the API can reject unknown targets early.

func (*Manager) DeleteGrant

func (m *Manager) DeleteGrant(ctx context.Context, name, namespace string) error

DeleteGrant removes an MCPAccessGrant.

func (*Manager) DeleteSession

func (m *Manager) DeleteSession(ctx context.Context, name, namespace string) error

DeleteSession removes an MCPAgentSession.

func (*Manager) DisableGrant

func (m *Manager) DisableGrant(ctx context.Context, name, namespace string) error

DisableGrant disables an MCPAccessGrant by setting spec.disabled to true.

func (*Manager) EnableGrant

func (m *Manager) EnableGrant(ctx context.Context, name, namespace string) error

EnableGrant enables an MCPAccessGrant by setting spec.disabled to false.

func (*Manager) GetGrant

func (m *Manager) GetGrant(ctx context.Context, name, namespace string) (*MCPAccessGrant, error)

GetGrant returns a specific MCPAccessGrant resource.

func (*Manager) GetMCPServerRef

func (m *Manager) GetMCPServerRef(ctx context.Context, ref ServerReference) (*mcpv1alpha1.MCPServer, error)

GetMCPServerRef returns the MCPServer referenced by ref.

func (*Manager) GetServerPolicy

func (m *Manager) GetServerPolicy(ctx context.Context, namespace, serverName string) (map[string]interface{}, error)

GetServerPolicy returns the rendered policy for a specific server if available.

func (*Manager) GetSession

func (m *Manager) GetSession(ctx context.Context, name, namespace string) (*MCPAgentSession, error)

GetSession returns a specific MCPAgentSession resource.

func (*Manager) ListGrants

func (m *Manager) ListGrants(ctx context.Context, namespace string) (*MCPAccessGrantList, error)

ListGrants returns all MCPAccessGrant resources, optionally filtered by namespace.

func (*Manager) ListMCPServers

func (m *Manager) ListMCPServers(ctx context.Context, namespace string) (*mcpv1alpha1.MCPServerList, error)

ListMCPServers returns all MCPServer resources, optionally filtered by namespace.

func (*Manager) ListSessions

func (m *Manager) ListSessions(ctx context.Context, namespace string) (*MCPAgentSessionList, error)

ListSessions returns all MCPAgentSession resources, optionally filtered by namespace.

func (*Manager) RevokeSession

func (m *Manager) RevokeSession(ctx context.Context, name, namespace string) error

RevokeSession revokes an MCPAgentSession by setting spec.revoked to true.

func (*Manager) UnrevokeSession

func (m *Manager) UnrevokeSession(ctx context.Context, name, namespace string) error

UnrevokeSession clears the revoked flag on an MCPAgentSession.

type Namespace

type Namespace string

Namespace identifies a Kubernetes namespace that contains MCP runtime resources.

func ResolveServerRefNamespace

func ResolveServerRefNamespace(ref ServerReference) Namespace

ResolveServerRefNamespace returns the namespace to resolve serverRef against. Empty or whitespace ref.Namespace defaults to DefaultMCPResourceNamespace.

type PolicyDecision

type PolicyDecision string

PolicyDecision defines policy decisions for tool access.

const (
	DecisionAllow PolicyDecision = "allow"
	DecisionDeny  PolicyDecision = mcpdefaults.PolicyDecisionDeny
	DecisionAudit PolicyDecision = "audit"
)

type SecretKeyRef

type SecretKeyRef struct {
	Name string `json:"name"`
	Key  string `json:"key"`
}

SecretKeyRef references a secret key.

type ServerName

type ServerName string

ServerName identifies an MCPServer resource by name.

type ServerReference

type ServerReference struct {
	Name      ServerName `json:"name"`
	Namespace Namespace  `json:"namespace,omitempty"`
}

ServerReference identifies an MCPServer.

type SessionSummary

type SessionSummary struct {
	Name           string          `json:"name"`
	Namespace      string          `json:"namespace"`
	ServerRef      ServerReference `json:"serverRef"`
	Subject        SubjectRef      `json:"subject"`
	ConsentedTrust TrustLevel      `json:"consentedTrust"`
	Revoked        bool            `json:"revoked"`
	ExpiresAt      *metav1.Time    `json:"expiresAt,omitempty"`
	Age            string          `json:"age"`
}

SessionSummary provides a simplified view of a session for UI display.

func ToSessionSummary

func ToSessionSummary(session MCPAgentSession) SessionSummary

ToSessionSummary converts an MCPAgentSession to a SessionSummary.

type SubjectRef

type SubjectRef struct {
	HumanID HumanID `json:"humanID,omitempty"`
	AgentID AgentID `json:"agentID,omitempty"`
	TeamID  TeamID  `json:"teamID,omitempty"`
}

SubjectRef identifies the human and optional agent a grant or session applies to.

type TeamID

type TeamID string

TeamID identifies a stable platform team principal.

type ToolRule

type ToolRule struct {
	Name          string         `json:"name"`
	Decision      PolicyDecision `json:"decision"`
	RequiredTrust TrustLevel     `json:"requiredTrust,omitempty"`
}

ToolRule controls access to an individual MCP tool.

type ToolSideEffect

type ToolSideEffect string

ToolSideEffect classifies whether a tool reads, mutates, or destructively changes state.

const (
	SideEffectRead        ToolSideEffect = "read"
	SideEffectWrite       ToolSideEffect = "write"
	SideEffectDestructive ToolSideEffect = "destructive"
)

type TrustLevel

type TrustLevel string

TrustLevel defines trust levels for access control.

const (
	TrustLow    TrustLevel = "low"
	TrustMedium TrustLevel = "medium"
	TrustHigh   TrustLevel = "high"
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL