Documentation
¶
Index ¶
- Constants
- func DisplayImageReference(image string) string
- func GatewayIsEnabled(gateway *GatewayConfig) bool
- func GenerateCRD(server *ServerMetadata, outputPath string) error
- func GenerateCRDsFromRegistry(registry *RegistryFile, outputDir string) error
- func NormalizePlatformDomain(raw string) string
- func ResolveMcpIngressHost() string
- func ResolvePlatformIngressHost() string
- func ResolveRegistryEndpoint() string
- func ResolveRegistryHost() string
- func ResolveRegistryPullHost() string
- func RewriteImageRegistryHost(image, registry string) (string, bool)
- type AnalyticsConfig
- type AuthConfig
- type EnvVar
- type GatewayConfig
- type InventoryItem
- type PolicyConfig
- type PolicyDecision
- type PolicyMode
- type PublishScope
- type RegistryFile
- type ResourceList
- type ResourceRequirements
- type RolloutConfig
- type RolloutStrategy
- type SecretEnvVar
- type SecretKeyRef
- type ServerMetadata
- type SessionConfig
- type ToolConfig
- type ToolRiskLevel
- type ToolSideEffect
- type TrustLevel
Constants ¶
const DefaultRegistryHost = "registry.local"
Variables ¶
This section is empty.
Functions ¶
func DisplayImageReference ¶
DisplayImageReference rewrites internal registry image refs for user-facing display. It prefers the public registry host when configured, and otherwise strips the internal host so cluster-only endpoints do not leak into UI/API responses.
func GatewayIsEnabled ¶
func GatewayIsEnabled(gateway *GatewayConfig) bool
GatewayIsEnabled reports whether metadata requests a gateway sidecar.
func GenerateCRD ¶
func GenerateCRD(server *ServerMetadata, outputPath string) error
GenerateCRD generates a Kubernetes CRD YAML file for a single server metadata entry at the given output path.
func GenerateCRDsFromRegistry ¶
func GenerateCRDsFromRegistry(registry *RegistryFile, outputDir string) error
GenerateCRDsFromRegistry renders CRD YAML files for every server in a registry into outputDir.
func NormalizePlatformDomain ¶
NormalizePlatformDomain returns a lowercased FQDN suitable for "registry." + d and "mcp." + d, or an empty string if the input is unusable.
func ResolveMcpIngressHost ¶
func ResolveMcpIngressHost() string
func ResolvePlatformIngressHost ¶
func ResolvePlatformIngressHost() string
ResolvePlatformIngressHost is the public hostname for the platform / admin dashboard UI: MCP_PLATFORM_INGRESS_HOST, else platform.<MCP_PLATFORM_DOMAIN> when the platform domain is set, else empty (path-based dev routing is used).
func ResolveRegistryEndpoint ¶
func ResolveRegistryEndpoint() string
ResolveRegistryEndpoint returns the registry endpoint used by pulls and in-cluster skopeo: MCP_REGISTRY_ENDPOINT, then MCP_REGISTRY_HOST, then registry.<MCP_PLATFORM_DOMAIN>, then the local default. It deliberately skips MCP_REGISTRY_INGRESS_HOST, the public auth-protected host, so an install that only names its ingress still gets the "set MCP_REGISTRY_ENDPOINT" guidance instead of pulling through the public edge.
func ResolveRegistryHost ¶
func ResolveRegistryHost() string
ResolveRegistryHost resolves the public host used for default image names, ingress, and registry credentials. Precedence is MCP_REGISTRY_INGRESS_HOST, MCP_REGISTRY_HOST, registry.<MCP_PLATFORM_DOMAIN>, then the local development default. MCP_REGISTRY_ENDPOINT is reserved for internal pulls and transfers, so it must not become a public host fallback.
func ResolveRegistryPullHost ¶
func ResolveRegistryPullHost() string
ResolveRegistryPullHost returns the registry host kubelet should use for in-cluster image pulls. Precedence: MCP_REGISTRY_PULL_HOST, MCP_REGISTRY_ENDPOINT, then bundled cluster DNS.
Public ingress hostnames are intentionally excluded. Workload pods must pull from the internal registry endpoint, not the auth-protected external ingress.
func RewriteImageRegistryHost ¶
RewriteImageRegistryHost replaces the registry portion of an image reference.
Types ¶
type AnalyticsConfig ¶
type AnalyticsConfig struct {
Disabled bool `yaml:"disabled,omitempty" json:"disabled,omitempty"`
IngestURL string `yaml:"ingestURL,omitempty" json:"ingestURL,omitempty"`
Source string `yaml:"source,omitempty" json:"source,omitempty"`
EventType string `yaml:"eventType,omitempty" json:"eventType,omitempty"`
APIKeySecretRef *SecretKeyRef `yaml:"apiKeySecretRef,omitempty" json:"apiKeySecretRef,omitempty"`
}
AnalyticsConfig configures analytics emission from the gateway sidecar. Emission is on by default whenever the operator has an analytics ingest URL configured; set Disabled to true to opt out per server.
type AuthConfig ¶
type AuthConfig struct {
TokenHeader string `yaml:"tokenHeader,omitempty" json:"tokenHeader,omitempty"`
IssuerURL string `yaml:"issuerURL,omitempty" json:"issuerURL,omitempty"`
Audience string `yaml:"audience,omitempty" json:"audience,omitempty"`
}
AuthConfig enables optional OAuth authentication at the gateway.
type EnvVar ¶
type EnvVar struct {
Name string `yaml:"name" json:"name"`
Value string `yaml:"value" json:"value"`
}
EnvVar defines a literal environment variable.
type GatewayConfig ¶
type GatewayConfig struct {
// Enabled turns the gateway sidecar on or off. When nil/omitted the sidecar
// is enabled. Set to false to opt out.
Enabled *bool `yaml:"enabled,omitempty" json:"enabled,omitempty"`
Image string `yaml:"image,omitempty" json:"image,omitempty"`
Port int32 `yaml:"port,omitempty" json:"port,omitempty"`
UpstreamURL string `yaml:"upstreamURL,omitempty" json:"upstreamURL,omitempty"`
StripPrefix string `yaml:"stripPrefix,omitempty" json:"stripPrefix,omitempty"`
Resources *ResourceRequirements `yaml:"resources,omitempty" json:"resources,omitempty"`
}
GatewayConfig configures an optional MCP proxy sidecar for a server.
type InventoryItem ¶
type InventoryItem struct {
Name string `yaml:"name" json:"name"`
Description string `yaml:"description,omitempty" json:"description,omitempty"`
Labels map[string]string `yaml:"labels,omitempty" json:"labels,omitempty"`
}
InventoryItem describes a named MCP prompt, resource, or task.
type PolicyConfig ¶
type PolicyConfig struct {
Mode PolicyMode `yaml:"mode,omitempty" json:"mode,omitempty"`
DefaultDecision PolicyDecision `yaml:"defaultDecision,omitempty" json:"defaultDecision,omitempty"`
EnforceOn string `yaml:"enforceOn,omitempty" json:"enforceOn,omitempty"`
PolicyVersion string `yaml:"policyVersion,omitempty" json:"policyVersion,omitempty"`
}
PolicyConfig configures authorization behavior at the gateway.
type PolicyDecision ¶
type PolicyDecision string
+kubebuilder:validation:Enum=allow;deny
const ( PolicyDecisionAllow PolicyDecision = mcpdefaults.PolicyDecisionAllow PolicyDecisionDeny PolicyDecision = mcpdefaults.PolicyDecisionDeny )
type PolicyMode ¶
type PolicyMode string
+kubebuilder:validation:Enum=oauth +kubebuilder:validation:Enum=allow-list;observe
const ( PolicyModeAllowList PolicyMode = mcpdefaults.PolicyModeAllowList PolicyModeObserve PolicyMode = "observe" )
type PublishScope ¶
type PublishScope string
PublishScope selects the platform catalog or tenant boundary for publishing.
const ( PublishScopeTenant PublishScope = "tenant" PublishScopeOrg PublishScope = "org" PublishScopePublic PublishScope = "public" )
type RegistryFile ¶
type RegistryFile struct {
// Version of the metadata format.
Version string `yaml:"version" json:"version"`
// Servers is a list of MCP server definitions.
Servers []ServerMetadata `yaml:"servers" json:"servers"`
}
RegistryFile represents the complete registry/metadata file.
func LoadFromDirectory ¶
func LoadFromDirectory(dirPath string) (*RegistryFile, error)
LoadFromDirectory aggregates all .yaml/.yml registry files in a directory into one registry object.
func LoadFromFile ¶
func LoadFromFile(filePath string) (*RegistryFile, error)
LoadFromFile reads a single registry YAML file from disk and applies default values.
type ResourceList ¶
type ResourceList struct {
CPU string `yaml:"cpu,omitempty" json:"cpu,omitempty"`
Memory string `yaml:"memory,omitempty" json:"memory,omitempty"`
}
ResourceList defines CPU and memory resources.
type ResourceRequirements ¶
type ResourceRequirements struct {
Limits *ResourceList `yaml:"limits,omitempty" json:"limits,omitempty"`
Requests *ResourceList `yaml:"requests,omitempty" json:"requests,omitempty"`
}
ResourceRequirements defines resource limits and requests.
type RolloutConfig ¶
type RolloutConfig struct {
Strategy RolloutStrategy `yaml:"strategy,omitempty" json:"strategy,omitempty"`
MaxSurge string `yaml:"maxSurge,omitempty" json:"maxSurge,omitempty"`
CanaryReplicas *int32 `yaml:"canaryReplicas,omitempty" json:"canaryReplicas,omitempty"`
}
RolloutConfig configures deployment rollout behavior.
type RolloutStrategy ¶
type RolloutStrategy string
+kubebuilder:validation:Enum=RollingUpdate;Recreate;Canary
const ( RolloutStrategyRollingUpdate RolloutStrategy = "RollingUpdate" RolloutStrategyRecreate RolloutStrategy = "Recreate" RolloutStrategyCanary RolloutStrategy = "Canary" )
type SecretEnvVar ¶
type SecretEnvVar struct {
Name string `yaml:"name" json:"name"`
SecretKeyRef *SecretKeyRef `yaml:"secretKeyRef,omitempty" json:"secretKeyRef,omitempty"`
}
SecretEnvVar defines a secret-backed environment variable.
type SecretKeyRef ¶
type SecretKeyRef struct {
Name string `yaml:"name" json:"name"`
Key string `yaml:"key" json:"key"`
}
SecretKeyRef points to a single key in a Kubernetes Secret.
type ServerMetadata ¶
type ServerMetadata struct {
// Name is the unique name of the MCP server.
Name string `yaml:"name" json:"name"`
// Description is a human-readable summary of what the MCP server provides.
Description string `yaml:"description,omitempty" json:"description,omitempty"`
// Image is the container image for the server.
Image string `yaml:"image" json:"image"`
// ImageTag is the tag of the container image (defaults to "latest").
ImageTag string `yaml:"imageTag,omitempty" json:"imageTag,omitempty"`
// Route is the route path for the server (defaults to name/mcp).
Route string `yaml:"route,omitempty" json:"route,omitempty"`
// IngressHost is the hostname for the server ingress route.
IngressHost string `yaml:"ingressHost,omitempty" json:"ingressHost,omitempty"`
// PublicPathPrefix enables hostless path-based routing and resolves to /<publicPathPrefix>/mcp.
PublicPathPrefix string `yaml:"publicPathPrefix,omitempty" json:"publicPathPrefix,omitempty"`
// Port is the port the container listens on (defaults to 8088).
Port int32 `yaml:"port,omitempty" json:"port,omitempty"`
// Replicas is the number of desired replicas (defaults to 1).
Replicas *int32 `yaml:"replicas,omitempty" json:"replicas,omitempty"`
// Resources defines resource limits and requests.
Resources *ResourceRequirements `yaml:"resources,omitempty" json:"resources,omitempty"`
// EnvVars are literal environment variables to pass to the container.
EnvVars []EnvVar `yaml:"envVars,omitempty" json:"envVars,omitempty"`
// SecretEnvVars are secret-backed environment variables to pass to the container.
SecretEnvVars []SecretEnvVar `yaml:"secretEnvVars,omitempty" json:"secretEnvVars,omitempty"`
// Namespace is the Kubernetes namespace (defaults to "mcp-servers").
Namespace string `yaml:"namespace,omitempty" json:"namespace,omitempty"`
// Scope selects a publish destination: tenant, org, or public.
Scope PublishScope `yaml:"scope,omitempty" json:"scope,omitempty"`
// TeamID is the stable platform team identifier that owns the server.
TeamID string `yaml:"teamID,omitempty" json:"teamID,omitempty"`
// Tools describes the MCP tool inventory exposed by the server.
Tools []ToolConfig `yaml:"tools,omitempty" json:"tools,omitempty"`
// Prompts describes the MCP prompt inventory exposed by the server.
Prompts []InventoryItem `yaml:"prompts,omitempty" json:"prompts,omitempty"`
// MCPResources describes the MCP resource inventory exposed by the server.
MCPResources []InventoryItem `yaml:"mcpResources,omitempty" json:"mcpResources,omitempty"`
// Tasks describes task templates or workflows exposed by the server.
Tasks []InventoryItem `yaml:"tasks,omitempty" json:"tasks,omitempty"`
// Auth configures how the gateway extracts human, agent, and session identity.
Auth *AuthConfig `yaml:"auth,omitempty" json:"auth,omitempty"`
// Policy configures gateway-side authorization behavior.
Policy *PolicyConfig `yaml:"policy,omitempty" json:"policy,omitempty"`
// Session configures server-side agent session behavior.
Session *SessionConfig `yaml:"session,omitempty" json:"session,omitempty"`
// Gateway configures an optional MCP proxy sidecar in front of the server container.
Gateway *GatewayConfig `yaml:"gateway,omitempty" json:"gateway,omitempty"`
// Analytics configures analytics emission for the gateway sidecar.
Analytics *AnalyticsConfig `yaml:"analytics,omitempty" json:"analytics,omitempty"`
// Rollout configures deployment rollout behavior.
Rollout *RolloutConfig `yaml:"rollout,omitempty" json:"rollout,omitempty"`
}
ServerMetadata defines the metadata for an MCP server.
type SessionConfig ¶
type SessionConfig struct {
Required bool `yaml:"required,omitempty" json:"required,omitempty"`
Store string `yaml:"store,omitempty" json:"store,omitempty"`
MaxLifetime string `yaml:"maxLifetime,omitempty" json:"maxLifetime,omitempty"`
IdleTimeout string `yaml:"idleTimeout,omitempty" json:"idleTimeout,omitempty"`
UpstreamTokenHeader string `yaml:"upstreamTokenHeader,omitempty" json:"upstreamTokenHeader,omitempty"`
}
SessionConfig configures server-side agent session behavior.
type ToolConfig ¶
type ToolConfig struct {
Name string `yaml:"name" json:"name"`
Description string `yaml:"description,omitempty" json:"description,omitempty"`
RequiredTrust TrustLevel `yaml:"requiredTrust,omitempty" json:"requiredTrust,omitempty"`
SideEffect ToolSideEffect `yaml:"sideEffect" json:"sideEffect"`
RiskLevel ToolRiskLevel `yaml:"riskLevel,omitempty" json:"riskLevel,omitempty"`
Labels map[string]string `yaml:"labels,omitempty" json:"labels,omitempty"`
}
ToolConfig describes one MCP tool exposed by a server.
type ToolRiskLevel ¶
type ToolRiskLevel string
const ( ToolRiskLevelLow ToolRiskLevel = "low" ToolRiskLevelMedium ToolRiskLevel = "medium" ToolRiskLevelHigh ToolRiskLevel = "high" )
type ToolSideEffect ¶
type ToolSideEffect string
+kubebuilder:validation:Enum=read;write;destructive
const ( ToolSideEffectRead ToolSideEffect = "read" ToolSideEffectWrite ToolSideEffect = "write" ToolSideEffectDestructive ToolSideEffect = "destructive" )
type TrustLevel ¶
type TrustLevel string
+kubebuilder:validation:Enum=low;medium;high
const ( TrustLevelLow TrustLevel = "low" TrustLevelMedium TrustLevel = "medium" TrustLevelHigh TrustLevel = "high" )