feat: expose direct ToolHive MCP endpoints - #245
Merged
Merged
Conversation
Drop spec.groupRef gateway from every aggregated MCPServer/MCPRemoteProxy, remove the vmcp.yaml and mcpgroup.yaml kustomization entries, and refresh aggregate-specific comments and the README. The 14 direct TunnelBinding routes are unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Removes the ToolHive VirtualMCPServer aggregate and exposes 14 existing backend proxy Services through individual Cloudflare Tunnel routes. GitHub, hero-ssh, and codebase-memory remain internal-only.
Fixes #
N/A — owner-approved direct MCP endpoint rollout.
Type of change
Validation
Impact and rollout
Cloudflare Access applications from the paired
tfroot-cloudflarePR must be applied successfully before this PR merges. This change then lets normal GitOps reconciliation create the direct routes. Verify Argo health, every generated proxy Service, CNAME/TXT ownership records, unauthenticated rejection, and authenticated non-mutatingtools/listcalls.The aggregate endpoint is removed; no client compatibility window is required by owner confirmation. Roll back by reverting these direct TunnelBinding subjects before reverting Cloudflare Access configuration.
Safety and secrets
AI-assisted change; review the complete direct-route inventory.
Owner waiver: the owner explicitly instructed proceeding after the delegated adversarial reviewer could not consume repository content. The infrastructure reviewer’s High rollout-order finding was addressed before this PR.