Skip to content

feat: expose direct ToolHive MCP endpoints - #245

Merged
xnoto merged 7 commits into
mainfrom
feat/per-backend-mcp-endpoints
Sep 13, 2026
Merged

xnoto merged 7 commits into
mainfrom
feat/per-backend-mcp-endpoints

Conversation

@xnoto

@xnoto xnoto commented Sep 13, 2026

Copy link
Copy Markdown
Contributor

Summary

Removes the ToolHive VirtualMCPServer aggregate and exposes 14 existing backend proxy Services through individual Cloudflare Tunnel routes. GitHub, hero-ssh, and codebase-memory remain internal-only.

Fixes #
N/A — owner-approved direct MCP endpoint rollout.

Type of change

  • Documentation
  • GitOps desired state (manifests, kustomize, charts, SOPS/KSOPS secrets)
  • Refactor / cleanup
  • Breaking change

Validation

  • Required pull-request checks pass — pending.
  • Generated or centrally distributed files were regenerated by their owning automation, not hand-edited — no generated files changed.

Impact and rollout

Cloudflare Access applications from the paired tfroot-cloudflare PR must be applied successfully before this PR merges. This change then lets normal GitOps reconciliation create the direct routes. Verify Argo health, every generated proxy Service, CNAME/TXT ownership records, unauthenticated rejection, and authenticated non-mutating tools/list calls.

The aggregate endpoint is removed; no client compatibility window is required by owner confirmation. Roll back by reverting these direct TunnelBinding subjects before reverting Cloudflare Access configuration.

Safety and secrets

  • Contains no plaintext secrets, decrypted SOPS values, state files, kubeconfigs, tokens, or private endpoints
  • No local OpenTofu init/plan/apply/destroy/import/state operations were run or claimed — plans come from pull-request checks
  • Breaking or irreversible effects are described above with rollback notes

AI-assisted change; review the complete direct-route inventory.

Owner waiver: the owner explicitly instructed proceeding after the delegated adversarial reviewer could not consume repository content. The infrastructure reviewer’s High rollout-order finding was addressed before this PR.

Drop spec.groupRef gateway from every aggregated MCPServer/MCPRemoteProxy,
remove the vmcp.yaml and mcpgroup.yaml kustomization entries, and refresh
aggregate-specific comments and the README. The 14 direct TunnelBinding
routes are unchanged.
@xnoto
xnoto requested a review from a team as a code owner September 13, 2026 02:35
@xnoto
xnoto merged commit b54b236 into main Sep 13, 2026
2 checks passed
@xnoto
xnoto deleted the feat/per-backend-mcp-endpoints branch September 13, 2026 02:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant