From 319973e73d5aa14a7a69d51b0c2032d10f059189 Mon Sep 17 00:00:00 2001 From: Mladen Todorovic Date: Mon, 21 Sep 2026 12:16:22 +0200 Subject: [PATCH 1/3] Improve Lightspeed integration docs --- charts/stackrox-mcp/README.md | 6 +-- charts/stackrox-mcp/templates/NOTES.txt | 2 +- docs/lightspeed-integration.md | 56 ++++++++++++++----------- 3 files changed, 36 insertions(+), 28 deletions(-) diff --git a/charts/stackrox-mcp/README.md b/charts/stackrox-mcp/README.md index 771eba7..2746049 100644 --- a/charts/stackrox-mcp/README.md +++ b/charts/stackrox-mcp/README.md @@ -92,7 +92,7 @@ The following table lists the configurable parameters of the StackRox MCP chart | Parameter | Description | Default | |-----------|-------------|---------| | `service.type` | Service type | `LoadBalancer` | -| `service.port` | Service port | `8080` | +| `service.port` | Service port | `443` | | `service.annotations` | Service annotations | `{}` | ### TLS Secret Configuration @@ -533,11 +533,11 @@ Test the health endpoint: ```bash # For HTTP (TLS disabled) -kubectl run -i --tty --rm debug --image=curlimages/curl --restart=Never -- \ +kubectl run -i --tty --rm debug --image=docker.io/curlimages/curl:latest --restart=Never -- \ curl http://stackrox-mcp.stackrox-mcp:8080/health # For HTTPS (TLS enabled) -kubectl run -i --tty --rm debug --image=curlimages/curl --restart=Never -- \ +kubectl run -i --tty --rm debug --image=docker.io/curlimages/curl:latest --restart=Never -- \ curl -k https://stackrox-mcp.stackrox-mcp.svc.cluster.local:8443/health ``` diff --git a/charts/stackrox-mcp/templates/NOTES.txt b/charts/stackrox-mcp/templates/NOTES.txt index b5320c2..a54b2d2 100644 --- a/charts/stackrox-mcp/templates/NOTES.txt +++ b/charts/stackrox-mcp/templates/NOTES.txt @@ -23,7 +23,7 @@ StackRox MCP Server Configuration: {{- end }} To test connectivity: - $ kubectl run -i --tty --rm debug --image=curlimages/curl --restart=Never -- \ + $ kubectl run -i --tty --rm debug --image=docker.io/curlimages/curl:latest --restart=Never -- \ curl -k {{ include "stackrox-mcp.portName" . }}://{{ include "stackrox-mcp.fullname" . }}.{{ .Release.Namespace }}:{{ .Values.service.port }}/health {{- if and (eq (include "stackrox-mcp.isOpenshift" .) "true") .Values.config.server.TLSEnabled (ne .Values.openshift.route.tls.termination "reencrypt") }} diff --git a/docs/lightspeed-integration.md b/docs/lightspeed-integration.md index 40b6464..dc0ecdf 100644 --- a/docs/lightspeed-integration.md +++ b/docs/lightspeed-integration.md @@ -13,40 +13,47 @@ Guide tested with OpenShift Lightspeed version `1.0.8`. tmp_stackrox_mcp_dir="stackrox-mcp-${RANDOM}" git clone --depth 1 --branch main https://github.com/stackrox/stackrox-mcp.git "${tmp_stackrox_mcp_dir}" - # Assuming that StackRox Central is installed on the same cluster in "stackrox" namespace. - helm install stackrox-mcp "${tmp_stackrox_mcp_dir}/charts/stackrox-mcp" --namespace stackrox-mcp --create-namespace + # Assuming StackRox Central is installed on the same cluster in the "stackrox" namespace. + # This installs MCP for a local Central: served over HTTP in-cluster and trusting + # Central's self-signed certificate. For production, use TLS (see the chart README). + helm upgrade stackrox-mcp "${tmp_stackrox_mcp_dir}/charts/stackrox-mcp" \ + --install \ + --namespace stackrox-mcp --create-namespace \ + --set config.central.insecureSkipTLSVerify=true \ + --set config.server.TLSEnabled=false \ + --set config.server.port=8080 \ + --set service.type=ClusterIP \ + --set service.port=8080 \ + --set openshift.route.tls.termination=edge \ + --set replicaCount=1 # Delete temp directory. rm -rf "${tmp_stackrox_mcp_dir}" ``` + The flags above adapt the chart (which defaults to TLS) for a local Central: + - `config.central.insecureSkipTLSVerify=true` — trust Central's self-signed certificate. + - `config.server.TLSEnabled=false` + `config.server.port=8080` — serve MCP over HTTP on 8080 (no server certificate needed). + - `service.type=ClusterIP` + `service.port=8080` — OpenShift Lightspeed reaches MCP via the in-cluster Service. + - `openshift.route.tls.termination=edge` — required because the pod now serves HTTP. + > **Note:** For advanced helm chart configuration options, see the [StackRox MCP Helm Chart README](../charts/stackrox-mcp/README.md). For OpenShift-specific deployment settings, refer to the [OpenShift Deployment](../charts/stackrox-mcp/README.md#openshift-deployment) section. - Verify the MCP server is running: ```bash - kubectl run -i --tty --rm debug --image=curlimages/curl --restart=Never -- \ + kubectl run -i --tty --rm debug --image=docker.io/curlimages/curl:latest --restart=Never -- \ curl http://stackrox-mcp.stackrox-mcp:8080/health ``` You should get `{"status":"ok"}` as a response. ### 3. Set Up Integration of StackRox MCP with OpenShift Lightspeed - Create an API token in StackRox Central with appropriate permissions. -- Create Authorization Header Secret - - Create a Base64 value for the authorization header secret: +- Create the `stackrox-mcp-authorization-header` secret in the `openshift-lightspeed` namespace (kubectl encodes the value for you): ```bash stackrox_api_token="" - echo -n "Bearer ${stackrox_api_token}" | base64 - ``` - - Create secret `stackrox-mcp-authorization-header` in the `openshift-lightspeed` namespace: - ```yaml - kind: Secret - apiVersion: v1 - metadata: - name: stackrox-mcp-authorization-header - namespace: openshift-lightspeed - data: - header: "" - type: Opaque + kubectl create secret generic stackrox-mcp-authorization-header \ + --namespace openshift-lightspeed \ + --from-literal=header="Bearer ${stackrox_api_token}" ``` - Configure OpenShift Lightspeed by editing the `OLSConfig` configuration for your OpenShift Lightspeed installation and add this section to `spec`: ```yaml @@ -54,13 +61,14 @@ Guide tested with OpenShift Lightspeed version `1.0.8`. - MCPServer mcpServers: - name: stackrox-mcp - streamableHTTP: - enableSSE: false - headers: - authorization: stackrox-mcp-authorization-header - sseReadTimeout: 30 - timeout: 60 - url: 'http://stackrox-mcp.stackrox-mcp:8080/mcp' + headers: + - name: authorization + valueFrom: + type: secret + secretRef: + name: stackrox-mcp-authorization-header + timeout: 120 + url: 'http://stackrox-mcp.stackrox-mcp:8080/mcp' ``` - After completing the setup, test your integration with a simple prompt: "List all clusters secured by StackRox" From 61f8f072755f8d842e098f7f69f9995de536e601 Mon Sep 17 00:00:00 2001 From: Mladen Todorovic Date: Mon, 21 Sep 2026 16:27:36 +0200 Subject: [PATCH 2/3] Use quey curl image --- charts/stackrox-mcp/README.md | 4 ++-- charts/stackrox-mcp/templates/NOTES.txt | 2 +- docs/lightspeed-integration.md | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/charts/stackrox-mcp/README.md b/charts/stackrox-mcp/README.md index 2746049..08162f1 100644 --- a/charts/stackrox-mcp/README.md +++ b/charts/stackrox-mcp/README.md @@ -533,11 +533,11 @@ Test the health endpoint: ```bash # For HTTP (TLS disabled) -kubectl run -i --tty --rm debug --image=docker.io/curlimages/curl:latest --restart=Never -- \ +kubectl run -i --tty --rm debug --image=quay.io/curl/curl:latest --restart=Never -- \ curl http://stackrox-mcp.stackrox-mcp:8080/health # For HTTPS (TLS enabled) -kubectl run -i --tty --rm debug --image=docker.io/curlimages/curl:latest --restart=Never -- \ +kubectl run -i --tty --rm debug --image=quay.io/curl/curl:latest --restart=Never -- \ curl -k https://stackrox-mcp.stackrox-mcp.svc.cluster.local:8443/health ``` diff --git a/charts/stackrox-mcp/templates/NOTES.txt b/charts/stackrox-mcp/templates/NOTES.txt index a54b2d2..8667e2a 100644 --- a/charts/stackrox-mcp/templates/NOTES.txt +++ b/charts/stackrox-mcp/templates/NOTES.txt @@ -23,7 +23,7 @@ StackRox MCP Server Configuration: {{- end }} To test connectivity: - $ kubectl run -i --tty --rm debug --image=docker.io/curlimages/curl:latest --restart=Never -- \ + $ kubectl run -i --tty --rm debug --image=quay.io/curl/curl:latest --restart=Never -- \ curl -k {{ include "stackrox-mcp.portName" . }}://{{ include "stackrox-mcp.fullname" . }}.{{ .Release.Namespace }}:{{ .Values.service.port }}/health {{- if and (eq (include "stackrox-mcp.isOpenshift" .) "true") .Values.config.server.TLSEnabled (ne .Values.openshift.route.tls.termination "reencrypt") }} diff --git a/docs/lightspeed-integration.md b/docs/lightspeed-integration.md index dc0ecdf..119ee2c 100644 --- a/docs/lightspeed-integration.md +++ b/docs/lightspeed-integration.md @@ -41,7 +41,7 @@ Guide tested with OpenShift Lightspeed version `1.0.8`. - Verify the MCP server is running: ```bash - kubectl run -i --tty --rm debug --image=docker.io/curlimages/curl:latest --restart=Never -- \ + kubectl run -i --tty --rm debug --image=quay.io/curl/curl:latest --restart=Never -- \ curl http://stackrox-mcp.stackrox-mcp:8080/health ``` You should get `{"status":"ok"}` as a response. From e4f929556a6272b6a21dcac8bd0cbc17ad02dd9d Mon Sep 17 00:00:00 2001 From: Mladen Todorovic Date: Mon, 21 Sep 2026 16:28:57 +0200 Subject: [PATCH 3/3] Fix used Lightspeed version --- docs/lightspeed-integration.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/lightspeed-integration.md b/docs/lightspeed-integration.md index 119ee2c..fdf2c63 100644 --- a/docs/lightspeed-integration.md +++ b/docs/lightspeed-integration.md @@ -1,6 +1,6 @@ # Guide for Setting Up StackRox MCP OpenShift Lightspeed Integration -Guide tested with OpenShift Lightspeed version `1.0.8`. +Guide tested with OpenShift Lightspeed version `1.1.3`. ### 1. Set Up OpenShift Lightspeed - Set up your OpenShift Lightspeed integration with a large language model (LLM) service. Detailed documentation can be found in the [Red Hat OpenShift Lightspeed Configuration Guide](https://docs.redhat.com/en/documentation/red_hat_openshift_lightspeed/1.0/html/configure/ols-configuring-openshift-lightspeed).