-
Notifications
You must be signed in to change notification settings - Fork 1
ROX-34380: Add docs to deploy with MCP lifecycle operator #257
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,66 @@ | ||
| # Guide for Deploying StackRox MCP with the MCP Lifecycle Operator | ||
|
|
||
| This guide describes how to deploy the StackRox MCP server using the [MCP Lifecycle Operator](https://catalog.redhat.com/en/software/containers/mcp-lifecycle-operator-beta/mcp-lifecycle-rhel9-operator/69de44471b613610210c8c01), which manages MCP servers through an `MCPServer` custom resource. | ||
|
|
||
| ### 1. Prerequisites | ||
| - The [MCP Lifecycle Operator](https://catalog.redhat.com/en/software/containers/mcp-lifecycle-operator-beta/mcp-lifecycle-rhel9-operator/69de44471b613610210c8c01) is installed on the cluster. | ||
| - StackRox Central is reachable from the cluster. This guide assumes Central is installed on the **same cluster** (for example, in the `stackrox` namespace). | ||
|
|
||
| ### 2. Create the namespace | ||
| ```bash | ||
| kubectl create namespace acs-mcp | ||
| ``` | ||
|
|
||
| ### 3. Deploy the MCP server | ||
| Create an `MCPServer` resource. The operator provisions the deployment and an in-cluster Service from this specification: | ||
| ```yaml | ||
| apiVersion: mcp.x-k8s.io/v1alpha1 | ||
| kind: MCPServer | ||
| metadata: | ||
| name: acs-mcp | ||
| namespace: acs-mcp | ||
| spec: | ||
| config: | ||
| env: | ||
| - name: STACKROX_MCP__TOOLS__CONFIG_MANAGER__ENABLED | ||
| value: 'true' | ||
| - name: STACKROX_MCP__TOOLS__VULNERABILITY__ENABLED | ||
| value: 'true' | ||
| - name: STACKROX_MCP__CENTRAL__INSECURE_SKIP_TLS_VERIFY | ||
| value: 'true' | ||
|
mtodor marked this conversation as resolved.
|
||
| port: 8080 | ||
| source: | ||
| containerImage: | ||
| ref: 'registry.redhat.io/agentic-cluster-security-suite-tech-preview/acs-mcp-server-rhel9:0.2' | ||
| type: ContainerImage | ||
| ``` | ||
|
|
||
| Apply it: | ||
| ```bash | ||
| kubectl apply -f mcpserver.yaml | ||
| ``` | ||
|
|
||
| The `spec.config.env` entries configure the MCP server: | ||
| - `STACKROX_MCP__TOOLS__CONFIG_MANAGER__ENABLED=true` — enable the config management tools (disabled by default). | ||
| - `STACKROX_MCP__TOOLS__VULNERABILITY__ENABLED=true` — enable the vulnerability management tools (disabled by default). | ||
|
|
||
| ### 4. Verify the deployment | ||
| - Check that the `MCPServer` resource and its pod are running: | ||
| ```bash | ||
| kubectl get mcpserver -n acs-mcp | ||
| kubectl get pods -n acs-mcp | ||
| ``` | ||
|
|
||
| - Verify the MCP server responds: | ||
| ```bash | ||
| kubectl run -i --tty --rm debug --image=quay.io/curl/curl:latest --restart=Never -- curl http://acs-mcp.acs-mcp:8080/health | ||
| ``` | ||
| You should get `{"status":"ok"}` as a response. | ||
|
|
||
| ### Appendix: Integrating with OpenShift Lightspeed | ||
| The operator exposes the MCP server through an in-cluster Service, so you can integrate it with OpenShift Lightspeed the same way as a Helm-based deployment. Follow [Step 3 of the OpenShift Lightspeed Integration Guide](lightspeed-integration.md) to create the authorization-header secret and update the `OLSConfig`. | ||
|
|
||
| When configuring `mcpServers` in the `OLSConfig`, set the `url` to the Service created by the operator: | ||
| ```yaml | ||
| url: 'http://acs-mcp.acs-mcp:8080/mcp' | ||
|
mtodor marked this conversation as resolved.
|
||
| ``` | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.