Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
67 changes: 41 additions & 26 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ them but the MCP server will be unable to connect to Itential Platform.

| Value | Description |
|:------|:------------|
| `mcp.platform.host` | Hostname or IP address of the Itential Platform instance the MCP server will connect to. |
| `env.ITENTIAL_MCP_PLATFORM_HOST` | Hostname or IP address of the Itential Platform instance the MCP server will connect to. |
| `credentials.platformUser` | Username for basic auth against Itential Platform. Set this or the OAuth2 credentials below. |
| `credentials.platformPassword` | Password for basic auth against Itential Platform. |
| `credentials.platformClientId` | OAuth 2.0 client ID. Use instead of basic auth credentials if your platform uses OAuth 2.0. |
Expand Down Expand Up @@ -50,7 +50,7 @@ Install with platform credentials passed directly on the command line:

```bash
helm install mcp . -f values.yaml \
--set mcp.platform.host=iap.example.com \
--set env.ITENTIAL_MCP_PLATFORM_HOST=iap.example.com \
--set credentials.platformUser=admin \
--set credentials.platformPassword=supersecret
```
Expand All @@ -59,7 +59,7 @@ Install referencing an existing credentials Secret:

```bash
helm install mcp . -f values.yaml \
--set mcp.platform.host=iap.example.com \
--set env.ITENTIAL_MCP_PLATFORM_HOST=iap.example.com \
--set credentials.secretName=my-mcp-credentials
```

Expand Down Expand Up @@ -114,21 +114,27 @@ Kubernetes deployments. The default is `sse`.
| `http` | Stateless HTTP. Use for service mesh deployments. |
| `stdio` | Standard I/O. Local CLI use only — do not use in Kubernetes. |

Set the transport mode via the `env` map:

```yaml
env:
ITENTIAL_MCP_SERVER_TRANSPORT: "http"
```

### TLS and Certificate Verification

The MCP server connects to Itential Platform over HTTPS by default. If IAP is using a
self-signed certificate or an internal CA, set `mcp.platform.disableVerify: true` to skip
certificate verification while keeping the connection encrypted.
self-signed certificate or an internal CA, set `ITENTIAL_MCP_PLATFORM_DISABLE_VERIFY` to
`"true"` to skip certificate verification while keeping the connection encrypted.

```yaml
mcp:
platform:
disableVerify: true
env:
ITENTIAL_MCP_PLATFORM_DISABLE_VERIFY: "true"
```

Do **not** use `mcp.platform.disableTls: true` unless IAP is genuinely running without TLS.
That setting disables TLS entirely and switches the client to HTTP, which will fail if IAP is
listening on an HTTPS port.
Do **not** set `ITENTIAL_MCP_PLATFORM_DISABLE_TLS` to `"true"` unless IAP is genuinely running
without TLS. That setting disables TLS entirely and switches the client to HTTP, which will fail
if IAP is listening on an HTTPS port.

### Integrating with Claude Desktop

Expand Down Expand Up @@ -246,26 +252,46 @@ tools.
### Tool Filtering

The MCP server exposes 56+ tools by default. You can reduce the exposed surface using the
`mcp.platform.includeTags` and `mcp.platform.excludeTags` values. These accept a
comma-separated list of tool group tags.
`ITENTIAL_MCP_SERVER_INCLUDE_TAGS` and `ITENTIAL_MCP_SERVER_EXCLUDE_TAGS` environment
variables. These accept a comma-separated list of tool group tags.

```yaml
env:
ITENTIAL_MCP_SERVER_INCLUDE_TAGS: "health,configuration_manager"
```

Or via `--set` on the command line:

```bash
helm install mcp . -f values.yaml \
--set mcp.platform.includeTags="health,configuration_manager"
--set 'env.ITENTIAL_MCP_SERVER_INCLUDE_TAGS=health,configuration_manager'
```

## Values

| Key | Type | Default | Description |
|:----|:-----|:--------|:------------|
| affinity | object | `{}` | Additional affinities |
| applicationPort | int | `8000` | The port the MCP server container listens on inside the pod. Must match `mcp.server.port`. |
| applicationPort | int | `8000` | The port the MCP server container listens on inside the pod. Must match `env.ITENTIAL_MCP_SERVER_PORT`. |
| credentials.secretName | string | `""` | Name of an existing Secret to use for platform credentials. When set, no Secret is created by the chart. |
| credentials.platformUser | string | `""` | Basic auth username for Itential Platform. Only used when `credentials.secretName` is empty. |
| credentials.platformPassword | string | `""` | Basic auth password for Itential Platform. Only used when `credentials.secretName` is empty. |
| credentials.platformClientId | string | `""` | OAuth 2.0 client ID. Only used when `credentials.secretName` is empty. |
| credentials.platformClientSecret | string | `""` | OAuth 2.0 client secret. Only used when `credentials.secretName` is empty. |
| deployment.enabled | bool | `true` | Toggle creation of the Deployment object. |
| env | map | See `values.yaml` | Non-sensitive environment variables passed to the MCP container. Keys must be valid `ITENTIAL_MCP_*` environment variable names. See [models.py](https://github.com/itential/itential-mcp/blob/devel/src/itential_mcp/config/models.py) for the full list. |
| env.ITENTIAL_MCP_PLATFORM_DISABLE_TLS | string | `"false"` | Disable TLS entirely for the platform connection (connects via HTTP). Only use if Itential Platform is not running TLS. For internal CA certs, use `ITENTIAL_MCP_PLATFORM_DISABLE_VERIFY` instead. |
| env.ITENTIAL_MCP_PLATFORM_DISABLE_VERIFY | string | `"false"` | Skip TLS certificate verification when connecting to Itential Platform. Use when Itential Platform uses a self-signed or internal CA cert. |
| env.ITENTIAL_MCP_PLATFORM_HOST | string | `""` | Hostname or IP address of the Itential Platform instance. |
| env.ITENTIAL_MCP_PLATFORM_PORT | string | `"3443"` | Port of the Itential Platform instance. |
| env.ITENTIAL_MCP_PLATFORM_TIMEOUT | string | `"30"` | Connection timeout in seconds. |
| env.ITENTIAL_MCP_PLATFORM_TTL | string | `"0"` | Authentication TTL in seconds before forcing reauthentication. Set to a value shorter than the Itential Platform token lifetime to avoid stale token errors. `0` disables forced reauthentication. |
| env.ITENTIAL_MCP_SERVER_HOST | string | `"0.0.0.0"` | The address the MCP server binds to inside the container. |
| env.ITENTIAL_MCP_SERVER_INCLUDE_TAGS | string | not set | Comma-separated list of tool tag groups to expose. Leave unset to expose all tools. |
| env.ITENTIAL_MCP_SERVER_EXCLUDE_TAGS | string | not set | Comma-separated list of tool tag groups to hide. |
| env.ITENTIAL_MCP_SERVER_PATH | string | `"/mcp"` | The HTTP path the MCP server mounts on. |
| env.ITENTIAL_MCP_SERVER_PORT | string | `"8000"` | The port the MCP server listens on. Must match `applicationPort`. |
| env.ITENTIAL_MCP_SERVER_TRANSPORT | string | `"sse"` | Transport mode. Use `sse` or `http` for Kubernetes. |
| image.pullPolicy | string | `"IfNotPresent"` | The image pull policy. |
| image.repository | string | `"ghcr.io/itential/itential-mcp"` | The image repository. |
| image.tag | string | `""` | The image tag. Defaults to the chart `appVersion` when empty. |
Expand All @@ -282,17 +308,6 @@ helm install mcp . -f values.yaml \
| livenessProbe.periodSeconds | int | `30` | How often to run the probe. |
| livenessProbe.successThreshold | int | `1` | Minimum consecutive successes to be considered healthy. |
| livenessProbe.timeoutSeconds | int | `5` | Seconds after which the probe times out. |
| mcp.platform.disableTls | bool | `false` | Disable TLS entirely for the platform connection (connects via HTTP). Only use if IAP is not running TLS. For internal CA certs, use `disableVerify` instead. |
| mcp.platform.disableVerify | bool | `false` | Skip TLS certificate verification when connecting to Itential Platform. Use when IAP uses a self-signed or internal CA cert. |
| mcp.platform.excludeTags | string | `""` | Comma-separated list of tool tag groups to hide. |
| mcp.platform.host | string | `""` | Hostname or IP address of the Itential Platform instance. |
| mcp.platform.includeTags | string | `""` | Comma-separated list of tool tag groups to expose. Leave empty to expose all. |
| mcp.platform.port | int | `3000` | Port of the Itential Platform instance. Set to `0` for auto-detection. |
| mcp.platform.timeout | int | `30` | Connection timeout in seconds. |
| mcp.server.host | string | `"0.0.0.0"` | The address the MCP server binds to inside the container. |
| mcp.server.path | string | `"/mcp"` | The HTTP path the MCP server mounts on. |
| mcp.server.port | int | `8000` | The port the MCP server listens on. Must match `applicationPort`. |
| mcp.server.transport | string | `"sse"` | Transport mode. Use `sse` or `http` for Kubernetes. |
| nodeSelector | object | `{"itential.io/app":"mcp"}` | Node selector labels. |
| podAnnotations | object | `{}` | Additional pod annotations. |
| podLabels | object | `{}` | Additional pod labels. |
Expand Down
28 changes: 3 additions & 25 deletions templates/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -43,31 +43,9 @@ spec:
containerPort: {{ .Values.applicationPort }}
protocol: TCP
env:
- name: ITENTIAL_MCP_SERVER_TRANSPORT
value: {{ .Values.mcp.server.transport | quote }}
- name: ITENTIAL_MCP_SERVER_HOST
value: {{ .Values.mcp.server.host | quote }}
- name: ITENTIAL_MCP_SERVER_PORT
value: {{ .Values.mcp.server.port | quote }}
- name: ITENTIAL_MCP_SERVER_PATH
value: {{ .Values.mcp.server.path | quote }}
- name: ITENTIAL_MCP_PLATFORM_HOST
value: {{ .Values.mcp.platform.host | quote }}
- name: ITENTIAL_MCP_PLATFORM_PORT
value: {{ .Values.mcp.platform.port | quote }}
- name: ITENTIAL_MCP_PLATFORM_DISABLE_TLS
value: {{ .Values.mcp.platform.disableTls | quote }}
- name: ITENTIAL_MCP_PLATFORM_DISABLE_VERIFY
value: {{ .Values.mcp.platform.disableVerify | quote }}
- name: ITENTIAL_MCP_PLATFORM_TIMEOUT
value: {{ .Values.mcp.platform.timeout | quote }}
{{- if .Values.mcp.platform.includeTags }}
- name: ITENTIAL_MCP_INCLUDE_TAGS
value: {{ .Values.mcp.platform.includeTags | quote }}
{{- end }}
{{- if .Values.mcp.platform.excludeTags }}
- name: ITENTIAL_MCP_EXCLUDE_TAGS
value: {{ .Values.mcp.platform.excludeTags | quote }}
{{- range $key, $value := .Values.env }}
- name: {{ $key }}
value: {{ $value | quote }}
{{- end }}
envFrom:
- secretRef:
Expand Down
60 changes: 30 additions & 30 deletions values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
replicaCount: 1

# applicationPort The port the MCP server container listens on inside the pod.
# Must match mcp.server.port.
# Must match env.ITENTIAL_MCP_SERVER_PORT.
applicationPort: 8000

# image The Itential MCP image to use, its version, and its location
Expand Down Expand Up @@ -104,35 +104,35 @@ startupProbe:
successThreshold: 1
path: "/mcp"

# mcp Server and platform connection configuration. These values are rendered into
# environment variables that the MCP server reads at startup.
mcp:
server:
# transport Must be "sse" or "http" for Kubernetes deployments. Do not use "stdio".
transport: "sse"
# host The address the MCP server binds to inside the container.
host: "0.0.0.0"
# port The port the MCP server listens on. Must match applicationPort.
port: 8000
# path The HTTP path the MCP server mounts on.
path: "/mcp"
platform:
# host The hostname or IP address of the Itential Platform instance.
host: ""
# port The port of the Itential Platform instance. Set to 0 for auto-detection.
port: 3000
# disableTls Set to true to disable TLS entirely (connects via HTTP). Only use if IAP is not
# running TLS. For self-signed or internal CA certs, use disableVerify instead.
disableTls: false
# disableVerify Set to true to skip TLS certificate verification when connecting to Itential
# Platform. Use this when IAP uses a self-signed or internal CA certificate.
disableVerify: false
# timeout Connection timeout in seconds.
timeout: 30
# includeTags Comma-separated list of tool tag groups to expose. Leave empty to expose all.
includeTags: ""
# excludeTags Comma-separated list of tool tag groups to hide.
excludeTags: ""
# env Non-sensitive environment variables passed to the MCP container. Keys must be valid
# ITENTIAL_MCP_* environment variable names. See the full list at:
# https://github.com/itential/itential-mcp/blob/devel/src/itential_mcp/config/models.py
env:
# ITENTIAL_MCP_SERVER_TRANSPORT Must be "sse" or "http" for Kubernetes deployments. Do not use "stdio".
ITENTIAL_MCP_SERVER_TRANSPORT: "sse"
# ITENTIAL_MCP_SERVER_HOST The address the MCP server binds to inside the container.
ITENTIAL_MCP_SERVER_HOST: "0.0.0.0"
# ITENTIAL_MCP_SERVER_PORT The port the MCP server listens on. Must match applicationPort.
ITENTIAL_MCP_SERVER_PORT: "8000"
# ITENTIAL_MCP_SERVER_PATH The HTTP path the MCP server mounts on.
ITENTIAL_MCP_SERVER_PATH: "/mcp"
# ITENTIAL_MCP_PLATFORM_HOST The hostname or IP address of the Itential Platform instance.
ITENTIAL_MCP_PLATFORM_HOST: ""
# ITENTIAL_MCP_PLATFORM_PORT The port of the Itential Platform instance.
ITENTIAL_MCP_PLATFORM_PORT: "3443"
# ITENTIAL_MCP_PLATFORM_DISABLE_TLS Set to "true" to disable TLS entirely (connects via HTTP).
# Only use if Itential Platform is not running TLS. For self-signed or internal CA certs,
# use ITENTIAL_MCP_PLATFORM_DISABLE_VERIFY instead.
ITENTIAL_MCP_PLATFORM_DISABLE_TLS: "false"
# ITENTIAL_MCP_PLATFORM_DISABLE_VERIFY Set to "true" to skip TLS certificate verification.
# Use when Itential Platform uses a self-signed or internal CA certificate.
ITENTIAL_MCP_PLATFORM_DISABLE_VERIFY: "false"
# ITENTIAL_MCP_PLATFORM_TIMEOUT Connection timeout in seconds.
ITENTIAL_MCP_PLATFORM_TIMEOUT: "30"
# ITENTIAL_MCP_PLATFORM_TTL Authentication TTL in seconds before forcing reauthentication.
# Set to a value shorter than the Itential Platform token lifetime to avoid stale token errors.
# 0 disables forced reauthentication.
ITENTIAL_MCP_PLATFORM_TTL: "0"

# credentials Platform authentication credentials. Sensitive values are stored in a Kubernetes
# Secret. Supports basic auth (user/password) or OAuth 2.0 (clientId/clientSecret).
Expand Down
Loading