Repository navigation
phase2/mcp-reconciler — full McpServer reconciler + JWKS + /mcp mount (S1) - #51
Merged
Merged
Conversation
…ount Phase 2 slice S1. Closes §14.6 column 3 (MCP 2026 server CRD). * controller/src/mcp_server_reconciler.rs — full reconciler: Ed25519 signing-key Secret, JWKS ConfigMap (OpenID Discovery-fed), finalizer, Conditions, SSA via field manager azureclaw-controller/mcp. * controller/src/helm_drift.rs — drift test enforces no divergence between Rust mcp_server_crd() and helm template. * deploy/helm/azureclaw/templates/crd-mcpserver.yaml — helm CRD mirror. * inference-router/src/main.rs — build_mcp_router() selects between bare /mcp (dev) and OAuth-2.1-gated /mcp (production); refuses to mount on misconfigured production mode. * inference-router/src/mcp/oauth.rs — new OAuthVerifierConfig::from_jwks_file constructor for controller-mounted JWKS. * docs/security-audits/2026-04-27-phase2-mcp-reconciler.md — full audit with two sign-offs; §0 enumerates 17 reused Phase 0/1 seams per the no-duplication rule. * CHANGELOG.md — Phase 2 / S1 entry. Tests: 829 workspace tests pass (controller bins 74 → 162, +9 new mcp_server_reconciler tests, +2 helm_drift tests). All CI gates green: fmt, clippy, no-stubs, no-custom-crypto, check-loc, security-audit-required, no-null-provider-prod, a2a-module-isolation, vendored-patch-audit. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This was referenced Apr 27, 2026
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
…ount (#51) Phase 2 slice S1. Closes §14.6 column 3 (MCP 2026 server CRD). * controller/src/mcp_server_reconciler.rs — full reconciler: Ed25519 signing-key Secret, JWKS ConfigMap (OpenID Discovery-fed), finalizer, Conditions, SSA via field manager azureclaw-controller/mcp. * controller/src/helm_drift.rs — drift test enforces no divergence between Rust mcp_server_crd() and helm template. * deploy/helm/azureclaw/templates/crd-mcpserver.yaml — helm CRD mirror. * inference-router/src/main.rs — build_mcp_router() selects between bare /mcp (dev) and OAuth-2.1-gated /mcp (production); refuses to mount on misconfigured production mode. * inference-router/src/mcp/oauth.rs — new OAuthVerifierConfig::from_jwks_file constructor for controller-mounted JWKS. * docs/security-audits/2026-04-27-phase2-mcp-reconciler.md — full audit with two sign-offs; §0 enumerates 17 reused Phase 0/1 seams per the no-duplication rule. * CHANGELOG.md — Phase 2 / S1 entry. Tests: 829 workspace tests pass (controller bins 74 → 162, +9 new mcp_server_reconciler tests, +2 helm_drift tests). All CI gates green: fmt, clippy, no-stubs, no-custom-crypto, check-loc, security-audit-required, no-null-provider-prod, a2a-module-isolation, vendored-patch-audit. Co-authored-by: Pal Lakatos-Toth <pallakatos@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Phase 2 slice S1 —
phase2/mcp-reconcilerCloses §14.6 column 3 (MCP 2026 server CRD): schema → full reconciler + route mount.
Phase 1 shipped the
McpServerCRD schema only. This slice ships the full reconciler, helm CRD, and the/mcpmount in the inference-router. Establishes the JWKS Secret + ConfigMap + route-mount pattern that S2 (ToolPolicy) and S3 (A2AAgent) reuse.What's new
controller/src/mcp_server_reconciler.rs— full reconciler (~600 LOC modeled onpairing_reconciler.rs):azureclaw.azure.com/mcpserver-cleanup(cascades Secret + ConfigMap deletion).rand::rng()+fill_bytes+SigningKey::from_bytes(mirrorsmesh_peer/mod.rs::MeshIdentity::generate— avoids enablingpkcs8feature oned25519-dalek2.2.0). Raw 32-byte private + 32-byte public stored in Secret of typeazureclaw.azure.com/mcp-signing-keywith akidannotation./.well-known/openid-configuration→jwks_uri), https-only, 10s timeout. Cached as ConfigMapmcp-{name}-jwks. PluggableJwksFetchertrait keeps tests network-free.Patch::Apply, field managerazureclaw-controller/mcp(per §10.4 Bump jsonwebtoken from 9.3.1 to 10.3.0 #1).status/conditions.rs.controller/src/mcp_server.rs— addedsigning_key_refandjwks_config_map_refLocalObjectReffields onMcpServerStatus.controller/src/helm_drift.rs— drift detector. Unit test parsesdeploy/helm/azureclaw/templates/crd-mcpserver.yaml, compares (canonicalized) withmcp_server_crd(). One-shotDUMP_MCP_CRD_YAML=1test regenerates the helm template on intentional schema changes.deploy/helm/azureclaw/templates/crd-mcpserver.yaml— auto-generated helm-side CRD mirror.inference-router/src/main.rs::build_mcp_router()— selects between devmcp_route()and OAuth-2.1-gatedprotected_mcp_route()based on env vars (MCP_PRODUCTION_MODE,MCP_JWKS_PATH,MCP_OAUTH_AUDIENCE,MCP_OAUTH_ISSUER,MCP_OAUTH_REQUIRED_SCOPES). On a misconfigured production mode the router refuses to mount rather than silently falling back to unauthenticated.inference-router/src/mcp/oauth.rs::OAuthVerifierConfig::from_jwks_file— new constructor for controller-mounted JWKS.Audit
docs/security-audits/2026-04-27-phase2-mcp-reconciler.md— full audit:Tests
cargo test -p azureclaw-controller --bins)mcp_server_reconciler::tests, +2 inhelm_drift::tests, rest are dormant Phase 1 tests now compiled)cargo test --workspace)cargo fmt --all -- --checkcargo clippy --all-targets -- -D warningsci/no-stubs.shci/no-custom-crypto.shci/check-loc.shci/security-audit-required.shci/no-null-provider-prod.shci/a2a-module-isolation.shci/vendored-patch-audit.sh§0.3 success-gate self-check
TODO/unimplemented!/panic!/.stubon production pathsmcp_server.rs)What's deferred (per audit doc §9)
phase2-conditions-ssa-leader) which touches every reconciler.MCP_PROTOCOL_VERSIONheader plumbing intobuild_mcp_router()— couples toEchoDispatcherreal-tool semantics, out of scope for S1.it.todoplaceholders — replaced incrementally by S2/S3.Phase 2 plan reminder
This is slice 1 of ~17. Same operational pattern as Phase 1: small
phase2/<slice>PRs intodev, then a finalphase2-integrationPRdev → main(S18). Seedocs/implementation-plan.md§8 +docs/competitive.md§14.6 + §15.Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com