chore(workplan): record CUST-WP-0067-T08 chart support and release sequence
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
12e1b8874d
commit
953d2f18b3
1 changed files with 30 additions and 0 deletions
|
|
@ -321,3 +321,33 @@ blocked on this task.
|
||||||
Acceptance: an MCP endpoint reachable from the node without traversing the
|
Acceptance: an MCP endpoint reachable from the node without traversing the
|
||||||
workstation; remote `dev-hub` registration points at it; the reverse MCP tunnel
|
workstation; remote `dev-hub` registration points at it; the reverse MCP tunnel
|
||||||
removed.
|
removed.
|
||||||
|
|
||||||
|
**Progress (2026-08-24):** chart support is written and validated — a gated
|
||||||
|
`mcp` Deployment and ClusterIP Service running the same image with
|
||||||
|
`-m mcp_server.server`, `API_BASE` defaulted to the in-cluster API Service, and
|
||||||
|
tcpSocket probes. `helm lint` and `helm template` are clean, and the templates
|
||||||
|
render nothing when `mcp.enabled` is false (the default).
|
||||||
|
|
||||||
|
Two things had to be fixed before the YAML would have worked:
|
||||||
|
|
||||||
|
- `mcp_server/server.py` hardcoded `host="127.0.0.1"`. A Service routes to the
|
||||||
|
pod IP, so a loopback bind is unreachable from anywhere but the pod itself.
|
||||||
|
Now `MCP_HOST`, still defaulting to loopback — the MCP layer proxies an
|
||||||
|
unauthenticated API and must not land on every interface by accident.
|
||||||
|
- The container command uses `-m mcp_server.server` rather than the file path,
|
||||||
|
so `/app` lands on `sys.path` instead of `/app/mcp_server`.
|
||||||
|
|
||||||
|
Deliberately **no Ingress** for this Service, for the same reason the API's
|
||||||
|
ingress is disabled: neither has authentication.
|
||||||
|
|
||||||
|
**Blocked on a release, not on more code.** The running image is
|
||||||
|
`main-76e6eda`, which predates the `MCP_HOST` change, so enabling `mcp` today
|
||||||
|
would deploy a pod that binds loopback and never becomes reachable. The order
|
||||||
|
is: merge, let CI build `main-<sha>`, then bump the tag *and* flip
|
||||||
|
`mcp.enabled: true` in `deploy/railiance/apps/helm/state-hub-values.yaml` in one
|
||||||
|
commit, then `helm upgrade`. The values file is deliberately left at
|
||||||
|
`enabled: false` so an unrelated `helm upgrade` cannot ship a broken MCP.
|
||||||
|
|
||||||
|
Noticed in passing, not part of this task: that values file pins
|
||||||
|
`main-697dd49` while the cluster runs `main-76e6eda`. Declared and running
|
||||||
|
state disagree, which deserves its own look.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue