An implementation of Model Context Protocol (MCP) server for Argo CD
helm repo add christianhuth https://charts.christianhuth.de
helm repo update
helm install my-release christianhuth/mcp-for-argocdThis chart bootstraps a MCP Server for Argo CD using the Helm package manager.
- Kubernetes 1.19+
To install the chart with the release name my-release:
helm repo add christianhuth https://charts.christianhuth.de
helm repo update
helm install my-release christianhuth/mcp-for-argocdThese commands deploy the MCP Server on the Kubernetes cluster in the default configuration. The Values section lists the values that can be configured during installation.
Tip: List all releases using
helm list
To uninstall the my-release deployment:
helm uninstall my-releaseThe command removes all the Kubernetes components associated with the chart and deletes the release.
| Key | Type | Default | Description |
|---|---|---|---|
| affinity | object | {} |
Affinity settings for pod assignment |
| argocd.auth.apiToken | string | "" |
API token for authentication with Argo CD |
| argocd.auth.existingSecret | string | "" |
Name of an existing Kubernetes Secret that contains the API token |
| argocd.auth.existingSecretKey | string | "argocd-api-token" |
Key within the existing secret that contains the API token |
| argocd.baseUrl | string | "" |
Base URL of the Argo CD instance to connect to |
| argocd.readOnly | bool | false |
Run the MCP Server in a ReadOnly mode to avoid resource or application modifications |
| argocd.skipTlsVerify | bool | false |
Disables TLS certificate validation when connecting to Argo CD instances using self-signed certificates or certificates from private CAs that aren't trusted by your system's certificate store |
| auth.allowUnauthenticated | bool | false |
Allow unauthenticated inbound access to the listener. Only enable this when something else (a service mesh, reverse proxy, or NetworkPolicy) already authenticates callers; the underlying app logs a warning if this is set on a non-loopback bind |
| auth.existingSecret | string | "" |
Name of an existing Kubernetes Secret that contains the inbound bearer token, instead of having the chart create one from token |
| auth.existingSecretKey | string | "mcp-auth-token" |
Key within the existing secret that contains the inbound bearer token |
| auth.token | string | "" |
Inbound bearer token callers must send as Authorization: Bearer <token>. Required unless allowUnauthenticated is true or existingSecret is set |
| autoscaling.enabled | bool | false |
|
| autoscaling.maxReplicas | int | 100 |
|
| autoscaling.minReplicas | int | 1 |
|
| autoscaling.targetCPUUtilizationPercentage | int | 80 |
|
| extraEnv | list | [] |
additional environment variables to be added to the pods |
| extraEnvFrom | list | [] |
additional environment variables from ConfigMaps or Secrets |
| fullnameOverride | string | "" |
String to fully override "mcp-for-argocd.fullname" |
| image.pullPolicy | string | "Always" |
image pull policy |
| image.registry | string | "ghcr.io" |
image registry |
| image.repository | string | "argoproj-labs/mcp-for-argocd" |
image repository |
| image.tag | string | "v0.9.0" |
Overrides the image tag |
| imagePullSecrets | list | [] |
If defined, uses a Secret to pull an image from a private Docker registry or repository. |
| ingress.annotations | object | {} |
|
| ingress.className | string | "" |
|
| ingress.enabled | bool | false |
|
| ingress.hosts[0].host | string | "chart-example.local" |
|
| ingress.hosts[0].paths[0].path | string | "/" |
|
| ingress.hosts[0].paths[0].pathType | string | "ImplementationSpecific" |
|
| ingress.tls | list | [] |
|
| livenessProbe.failureThreshold | int | 3 |
Failure threshold for livenessProbe |
| livenessProbe.initialDelaySeconds | int | 3 |
Initial delay seconds for livenessProbe |
| livenessProbe.periodSeconds | int | 5 |
Period seconds for livenessProbe |
| livenessProbe.successThreshold | int | 1 |
Success threshold for livenessProbe |
| livenessProbe.timeoutSeconds | int | 1 |
Timeout seconds for livenessProbe |
| nameOverride | string | "" |
Provide a name in place of mcp-for-argocd |
| nodeSelector | object | {} |
Node labels for pod assignment |
| podAnnotations | object | {} |
Annotations to be added to pods |
| podSecurityContext | object | see values.yaml | pod-level security context |
| readinessProbe.failureThreshold | int | 3 |
Failure threshold for readinessProbe |
| readinessProbe.initialDelaySeconds | int | 3 |
Initial delay seconds for readinessProbe |
| readinessProbe.periodSeconds | int | 5 |
Period seconds for readinessProbe |
| readinessProbe.successThreshold | int | 1 |
Success threshold for readinessProbe |
| readinessProbe.timeoutSeconds | int | 1 |
Timeout seconds for readinessProbe |
| replicaCount | int | 1 |
Number of replicas |
| resources | object | see values.yaml | Resource limits and requests for the pods. |
| revisionHistoryLimit | int | 10 |
The number of old ReplicaSets to retain |
| route.main.additionalRules | list | [] |
Additional custom rules that can be added to the route |
| route.main.annotations | object | {} |
Add annotations to the route |
| route.main.apiVersion | string | "gateway.networking.k8s.io/v1" |
Set the route apiVersion, e.g. gateway.networking.k8s.io/v1 or gateway.networking.k8s.io/v1alpha2 |
| route.main.enabled | bool | false |
Enables or disables the route |
| route.main.filters | list | [] |
Filters define the filters that are applied to requests that match this rule. |
| route.main.hostnames | list | [] |
Hostnames to be matched |
| route.main.httpsRedirect | bool | false |
adds a filter for redirecting to https (HTTP 301 Moved Permanently). To redirect HTTP traffic to HTTPS, you need to have a Gateway with both HTTP and HTTPS listeners. Matches and filters do not take effect if enabled. Ref. https://gateway-api.sigs.k8s.io/guides/http-redirect-rewrite/ |
| route.main.kind | string | "HTTPRoute" |
Set the route kind Valid options are GRPCRoute, HTTPRoute, TCPRoute, TLSRoute, UDPRoute |
| route.main.labels | object | {} |
Add labels to the route |
| route.main.matches | list | see values.yaml | define conditions used for matching the rule against incoming HTTP requests. |
| route.main.parentRefs | list | [] |
Parent references (Gateway) |
| route.main.timeouts | object | {} |
defines the timeouts that can be configured for an HTTP request |
| securityContext | object | see values.yaml | container-level security context |
| service.port | int | 80 |
Kubernetes port where service is exposed |
| service.type | string | "ClusterIP" |
Kubernetes service type |
| serviceAccount.annotations | object | {} |
Annotations to add to the service account |
| serviceAccount.create | bool | true |
Specifies whether a service account should be created |
| serviceAccount.name | string | "" |
The name of the service account to use. If not set and create is true, a name is generated using the fullname template |
| startupProbe.failureThreshold | int | 3 |
Failure threshold for startupProbe |
| startupProbe.initialDelaySeconds | int | 3 |
Initial delay seconds for startupProbe |
| startupProbe.periodSeconds | int | 5 |
Period seconds for startupProbe |
| startupProbe.successThreshold | int | 1 |
Success threshold for startupProbe |
| startupProbe.timeoutSeconds | int | 1 |
Timeout seconds for startupProbe |
| tolerations | list | [] |
Toleration labels for pod assignment |
Specify each parameter using the --set key=value[,key=value] argument to helm install.
Alternatively, a YAML file that specifies the values for the parameters can be provided while installing the chart. For example,
helm install my-release -f values.yaml christianhuth/mcp-for-argocd