Skip to content

Allow workload identity for cluster-local MCP services - #143

Merged
Andrew Chung (andrewkcchung) merged 2 commits into
feature/platform-capability-snapshotfrom
fix/cluster-local-mcp-workload-identity
Oct 7, 2026
Merged

Andrew Chung (andrewkcchung) merged 2 commits into
feature/platform-capability-snapshotfrom
fix/cluster-local-mcp-workload-identity

Conversation

@andrewkcchung

@andrewkcchung Andrew Chung (andrewkcchung) commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • allow deployment-owned workload identity for exact Kubernetes Service FQDNs over cluster-local HTTP
  • retain HTTPS for every other remote MCP endpoint
  • reject incomplete or lookalike cluster-local names, IP addresses, embedded credentials, and fragments
  • document the constrained transport exception

Motivation

PilotSwarm currently owns workload-identity token acquisition and exact-URL header binding for deployment-configured MCP servers. Some deployments expose an MCP server as an internal Kubernetes Service rather than through an HTTPS ingress.

This change accepts only the canonical http://<service>.<namespace>.svc.cluster.local[/path] form for that deployment-owned path. The generated authorization headers remain bound to the exact configured URL. Arbitrary HTTP endpoints remain fail-closed, while external MCP endpoints continue to require HTTPS.

This preserves the current ownership structure: PilotSwarm provides the generic workload-identity transport mechanism, and deployments provide server-specific URLs and scopes.

Validation

  • npm run build --workspace=packages/sdk
  • node --test packages/sdk/test/unit/mcp-workload-identity.test.mjs
  • npm run lint --workspace=packages/sdk
  • deployed the PR worker payload to a Kubernetes repository-worker fleet using an exact cluster-local HTTP MCP Service URL
  • confirmed the worker acquired and injected deployment-owned workload-identity headers bound to that URL
  • completed a bounded read-only MCP tool invocation through the internal Service with no caller credential
  • retained rejection coverage for arbitrary HTTP hosts, IP addresses, incomplete names, lookalike suffixes, credentials, and fragments

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@andrewkcchung
Andrew Chung (andrewkcchung) marked this pull request as ready for review October 7, 2026 01:45
@andrewkcchung
Andrew Chung (andrewkcchung) merged commit c00af97 into feature/platform-capability-snapshot Oct 7, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant