mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-07 02:59:05 +00:00
Adds a standalone MCP server (provisioning_mcp/) that lets authenticated AI agents provision ephemeral LiteLLM deployments from the helm/litellm chart for end-to-end testing. Given a repo URL and git revision it derives the component image repos, optionally stands up throwaway in-cluster Postgres/Redis, and runs helm upgrade --install in the litellm namespace. - OAuth 2.0 resource-server auth: validates JWT bearer tokens against the issuer's JWKS (signature, iss, aud, exp, required scope). - Tools: provision / delete / status / list deployments. - Dockerfile pins + checksum-verifies helm and kubectl; namespaced RBAC and Deployment manifests under deploy/. - Unit tests cover auth, naming/registry derivation, manifests, and the provisioning flow (35 tests). https://claude.ai/code/session_019WDsdJNGjNyUNrso3xigSV
54 lines
1.7 KiB
YAML
54 lines
1.7 KiB
YAML
# Namespaced RBAC: the provisioning MCP can manage only the `litellm` namespace.
|
|
# No cluster-scoped permissions are granted, so the namespace must already exist
|
|
# (see namespace.yaml) — the server never uses `helm --create-namespace`.
|
|
apiVersion: v1
|
|
kind: ServiceAccount
|
|
metadata:
|
|
name: litellm-provisioning-mcp
|
|
namespace: litellm
|
|
---
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
kind: Role
|
|
metadata:
|
|
name: litellm-provisioning-mcp
|
|
namespace: litellm
|
|
rules:
|
|
# Core objects created by the chart, the migration job, and the ephemeral
|
|
# datastores. Secrets cover both the generated master key / DB credentials and
|
|
# helm's own release-state storage.
|
|
- apiGroups: [""]
|
|
resources:
|
|
- pods
|
|
- pods/log
|
|
- services
|
|
- configmaps
|
|
- secrets
|
|
- serviceaccounts
|
|
- persistentvolumeclaims
|
|
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
|
|
- apiGroups: ["apps"]
|
|
resources: ["deployments", "replicasets"]
|
|
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
|
|
- apiGroups: ["batch"]
|
|
resources: ["jobs"]
|
|
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
|
|
- apiGroups: ["autoscaling"]
|
|
resources: ["horizontalpodautoscalers"]
|
|
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
|
|
- apiGroups: ["networking.k8s.io"]
|
|
resources: ["ingresses"]
|
|
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
|
|
---
|
|
apiVersion: rbac.authorization.k8s.io/v1
|
|
kind: RoleBinding
|
|
metadata:
|
|
name: litellm-provisioning-mcp
|
|
namespace: litellm
|
|
roleRef:
|
|
apiGroup: rbac.authorization.k8s.io
|
|
kind: Role
|
|
name: litellm-provisioning-mcp
|
|
subjects:
|
|
- kind: ServiceAccount
|
|
name: litellm-provisioning-mcp
|
|
namespace: litellm
|