litellm/provisioning_mcp/deploy/rbac.yaml
Claude af14aa6818
feat(provisioning-mcp): add MCP server for on-the-fly LiteLLM e2e deployments
Adds a standalone MCP server (provisioning_mcp/) that lets authenticated AI
agents provision ephemeral LiteLLM deployments from the helm/litellm chart for
end-to-end testing. Given a repo URL and git revision it derives the component
image repos, optionally stands up throwaway in-cluster Postgres/Redis, and runs
helm upgrade --install in the litellm namespace.

- OAuth 2.0 resource-server auth: validates JWT bearer tokens against the
  issuer's JWKS (signature, iss, aud, exp, required scope).
- Tools: provision / delete / status / list deployments.
- Dockerfile pins + checksum-verifies helm and kubectl; namespaced RBAC and
  Deployment manifests under deploy/.
- Unit tests cover auth, naming/registry derivation, manifests, and the
  provisioning flow (35 tests).

https://claude.ai/code/session_019WDsdJNGjNyUNrso3xigSV
2026-05-24 00:07:15 +00:00

54 lines
1.7 KiB
YAML

# Namespaced RBAC: the provisioning MCP can manage only the `litellm` namespace.
# No cluster-scoped permissions are granted, so the namespace must already exist
# (see namespace.yaml) — the server never uses `helm --create-namespace`.
apiVersion: v1
kind: ServiceAccount
metadata:
name: litellm-provisioning-mcp
namespace: litellm
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: litellm-provisioning-mcp
namespace: litellm
rules:
# Core objects created by the chart, the migration job, and the ephemeral
# datastores. Secrets cover both the generated master key / DB credentials and
# helm's own release-state storage.
- apiGroups: [""]
resources:
- pods
- pods/log
- services
- configmaps
- secrets
- serviceaccounts
- persistentvolumeclaims
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: ["apps"]
resources: ["deployments", "replicasets"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: ["batch"]
resources: ["jobs"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: ["autoscaling"]
resources: ["horizontalpodautoscalers"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: ["networking.k8s.io"]
resources: ["ingresses"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: litellm-provisioning-mcp
namespace: litellm
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: litellm-provisioning-mcp
subjects:
- kind: ServiceAccount
name: litellm-provisioning-mcp
namespace: litellm