Skip to content

[ROB-3039] GitHub App credentials mcp config - #1717

Merged
Avi-Robusta merged 7 commits into
masterfrom
better-github-mcp-config
Mar 11, 2026
Merged

Avi-Robusta merged 7 commits into
masterfrom
better-github-mcp-config

Conversation

@Avi-Robusta

@Avi-Robusta Avi-Robusta commented Mar 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary by CodeRabbit

  • New Features

    • Added GitHub App authentication as an alternative to Personal Access Token, supporting GitHub.com and Enterprise.
  • Documentation

    • Reworked GitHub MCP docs with clearer prerequisites, unified in-cluster deployment guidance, simplified Helm/config examples, and updated in-cluster endpoints.
  • Chores

    • Moved token management to the in-cluster MCP component and removed the legacy local token refresh mechanism.
  • Tests

    • Updated tests to use a renamed dynamic token variable and removed GitHub App token-manager tests.

Signed-off-by: avi@robusta.dev <avi@robusta.dev>
Signed-off-by: avi@robusta.dev <avi@robusta.dev>
Signed-off-by: avi@robusta.dev <avi@robusta.dev>
@github-actions

github-actions Bot commented Mar 9, 2026 •

Copy link
Copy Markdown
Contributor

📂 Previous Runs

📜 Run @ ecb5beb (#22941671416)

✅ Results of HolmesGPT evals

Automatically triggered by commit ecb5beb on branch better-github-mcp-config

View workflow logs

Results of HolmesGPT evals

  • ask_holmes: 10/10 test cases were successful, 0 regressions
Status Test case Time Turns Tools Cost Total tokens Input Output Cached Non-cached Reasoning Max output Compactions
✅ 09_crashpod 30.3s 5 10 $0.2352 104,309 102,502 1,807 78,116 24,386 — 557 —
✅ 101_loki_historical_logs_pod_deleted 51.4s 7 13 $0.3037 158,719 155,870 2,849 128,798 27,072 — 610 —
✅ 111_pod_names_contain_service 29.0s 5 9 $0.2185 100,235 98,585 1,650 76,222 22,363 — 505 —
✅ 112_find_pvcs_by_uuid 28.8s 5 6 $0.2174 99,279 97,526 1,753 75,730 21,796 — 618 —
✅ 12_job_crashing 36.2s 6 15 $0.2799 139,988 137,878 2,110 110,178 27,700 — 508 —
✅ 176_network_policy_blocking_traffic_no_runbooks 44.9s 7 14 $0.2786 153,711 151,546 2,165 125,604 25,942 — 566 —
✅ 227_count_configmaps_per_namespace[0] 23.1s 5 10 $0.1991 95,319 94,017 1,302 73,112 20,905 — 430 —
✅ 24_misconfigured_pvc 33.0s 6 12 $0.2388 119,978 118,134 1,844 94,611 23,523 — 483 —
✅ 43_current_datetime_from_prompt 4.7s 1 — $0.1094 17,130 17,003 127 0 17,003 — 127 —
✅ 61_exact_match_counting 11.3s 3 2 $0.1356 52,409 52,095 314 34,400 17,695 — 175 —
Total 29.3s avg 5.0 avg 10.1 avg $2.2162 1,041,077 1,025,156 15,921 796,771 228,385 — 618 —

Benchmark comparison unavailable: No ci-benchmark experiments found

Benchmark Comparison Details

Baseline: latest ci-benchmark experiment on master

Status: No ci-benchmark experiments found

Comparison indicators:

  • ±0% — diff under 10% (within noise threshold)
  • ↑N%/↓N% — diff 10-25%
  • ↑N%/↓N% — diff over 25% (significant)
📜 Run @ 888e299 (#22843859059)

✅ Results of HolmesGPT evals

Automatically triggered by commit 888e299 on branch better-github-mcp-config

View workflow logs

Results of HolmesGPT evals

  • ask_holmes: 10/10 test cases were successful, 0 regressions
Status Test case Time Turns Tools Cost Total tokens Input Output Cached Non-cached Reasoning Max output Compactions
✅ 09_crashpod 34.6s 5 10 $0.2333 104,885 103,043 1,842 79,327 23,716 — 760 —
✅ 101_loki_historical_logs_pod_deleted 64.6s 5 11 $0.4067 110,780 108,364 2,416 57,361 51,003 — 783 —
✅ 111_pod_names_contain_service 60.1s 6 9 $0.3542 118,894 117,124 1,770 73,308 43,816 — 491 —
✅ 112_find_pvcs_by_uuid 36.7s 5 4 $0.2968 95,215 94,076 1,139 55,592 38,484 — 292 —
✅ 12_job_crashing 70.0s 6 18 $0.4612 143,048 140,368 2,680 83,434 56,934 — 587 —
✅ 176_network_policy_blocking_traffic_no_runbooks 71.8s 7 15 $0.4405 155,765 153,222 2,543 100,708 52,514 — 776 —
✅ 227_count_configmaps_per_namespace[0] 37.4s 5 9 $0.3093 93,965 92,649 1,316 52,602 40,047 — 618 —
✅ 24_misconfigured_pvc 63.5s 6 15 $0.3867 123,484 121,361 2,123 73,467 47,894 — 590 —
✅ 43_current_datetime_from_prompt 5.7s 1 — $0.1102 17,150 16,991 159 0 16,991 — 159 —
✅ 61_exact_match_counting 34.2s 4 4 $0.2538 71,424 70,970 454 34,976 35,994 — 237 —
Total 47.8s avg 5.0 avg 10.6 avg $3.2526 1,034,610 1,018,168 16,442 610,775 407,393 — 783 —

Benchmark comparison unavailable: No ci-benchmark experiments found

Benchmark Comparison Details

Baseline: latest ci-benchmark experiment on master

Status: No ci-benchmark experiments found

Comparison indicators:

  • ±0% — diff under 10% (within noise threshold)
  • ↑N%/↓N% — diff 10-25%
  • ↑N%/↓N% — diff over 25% (significant)
📜 Run @ 0ee5242 (#22843647858)

✅ Results of HolmesGPT evals

Automatically triggered by commit 0ee5242 on branch better-github-mcp-config

View workflow logs

Results of HolmesGPT evals

  • ask_holmes: 10/10 test cases were successful, 0 regressions
Status Test case Time Turns Tools Cost Total tokens Input Output Cached Non-cached Reasoning Max output Compactions
✅ 09_crashpod 33.9s 6 10 $0.2416 120,259 118,442 1,817 94,384 24,058 — 634 —
✅ 101_loki_historical_logs_pod_deleted 51.2s 6 14 $0.2975 137,097 134,174 2,923 106,573 27,601 — 776 —
✅ 111_pod_names_contain_service 31.8s 5 8 $0.2139 96,885 95,243 1,642 73,378 21,865 — 499 —
✅ 112_find_pvcs_by_uuid 31.8s 7 6 $0.2243 134,485 132,953 1,532 112,160 20,793 — 325 —
✅ 12_job_crashing 39.1s 6 17 $0.2889 144,027 141,681 2,346 113,872 27,809 — 590 —
✅ 176_network_policy_blocking_traffic_no_runbooks 44.7s 8 18 $0.3181 183,437 180,794 2,643 152,430 28,364 — 634 —
✅ 227_count_configmaps_per_namespace[0] 28.2s 6 11 $0.2153 115,207 113,712 1,495 92,614 21,098 — 430 —
✅ 24_misconfigured_pvc 34.7s 6 12 $0.2367 120,316 118,492 1,824 95,434 23,058 — 475 —
✅ 43_current_datetime_from_prompt 5.6s 1 — $0.1102 17,151 16,991 160 0 16,991 — 160 —
✅ 61_exact_match_counting 17.2s 4 4 $0.1551 71,797 71,245 552 52,859 18,386 — 334 —
Total 31.8s avg 5.5 avg 11.1 avg $2.3017 1,140,661 1,123,727 16,934 893,704 230,023 — 776 —

Benchmark comparison unavailable: No ci-benchmark experiments found

Benchmark Comparison Details

Baseline: latest ci-benchmark experiment on master

Status: No ci-benchmark experiments found

Comparison indicators:

  • ±0% — diff under 10% (within noise threshold)
  • ↑N%/↓N% — diff 10-25%
  • ↑N%/↓N% — diff over 25% (significant)

✅ Results of HolmesGPT evals

Automatically triggered by commit 9f69409 on branch better-github-mcp-config

View workflow logs

Results of HolmesGPT evals

  • ask_holmes: 10/10 test cases were successful, 0 regressions
Status Test case Time Turns Tools Cost Total tokens Input Output Cached Non-cached Reasoning Max output Compactions
✅ 09_crashpod 37.1s 8 11 $0.2628 163,291 161,479 1,812 137,554 23,925 — 393 —
✅ 101_loki_historical_logs_pod_deleted 36.4s 5 11 $0.2558 108,996 106,672 2,324 81,357 25,315 — 783 —
✅ 111_pod_names_contain_service 32.2s 6 9 $0.2360 121,297 119,514 1,783 96,511 23,003 — 623 —
✅ 112_find_pvcs_by_uuid 20.2s 4 4 $0.1880 78,883 77,777 1,106 56,652 21,125 — 503 —
✅ 12_job_crashing 33.4s 6 15 $0.2660 134,550 132,478 2,072 106,571 25,907 — 530 —
✅ 176_network_policy_blocking_traffic_no_runbooks 50.4s 9 17 $0.3337 207,346 204,661 2,685 175,728 28,933 — 432 —
✅ 227_count_configmaps_per_namespace[0] 25.7s 6 11 $0.2173 117,356 115,866 1,490 94,627 21,239 — 430 —
✅ 24_misconfigured_pvc 31.9s 6 14 $0.2493 124,535 122,666 1,869 97,783 24,883 — 548 —
✅ 43_current_datetime_from_prompt 4.3s 1 — $0.1111 17,465 17,359 106 0 17,359 — 106 —
✅ 61_exact_match_counting 12.9s 3 2 $0.1406 53,709 53,314 395 35,207 18,107 — 275 —
Total 28.4s avg 5.4 avg 10.4 avg $2.2606 1,127,428 1,111,786 15,642 881,990 229,796 — 783 —

Benchmark comparison unavailable: No ci-benchmark experiments found

Benchmark Comparison Details

Baseline: latest ci-benchmark experiment on master

Status: No ci-benchmark experiments found

Comparison indicators:

  • ±0% — diff under 10% (within noise threshold)
  • ↑N%/↓N% — diff 10-25%
  • ↑N%/↓N% — diff over 25% (significant)
📖 Legend
Icon Meaning
✅ The test was successful
➖ The test was skipped
⚠️ The test failed but is known to be flaky or known to fail
🚧 The test had a setup failure (not a code regression)
🔧 The test failed due to mock data issues (not a code regression)
🚫 The test was throttled by API rate limits/overload
❌ The test failed and should be fixed before merging the PR
🔄 Re-run evals manually

⚠️ Warning: /eval comments always run using the workflow from master, not from this PR branch. If you modified the GitHub Action (e.g., added secrets or env vars), those changes won't take effect.

To test workflow changes, use the GitHub CLI or Actions UI instead:

gh workflow run eval-regression.yaml --repo HolmesGPT/holmesgpt --ref better-github-mcp-config -f markers=regression -f filter=

Option 1: Comment on this PR with /eval:

/eval
tags: regression

Or with more options (one per line):

/eval
model: gpt-4o
tags: regression
filter: 09_crashpod
iterations: 5

Run evals on a different branch (e.g., master) for comparison:

/eval
branch: master
tags: regression
Option Description
model Model(s) to test (default: same as automatic runs)
tags Pytest tags / markers (no default - runs all tests!)
filter Pytest -k filter (use /list to see valid eval names)
iterations Number of runs, max 10
branch Run evals on a different branch (for cross-branch comparison)

Quick re-run: Use /rerun to re-run the most recent /eval on this PR with the same parameters.

Option 2: Trigger via GitHub Actions UI → "Run workflow"

Option 3: Add PR labels to include extra evals in automatic regression runs:

Label Effect
evals-tag-<name> Run tests with tag <name> alongside regression
evals-id-<name> Run a specific eval by test ID

Examples: evals-tag-easy, evals-id-09_crashpod

🏷️ Valid tags

benchmark, chain-of-causation, compaction, confluence, context_window, coralogix, counting, database, datadog, datetime, db-connectors, easy, elasticsearch, embeds, fast, frontend, grafana-dashboard, hard, integration, kafka, kubernetes, leaked-information, logs, loki, medium, metrics, network, newrelic, no-cicd, numerical, one-test, port-forward, prometheus, question-answer, regression, runbooks, slackbot, storage, toolset-limitation, traces, transparency


Commands: /eval · /rerun · /list

CLI: gh workflow run eval-regression.yaml --repo HolmesGPT/holmesgpt --ref better-github-mcp-config -f markers=regression -f filter=

@coderabbitai

coderabbitai Bot commented Mar 9, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: d3db73b3-f321-4d19-99ba-e2a9b5b223b2

📥 Commits

Reviewing files that changed from the base of the PR and between 888e299 and ecb5beb.

📒 Files selected for processing (1)
  • helm/holmes/values.yaml
🚧 Files skipped from review as they are similar to previous changes (1)
  • helm/holmes/values.yaml

Walkthrough

Switches GitHub token management from in-process Python to an in-cluster github-app-mcp image and adds GitHub App authentication as an alternative to PATs. Updates docs, Helm charts, and tests; removes the Python GitHub App token manager and its tests; routes MCP traffic to in-cluster /mcp with streamable-http for the App flow.

Changes

Cohort / File(s) Summary
Docs
docs/data-sources/builtin-toolsets/github-mcp.md
Rewrote to document two auth methods (PAT vs GitHub App), updated prerequisites, emphasize in-cluster MCP deployment, and note github-app-mcp handles token generation/refresh.
Helm templates & values
helm/holmes/templates/mcp-servers/github/deployment.yaml, helm/holmes/templates/toolset-config.yaml, helm/holmes/values.yaml
Added conditional logic to select github-app-mcp vs PAT image, switch command/args and transport (streamableHttp for App), inject GITHUB_APP_* env vars from secret, add mcpAddons.githubApp values, and route MCP URL to in-cluster /mcp.
Core code removal
holmes/utils/github_app_token_manager.py, holmes/core/toolset_manager.py
Removed the github_app_token_manager module (JWT generation, token exchange, background refresh, env var population); removed its startup invocation/import from toolset_manager.
Tests
tests/test_mcp_toolset.py, tests/utils/test_github_app_token_manager.py
Updated MCP test to use SOME_DYNAMIC_TOKEN and renamed toolset key; deleted the test suite for the removed token manager.

Sequence Diagram(s)

sequenceDiagram
    participant Holmes as Holmes CLI/Pod
    participant MCP as In-cluster MCP Server
    participant GitHubMCP as github-app-mcp Image
    participant GitHub as GitHub API

    Note over GitHubMCP,GitHub: github-app-mcp manages App tokens
    GitHubMCP->>GitHubMCP: Read GITHUB_APP_* from Secret
    GitHubMCP->>GitHub: POST /app/installations/{id}/access_tokens (with JWT)
    GitHub-->>GitHubMCP: Return installation token
    GitHubMCP->>MCP: Expose /mcp and use token for proxied requests

    loop Periodic refresh
        GitHubMCP->>GitHubMCP: Generate new JWT
        GitHubMCP->>GitHub: Refresh installation token
        GitHub-->>GitHubMCP: New token
    end

    Holmes->>MCP: Connect to /mcp (streamableHttp)
    MCP->>GitHubMCP: Proxy GitHub API operations
    GitHubMCP->>GitHub: API requests using managed token
    GitHub-->>GitHubMCP: API responses
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested reviewers

  • arikalon1
  • RoiGlinik
🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main change: adding GitHub App credentials configuration support for the MCP server, which is the primary focus across documentation, Helm charts, and code modifications.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actions Bot commented Mar 9, 2026 •

Copy link
Copy Markdown
Contributor

✅ Docker images ready for 5cbd3181 (built in 1m 17s)

⚠️ Warning: does not support ARM (ARM images are built on release only - not on every PR)

Use these tags to pull the images for testing.

📋 Copy commands

⚠️ Temporary images are deleted after 30 days. Copy to a permanent registry before using them:

gcloud auth configure-docker us-central1-docker.pkg.dev
docker pull us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes:5cbd3181
docker tag us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes:5cbd3181 me-west1-docker.pkg.dev/robusta-development/development/holmes-dev:5cbd3181
docker push me-west1-docker.pkg.dev/robusta-development/development/holmes-dev:5cbd3181
docker pull us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes-operator:5cbd3181
docker tag us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes-operator:5cbd3181 me-west1-docker.pkg.dev/robusta-development/development/holmes-operator-dev:5cbd3181
docker push me-west1-docker.pkg.dev/robusta-development/development/holmes-operator-dev:5cbd3181

Patch Helm values in one line (choose the chart you use):

HolmesGPT chart:

helm upgrade --install holmesgpt ./helm/holmes \
  --set registry=me-west1-docker.pkg.dev/robusta-development/development \
  --set image=holmes-dev:5cbd3181 \
  --set operator.registry=me-west1-docker.pkg.dev/robusta-development/development \
  --set operator.image=holmes-operator-dev:5cbd3181

Robusta wrapper chart:

helm upgrade --install robusta robusta/robusta \
  --reuse-values \
  --set holmes.registry=me-west1-docker.pkg.dev/robusta-development/development \
  --set holmes.image=holmes-dev:5cbd3181 \
  --set holmes.operator.registry=me-west1-docker.pkg.dev/robusta-development/development \
  --set holmes.operator.image=holmes-operator-dev:5cbd3181

@netlify

netlify Bot commented Mar 9, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for holmes-docs ready!

Name Link
🔨 Latest commit 9f69409
🔍 Latest deploy log https://app.netlify.com/projects/holmes-docs/deploys/69b123b96031e00008f027a9
😎 Deploy Preview https://deploy-preview-1717--holmes-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions

github-actions Bot commented Mar 9, 2026 •

Copy link
Copy Markdown
Contributor

🔬 CLI Performance Benchmark

🟡 Startup Time (no LLM)

Measures holmes version execution time (imports + initialization)

Metric PR Master Change
Cold Start 11.10s 11.13s -0.3%
Warm Mean 5.17s 5.12s +0.9%
Warm Min 5.00s 5.04s
Warm Max 5.26s 5.26s

🟡 Full CLI with LLM

Measures holmes ask execution time (OpenRouter + Haiku 4.5)

Metric PR Master Change
Cold Start 27.62s 26.52s +4.2%
Warm Mean 7.67s 7.66s +0.1%
Warm Min 7.22s 7.39s
Warm Max 8.05s 7.95s

PR: 5cbd3181 | Master: 75ee1411 | Iterations: 5

Signed-off-by: avi@robusta.dev <avi@robusta.dev>
@Avi-Robusta Avi-Robusta changed the title [ROB-3039] Better GitHub mcp config [ROB-3039] GitHub App credentials mcp config Mar 9, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@docs/data-sources/builtin-toolsets/github-mcp.md`:
- Around line 306-363: The Deployment example for github-mcp-server is missing
creation of the holmes-github-app Secret and a Service to expose
github-mcp-server, so update the docs to either (a) include YAML snippets that
create the holmes-github-app Secret (containing GITHUB_APP_ID,
GITHUB_APP_INSTALLATION_ID, GITHUB_APP_PRIVATE_KEY) and a ClusterIP Service
named github-mcp-server in the holmes-mcp namespace, or (b) explicitly tell
readers to reuse the PAT CLI example’s Secret and Service steps before adding
the mcp_servers entry in ~/.holmes/config.yaml; reference the Deployment
resource name github-mcp-server, the secret name holmes-github-app, and the
config key mcp_servers.github.url so maintainers know exactly what to add or
point to.
- Around line 7-12: The prerequisites section is misleading for GitHub App users
because the overview lists both "Personal Access Token (PAT)" and "GitHub App"
but the following paragraph implies a PAT is required; update the docs to split
or clarify prerequisites per auth method: under the "Personal Access Token
(PAT)" subsection state explicitly that a PAT is required and how to provide it
to the `github-mcp` image, and under the "GitHub App" subsection remove any PAT
requirement and instead describe the credentials needed for the `github-app-mcp`
image (App ID, private key, installation ID) and how tokens are
generated/rotated by that image so readers using "GitHub App" aren’t directed to
create a PAT.

In `@helm/holmes/templates/mcp-servers/github/deployment.yaml`:
- Around line 65-111: The template currently lets auth.githubApp.secretName
silently override auth.secretName causing image/transport/env mismatches; add a
render-time guard that fails fast if both
.Values.mcpAddons.github.auth.githubApp.secretName and
.Values.mcpAddons.github.auth.secretName are set (e.g. compute a boolean
$hasGitHubApp and call required or fail with a clear message when both are
present) in helm/holmes/templates/mcp-servers/github/deployment.yaml, and apply
the same $hasGitHubApp guard/conditional in
helm/holmes/templates/toolset-config.yaml so the image, args/--outputTransport,
and env blocks stay in sync and misconfiguration is prevented at render time.

In `@helm/holmes/values.yaml`:
- Around line 327-332: Update the GitHub App secret example in values.yaml so it
creates all required keys for the GitHub App flow: include GITHUB_APP_ID,
GITHUB_APP_INSTALLATION_ID and GITHUB_APP_PRIVATE_KEY in the kubectl create
secret generic command (or replace the one-liner with a note pointing to the
detailed example), ensuring the example secret name and namespace remain
consistent with the rest of the chart; edit the block containing the current
example that references GITHUB_APP_ID to either inline a full kubectl create
secret generic ... --from-literal=GITHUB_APP_ID=...
--from-literal=GITHUB_APP_INSTALLATION_ID=...
--from-file=GITHUB_APP_PRIVATE_KEY=... or add an explicit pointer to the
detailed example below so the pod receives all three values.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: cdec7c2e-d980-4ff3-96a8-24a8b796b10c

📥 Commits

Reviewing files that changed from the base of the PR and between 39b8509 and 0ee5242.

📒 Files selected for processing (8)
  • docs/data-sources/builtin-toolsets/github-mcp.md
  • helm/holmes/templates/mcp-servers/github/deployment.yaml
  • helm/holmes/templates/toolset-config.yaml
  • helm/holmes/values.yaml
  • holmes/core/toolset_manager.py
  • holmes/utils/github_app_token_manager.py
  • tests/test_mcp_toolset.py
  • tests/utils/test_github_app_token_manager.py
💤 Files with no reviewable changes (3)
  • holmes/core/toolset_manager.py
  • tests/utils/test_github_app_token_manager.py
  • holmes/utils/github_app_token_manager.py

Comment thread docs/data-sources/builtin-toolsets/github-mcp.md
Comment thread docs/data-sources/builtin-toolsets/github-mcp.md Outdated
Comment thread helm/holmes/templates/mcp-servers/github/deployment.yaml
Comment thread helm/holmes/values.yaml

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

♻️ Duplicate comments (2)
docs/data-sources/builtin-toolsets/github-mcp.md (2)

320-377: ⚠️ Potential issue | 🟡 Minor

Add the Service to the GitHub App CLI example.

This flow points mcp_servers.github.config.url at github-mcp-server.holmes-mcp.svc.cluster.local:8000/mcp, but the example only creates the Secret and Deployment. Without a Service, that DNS name will not resolve, so the CLI example is still incomplete as written.

Suggested doc patch
     ```yaml
     apiVersion: apps/v1
     kind: Deployment
     metadata:
       name: github-mcp-server
@@
             - name: GITHUB_APP_PRIVATE_KEY
               valueFrom:
                 secretKeyRef:
                   name: holmes-github-app
                   key: GITHUB_APP_PRIVATE_KEY
+    ---
+    apiVersion: v1
+    kind: Service
+    metadata:
+      name: github-mcp-server
+      namespace: holmes-mcp
+    spec:
+      selector:
+        app: github-mcp-server
+      ports:
+      - port: 8000
+        targetPort: 8000
+        protocol: TCP
+        name: http
     ```
+
+    Apply it to the cluster:
+
+    ```bash
+    kubectl apply -f github-app-mcp-deployment.yaml
+    ```
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@docs/data-sources/builtin-toolsets/github-mcp.md` around lines 320 - 377, The
documentation is missing a Kubernetes Service for the github-mcp-server
Deployment so the DNS github-mcp-server.holmes-mcp.svc.cluster.local:8000 will
not resolve; add a Service manifest that selects pods with label app:
github-mcp-server and exposes port 8000 (port 8000 -> targetPort 8000, TCP) with
the same name (e.g., github-mcp-server) and include instructions to apply the
manifest (kubectl apply -f ...) so mcp_servers.github.config.url can reach the
MCP server.

7-12: ⚠️ Potential issue | 🟡 Minor

Clarify prerequisites per auth method.

The overview now says PAT and GitHub App are both supported, but the next section still opens by saying a GitHub PAT is required before deployment. That still sends GitHub App users down the wrong path; scope the PAT prerequisite to the PAT flow or split prerequisites by auth method.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@docs/data-sources/builtin-toolsets/github-mcp.md` around lines 7 - 12, The
prerequisites section currently states a GitHub PAT is required globally; update
the docs to scope prerequisites per authentication method by either (A) moving
the PAT prerequisite into the PAT flow and labeling it for "Personal Access
Token (PAT) / github-mcp image" or (B) splitting the prerequisites into two
subsections titled "PAT (github-mcp image)" and "GitHub App (github-app-mcp
image)" and listing only the relevant credentials/permissions for each (PAT and
scopes for PAT flow; App ID, private key, installation ID, and required
permissions for GitHub App flow).
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Duplicate comments:
In `@docs/data-sources/builtin-toolsets/github-mcp.md`:
- Around line 320-377: The documentation is missing a Kubernetes Service for the
github-mcp-server Deployment so the DNS
github-mcp-server.holmes-mcp.svc.cluster.local:8000 will not resolve; add a
Service manifest that selects pods with label app: github-mcp-server and exposes
port 8000 (port 8000 -> targetPort 8000, TCP) with the same name (e.g.,
github-mcp-server) and include instructions to apply the manifest (kubectl apply
-f ...) so mcp_servers.github.config.url can reach the MCP server.
- Around line 7-12: The prerequisites section currently states a GitHub PAT is
required globally; update the docs to scope prerequisites per authentication
method by either (A) moving the PAT prerequisite into the PAT flow and labeling
it for "Personal Access Token (PAT) / github-mcp image" or (B) splitting the
prerequisites into two subsections titled "PAT (github-mcp image)" and "GitHub
App (github-app-mcp image)" and listing only the relevant
credentials/permissions for each (PAT and scopes for PAT flow; App ID, private
key, installation ID, and required permissions for GitHub App flow).

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: a262d8ec-0230-4781-837b-43f574b74ab9

📥 Commits

Reviewing files that changed from the base of the PR and between 0ee5242 and 888e299.

📒 Files selected for processing (1)
  • docs/data-sources/builtin-toolsets/github-mcp.md

@Avi-Robusta
Avi-Robusta enabled auto-merge (squash) March 11, 2026 07:30
@Avi-Robusta
Avi-Robusta merged commit f0aa88c into master Mar 11, 2026
21 of 22 checks passed
@Avi-Robusta
Avi-Robusta deleted the better-github-mcp-config branch March 11, 2026 08:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants