Skip to content

ROB-3465 k8s mcp addon - #1992

Merged
RoiGlinik merged 10 commits into
masterfrom
ROB-3465-k8s-mcp-addon
May 6, 2026
Merged

RoiGlinik merged 10 commits into
masterfrom
ROB-3465-k8s-mcp-addon

Conversation

@RoiGlinik

@RoiGlinik RoiGlinik commented May 4, 2026 •

Copy link
Copy Markdown
Collaborator

Summary by CodeRabbit

  • New Features
    • Kubernetes MCP server addon for model-context protocol integration
    • Toggleable RBAC mode and explicit k8sRBAC setting
    • Optional ServiceAccount creation with annotation and imagePullSecrets support; token automount disabled by default
    • Configurable MCP deployment options (image, resources, kubeconfig/secret, OAuth, extra args)
    • NetworkPolicy to restrict MCP ingress to the MCP service
    • Read-only / disable-destructive controls for Kubernetes operations
    • Customizable LLM instruction templates for the Kubernetes MCP

Signed-off-by: Roi Glinik <groi.tech@gmail.com>
Signed-off-by: Roi Glinik <groi.tech@gmail.com>
Signed-off-by: Roi Glinik <groi.tech@gmail.com>
Signed-off-by: Roi Glinik <groi.tech@gmail.com>
Signed-off-by: Roi Glinik <groi.tech@gmail.com>
Signed-off-by: Roi Glinik <groi.tech@gmail.com>

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This repository is configured for manual code reviews. Comment @claude review to trigger a review and subscribe this PR to future pushes, or @claude review once for a one-time review.

Tip: disable this comment in your organization's Code Review settings.

@coderabbitai

coderabbitai Bot commented May 4, 2026 •

Copy link
Copy Markdown
Contributor

Walkthrough

Adds a configurable Kubernetes MCP server Helm addon and RBAC/service-account controls: new mcpAddons.kubernetes values, templates for Deployment, ConfigMap, optional Secret, Service, ServiceAccount, ClusterRoleBinding, NetworkPolicy, an LLM-instructions helper, and a k8sRBAC flag that alters service-account/ClusterRole rendering. (≤50 words)

Changes

Kubernetes MCP Server Addon & RBAC

Layer / File(s) Summary
Values Configuration
helm/holmes/values.yaml
Adds k8sRBAC: false and a new mcpAddons.kubernetes block (enabled, image/registry/imagePullPolicy, serviceAccount, createClusterRoleBinding/clusterRole, config: readOnly/disableDestructive/toolsets/logLevel/extraArgs, kubeconfig secret wiring, serverConfig/configSecret, oauth, resources, networkPolicy, llmInstructions, scheduling).
Data Shape / Validation
helm/holmes/templates/mcp-servers/kubernetes/deployment.yaml
Rendering-time logic to select MCP config source, fail if both serverConfig and config.configSecret.secretName are set; derive generated Secret name when serverConfig provided.
Config Resources
helm/holmes/templates/mcp-servers/kubernetes/deployment.yaml
Adds ConfigMap and conditional Secret (stringData.config.toml) to hold MCP server configuration when serverConfig is used.
Core Deployment
helm/holmes/templates/mcp-servers/kubernetes/deployment.yaml
Creates Deployment for k8s MCP server with conditional container args (--config, --read-only, --disable-destructive, --toolsets, --log-level, extraArgs), optional mounts for kubeconfig and/or MCP config, and readiness/liveness probes on port 8000.
Service
helm/holmes/templates/mcp-servers/kubernetes/deployment.yaml
Adds Service selecting MCP pods and exposing TCP/8000.
RBAC / ServiceAccount
helm/holmes/templates/holmesgpt-rbac-service-account.yaml, helm/holmes/templates/mcp-servers/kubernetes/deployment.yaml, helm/holmes/templates/holmesgpt-service-account.yaml
New conditional ServiceAccount template with optional annotations, automountServiceAccountToken: false, and optional imagePullSecrets. Existing ClusterRole rendering narrowed to and .Values.createServiceAccount (not .Values.k8sRBAC). Deployment can optionally create ServiceAccount and ClusterRoleBinding.
Network Policy
helm/holmes/templates/mcp-servers/kubernetes/networkpolicy.yaml
Adds conditional NetworkPolicy restricting ingress to TCP/8000 from pods labeled app: holmes.
Helper Templates
helm/holmes/templates/mcp-servers/kubernetes/_helpers.tpl
Adds holmes.kubernetesMcp.llmInstructions helper: uses .Values.mcpAddons.kubernetes.llmInstructions if present or emits default multi-section LLM instructions.
Toolset Integration
helm/holmes/templates/toolset-config.yaml
When k8sRBAC is true, merges RBAC overrides to disable certain toolsets before rendering; injects the mcpAddons.kubernetes server entry into MCP servers list and conditionally attaches oauth config.

Sequence Diagram(s)

sequenceDiagram
    autonumber
    participant User as rgba(66,133,244,0.5) User/Helm
    participant Helm as rgba(219,68,55,0.5) Helm chart
    participant K8sAPI as rgba(15,157,88,0.5) Kubernetes API
    participant MCP as rgba(171,71,188,0.5) MCP Deployment
    participant SecretStore as rgba(244,180,0,0.5) Secret/ConfigMap

    User->>Helm: render with mcpAddons.kubernetes enabled
    Helm->>Helm: validate config sources (fail if both serverConfig & configSecret)
    Helm->>SecretStore: optionally create Secret (stringData.config.toml)
    Helm->>K8sAPI: apply ConfigMap, Secret, Deployment, Service, ServiceAccount, NetworkPolicy, ClusterRoleBinding (conditional)
    K8sAPI->>MCP: schedule pod with mounts (kubeconfig / config)
    MCP->>K8sAPI: probe readiness/liveness on :8000
    User->>MCP: interact via Service on port 8000
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

  • HolmesGPT/holmesgpt#736: Modifies the same service-account / ClusterRole rendering logic and is directly related to RBAC condition changes.

Suggested reviewers

  • arikalon1
  • Avi-Robusta
  • moshemorad
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'ROB-3465 k8s mcp addon' accurately describes the main change: adding Kubernetes MCP addon support with RBAC configuration to the Helm chart.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@netlify

netlify Bot commented May 4, 2026 •

Copy link
Copy Markdown

❌ Deploy Preview for holmes-docs failed. Why did it fail? →

Name Link
🔨 Latest commit cfd2ed3
🔍 Latest deploy log https://app.netlify.com/projects/holmes-docs/deploys/69fb1cb3b7002f00088639f6

@github-actions

github-actions Bot commented May 4, 2026 •

Copy link
Copy Markdown
Contributor

📂 Previous Runs

📜 #3 · Run @ __6e907fd__ (#25430775664) — May 6, 10:55 UTC

✅ Results of HolmesGPT evals

Automatically triggered by commit 6e907fd on branch ROB-3465-k8s-mcp-addon

View workflow logs

Results of HolmesGPT evals

  • ask_holmes: 11/11 test cases were successful, 0 regressions
Status Test case Time Turns Tools Cost Total tokens Input Max input Output Max output Cached Non-cached Reasoning Compactions
✅ 09_crashpod 37.1s 5 10 $0.2431 104,103 101,958 23,445 2,145 794 77,692 24,266 107 —
✅ 101_loki_historical_logs_pod_deleted 59.7s 8 15 $0.3311 184,102 180,762 26,474 3,340 927 153,176 27,586 173 —
✅ 112_find_pvcs_by_uuid 30.3s 6 5 $0.2114 114,056 112,581 20,546 1,475 302 92,021 20,560 104 —
✅ 12_job_crashing 37.7s 6 13 $0.2652 135,674 133,598 25,068 2,076 527 108,008 25,590 48 —
✅ 176_network_policy_blocking_traffic_no_skills 42.3s 5 13 $0.2800 115,458 112,840 26,713 2,618 963 85,111 27,729 100 —
✅ 227_count_configmaps_per_namespace[0] 23.8s 5 9 $0.2044 95,202 93,948 20,952 1,254 586 71,747 22,201 73 —
✅ 243_pod_names_contain_service 30.2s 4 9 $0.2121 80,148 78,409 22,057 1,739 905 55,767 22,642 56 —
✅ 24_misconfigured_pvc 40.8s 7 15 $0.2701 145,488 143,172 23,785 2,316 488 118,525 24,647 99 —
✅ 43_current_datetime_from_prompt 5.7s 1 — $0.1090 17,098 16,982 16,982 116 116 0 16,982 77 —
✅ 51_logs_summarize_errors 37.1s 4 5 $0.1866 77,420 76,308 20,981 1,112 363 55,315 20,993 56 —
✅ 61_exact_match_counting 11.3s 3 3 $0.1389 52,992 52,623 17,961 369 222 34,651 17,972 46 —
Total 32.4s avg 4.9 avg 9.7 avg $2.4520 1,121,741 1,103,181 26,713 18,560 963 852,013 251,168 939 —
Benchmark Comparison Details

Baseline: latest ci-benchmark experiment on master

Status: Success - 73 test/model combinations loaded

Benchmark experiment:

No benchmark data available for comparison.

Benchmark has no cost, total tokens, cached tokens data. Will appear after the next weekly benchmark run.

Comparison indicators:

  • ±0% — diff under 10% (within noise threshold)
  • ↑N%/↓N% — diff 10-25%
  • ↑N%/↓N% — diff over 25% (significant)
📜 #2 · Run @ __244f46a__ (#25425657473) — May 6, 08:59 UTC

✅ Results of HolmesGPT evals

Automatically triggered by commit 244f46a on branch ROB-3465-k8s-mcp-addon

View workflow logs

Results of HolmesGPT evals

  • ask_holmes: 11/11 test cases were successful, 0 regressions
Status Test case Time Turns Tools Cost Total tokens Input Max input Output Max output Cached Non-cached Reasoning Compactions
✅ 09_crashpod 35.6s 5 9 $0.2315 103,674 101,793 22,995 1,881 575 78,498 23,295 101 —
✅ 101_loki_historical_logs_pod_deleted 67.9s 8 17 $0.3561 193,563 189,907 28,457 3,656 733 160,095 29,812 133 —
✅ 112_find_pvcs_by_uuid 25.2s 5 4 $0.2034 97,443 96,285 21,958 1,158 288 74,314 21,971 95 —
✅ 12_job_crashing 36.3s 5 13 $0.2483 111,863 109,860 24,903 2,003 582 84,944 24,916 49 —
✅ 176_network_policy_blocking_traffic_no_skills 49.2s 7 13 $0.3018 157,505 154,960 25,958 2,545 782 126,450 28,510 113 —
✅ 227_count_configmaps_per_namespace[0] 24.5s 5 9 $0.2006 95,037 93,811 20,907 1,226 578 72,278 21,533 54 —
✅ 243_pod_names_contain_service 36.1s 5 9 $0.2307 101,516 99,501 22,482 2,015 603 76,724 22,777 46 —
✅ 24_misconfigured_pvc 38.6s 6 12 $0.2561 127,229 124,984 23,529 2,245 521 100,975 24,009 110 —
✅ 43_current_datetime_from_prompt 5.1s 1 — $0.1098 17,128 16,982 16,982 146 146 0 16,982 93 —
✅ 51_logs_summarize_errors 23.6s 4 5 $0.1842 77,149 76,106 20,875 1,043 354 55,219 20,887 64 —
✅ 61_exact_match_counting 8.9s 2 1 $0.1244 34,678 34,397 17,406 281 213 16,981 17,416 97 —
Total 31.9s avg 4.8 avg 9.2 avg $2.4468 1,116,785 1,098,586 28,457 18,199 782 846,478 252,108 955 —
Benchmark Comparison Details

Baseline: latest ci-benchmark experiment on master

Status: Success - 73 test/model combinations loaded

Benchmark experiment:

No benchmark data available for comparison.

Benchmark has no cost, total tokens, cached tokens data. Will appear after the next weekly benchmark run.

Comparison indicators:

  • ±0% — diff under 10% (within noise threshold)
  • ↑N%/↓N% — diff 10-25%
  • ↑N%/↓N% — diff over 25% (significant)
📜 #1 · Run @ __060fd1d__ (#25306655305) — May 4, 07:40 UTC

✅ Results of HolmesGPT evals

Automatically triggered by commit 060fd1d on branch ROB-3465-k8s-mcp-addon

View workflow logs

Results of HolmesGPT evals

  • ask_holmes: 11/11 test cases were successful, 0 regressions
Status Test case Time Turns Tools Cost Total tokens Input Max input Output Max output Cached Non-cached Reasoning Compactions
✅ 09_crashpod 32.1s 4 9 $0.2244 82,444 80,483 23,049 1,961 968 56,864 23,619 — —
✅ 101_loki_historical_logs_pod_deleted 49.4s 6 13 $0.3019 137,661 134,754 26,730 2,907 864 106,216 28,538 — —
✅ 112_find_pvcs_by_uuid 25.0s 4 5 $0.2084 81,838 80,402 22,737 1,436 607 57,321 23,081 — —
✅ 12_job_crashing 49.1s 7 17 $0.3265 172,108 169,061 28,360 3,047 741 140,090 28,971 — —
✅ 176_network_policy_blocking_traffic_no_skills 57.5s 9 16 $0.3575 214,733 211,700 28,167 3,033 619 180,442 31,258 — —
✅ 227_count_configmaps_per_namespace[0] 22.4s 4 9 $0.1937 77,595 76,365 20,958 1,230 585 54,471 21,894 — —
✅ 243_pod_names_contain_service 33.0s 5 8 $0.2165 99,772 98,092 21,810 1,680 429 76,269 21,823 — —
✅ 24_misconfigured_pvc 35.5s 6 11 $0.2441 123,005 120,964 22,480 2,041 513 97,747 23,217 — —
✅ 43_current_datetime_from_prompt 5.0s 1 — $0.1091 17,100 16,982 16,982 118 118 0 16,982 — —
✅ 51_logs_summarize_errors 22.9s 4 5 $0.1885 78,153 77,064 21,337 1,089 343 55,715 21,349 — —
✅ 61_exact_match_counting 11.7s 3 3 $0.1391 53,011 52,636 17,970 375 228 34,655 17,981 — —
Total 31.2s avg 4.8 avg 9.6 avg $2.5096 1,137,420 1,118,503 28,360 18,917 968 859,790 258,713 — —
Benchmark Comparison Details

Baseline: latest ci-benchmark experiment on master

Status: Success - 73 test/model combinations loaded

Benchmark experiment:

No benchmark data available for comparison.

Benchmark has no cost, total tokens, cached tokens data. Will appear after the next weekly benchmark run.

Comparison indicators:

  • ±0% — diff under 10% (within noise threshold)
  • ↑N%/↓N% — diff 10-25%
  • ↑N%/↓N% — diff over 25% (significant)

✅ Results of HolmesGPT evals

Automatically triggered by commit cfd2ed3 on branch ROB-3465-k8s-mcp-addon

View workflow logs

Results of HolmesGPT evals

  • ask_holmes: 11/11 test cases were successful, 0 regressions
Status Test case Time Turns Tools Cost Total tokens Input Max input Output Max output Cached Non-cached Reasoning Compactions
✅ 09_crashpod 38.1s 5 11 $0.2462 104,835 102,614 23,660 2,221 877 78,216 24,398 98 —
✅ 101_loki_historical_logs_pod_deleted 39.5s 5 9 $0.2541 105,550 103,295 24,006 2,255 698 77,509 25,786 100 —
✅ 112_find_pvcs_by_uuid 30.9s 6 6 $0.2132 114,631 113,169 20,627 1,462 377 92,216 20,953 91 —
✅ 12_job_crashing 41.1s 6 16 $0.2908 140,181 137,620 26,521 2,561 596 109,874 27,746 112 —
✅ 176_network_policy_blocking_traffic_no_skills 55.9s 8 15 $0.3163 182,102 179,248 26,622 2,854 867 152,132 27,116 109 —
✅ 227_count_configmaps_per_namespace[0] 24.4s 5 9 $0.2008 94,333 92,921 20,416 1,412 703 72,148 20,773 79 —
✅ 243_pod_names_contain_service 40.7s 6 10 $0.2486 119,941 117,780 22,715 2,161 758 93,932 23,848 116 —
✅ 24_misconfigured_pvc 35.1s 6 13 $0.2449 120,677 118,643 22,914 2,034 560 95,078 23,565 55 —
✅ 43_current_datetime_from_prompt 4.4s 1 — $0.1094 17,115 16,982 16,982 133 133 0 16,982 85 —
✅ 51_logs_summarize_errors 22.5s 4 5 $0.1879 77,940 76,850 21,254 1,090 340 55,584 21,266 58 —
✅ 61_exact_match_counting 7.3s 2 1 $0.1227 34,567 34,338 17,347 229 160 16,981 17,357 56 —
Total 30.9s avg 4.9 avg 9.5 avg $2.4349 1,111,872 1,093,460 26,622 18,412 877 843,670 249,790 959 —
Benchmark Comparison Details

Baseline: latest ci-benchmark experiment on master

Status: Success - 73 test/model combinations loaded

Benchmark experiment:

No benchmark data available for comparison.

Benchmark has no cost, total tokens, cached tokens data. Will appear after the next weekly benchmark run.

Comparison indicators:

  • ±0% — diff under 10% (within noise threshold)
  • ↑N%/↓N% — diff 10-25%
  • ↑N%/↓N% — diff over 25% (significant)
📖 Legend
Icon Meaning
✅ The test was successful
➖ The test was skipped
⚠️ The test failed but is known to be flaky or known to fail
🚧 The test had a setup failure (not a code regression)
🔧 The test failed due to mock data issues (not a code regression)
🚫 The test was throttled by API rate limits/overload
❌ The test failed and should be fixed before merging the PR
🔄 Re-run evals manually

⚠️ Warning: /eval comments always run using the workflow from master, not from this PR branch. If you modified the GitHub Action (e.g., added secrets or env vars), those changes won't take effect.

To test workflow changes, use the GitHub CLI or Actions UI instead:

gh workflow run eval-regression.yaml --repo HolmesGPT/holmesgpt --ref ROB-3465-k8s-mcp-addon -f markers=regression -f filter=

Option 1: Comment on this PR with /eval:

/eval
tags: regression

Or with more options (one per line):

/eval
model: gpt-4o
tags: regression
id: 09_crashpod
iterations: 5

Run evals on a different branch (e.g., master) for comparison:

/eval
branch: master
tags: regression
Option Description
model Model(s) to test (default: same as automatic runs)
tags Pytest tags / markers (no default - runs all tests!)
id Eval ID / pytest -k filter (use /list to see valid eval names)
iterations Number of runs, max 10
branch Run evals on a different branch (for cross-branch comparison)

Quick re-run: Use /rerun to re-run the most recent /eval on this PR with the same parameters.

Option 2: Trigger via GitHub Actions UI → "Run workflow"

Option 3: Add PR labels to include extra evals (applies to both automatic runs and /eval comments):

Label Effect
evals-tag-<name> Run tests with tag <name> alongside regression
evals-id-<name> Run a specific eval by test ID
evals-model-<name> Override the model (use model list name, e.g. sonnet-4.5)

Examples: evals-tag-easy, evals-id-09_crashpod, evals-model-sonnet-4.5

🏷️ Valid tags

benchmark, chain-of-causation, compaction, confluence, context_window, conversation_worker, coralogix, counting, database, datadog, datetime, db-connectors, easy, elasticsearch, embeds, fast, frontend, grafana, hard, images, integration, kafka, kubernetes, leaked-information, logs, loki, manual, mcp, medium, metrics, network, newrelic, no-cicd, numerical, one-test, port-forward, prometheus, question-answer, regression, skills, slackbot, storage, token-limit, toolset-limitation, traces, transparency, victorialogs

🤖 Valid models

deepseek-chat, deepseek-r1-reasoner, deepseek-reasoner, deepseek-v3.2-chat, gemini-3-flash-preview, gemini-3-pro-preview, gemini-3.1-pro-preview, gpt-4.1, gpt-5.2-high-reasoning, gpt-5.3-codex, gpt-5.4, haiku-4.5, kimi-2.5, kimi-2.5-openrouter, opus-4.5, opus-4.6, opus-4.7, qwen-next-80B-instruct, qwen-next-80B-thinking, sonnet-4.5, sonnet-4.6


Commands: /eval · /rerun · /list

CLI: gh workflow run eval-regression.yaml --repo HolmesGPT/holmesgpt --ref ROB-3465-k8s-mcp-addon -f markers=regression -f filter=

@github-actions

github-actions Bot commented May 4, 2026 •

Copy link
Copy Markdown
Contributor

✅ Docker images ready for bf6b1ccb (built in 6m 40s)

⚠️ Warning: does not support ARM (ARM images are built on release only - not on every PR)

Use these tags to pull the images for testing.

📋 Copy commands

⚠️ Temporary images are deleted after 30 days. Copy to a permanent registry before using them:

gcloud auth configure-docker us-central1-docker.pkg.dev
docker pull us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes:bf6b1ccb
docker tag us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes:bf6b1ccb me-west1-docker.pkg.dev/robusta-development/development/holmes-dev:bf6b1ccb
docker push me-west1-docker.pkg.dev/robusta-development/development/holmes-dev:bf6b1ccb
docker pull us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes-operator:bf6b1ccb
docker tag us-central1-docker.pkg.dev/robusta-development/temporary-builds/holmes-operator:bf6b1ccb me-west1-docker.pkg.dev/robusta-development/development/holmes-operator-dev:bf6b1ccb
docker push me-west1-docker.pkg.dev/robusta-development/development/holmes-operator-dev:bf6b1ccb

Patch Helm values in one line (choose the chart you use):

HolmesGPT chart:

helm upgrade --install holmesgpt ./helm/holmes \
  --set registry=me-west1-docker.pkg.dev/robusta-development/development \
  --set image=holmes-dev:bf6b1ccb \
  --set operator.registry=me-west1-docker.pkg.dev/robusta-development/development \
  --set operator.image=holmes-operator-dev:bf6b1ccb

Robusta wrapper chart:

helm upgrade --install robusta robusta/robusta \
  --reuse-values \
  --set holmes.registry=me-west1-docker.pkg.dev/robusta-development/development \
  --set holmes.image=holmes-dev:bf6b1ccb \
  --set holmes.operator.registry=me-west1-docker.pkg.dev/robusta-development/development \
  --set holmes.operator.image=holmes-operator-dev:bf6b1ccb

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@helm/holmes/templates/holmesgpt-rbac-service-account.yaml`:
- Around line 1-18: The template holmesgpt-rbac-service-account.yaml creates
only a ServiceAccount when .Values.k8sRBAC is true, but the corresponding
ClusterRole/ClusterRoleBinding from holmesgpt-service-account.yaml are skipped
when k8sRBAC=true, leaving the holmes service account without permissions; fix
by adding ClusterRole and ClusterRoleBinding resources that are rendered when
.Values.k8sRBAC is true (or by changing holmesgpt-service-account.yaml
conditionals so its ClusterRole/ClusterRoleBinding are also emitted for
k8sRBAC=true), ensure the ClusterRole rules match the existing operator rules
you intend to grant, and set the ClusterRoleBinding subject to the
ServiceAccount using include "holmes.serviceAccountName" and .Release.Namespace
so the holmes GPT SA gets the intended cluster permissions.

In `@helm/holmes/templates/mcp-servers/kubernetes/_helpers.tpl`:
- Around line 21-35: Add a new explicit guideline to the checklist in
helm/holmes/templates/mcp-servers/kubernetes/_helpers.tpl (the block ending with
"{{- end -}}") that mandates when any tool/command/API call fails the error must
include: the exact executed command or query, the namespace and
time-range/filters/parameters used, and the full underlying API error response;
update the checklist near items "Check events"/"Inspect pods"/"Examine
resources" so all diagnostic steps reference this requirement and ensure the
guidance text is clear and unambiguous.

In `@helm/holmes/templates/mcp-servers/kubernetes/deployment.yaml`:
- Around line 122-126: The secret volume mounts for the kubeconfig and
configSecret are not mapping secret keys to the expected filenames, so if a user
sets non-default secretKey values the mounted filenames will be wrong; update
the secret volume definitions referenced by
.Values.mcpAddons.kubernetes.config.kubeconfig.secretName and
.Values.mcpAddons.kubernetes.config.configSecret.secretName to include an items:
mapping that maps each secretKey (e.g.
.Values.mcpAddons.kubernetes.config.kubeconfig.secretKey and
.Values.mcpAddons.kubernetes.config.configSecret.secretKey) to the expected
filenames (kubeconfig and config.toml respectively) so the container sees
/etc/kubernetes/kubeconfig and the expected config file name; make the same
change for the second secret block mentioned around lines 154-165.

In `@helm/holmes/templates/mcp-servers/kubernetes/networkpolicy.yaml`:
- Around line 23-27: The ingress podSelector is too broad and will fail if you
only change the NetworkPolicy; update the Holmes pod template in
helm/holmes/templates/holmes.yaml to add the release-scoped label key
"app.kubernetes.io/instance": {{ .Release.Name }} (or equivalent Helm tpl) to
the pod metadata/labels, and then update
helm/holmes/templates/mcp-servers/kubernetes/networkpolicy.yaml to replace the
current from.podSelector.matchLabels: { app: holmes } with a selector that
matches the same release-scoped label (app.kubernetes.io/instance: {{
.Release.Name }}), ensuring both the Deployment/Pod template and the
NetworkPolicy use the identical label key/value so connectivity is preserved.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 500b916b-8f21-4627-86bf-e7a5b52c324d

📥 Commits

Reviewing files that changed from the base of the PR and between 408f7b0 and 060fd1d.

📒 Files selected for processing (7)
  • helm/holmes/templates/holmesgpt-rbac-service-account.yaml
  • helm/holmes/templates/holmesgpt-service-account.yaml
  • helm/holmes/templates/mcp-servers/kubernetes/_helpers.tpl
  • helm/holmes/templates/mcp-servers/kubernetes/deployment.yaml
  • helm/holmes/templates/mcp-servers/kubernetes/networkpolicy.yaml
  • helm/holmes/templates/toolset-config.yaml
  • helm/holmes/values.yaml

Comment thread helm/holmes/templates/holmesgpt-rbac-service-account.yaml
Comment thread helm/holmes/templates/mcp-servers/kubernetes/_helpers.tpl
Comment thread helm/holmes/templates/mcp-servers/kubernetes/deployment.yaml
Comment thread helm/holmes/templates/mcp-servers/kubernetes/networkpolicy.yaml

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (2)
helm/holmes/values.yaml (2)

689-690: 💤 Low value

Consider defaulting networkPolicy.enabled to true for the Kubernetes MCP addon.

This addon is granted view (and optionally cluster-admin) on the cluster API and exposes a service that can read/mutate cluster state. Other privileged-ish addons (aws, mariadb, github) default to true with a "recommended" comment. Defaulting to false here weakens the security posture out of the box. If there's a rendering reason it has to be off (e.g. egress to in-cluster API server is awkward to express), a comment explaining the rationale would help.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@helm/holmes/values.yaml` around lines 689 - 690, Default the Kubernetes MCP
addon's networkPolicy to enabled by setting networkPolicy.enabled: true (or, if
enabling breaks chart rendering, add an explanatory comment next to the
networkPolicy block describing the rendering/egress limitation and why it must
remain false). Update the values entry for networkPolicy (symbol:
networkPolicy.enabled) so it defaults to true like other privileged addons (aws,
mariadb, github), or include the rationale comment explaining why it remains
false.

779-788: 💤 Low value

Trailing blank lines and trailing whitespace at end of file.

Lines 779-788 add 9 blank lines plus trailing whitespace on line 788. Likely an editor artifact; trim to a single trailing newline.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@helm/holmes/values.yaml` around lines 779 - 788, Remove the extra blank lines
and trailing whitespace at the end of values.yaml (the EOF region shown in the
diff); trim all trailing spaces on the final line, collapse the multiple blank
lines to a single newline, and ensure the file ends with exactly one trailing
newline character.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@helm/holmes/values.yaml`:
- Around line 638-640: The values field kubeconfig.secretKey is declared but not
used in the deployment template; update the Kubernetes deployment template
(templates/mcp-servers/kubernetes/deployment.yaml) to read the key from
.Values.mcpAddons.kubernetes.config.kubeconfig.secretKey instead of the
hardcoded "kubeconfig" so the projected/secret volume uses the user-provided
secret key (ensure you preserve the existing default behavior when the value is
empty or unset), and if you prefer not to support a configurable key remove
kubeconfig.secretKey from values.yaml and any docs to avoid a misleading option.
- Around line 666-668: The values.yaml contains an unused field
configSecret.secretKey while the deployment template
(helm/holmes/templates/mcp-servers/kubernetes/deployment.yaml) mounts the whole
secret without an items selector; either remove configSecret.secretKey from
values.yaml and update docs to require the secret key be named config.toml, or
modify the deployment template to add an items block on the secret volume that
references .Values.mcpAddons.kubernetes.config.configSecret.secretKey so the
secret is mounted per-key; update any gating logic that checks $useConfigFile to
continue relying on configSecret.secretName only.

---

Nitpick comments:
In `@helm/holmes/values.yaml`:
- Around line 689-690: Default the Kubernetes MCP addon's networkPolicy to
enabled by setting networkPolicy.enabled: true (or, if enabling breaks chart
rendering, add an explanatory comment next to the networkPolicy block describing
the rendering/egress limitation and why it must remain false). Update the values
entry for networkPolicy (symbol: networkPolicy.enabled) so it defaults to true
like other privileged addons (aws, mariadb, github), or include the rationale
comment explaining why it remains false.
- Around line 779-788: Remove the extra blank lines and trailing whitespace at
the end of values.yaml (the EOF region shown in the diff); trim all trailing
spaces on the final line, collapse the multiple blank lines to a single newline,
and ensure the file ends with exactly one trailing newline character.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 05970eb5-7f52-4ea1-b11b-f5af0abefb13

📥 Commits

Reviewing files that changed from the base of the PR and between 060fd1d and 244f46a.

📒 Files selected for processing (1)
  • helm/holmes/values.yaml

Comment thread helm/holmes/values.yaml
Comment thread helm/holmes/values.yaml
RoiGlinik added 2 commits May 6, 2026 13:48
Signed-off-by: Roi Glinik <groi.tech@gmail.com>
@RoiGlinik
RoiGlinik enabled auto-merge (squash) May 6, 2026 10:53

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (3)
helm/holmes/templates/mcp-servers/kubernetes/deployment.yaml (3)

78-78: 💤 Low value

Confirm pod behavior when serviceAccount.create=false and a different SA is used.

The pod always sets serviceAccountName from mcpAddons.kubernetes.serviceAccount.name regardless of serviceAccount.create. That correctly supports "bring your own SA", but make sure the docs in values.yaml (around lines 612-621) explicitly state that disabling create requires the user to provision an SA whose name matches serviceAccount.name, otherwise the pod will land on a non-existent SA and silently fail RBAC checks at runtime.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@helm/holmes/templates/mcp-servers/kubernetes/deployment.yaml` at line 78,
Deployment always sets serviceAccountName from
mcpAddons.kubernetes.serviceAccount.name regardless of serviceAccount.create, so
update the values.yaml documentation near the serviceAccount block to explicitly
state that when serviceAccount.create=false the operator/user must provision a
ServiceAccount with the exact name specified in
mcpAddons.kubernetes.serviceAccount.name; mention that otherwise pods will
reference a non-existent SA and silently fail RBAC checks at runtime, and
optionally suggest adding a pre-install validation or helm note to remind users
to create the SA beforehand.

17-29: 💤 Low value

Empty ConfigMap is unused — clarify intent or remove.

The {{ .Release.Name }}-k8s-mcp-config ConfigMap is created with data: {} and never referenced anywhere in this template (no volumeMount, no envFrom). It just produces a stray resource on every install. Either drop it, or add a comment documenting the future intent (e.g., "reserved for user-supplied non-secret config") so reviewers and operators understand why it exists.

♻️ Proposed removal
-apiVersion: v1
-kind: ConfigMap
-metadata:
-  name: {{ .Release.Name }}-k8s-mcp-config
-  namespace: {{ .Release.Namespace }}
-  labels:
-    app: {{ .Release.Name }}-k8s-mcp
-    app.kubernetes.io/name: k8s-mcp-server
-    app.kubernetes.io/instance: {{ .Release.Name }}
-    app.kubernetes.io/component: mcp-server
-    app.kubernetes.io/part-of: holmes
-data: {}
-{{- if $serverConfig }}
----
+{{- if $serverConfig }}
+---
 apiVersion: v1
 kind: Secret
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@helm/holmes/templates/mcp-servers/kubernetes/deployment.yaml` around lines 17
- 29, The ConfigMap resource named {{ .Release.Name }}-k8s-mcp-config is created
with empty data and never referenced; either remove the entire ConfigMap block
or, if intended as a placeholder, add a clear comment above the resource (e.g.,
"reserved for user-supplied non-secret config") and include at least one
explicit use (volume/envFrom) or a README note; update the template by deleting
the ConfigMap stanza or adding the explanatory comment and a TODO reference so
reviewers/operators understand its purpose.

130-139: 💤 Low value

Use httpGet probe pointing to the /health endpoint instead of TCP.

The kubernetes-mcp-server exposes an HTTP health endpoint at GET /health, making it ideal for readiness and liveness probes. This will catch protocol-level failures and server hangs earlier than TCP probes, which only verify the socket is open. Replace the tcpSocket blocks with httpGet pointing to http://localhost:8000/health.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@helm/holmes/templates/mcp-servers/kubernetes/deployment.yaml` around lines
130 - 139, Replace the tcpSocket probes with HTTP GET probes: update the
readinessProbe and livenessProbe blocks for kubernetes-mcp-server to use httpGet
on port 8000 and path /health (e.g., readinessProbe.httpGet.path = "/health",
readinessProbe.httpGet.port = 8000 and same for livenessProbe) and keep or
adjust initialDelaySeconds and periodSeconds as appropriate; ensure the probes
target localhost (default host) so the server's HTTP /health endpoint is used
instead of plain TCP.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@helm/holmes/templates/mcp-servers/kubernetes/deployment.yaml`:
- Line 78: Deployment always sets serviceAccountName from
mcpAddons.kubernetes.serviceAccount.name regardless of serviceAccount.create, so
update the values.yaml documentation near the serviceAccount block to explicitly
state that when serviceAccount.create=false the operator/user must provision a
ServiceAccount with the exact name specified in
mcpAddons.kubernetes.serviceAccount.name; mention that otherwise pods will
reference a non-existent SA and silently fail RBAC checks at runtime, and
optionally suggest adding a pre-install validation or helm note to remind users
to create the SA beforehand.
- Around line 17-29: The ConfigMap resource named {{ .Release.Name
}}-k8s-mcp-config is created with empty data and never referenced; either remove
the entire ConfigMap block or, if intended as a placeholder, add a clear comment
above the resource (e.g., "reserved for user-supplied non-secret config") and
include at least one explicit use (volume/envFrom) or a README note; update the
template by deleting the ConfigMap stanza or adding the explanatory comment and
a TODO reference so reviewers/operators understand its purpose.
- Around line 130-139: Replace the tcpSocket probes with HTTP GET probes: update
the readinessProbe and livenessProbe blocks for kubernetes-mcp-server to use
httpGet on port 8000 and path /health (e.g., readinessProbe.httpGet.path =
"/health", readinessProbe.httpGet.port = 8000 and same for livenessProbe) and
keep or adjust initialDelaySeconds and periodSeconds as appropriate; ensure the
probes target localhost (default host) so the server's HTTP /health endpoint is
used instead of plain TCP.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: ab09378e-188a-40bc-bcea-5b31f94cc1e0

📥 Commits

Reviewing files that changed from the base of the PR and between 244f46a and cfd2ed3.

📒 Files selected for processing (2)
  • helm/holmes/templates/mcp-servers/kubernetes/deployment.yaml
  • helm/holmes/values.yaml

@RoiGlinik
RoiGlinik merged commit dba45e5 into master May 6, 2026
14 of 19 checks passed
@RoiGlinik
RoiGlinik deleted the ROB-3465-k8s-mcp-addon branch May 6, 2026 11:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants