chore(toolhive): pin the MCP server images to digests - #4215
Conversation
Every other container image in the repo carries a digest; the MCP servers were the gap. Renovate already tracks these as the toolhive-mcp group and rewrites tag and digest together, so the digest only has to be written once.
Pinned to the digest the pods are already running, so this commit changes nothing at runtime. It makes the drift visible instead: the registry's master tag has since moved to 6d37df97, which Renovate will now raise as a reviewable digest PR rather than applying on the next unrelated restart.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (8)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
📝 WalkthroughWalkthroughThe Kubernetes Toolhive MCPServer manifests now use SHA256-pinned container image references for both primary and optional server instances across eight configurations. ChangesToolhive image digest pinning
Estimated code review effort: 1 (Trivial) | ~5 minutes Possibly related PRs
Suggested labels: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/postgres-mcp
! ± value change
- crystaldba/postgres-mcp:0.3.0
+ crystaldba/postgres-mcp:0.3.0@sha256:dbbd346860d29f1543e991f30f3284bf4ab5f096d049ecc3426528f20b1b6e6b
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/postgres-mcp-opt
! ± value change
- crystaldba/postgres-mcp:0.3.0
+ crystaldba/postgres-mcp:0.3.0@sha256:dbbd346860d29f1543e991f30f3284bf4ab5f096d049ecc3426528f20b1b6e6b
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/karakeep
! ± value change
- ghcr.io/karakeep-app/karakeep-mcp:0.32.0
+ ghcr.io/karakeep-app/karakeep-mcp:0.32.0@sha256:8b2f784ad0ffc5dbc75485f125e23fdd033d4c9d05d680e8f090b6b6aa93c2f6
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/karakeep-opt
! ± value change
- ghcr.io/karakeep-app/karakeep-mcp:0.32.0
+ ghcr.io/karakeep-app/karakeep-mcp:0.32.0@sha256:8b2f784ad0ffc5dbc75485f125e23fdd033d4c9d05d680e8f090b6b6aa93c2f6
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/searxng
! ± value change
- ghcr.io/rcdailey/mcp-searxng:0.8.0
+ ghcr.io/rcdailey/mcp-searxng:0.8.0@sha256:5f4359be5f43b3bb77daabc60884dcd8c1d05a3c0b761ad78730da8453a660a2
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/searxng-opt
! ± value change
- ghcr.io/rcdailey/mcp-searxng:0.8.0
+ ghcr.io/rcdailey/mcp-searxng:0.8.0@sha256:5f4359be5f43b3bb77daabc60884dcd8c1d05a3c0b761ad78730da8453a660a2
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/flux-operator
! ± value change
- ghcr.io/controlplaneio-fluxcd/flux-operator-mcp:v0.57.0
+ ghcr.io/controlplaneio-fluxcd/flux-operator-mcp:v0.57.0@sha256:a53ae414ec4f7671697707c69a61f0209842dfc108ad2fb13461b118d7475e3d
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/flux-operator-opt
! ± value change
- ghcr.io/controlplaneio-fluxcd/flux-operator-mcp:v0.57.0
+ ghcr.io/controlplaneio-fluxcd/flux-operator-mcp:v0.57.0@sha256:a53ae414ec4f7671697707c69a61f0209842dfc108ad2fb13461b118d7475e3d
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/talos-mcp
! ± value change
- registry.erwanleboucher.dev/eleboucher/talos-mcp:0.0.2
+ registry.erwanleboucher.dev/eleboucher/talos-mcp:0.0.2@sha256:ad1b388e20cbe171763ba0ff85ed32856f2573c9c40f5081a83c96b3b57f0d35
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/talos-mcp-opt
! ± value change
- registry.erwanleboucher.dev/eleboucher/talos-mcp:0.0.2
+ registry.erwanleboucher.dev/eleboucher/talos-mcp:0.0.2@sha256:ad1b388e20cbe171763ba0ff85ed32856f2573c9c40f5081a83c96b3b57f0d35
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/grafana
! ± value change
- grafana/mcp-grafana:0.17.2
+ grafana/mcp-grafana:0.17.2@sha256:d5b51db0c8eaafc6ed3fede5bfcc8d67b2384a40cf3d493086e378855ceba882
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/grafana-opt
! ± value change
- grafana/mcp-grafana:0.17.2
+ grafana/mcp-grafana:0.17.2@sha256:d5b51db0c8eaafc6ed3fede5bfcc8d67b2384a40cf3d493086e378855ceba882
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/github
! ± value change
- ghcr.io/github/github-mcp-server:v1.7.0
+ ghcr.io/github/github-mcp-server:v1.7.0@sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/github-opt
! ± value change
- ghcr.io/github/github-mcp-server:v1.7.0
+ ghcr.io/github/github-mcp-server:v1.7.0@sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/kubesearch
! ± value change
- ghcr.io/perfectra1n/kubesearch-mcp:master
+ ghcr.io/perfectra1n/kubesearch-mcp:master@sha256:7a8b6910dfb6ccbff807932d8054f11d645e66fcdcb707aab88102aab6f1729f
@@ spec.image @@
# toolhive.stacklok.dev/v1beta1/MCPServer/ai/kubesearch-opt
! ± value change
- ghcr.io/perfectra1n/kubesearch-mcp:master
+ ghcr.io/perfectra1n/kubesearch-mcp:master@sha256:7a8b6910dfb6ccbff807932d8054f11d645e66fcdcb707aab88102aab6f1729f
|
AI Automated ReviewAnalysis engine: qwen-3.6-fast@http://litellm.ai.svc.cluster.local/v1 (openai) RecommendationApprove. This PR adds SHA256 digests to the remaining 8 unpinned MCP server images in the ToolHive config directory, bringing the repo's image pinning from 59/67 to 67/67. The change is purely additive (appending Change-by-change findingsAll 8 files follow an identical pattern: appending the correct SHA256 digest to each
Standards Compliance
Unknowns / Needs Verification
Tool Harness FindingsTool harness planning was pending; no findings to report. This is a clean, well-documented operational improvement that strengthens supply-chain integrity without changing runtime behavior. The author's verification methodology (cross-referencing against live pods) is thorough and appropriate. |
The MCP servers were the only container-image gap in the repo: 59 of 67 image tag references already carry a digest, and these 8 were the remainder. Flux
OCIRepositorychart tags stay unpinned, which is the existing convention (0 of ~48 pinned) and is untouched here.Renovate maintains a digest once one exists but never adds one, so it has to be written by hand once. Proof it maintains them, from
d4ec78f73:.renovaterc.json5already groups these astoolhive-mcp, so no config change is needed.Every digest was verified against the live pod
imageIDin namespaceai, so this is a zero-rollout change:a53ae414c491ffdfd5b51db08b2f784a7a8b6910dbbd34685f4359bead1b388ekubesearch is a separate commit. It tracks a rolling
mastertag and had already drifted: pods run7a8b6910while the registry'smasternow resolves to6d37df97. It is pinned to the digest already running, so nothing changes now; the pending drift becomes a reviewable Renovate digest PR instead of arriving on the next unrelated restart. Drop that commit if the rolling tag is preferred, the other seven are independent.kustomize buildrenders all 18 refs digest-pinned, 0 unpinned.Not included, both worth a separate PR: a
pinDigests: truerule scoped tokubernetes/apps/ai/toolhive/config/**so future MCP images arrive pinned, and a digest-automerge rule for these eight (today only/home-operations/images automerge digests). Also noted:kubesearch-mcppublishes semver tags (1.0.1), so it does not have to stay on a rolling tag.Summary by CodeRabbit