feat: add tlsConfig (insecureSkipVerify, caCertPem) for HTTP/SSE MCP client connections in Bifrost Helm chart - #3783
Conversation
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (5)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
📝 WalkthroughWalkthroughAdds TLS configuration support for MCP HTTP/SSE clients: JSON and Helm values schemas, Helm template mapping from ChangesMCP TLS Configuration
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
tlsConfig (insecureSkipVerify, caCertPem) for HTTP/SSE MCP client connections in Bifrost Helm chart
This stack of pull requests is managed by Graphite. Learn more about stacking. |
Confidence Score: 5/5Safe to merge; the Go backend already handles tls_config fully and the Helm layer correctly guards against emitting empty or inappropriate TLS objects. All changed files are Helm chart wiring and schema documentation. The underlying Go implementation for MCPTLSConfig already exists and is well-tested. The template logic correctly uses hasKey for boolean handling and an empty-dict guard. The only findings are minor description inconsistencies (websocket omitted from schema descriptions) that do not affect runtime behavior. Both schema description strings in transports/config.schema.json and helm-charts/bifrost/values.schema.json omit websocket despite the template handling it. Important Files Changed
Reviews (6): Last reviewed commit: "chore: add support to config json and he..." | Re-trigger Greptile |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@helm-charts/bifrost/templates/_helpers.tpl`:
- Around line 956-966: The current mapping always sets tls_config when
$client.tlsConfig exists; update the block in _helpers.tpl to only build and set
the "tls_config" key ($cc "tls_config") when the client's connection type is one
of http, sse, or websocket (if you still accept that alias) by checking the
client's connection type (e.g. $client.connection.type or $client.type) before
creating $tls and calling set; keep the existing field mappings for
$client.tlsConfig.insecureSkipVerify and $client.tlsConfig.caCertPem but wrap
the whole mapping in a guard that tests the connection type against
"http","sse","websocket".
In `@helm-charts/bifrost/values.yaml`:
- Line 381: The YAML comment line containing "# # [Upcoming] TLS configuration
for HTTP and SSE connection types." is stale; remove the "[Upcoming]" marker so
the comment reads "# # TLS configuration for HTTP and SSE connection types."
to avoid misleading users—update the comment text in the same block (the TLS
example comment) accordingly.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: bbae8f94-b2fe-42fd-b182-57345630fead
📒 Files selected for processing (4)
helm-charts/bifrost/README.mdhelm-charts/bifrost/templates/_helpers.tplhelm-charts/bifrost/values.yamltransports/config.schema.json
5f5e06c to
6215cf7
Compare
6215cf7 to
47a526b
Compare
47a526b to
1bafb9f
Compare
6ae7faf to
71ea8a2
Compare
1bafb9f to
0e8975b
Compare
71ea8a2 to
cdea6c3
Compare
Merge activity
|
The base branch was changed.
0e8975b to
d919262
Compare
…P client connections in Bifrost Helm chart (#3783) ## Summary Adds TLS configuration support (`tlsConfig`) for HTTP and SSE MCP client connections in the Bifrost Helm chart, allowing operators to connect to MCP servers that use self-signed or private CA certificates, or to disable TLS verification in development/testing environments. ## Changes - Added `tls_config` object to the MCP client config JSON schema (`config.schema.json`) with `insecure_skip_verify` and `ca_cert_pem` fields. - Updated `_helpers.tpl` to map `tlsConfig.insecureSkipVerify` → `tls_config.insecure_skip_verify` and `tlsConfig.caCertPem` → `tls_config.ca_cert_pem` in the generated config JSON. - Added a commented example `tlsConfig` block in `values.yaml` for the `clientConfigs[]` array. - Documented the new fields in `README.md` under an "Upcoming" changelog entry and the values reference table. - `caCertPem` supports both a literal PEM string and an `env.VAR_NAME` reference for reading the certificate from an environment variable. - `insecureSkipVerify` takes priority over `caCertPem` when both are set; it is intended for development/testing only and is not recommended for production. ## Type of change - [ ] Bug fix - [x] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI ## Affected areas - [ ] Core (Go) - [ ] Transports (HTTP) - [ ] Providers/Integrations - [ ] Plugins - [ ] UI (React) - [x] Docs ## How to test Deploy the Helm chart with an MCP client config that uses a self-signed CA certificate: ```yaml bifrost: mcp: clientConfigs: - name: "example-https-mcp" connectionType: "http" connectionString: "https://my-internal-mcp.corp/mcp" tlsConfig: insecureSkipVerify: false caCertPem: "env.MY_MCP_CA_CERT" ``` Verify the generated ConfigMap contains the expected `tls_config` JSON: ```sh helm template . -f values.yaml | grep -A5 tls_config ``` Expected output should include: ```json "tls_config": { "insecure_skip_verify": false, "ca_cert_pem": "env.MY_MCP_CA_CERT" } ``` **New config fields:** | Field | Description | Default | |---|---|---| | `bifrost.mcp.clientConfigs[].tlsConfig.insecureSkipVerify` | Disable TLS certificate verification (dev/test only) | `false` | | `bifrost.mcp.clientConfigs[].tlsConfig.caCertPem` | PEM-encoded CA cert or `env.VAR_NAME` reference | `""` | ## Screenshots/Recordings N/A ## Breaking changes - [x] No ## Related issues N/A ## Security considerations - `insecureSkipVerify: true` disables TLS certificate verification entirely and should never be used in production environments. This is documented explicitly in the schema, README, and values comments. - `caCertPem` supports `env.VAR_NAME` references to avoid embedding sensitive certificate material directly in Helm values. ## Checklist - [ ] I read `docs/contributing/README.md` and followed the guidelines - [ ] I added/updated tests where appropriate - [x] I updated documentation where needed - [ ] I verified builds succeed (Go and UI) - [ ] I verified the CI pipeline passes locally if applicable
## Summary This PR releases **core v1.5.14**, **framework v1.3.14**, **transports v1.5.6**, and bumps all dependent plugins to their respective `.14` patch versions. It delivers a broad set of new capabilities across MCP authentication, key rotation, OTel metrics, Bedrock/Anthropic compatibility, and UI improvements, alongside a number of targeted bug fixes and refactors. ## Changes - **Direct API Key Header** — Providers can now receive an API key passed directly via a request header (#3817) - **MCP Per-User Auth** — Introduced `MCPCredentialStore` abstraction, per-user MCP credential reconciliation, and a new per-user header auth type with lazy-auth submission flow (#3656, #3702, #3703, #3704, #3705) - **MCP TLS Configuration** — Added configurable TLS (`insecureSkipVerify`, `caCertPem`) for HTTP/SSE MCP client connections (#3779, #3783) - **MCP Sessions Management** — Filter, search, and pagination on the MCP sessions list API and table, plus a `can_reauth` identity gate (#3823, #3824, #3825) - **Key Rotation** — Keys now rotate on 401/402/403 responses; returns `502 upstream_credentials_exhausted` when all keys are permanently exhausted. Added `triggered_rotation` to `KeyAttemptRecord` and tightened `bifrost_key_rotation_events_total` semantics (#3430, #3491) - **OTel Metrics** — Added OTel spec-compatible metrics (backward compatible) with provider cache and semantic cache attributes in metrics export (#3865, #3816) - **Opus 4.8 Support** — System message handling and general compatibility for Opus 4.8 (#3868, #3878) - **Dimension Rankings** — New `GetDimensionRankings` API and dashboard tabs for team, customer, BU, and user rankings (#3766) - **Model Pricing Attributes** — `additional_attributes` field on model pricing rows with management API and UI editor (#3829) - **Prompt Cache Retention** — Added prompt cache retention parameter on responses requests (#3810) - **Tool Call Execution UI** — Inline tool-call execution, stop streaming, bulk execute/submit, and a redesigned tool-call UI (#3837, #3843) - **Sheet Navigation** — Prev/next keyboard navigation and URL state across virtual key, MCP client, and routing rule sheets (#3739, #3740, #3744, #3745) - **Bedrock Tool Name Truncation** — Truncate Bedrock function/tool names to the provider length limit - **Bedrock Guardrails** — Set guardrail config in Bedrock requests built from responses (#3862) - **Anthropic Tool Use** — Default `tool_use` input to `{}` when arguments are absent (#3880) - **Responses Streaming** — Fixed responses stream events (#3838) - **Compat Flow** — Fixed missing parameter parsing on the compat flow (#3881) - **Passthrough API Version** — Set a default API version in passthrough requests as a fallback (#3853) - **Virtual Key Updates** — Avoid overriding optional fields during virtual key update (#3855) - **User-Mode Flows** — Gate user-mode flows on caller `user_id`, skip temp token mint, and unify flow/credential kind filtering for pending flows (#3841, #3859) - **Partial Tool Calls** — Handle partial tool call execution failures and return successful results (#3849) - **URL Query Escaping** — Support escaped characters in URL query parameters (#3826) - **MCP Auth Errors** — Inline banner and retry support for MCP auth-required errors (#3856) - **Renamed Resolvers** — `staticHeadersResolver`/`serverOAuthResolver` renamed to `sharedHeadersResolver`/`sharedOAuthResolver` (#3840) - **Starlark Nested Tool Calls** — Exposed `RunWithPluginPipeline` on `ClientManager` and routed Starlark nested tool calls through the canonical plugin gate (#3794) - **Deferred-Fill OAuth Removed** — Removed deferred-fill user-mode OAuth flow support (#3839) - **Go 1.26.3** — Upgraded toolchain to Go 1.26.3 (#3782) ## Type of change - [x] Bug fix - [x] Feature - [x] Refactor - [ ] Documentation - [x] Chore/CI ## Affected areas - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [x] UI (React) - [ ] Docs ## How to test ```sh # Core/Transports go version # should report go1.26.3 go test ./... # UI cd ui pnpm i || npm i pnpm test || npm test pnpm build || npm run build ``` - Validate MCP per-user auth by configuring a per-user header auth type and confirming credentials are stored and reconciled on virtual key and MCP client changes. - Validate key rotation by triggering a 401/402/403 from an upstream provider and confirming rotation occurs; exhaust all keys and confirm a `502 upstream_credentials_exhausted` is returned. - Validate OTel metrics output includes `provider_cache` and `semantic_cache` attributes. - Validate Bedrock requests with tool names exceeding the provider limit are truncated correctly. - Validate Opus 4.8 system message handling by sending a request with a system message to an Opus 4.8 endpoint. ## Breaking changes - [x] Yes - [ ] No The deferred-fill user-mode OAuth flow has been removed (#3839). Any integrations relying on that flow must migrate to the new per-user credential store approach. The `staticHeadersResolver` and `serverOAuthResolver` identifiers have been renamed to `sharedHeadersResolver` and `sharedOAuthResolver` respectively (#3840); any direct references must be updated. ## Related issues #3817, #3656, #3702, #3703, #3704, #3705, #3779, #3783, #3823, #3824, #3825, #3430, #3491, #3865, #3816, #3868, #3878, #3766, #3829, #3810, #3837, #3843, #3739, #3740, #3744, #3745, #3862, #3880, #3838, #3881, #3853, #3855, #3841, #3859, #3849, #3826, #3856, #3840, #3794, #3839, #3782, #3724, #3814, #3836, #3869, #3886 ## Security considerations - MCP per-user credentials are stored via the new `MCPCredentialStore` abstraction; ensure the backing store is appropriately access-controlled and that credential values are encrypted at rest. - The direct API key header feature passes provider secrets via HTTP headers; ensure TLS is enforced on all ingress paths and that headers are not logged in plaintext. - User-mode flows are now gated on `caller user_id` and temp token minting is skipped where appropriate, reducing the surface for privilege escalation. - TLS configuration for MCP HTTP/SSE connections supports `insecureSkipVerify`; this should only be enabled in controlled environments. ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable
## ✨ Features - **Direct API Key Header** - Pass a provider API key directly via request header (#3817) - **MCP Per-User Authentication** - New per-user header auth type with credential storage and lazy-auth submission flow (#3703, #3704, #3705) - **MCP TLS Configuration** - Configurable TLS (insecureSkipVerify, caCertPem) for HTTP/SSE MCP client connections (#3779, #3783) - **MCP Sessions Management** - Filter, search, and pagination on the MCP sessions list API and table, plus a can_reauth identity gate (#3823, #3824, #3825) - **Tool Call Execution UI** - Inline tool-call execution, stop streaming, bulk execute/submit, and a redesigned tool-call UI (#3837, #3843) - **Dimension Rankings Dashboard** - New dashboard tabs for team, customer, BU, and user rankings, backed by a GetDimensionRankings API (#3766) - **Model Pricing Attributes** - additional_attributes on model pricing rows with management API and UI editor (#3829) - **Prompt Cache Retention** - Prompt cache retention parameter on responses requests (#3810) - **Opus 4.8 Support** - System message handling and compatibility for Opus 4.8 (#3878, #3868) - **Key Rotation** - Rotate keys on 401/402/403 and return 502 upstream_credentials_exhausted when all keys are permanently dead (#3491) - **OTel Metrics** - OTel spec compatible metrics plus provider and semantic cache attributes in metrics export (#3865, #3816) - **Sheet Navigation** - Prev/next keyboard navigation and URL state across virtual key, MCP client, and routing rule sheets (#3739, #3740, #3744, #3745) - **Go 1.26.3** - Upgraded toolchain to Go 1.26.3 (#3782) ## 🐞 Fixed - **Bedrock Tool Names** - Truncate Bedrock function/tool names to the provider length limit - **Bedrock Guardrails** - Set guardrail config in Bedrock request built from responses (#3862) - **Anthropic Tool Use** - Default Anthropic tool_use input to {} when arguments are absent (#3880) - **Responses Streaming** - Fixed responses stream events (#3838) - **Compat Flow** - Fixed missing parameter parsing on the compat flow (#3881) - **Passthrough API Version** - Set a default API version in passthrough requests as a fallback (#3853) - **Virtual Key Updates** - Avoid overriding optional fields during virtual key update (#3855) - **User-Mode Flows** - Gate user-mode flows on caller user_id, skip temp token mint, and unify flow/credential kind filtering for pending flows (#3841, #3859) - **Partial Tool Calls** - Handle partial tool call execution failures and return successful results (#3849) - **URL Query Escaping** - Support escaped characters in URL query parameters (#3826) - **MCP Auth Errors** - Inline banner and retry support for MCP auth-required errors (#3856) - **JSON Editor Height** - Cap JSON editor max height at 400px in message views (#3842)
…P client connections in Bifrost Helm chart (maximhq#3783) ## Summary Adds TLS configuration support (`tlsConfig`) for HTTP and SSE MCP client connections in the Bifrost Helm chart, allowing operators to connect to MCP servers that use self-signed or private CA certificates, or to disable TLS verification in development/testing environments. ## Changes - Added `tls_config` object to the MCP client config JSON schema (`config.schema.json`) with `insecure_skip_verify` and `ca_cert_pem` fields. - Updated `_helpers.tpl` to map `tlsConfig.insecureSkipVerify` → `tls_config.insecure_skip_verify` and `tlsConfig.caCertPem` → `tls_config.ca_cert_pem` in the generated config JSON. - Added a commented example `tlsConfig` block in `values.yaml` for the `clientConfigs[]` array. - Documented the new fields in `README.md` under an "Upcoming" changelog entry and the values reference table. - `caCertPem` supports both a literal PEM string and an `env.VAR_NAME` reference for reading the certificate from an environment variable. - `insecureSkipVerify` takes priority over `caCertPem` when both are set; it is intended for development/testing only and is not recommended for production. ## Type of change - [ ] Bug fix - [x] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI ## Affected areas - [ ] Core (Go) - [ ] Transports (HTTP) - [ ] Providers/Integrations - [ ] Plugins - [ ] UI (React) - [x] Docs ## How to test Deploy the Helm chart with an MCP client config that uses a self-signed CA certificate: ```yaml bifrost: mcp: clientConfigs: - name: "example-https-mcp" connectionType: "http" connectionString: "https://my-internal-mcp.corp/mcp" tlsConfig: insecureSkipVerify: false caCertPem: "env.MY_MCP_CA_CERT" ``` Verify the generated ConfigMap contains the expected `tls_config` JSON: ```sh helm template . -f values.yaml | grep -A5 tls_config ``` Expected output should include: ```json "tls_config": { "insecure_skip_verify": false, "ca_cert_pem": "env.MY_MCP_CA_CERT" } ``` **New config fields:** | Field | Description | Default | |---|---|---| | `bifrost.mcp.clientConfigs[].tlsConfig.insecureSkipVerify` | Disable TLS certificate verification (dev/test only) | `false` | | `bifrost.mcp.clientConfigs[].tlsConfig.caCertPem` | PEM-encoded CA cert or `env.VAR_NAME` reference | `""` | ## Screenshots/Recordings N/A ## Breaking changes - [x] No ## Related issues N/A ## Security considerations - `insecureSkipVerify: true` disables TLS certificate verification entirely and should never be used in production environments. This is documented explicitly in the schema, README, and values comments. - `caCertPem` supports `env.VAR_NAME` references to avoid embedding sensitive certificate material directly in Helm values. ## Checklist - [ ] I read `docs/contributing/README.md` and followed the guidelines - [ ] I added/updated tests where appropriate - [x] I updated documentation where needed - [ ] I verified builds succeed (Go and UI) - [ ] I verified the CI pipeline passes locally if applicable
## Summary This PR releases **core v1.5.14**, **framework v1.3.14**, **transports v1.5.6**, and bumps all dependent plugins to their respective `.14` patch versions. It delivers a broad set of new capabilities across MCP authentication, key rotation, OTel metrics, Bedrock/Anthropic compatibility, and UI improvements, alongside a number of targeted bug fixes and refactors. ## Changes - **Direct API Key Header** — Providers can now receive an API key passed directly via a request header (maximhq#3817) - **MCP Per-User Auth** — Introduced `MCPCredentialStore` abstraction, per-user MCP credential reconciliation, and a new per-user header auth type with lazy-auth submission flow (maximhq#3656, maximhq#3702, maximhq#3703, maximhq#3704, maximhq#3705) - **MCP TLS Configuration** — Added configurable TLS (`insecureSkipVerify`, `caCertPem`) for HTTP/SSE MCP client connections (maximhq#3779, maximhq#3783) - **MCP Sessions Management** — Filter, search, and pagination on the MCP sessions list API and table, plus a `can_reauth` identity gate (maximhq#3823, maximhq#3824, maximhq#3825) - **Key Rotation** — Keys now rotate on 401/402/403 responses; returns `502 upstream_credentials_exhausted` when all keys are permanently exhausted. Added `triggered_rotation` to `KeyAttemptRecord` and tightened `bifrost_key_rotation_events_total` semantics (maximhq#3430, maximhq#3491) - **OTel Metrics** — Added OTel spec-compatible metrics (backward compatible) with provider cache and semantic cache attributes in metrics export (maximhq#3865, maximhq#3816) - **Opus 4.8 Support** — System message handling and general compatibility for Opus 4.8 (maximhq#3868, maximhq#3878) - **Dimension Rankings** — New `GetDimensionRankings` API and dashboard tabs for team, customer, BU, and user rankings (maximhq#3766) - **Model Pricing Attributes** — `additional_attributes` field on model pricing rows with management API and UI editor (maximhq#3829) - **Prompt Cache Retention** — Added prompt cache retention parameter on responses requests (maximhq#3810) - **Tool Call Execution UI** — Inline tool-call execution, stop streaming, bulk execute/submit, and a redesigned tool-call UI (maximhq#3837, maximhq#3843) - **Sheet Navigation** — Prev/next keyboard navigation and URL state across virtual key, MCP client, and routing rule sheets (maximhq#3739, maximhq#3740, maximhq#3744, maximhq#3745) - **Bedrock Tool Name Truncation** — Truncate Bedrock function/tool names to the provider length limit - **Bedrock Guardrails** — Set guardrail config in Bedrock requests built from responses (maximhq#3862) - **Anthropic Tool Use** — Default `tool_use` input to `{}` when arguments are absent (maximhq#3880) - **Responses Streaming** — Fixed responses stream events (maximhq#3838) - **Compat Flow** — Fixed missing parameter parsing on the compat flow (maximhq#3881) - **Passthrough API Version** — Set a default API version in passthrough requests as a fallback (maximhq#3853) - **Virtual Key Updates** — Avoid overriding optional fields during virtual key update (maximhq#3855) - **User-Mode Flows** — Gate user-mode flows on caller `user_id`, skip temp token mint, and unify flow/credential kind filtering for pending flows (maximhq#3841, maximhq#3859) - **Partial Tool Calls** — Handle partial tool call execution failures and return successful results (maximhq#3849) - **URL Query Escaping** — Support escaped characters in URL query parameters (maximhq#3826) - **MCP Auth Errors** — Inline banner and retry support for MCP auth-required errors (maximhq#3856) - **Renamed Resolvers** — `staticHeadersResolver`/`serverOAuthResolver` renamed to `sharedHeadersResolver`/`sharedOAuthResolver` (maximhq#3840) - **Starlark Nested Tool Calls** — Exposed `RunWithPluginPipeline` on `ClientManager` and routed Starlark nested tool calls through the canonical plugin gate (maximhq#3794) - **Deferred-Fill OAuth Removed** — Removed deferred-fill user-mode OAuth flow support (maximhq#3839) - **Go 1.26.3** — Upgraded toolchain to Go 1.26.3 (maximhq#3782) ## Type of change - [x] Bug fix - [x] Feature - [x] Refactor - [ ] Documentation - [x] Chore/CI ## Affected areas - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [x] UI (React) - [ ] Docs ## How to test ```sh # Core/Transports go version # should report go1.26.3 go test ./... # UI cd ui pnpm i || npm i pnpm test || npm test pnpm build || npm run build ``` - Validate MCP per-user auth by configuring a per-user header auth type and confirming credentials are stored and reconciled on virtual key and MCP client changes. - Validate key rotation by triggering a 401/402/403 from an upstream provider and confirming rotation occurs; exhaust all keys and confirm a `502 upstream_credentials_exhausted` is returned. - Validate OTel metrics output includes `provider_cache` and `semantic_cache` attributes. - Validate Bedrock requests with tool names exceeding the provider limit are truncated correctly. - Validate Opus 4.8 system message handling by sending a request with a system message to an Opus 4.8 endpoint. ## Breaking changes - [x] Yes - [ ] No The deferred-fill user-mode OAuth flow has been removed (maximhq#3839). Any integrations relying on that flow must migrate to the new per-user credential store approach. The `staticHeadersResolver` and `serverOAuthResolver` identifiers have been renamed to `sharedHeadersResolver` and `sharedOAuthResolver` respectively (maximhq#3840); any direct references must be updated. ## Related issues maximhq#3817, maximhq#3656, maximhq#3702, maximhq#3703, maximhq#3704, maximhq#3705, maximhq#3779, maximhq#3783, maximhq#3823, maximhq#3824, maximhq#3825, maximhq#3430, maximhq#3491, maximhq#3865, maximhq#3816, maximhq#3868, maximhq#3878, maximhq#3766, maximhq#3829, maximhq#3810, maximhq#3837, maximhq#3843, maximhq#3739, maximhq#3740, maximhq#3744, maximhq#3745, maximhq#3862, maximhq#3880, maximhq#3838, maximhq#3881, maximhq#3853, maximhq#3855, maximhq#3841, maximhq#3859, maximhq#3849, maximhq#3826, maximhq#3856, maximhq#3840, maximhq#3794, maximhq#3839, maximhq#3782, maximhq#3724, maximhq#3814, maximhq#3836, maximhq#3869, maximhq#3886 ## Security considerations - MCP per-user credentials are stored via the new `MCPCredentialStore` abstraction; ensure the backing store is appropriately access-controlled and that credential values are encrypted at rest. - The direct API key header feature passes provider secrets via HTTP headers; ensure TLS is enforced on all ingress paths and that headers are not logged in plaintext. - User-mode flows are now gated on `caller user_id` and temp token minting is skipped where appropriate, reducing the surface for privilege escalation. - TLS configuration for MCP HTTP/SSE connections supports `insecureSkipVerify`; this should only be enabled in controlled environments. ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable
## ✨ Features - **Direct API Key Header** - Pass a provider API key directly via request header (maximhq#3817) - **MCP Per-User Authentication** - New per-user header auth type with credential storage and lazy-auth submission flow (maximhq#3703, maximhq#3704, maximhq#3705) - **MCP TLS Configuration** - Configurable TLS (insecureSkipVerify, caCertPem) for HTTP/SSE MCP client connections (maximhq#3779, maximhq#3783) - **MCP Sessions Management** - Filter, search, and pagination on the MCP sessions list API and table, plus a can_reauth identity gate (maximhq#3823, maximhq#3824, maximhq#3825) - **Tool Call Execution UI** - Inline tool-call execution, stop streaming, bulk execute/submit, and a redesigned tool-call UI (maximhq#3837, maximhq#3843) - **Dimension Rankings Dashboard** - New dashboard tabs for team, customer, BU, and user rankings, backed by a GetDimensionRankings API (maximhq#3766) - **Model Pricing Attributes** - additional_attributes on model pricing rows with management API and UI editor (maximhq#3829) - **Prompt Cache Retention** - Prompt cache retention parameter on responses requests (maximhq#3810) - **Opus 4.8 Support** - System message handling and compatibility for Opus 4.8 (maximhq#3878, maximhq#3868) - **Key Rotation** - Rotate keys on 401/402/403 and return 502 upstream_credentials_exhausted when all keys are permanently dead (maximhq#3491) - **OTel Metrics** - OTel spec compatible metrics plus provider and semantic cache attributes in metrics export (maximhq#3865, maximhq#3816) - **Sheet Navigation** - Prev/next keyboard navigation and URL state across virtual key, MCP client, and routing rule sheets (maximhq#3739, maximhq#3740, maximhq#3744, maximhq#3745) - **Go 1.26.3** - Upgraded toolchain to Go 1.26.3 (maximhq#3782) ## 🐞 Fixed - **Bedrock Tool Names** - Truncate Bedrock function/tool names to the provider length limit - **Bedrock Guardrails** - Set guardrail config in Bedrock request built from responses (maximhq#3862) - **Anthropic Tool Use** - Default Anthropic tool_use input to {} when arguments are absent (maximhq#3880) - **Responses Streaming** - Fixed responses stream events (maximhq#3838) - **Compat Flow** - Fixed missing parameter parsing on the compat flow (maximhq#3881) - **Passthrough API Version** - Set a default API version in passthrough requests as a fallback (maximhq#3853) - **Virtual Key Updates** - Avoid overriding optional fields during virtual key update (maximhq#3855) - **User-Mode Flows** - Gate user-mode flows on caller user_id, skip temp token mint, and unify flow/credential kind filtering for pending flows (maximhq#3841, maximhq#3859) - **Partial Tool Calls** - Handle partial tool call execution failures and return successful results (maximhq#3849) - **URL Query Escaping** - Support escaped characters in URL query parameters (maximhq#3826) - **MCP Auth Errors** - Inline banner and retry support for MCP auth-required errors (maximhq#3856) - **JSON Editor Height** - Cap JSON editor max height at 400px in message views (maximhq#3842)
…P client connections in Bifrost Helm chart (maximhq#3783) ## Summary Adds TLS configuration support (`tlsConfig`) for HTTP and SSE MCP client connections in the Bifrost Helm chart, allowing operators to connect to MCP servers that use self-signed or private CA certificates, or to disable TLS verification in development/testing environments. ## Changes - Added `tls_config` object to the MCP client config JSON schema (`config.schema.json`) with `insecure_skip_verify` and `ca_cert_pem` fields. - Updated `_helpers.tpl` to map `tlsConfig.insecureSkipVerify` → `tls_config.insecure_skip_verify` and `tlsConfig.caCertPem` → `tls_config.ca_cert_pem` in the generated config JSON. - Added a commented example `tlsConfig` block in `values.yaml` for the `clientConfigs[]` array. - Documented the new fields in `README.md` under an "Upcoming" changelog entry and the values reference table. - `caCertPem` supports both a literal PEM string and an `env.VAR_NAME` reference for reading the certificate from an environment variable. - `insecureSkipVerify` takes priority over `caCertPem` when both are set; it is intended for development/testing only and is not recommended for production. ## Type of change - [ ] Bug fix - [x] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI ## Affected areas - [ ] Core (Go) - [ ] Transports (HTTP) - [ ] Providers/Integrations - [ ] Plugins - [ ] UI (React) - [x] Docs ## How to test Deploy the Helm chart with an MCP client config that uses a self-signed CA certificate: ```yaml bifrost: mcp: clientConfigs: - name: "example-https-mcp" connectionType: "http" connectionString: "https://my-internal-mcp.corp/mcp" tlsConfig: insecureSkipVerify: false caCertPem: "env.MY_MCP_CA_CERT" ``` Verify the generated ConfigMap contains the expected `tls_config` JSON: ```sh helm template . -f values.yaml | grep -A5 tls_config ``` Expected output should include: ```json "tls_config": { "insecure_skip_verify": false, "ca_cert_pem": "env.MY_MCP_CA_CERT" } ``` **New config fields:** | Field | Description | Default | |---|---|---| | `bifrost.mcp.clientConfigs[].tlsConfig.insecureSkipVerify` | Disable TLS certificate verification (dev/test only) | `false` | | `bifrost.mcp.clientConfigs[].tlsConfig.caCertPem` | PEM-encoded CA cert or `env.VAR_NAME` reference | `""` | ## Screenshots/Recordings N/A ## Breaking changes - [x] No ## Related issues N/A ## Security considerations - `insecureSkipVerify: true` disables TLS certificate verification entirely and should never be used in production environments. This is documented explicitly in the schema, README, and values comments. - `caCertPem` supports `env.VAR_NAME` references to avoid embedding sensitive certificate material directly in Helm values. ## Checklist - [ ] I read `docs/contributing/README.md` and followed the guidelines - [ ] I added/updated tests where appropriate - [x] I updated documentation where needed - [ ] I verified builds succeed (Go and UI) - [ ] I verified the CI pipeline passes locally if applicable
## Summary This PR releases **core v1.5.14**, **framework v1.3.14**, **transports v1.5.6**, and bumps all dependent plugins to their respective `.14` patch versions. It delivers a broad set of new capabilities across MCP authentication, key rotation, OTel metrics, Bedrock/Anthropic compatibility, and UI improvements, alongside a number of targeted bug fixes and refactors. ## Changes - **Direct API Key Header** — Providers can now receive an API key passed directly via a request header (maximhq#3817) - **MCP Per-User Auth** — Introduced `MCPCredentialStore` abstraction, per-user MCP credential reconciliation, and a new per-user header auth type with lazy-auth submission flow (maximhq#3656, maximhq#3702, maximhq#3703, maximhq#3704, maximhq#3705) - **MCP TLS Configuration** — Added configurable TLS (`insecureSkipVerify`, `caCertPem`) for HTTP/SSE MCP client connections (maximhq#3779, maximhq#3783) - **MCP Sessions Management** — Filter, search, and pagination on the MCP sessions list API and table, plus a `can_reauth` identity gate (maximhq#3823, maximhq#3824, maximhq#3825) - **Key Rotation** — Keys now rotate on 401/402/403 responses; returns `502 upstream_credentials_exhausted` when all keys are permanently exhausted. Added `triggered_rotation` to `KeyAttemptRecord` and tightened `bifrost_key_rotation_events_total` semantics (maximhq#3430, maximhq#3491) - **OTel Metrics** — Added OTel spec-compatible metrics (backward compatible) with provider cache and semantic cache attributes in metrics export (maximhq#3865, maximhq#3816) - **Opus 4.8 Support** — System message handling and general compatibility for Opus 4.8 (maximhq#3868, maximhq#3878) - **Dimension Rankings** — New `GetDimensionRankings` API and dashboard tabs for team, customer, BU, and user rankings (maximhq#3766) - **Model Pricing Attributes** — `additional_attributes` field on model pricing rows with management API and UI editor (maximhq#3829) - **Prompt Cache Retention** — Added prompt cache retention parameter on responses requests (maximhq#3810) - **Tool Call Execution UI** — Inline tool-call execution, stop streaming, bulk execute/submit, and a redesigned tool-call UI (maximhq#3837, maximhq#3843) - **Sheet Navigation** — Prev/next keyboard navigation and URL state across virtual key, MCP client, and routing rule sheets (maximhq#3739, maximhq#3740, maximhq#3744, maximhq#3745) - **Bedrock Tool Name Truncation** — Truncate Bedrock function/tool names to the provider length limit - **Bedrock Guardrails** — Set guardrail config in Bedrock requests built from responses (maximhq#3862) - **Anthropic Tool Use** — Default `tool_use` input to `{}` when arguments are absent (maximhq#3880) - **Responses Streaming** — Fixed responses stream events (maximhq#3838) - **Compat Flow** — Fixed missing parameter parsing on the compat flow (maximhq#3881) - **Passthrough API Version** — Set a default API version in passthrough requests as a fallback (maximhq#3853) - **Virtual Key Updates** — Avoid overriding optional fields during virtual key update (maximhq#3855) - **User-Mode Flows** — Gate user-mode flows on caller `user_id`, skip temp token mint, and unify flow/credential kind filtering for pending flows (maximhq#3841, maximhq#3859) - **Partial Tool Calls** — Handle partial tool call execution failures and return successful results (maximhq#3849) - **URL Query Escaping** — Support escaped characters in URL query parameters (maximhq#3826) - **MCP Auth Errors** — Inline banner and retry support for MCP auth-required errors (maximhq#3856) - **Renamed Resolvers** — `staticHeadersResolver`/`serverOAuthResolver` renamed to `sharedHeadersResolver`/`sharedOAuthResolver` (maximhq#3840) - **Starlark Nested Tool Calls** — Exposed `RunWithPluginPipeline` on `ClientManager` and routed Starlark nested tool calls through the canonical plugin gate (maximhq#3794) - **Deferred-Fill OAuth Removed** — Removed deferred-fill user-mode OAuth flow support (maximhq#3839) - **Go 1.26.3** — Upgraded toolchain to Go 1.26.3 (maximhq#3782) ## Type of change - [x] Bug fix - [x] Feature - [x] Refactor - [ ] Documentation - [x] Chore/CI ## Affected areas - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [x] UI (React) - [ ] Docs ## How to test ```sh # Core/Transports go version # should report go1.26.3 go test ./... # UI cd ui pnpm i || npm i pnpm test || npm test pnpm build || npm run build ``` - Validate MCP per-user auth by configuring a per-user header auth type and confirming credentials are stored and reconciled on virtual key and MCP client changes. - Validate key rotation by triggering a 401/402/403 from an upstream provider and confirming rotation occurs; exhaust all keys and confirm a `502 upstream_credentials_exhausted` is returned. - Validate OTel metrics output includes `provider_cache` and `semantic_cache` attributes. - Validate Bedrock requests with tool names exceeding the provider limit are truncated correctly. - Validate Opus 4.8 system message handling by sending a request with a system message to an Opus 4.8 endpoint. ## Breaking changes - [x] Yes - [ ] No The deferred-fill user-mode OAuth flow has been removed (maximhq#3839). Any integrations relying on that flow must migrate to the new per-user credential store approach. The `staticHeadersResolver` and `serverOAuthResolver` identifiers have been renamed to `sharedHeadersResolver` and `sharedOAuthResolver` respectively (maximhq#3840); any direct references must be updated. ## Related issues maximhq#3817, maximhq#3656, maximhq#3702, maximhq#3703, maximhq#3704, maximhq#3705, maximhq#3779, maximhq#3783, maximhq#3823, maximhq#3824, maximhq#3825, maximhq#3430, maximhq#3491, maximhq#3865, maximhq#3816, maximhq#3868, maximhq#3878, maximhq#3766, maximhq#3829, maximhq#3810, maximhq#3837, maximhq#3843, maximhq#3739, maximhq#3740, maximhq#3744, maximhq#3745, maximhq#3862, maximhq#3880, maximhq#3838, maximhq#3881, maximhq#3853, maximhq#3855, maximhq#3841, maximhq#3859, maximhq#3849, maximhq#3826, maximhq#3856, maximhq#3840, maximhq#3794, maximhq#3839, maximhq#3782, maximhq#3724, maximhq#3814, maximhq#3836, maximhq#3869, maximhq#3886 ## Security considerations - MCP per-user credentials are stored via the new `MCPCredentialStore` abstraction; ensure the backing store is appropriately access-controlled and that credential values are encrypted at rest. - The direct API key header feature passes provider secrets via HTTP headers; ensure TLS is enforced on all ingress paths and that headers are not logged in plaintext. - User-mode flows are now gated on `caller user_id` and temp token minting is skipped where appropriate, reducing the surface for privilege escalation. - TLS configuration for MCP HTTP/SSE connections supports `insecureSkipVerify`; this should only be enabled in controlled environments. ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable
## ✨ Features - **Direct API Key Header** - Pass a provider API key directly via request header (maximhq#3817) - **MCP Per-User Authentication** - New per-user header auth type with credential storage and lazy-auth submission flow (maximhq#3703, maximhq#3704, maximhq#3705) - **MCP TLS Configuration** - Configurable TLS (insecureSkipVerify, caCertPem) for HTTP/SSE MCP client connections (maximhq#3779, maximhq#3783) - **MCP Sessions Management** - Filter, search, and pagination on the MCP sessions list API and table, plus a can_reauth identity gate (maximhq#3823, maximhq#3824, maximhq#3825) - **Tool Call Execution UI** - Inline tool-call execution, stop streaming, bulk execute/submit, and a redesigned tool-call UI (maximhq#3837, maximhq#3843) - **Dimension Rankings Dashboard** - New dashboard tabs for team, customer, BU, and user rankings, backed by a GetDimensionRankings API (maximhq#3766) - **Model Pricing Attributes** - additional_attributes on model pricing rows with management API and UI editor (maximhq#3829) - **Prompt Cache Retention** - Prompt cache retention parameter on responses requests (maximhq#3810) - **Opus 4.8 Support** - System message handling and compatibility for Opus 4.8 (maximhq#3878, maximhq#3868) - **Key Rotation** - Rotate keys on 401/402/403 and return 502 upstream_credentials_exhausted when all keys are permanently dead (maximhq#3491) - **OTel Metrics** - OTel spec compatible metrics plus provider and semantic cache attributes in metrics export (maximhq#3865, maximhq#3816) - **Sheet Navigation** - Prev/next keyboard navigation and URL state across virtual key, MCP client, and routing rule sheets (maximhq#3739, maximhq#3740, maximhq#3744, maximhq#3745) - **Go 1.26.3** - Upgraded toolchain to Go 1.26.3 (maximhq#3782) ## 🐞 Fixed - **Bedrock Tool Names** - Truncate Bedrock function/tool names to the provider length limit - **Bedrock Guardrails** - Set guardrail config in Bedrock request built from responses (maximhq#3862) - **Anthropic Tool Use** - Default Anthropic tool_use input to {} when arguments are absent (maximhq#3880) - **Responses Streaming** - Fixed responses stream events (maximhq#3838) - **Compat Flow** - Fixed missing parameter parsing on the compat flow (maximhq#3881) - **Passthrough API Version** - Set a default API version in passthrough requests as a fallback (maximhq#3853) - **Virtual Key Updates** - Avoid overriding optional fields during virtual key update (maximhq#3855) - **User-Mode Flows** - Gate user-mode flows on caller user_id, skip temp token mint, and unify flow/credential kind filtering for pending flows (maximhq#3841, maximhq#3859) - **Partial Tool Calls** - Handle partial tool call execution failures and return successful results (maximhq#3849) - **URL Query Escaping** - Support escaped characters in URL query parameters (maximhq#3826) - **MCP Auth Errors** - Inline banner and retry support for MCP auth-required errors (maximhq#3856) - **JSON Editor Height** - Cap JSON editor max height at 400px in message views (maximhq#3842)

Summary
Adds TLS configuration support (
tlsConfig) for HTTP and SSE MCP client connections in the Bifrost Helm chart, allowing operators to connect to MCP servers that use self-signed or private CA certificates, or to disable TLS verification in development/testing environments.Changes
tls_configobject to the MCP client config JSON schema (config.schema.json) withinsecure_skip_verifyandca_cert_pemfields._helpers.tplto maptlsConfig.insecureSkipVerify→tls_config.insecure_skip_verifyandtlsConfig.caCertPem→tls_config.ca_cert_pemin the generated config JSON.tlsConfigblock invalues.yamlfor theclientConfigs[]array.README.mdunder an "Upcoming" changelog entry and the values reference table.caCertPemsupports both a literal PEM string and anenv.VAR_NAMEreference for reading the certificate from an environment variable.insecureSkipVerifytakes priority overcaCertPemwhen both are set; it is intended for development/testing only and is not recommended for production.Type of change
Affected areas
How to test
Deploy the Helm chart with an MCP client config that uses a self-signed CA certificate:
Verify the generated ConfigMap contains the expected
tls_configJSON:Expected output should include:
New config fields:
bifrost.mcp.clientConfigs[].tlsConfig.insecureSkipVerifyfalsebifrost.mcp.clientConfigs[].tlsConfig.caCertPemenv.VAR_NAMEreference""Screenshots/Recordings
N/A
Breaking changes
Related issues
N/A
Security considerations
insecureSkipVerify: truedisables TLS certificate verification entirely and should never be used in production environments. This is documented explicitly in the schema, README, and values comments.caCertPemsupportsenv.VAR_NAMEreferences to avoid embedding sensitive certificate material directly in Helm values.Checklist
docs/contributing/README.mdand followed the guidelines