io.github.nogoo9/no-crd MCP Server
io.github.nogoo9/no-crd
What is the io.github.nogoo9/no-crd MCP server?
Dynamic pod spawner & proxy for ephemeral AI agent workspaces on Kubernetes without CRDs
How to install io.github.nogoo9/no-crd
Copy-paste configuration for popular MCP clients.
KUBECONFIGPath to the Kubernetes API credentials configuration file
BASE_URLHosting URL subpath prefix for gateways and reverse proxies
STATELESSDisable in-memory session tracking for stateless execution
TLS_CERTLocal file path containing TLS public certificate (HTTPS)
TLS_KEYsecretLocal file path containing TLS private key (HTTPS)
TLS_CALocal file path containing trusted client Certificate Authority
NODE_TLS_REJECT_UNAUTHORIZEDSet to '0' to allow connection to unverified TLS endpoints
REGISTRY_URLDefault container registry for workspace image resolution
TEMPLATES_DIRLocal filesystem directory containing custom YAML/JSON templates
BUILTIN_TEMPLATESEnable loading of standard pre-configured templates (default: true)
AUTH_ENABLEDEnforce JWT verification and user tenant isolation (default: false)
JWT_VERIFICATION_REQUIREDSet to 'false' to skip OIDC cryptographic signature checks
JWT_SECRETsecretHMAC-SHA symmetric secret key to sign/verify JWT tokens
JWT_PUBLIC_KEYsecretPEM public key to verify asymmetric OIDC signatures
JWKS_URIDiscovery URI to fetch keys from OIDC provider dynamically
INTROSPECTION_ENDPOINTRFC 7662 compliant token introspection validation endpoint
OAUTH_CLIENT_IDClient identifier for OAuth2 authentication flows
OAUTH_CLIENT_SECRETsecretClient secret credentials used for token introspection
JWT_AUDIENCETarget audience check value for incoming OIDC tokens
AUTH_ISSUERExpected token issuer authority check value (e.g. Keycloak)
AUTH_SUB_JSONPATHJSONPath pattern to extract user identity subject from token
AUTH_ADMIN_ROLEBypass role name that grants admin access (default: nogoo9-admin)
AUTH_ADMIN_USERSComma-separated list of user subject IDs (sub) granted admin privileges without OIDC scope/role claims
PROXY_SESSION_TTLActive lifetime in seconds for signed proxy session cookies
PROXY_SESSION_SECRETsecretSecret key for session cookie signing
UI_ENABLEDServe the built-in HTML dashboard (default: true)
THEMES_DIRFilesystem directory to scan for custom CSS themes
THEMES_CONFIGMAPConfigMap name storing dynamic CSS theme overrides
DOCS_DIRDirectory containing static documentation web files to serve
OAUTH_DISCOVERY_URLStandard OIDC .well-known configuration discovery endpoint
OAUTH_LOGIN_METHODUI SSO flow login method: 'redirect' or silent 'iframe'
UI_TITLECustom dashboard header title for white-label branding
UI_SUBTITLECustom dashboard subtitle text below the header title
Related MCP servers

io.github.nogoo9/mcp-server-cloud-fs
Cloud replacement for mcp-server-filesystem — 20 tools for S3, Azure Blob, and GCS

Nogra
Verify-before-done trust layer for AI-assisted work. 32 tools, local-first, no credentials.

Voice interface for Claude Code: talk to your agent and it talks back while it works.
Read-only MCP for identity resolution and write guardrails.

Colors-LE
Extract colors from stylesheets and code, with their notation and position.

Dates-LE
Extract dates and timestamps from logs, data files and code, with their format and position.