PluginBench
MCP Server
Active
Apache-2.0

io.github.nogoo9/no-crd MCP Server

io.github.nogoo9/no-crd

What is the io.github.nogoo9/no-crd MCP server?

Dynamic pod spawner & proxy for ephemeral AI agent workspaces on Kubernetes without CRDs

How to install io.github.nogoo9/no-crd

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • KUBECONFIG

    Path to the Kubernetes API credentials configuration file

  • BASE_URL

    Hosting URL subpath prefix for gateways and reverse proxies

  • STATELESS

    Disable in-memory session tracking for stateless execution

  • TLS_CERT

    Local file path containing TLS public certificate (HTTPS)

  • TLS_KEY
    secret

    Local file path containing TLS private key (HTTPS)

  • TLS_CA

    Local file path containing trusted client Certificate Authority

  • NODE_TLS_REJECT_UNAUTHORIZED

    Set to '0' to allow connection to unverified TLS endpoints

  • REGISTRY_URL

    Default container registry for workspace image resolution

  • TEMPLATES_DIR

    Local filesystem directory containing custom YAML/JSON templates

  • BUILTIN_TEMPLATES

    Enable loading of standard pre-configured templates (default: true)

  • AUTH_ENABLED

    Enforce JWT verification and user tenant isolation (default: false)

  • JWT_VERIFICATION_REQUIRED

    Set to 'false' to skip OIDC cryptographic signature checks

  • JWT_SECRET
    secret

    HMAC-SHA symmetric secret key to sign/verify JWT tokens

  • JWT_PUBLIC_KEY
    secret

    PEM public key to verify asymmetric OIDC signatures

  • JWKS_URI

    Discovery URI to fetch keys from OIDC provider dynamically

  • INTROSPECTION_ENDPOINT

    RFC 7662 compliant token introspection validation endpoint

  • OAUTH_CLIENT_ID

    Client identifier for OAuth2 authentication flows

  • OAUTH_CLIENT_SECRET
    secret

    Client secret credentials used for token introspection

  • JWT_AUDIENCE

    Target audience check value for incoming OIDC tokens

  • AUTH_ISSUER

    Expected token issuer authority check value (e.g. Keycloak)

  • AUTH_SUB_JSONPATH

    JSONPath pattern to extract user identity subject from token

  • AUTH_ADMIN_ROLE

    Bypass role name that grants admin access (default: nogoo9-admin)

  • AUTH_ADMIN_USERS

    Comma-separated list of user subject IDs (sub) granted admin privileges without OIDC scope/role claims

  • PROXY_SESSION_TTL

    Active lifetime in seconds for signed proxy session cookies

  • PROXY_SESSION_SECRET
    secret

    Secret key for session cookie signing

  • UI_ENABLED

    Serve the built-in HTML dashboard (default: true)

  • THEMES_DIR

    Filesystem directory to scan for custom CSS themes

  • THEMES_CONFIGMAP

    ConfigMap name storing dynamic CSS theme overrides

  • DOCS_DIR

    Directory containing static documentation web files to serve

  • OAUTH_DISCOVERY_URL

    Standard OIDC .well-known configuration discovery endpoint

  • OAUTH_LOGIN_METHOD

    UI SSO flow login method: 'redirect' or silent 'iframe'

  • UI_TITLE

    Custom dashboard header title for white-label branding

  • UI_SUBTITLE

    Custom dashboard subtitle text below the header title

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "no-crd": {
      "command": "bunx",
      "args": [
        "-y",
        "@nogoo9/no-crd",
        "--transport",
        "--mode",
        "--namespace",
        "--port",
        "--host",
        "--log-level",
        "--disable-permission-checks",
        "--cors-origin",
        "--cors-methods",
        "--cors-headers",
        "--cors-allow-credentials",
        "--auth-required-read-scope",
        "--auth-required-write-scope",
        "--auth-scope-jsonpath",
        "--auth-required-read-role",
        "--auth-required-write-role",
        "--auth-roles-jsonpath"
      ],
      "env": {
        "KUBECONFIG": "<YOUR_KUBECONFIG>",
        "BASE_URL": "<YOUR_BASE_URL>",
        "STATELESS": "<YOUR_STATELESS>",
        "TLS_CERT": "<YOUR_TLS_CERT>",
        "TLS_KEY": "<YOUR_TLS_KEY>",
        "TLS_CA": "<YOUR_TLS_CA>",
        "NODE_TLS_REJECT_UNAUTHORIZED": "<YOUR_NODE_TLS_REJECT_UNAUTHORIZED>",
        "REGISTRY_URL": "<YOUR_REGISTRY_URL>",
        "TEMPLATES_DIR": "<YOUR_TEMPLATES_DIR>",
        "BUILTIN_TEMPLATES": "<YOUR_BUILTIN_TEMPLATES>",
        "AUTH_ENABLED": "<YOUR_AUTH_ENABLED>",
        "JWT_VERIFICATION_REQUIRED": "<YOUR_JWT_VERIFICATION_REQUIRED>",
        "JWT_SECRET": "<YOUR_JWT_SECRET>",
        "JWT_PUBLIC_KEY": "<YOUR_JWT_PUBLIC_KEY>",
        "JWKS_URI": "<YOUR_JWKS_URI>",
        "INTROSPECTION_ENDPOINT": "<YOUR_INTROSPECTION_ENDPOINT>",
        "OAUTH_CLIENT_ID": "<YOUR_OAUTH_CLIENT_ID>",
        "OAUTH_CLIENT_SECRET": "<YOUR_OAUTH_CLIENT_SECRET>",
        "JWT_AUDIENCE": "<YOUR_JWT_AUDIENCE>",
        "AUTH_ISSUER": "<YOUR_AUTH_ISSUER>",
        "AUTH_SUB_JSONPATH": "<YOUR_AUTH_SUB_JSONPATH>",
        "AUTH_ADMIN_ROLE": "<YOUR_AUTH_ADMIN_ROLE>",
        "AUTH_ADMIN_USERS": "<YOUR_AUTH_ADMIN_USERS>",
        "PROXY_SESSION_TTL": "<YOUR_PROXY_SESSION_TTL>",
        "PROXY_SESSION_SECRET": "<YOUR_PROXY_SESSION_SECRET>",
        "UI_ENABLED": "<YOUR_UI_ENABLED>",
        "THEMES_DIR": "<YOUR_THEMES_DIR>",
        "THEMES_CONFIGMAP": "<YOUR_THEMES_CONFIGMAP>",
        "DOCS_DIR": "<YOUR_DOCS_DIR>",
        "OAUTH_DISCOVERY_URL": "<YOUR_OAUTH_DISCOVERY_URL>",
        "OAUTH_LOGIN_METHOD": "<YOUR_OAUTH_LOGIN_METHOD>",
        "UI_TITLE": "<YOUR_UI_TITLE>",
        "UI_SUBTITLE": "<YOUR_UI_SUBTITLE>"
      }
    }
  }
}

Related MCP servers

Cloud replacement for mcp-server-filesystem — 20 tools for S3, Azure Blob, and GCS

2
TypeScript
View repository →
NONogra logo

Nogra

Maintained

Verify-before-done trust layer for AI-assisted work. 32 tools, local-first, no credentials.

0
Python
View repository →

Voice interface for Claude Code: talk to your agent and it talks back while it works.

5
Python
MIT
View repository →

Read-only MCP for identity resolution and write guardrails.

COColors-LE logo

Colors-LE

Active

Extract colors from stylesheets and code, with their notation and position.

2
TypeScript
MIT
View repository →
DADates-LE logo

Dates-LE

Active

Extract dates and timestamps from logs, data files and code, with their format and position.

1
TypeScript
MIT
View repository →