NO Crd MCP Server
by nogoo9io.github.nogoo9/no-crdv0.18.0
Dynamic pod spawner & proxy for ephemeral AI agent workspaces on Kubernetes without CRDs
context tax
queued
security
queued
cold start
queued
freshness
Maintained58d ago
Install NO Crd MCP server
Install in Claude Code
claude mcp add no-crd -e TLS_KEY='<tls-key>' -e JWT_SECRET='<jwt-secret>' -e JWT_PUBLIC_KEY='<jwt-public-key>' -e OAUTH_CLIENT_SECRET='<oauth-client-secret>' -e PROXY_SESSION_SECRET='<proxy-session-secret>' -- npx -y @nogoo9/no-crdInstall in Cursor
{
"mcpServers": {
"no-crd": {
"command": "npx",
"args": [
"-y",
"@nogoo9/no-crd"
],
"env": {
"TLS_KEY": "<tls-key>",
"JWT_SECRET": "<jwt-secret>",
"JWT_PUBLIC_KEY": "<jwt-public-key>",
"OAUTH_CLIENT_SECRET": "<oauth-client-secret>",
"PROXY_SESSION_SECRET": "<proxy-session-secret>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"no-crd": {
"command": "npx",
"args": [
"-y",
"@nogoo9/no-crd"
],
"env": {
"TLS_KEY": "<tls-key>",
"JWT_SECRET": "<jwt-secret>",
"JWT_PUBLIC_KEY": "<jwt-public-key>",
"OAUTH_CLIENT_SECRET": "<oauth-client-secret>",
"PROXY_SESSION_SECRET": "<proxy-session-secret>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"no-crd": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@nogoo9/no-crd"
],
"env": {
"TLS_KEY": "<tls-key>",
"JWT_SECRET": "<jwt-secret>",
"JWT_PUBLIC_KEY": "<jwt-public-key>",
"OAUTH_CLIENT_SECRET": "<oauth-client-secret>",
"PROXY_SESSION_SECRET": "<proxy-session-secret>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"no-crd": {
"command": "npx",
"args": [
"-y",
"@nogoo9/no-crd"
],
"env": {
"TLS_KEY": "<tls-key>",
"JWT_SECRET": "<jwt-secret>",
"JWT_PUBLIC_KEY": "<jwt-public-key>",
"OAUTH_CLIENT_SECRET": "<oauth-client-secret>",
"PROXY_SESSION_SECRET": "<proxy-session-secret>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| KUBECONFIG | — | — | Path to the Kubernetes API credentials configuration file |
| BASE_URL | — | — | Hosting URL subpath prefix for gateways and reverse proxies |
| STATELESS | — | — | Disable in-memory session tracking for stateless execution |
| TLS_CERT | — | — | Local file path containing TLS public certificate (HTTPS) |
| TLS_KEY | — | yes | Local file path containing TLS private key (HTTPS) |
| TLS_CA | — | — | Local file path containing trusted client Certificate Authority |
| NODE_TLS_REJECT_UNAUTHORIZED | — | — | Set to '0' to allow connection to unverified TLS endpoints |
| REGISTRY_URL | — | — | Default container registry for workspace image resolution |
| TEMPLATES_DIR | — | — | Local filesystem directory containing custom YAML/JSON templates |
| BUILTIN_TEMPLATES | — | — | Enable loading of standard pre-configured templates (default: true) |
| AUTH_ENABLED | — | — | Enforce JWT verification and user tenant isolation (default: false) |
| JWT_VERIFICATION_REQUIRED | — | — | Set to 'false' to skip OIDC cryptographic signature checks |
| JWT_SECRET | — | yes | HMAC-SHA symmetric secret key to sign/verify JWT tokens |
| JWT_PUBLIC_KEY | — | yes | PEM public key to verify asymmetric OIDC signatures |
| JWKS_URI | — | — | Discovery URI to fetch keys from OIDC provider dynamically |
| INTROSPECTION_ENDPOINT | — | — | RFC 7662 compliant token introspection validation endpoint |
| OAUTH_CLIENT_ID | — | — | Client identifier for OAuth2 authentication flows |
| OAUTH_CLIENT_SECRET | — | yes | Client secret credentials used for token introspection |
| JWT_AUDIENCE | — | — | Target audience check value for incoming OIDC tokens |
| AUTH_ISSUER | — | — | Expected token issuer authority check value (e.g. Keycloak) |
| AUTH_SUB_JSONPATH | — | — | JSONPath pattern to extract user identity subject from token |
| AUTH_ADMIN_ROLE | — | — | Bypass role name that grants admin access (default: nogoo9-admin) |
| AUTH_ADMIN_USERS | — | — | Comma-separated list of user subject IDs (sub) granted admin privileges without OIDC scope/role claims |
| PROXY_SESSION_TTL | — | — | Active lifetime in seconds for signed proxy session cookies |
| PROXY_SESSION_SECRET | — | yes | Secret key for session cookie signing |
| UI_ENABLED | — | — | Serve the built-in HTML dashboard (default: true) |
| THEMES_DIR | — | — | Filesystem directory to scan for custom CSS themes |
| THEMES_CONFIGMAP | — | — | ConfigMap name storing dynamic CSS theme overrides |
| DOCS_DIR | — | — | Directory containing static documentation web files to serve |
| OAUTH_DISCOVERY_URL | — | — | Standard OIDC .well-known configuration discovery endpoint |
| OAUTH_LOGIN_METHOD | — | — | UI SSO flow login method: 'redirect' or silent 'iframe' |
| UI_TITLE | — | — | Custom dashboard header title for white-label branding |
| UI_SUBTITLE | — | — | Custom dashboard subtitle text below the header title |
Freshness
Maintained — last maintenance signal 58d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-08-12 · 58d ago · GitHub
Latest release
2026-08-12 · 58d ago · GitHub · v0.18.0
Package published
no data · npm/PyPI
Registry entry updated
2026-08-12 · 58d ago · official registry · v0.18.0
FAQ
›How do I install the NO Crd MCP server in Claude Code?
Run: claude mcp add no-crd -e TLS_KEY='<tls-key>' -e JWT_SECRET='<jwt-secret>' -e JWT_PUBLIC_KEY='<jwt-public-key>' -e OAUTH_CLIENT_SECRET='<oauth-client-secret>' -e PROXY_SESSION_SECRET='<proxy-session-secret>' -- npx -y @nogoo9/no-crd. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does NO Crd require an API key?
Yes. It expects TLS_KEY, JWT_SECRET, JWT_PUBLIC_KEY, OAUTH_CLIENT_SECRET, PROXY_SESSION_SECRET, of which 5 are secrets.
›Can I use NO Crd as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is NO Crd in the official MCP registry?
Yes, as io.github.nogoo9/no-crd.
Alternatives to NO Crd
Other devops & ci/cd MCP servers.