Skip to content

Add research note: ToolHive — Secure Runtime and Gateway for MCP Servers - #38

Open
rkoster wants to merge 1 commit into
mainfrom
research/toolhive
Open

Add research note: ToolHive — Secure Runtime and Gateway for MCP Servers#38
rkoster wants to merge 1 commit into
mainfrom
research/toolhive

Conversation

@rkoster

@rkoster rkoster commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Summary

Research note on Stacklok's flagship project, ToolHive — a platform for running MCP (Model Context Protocol) servers with per-server container isolation and a gateway that centralizes authentication, authorization, and observability.

Covers: container/permission-profile isolation, the frontend/backend auth split, Cedar-based authorization, the Kubernetes Operator, the Registry Server (provenance/signing), and current MCP ecosystem/transport context. Raises CF-relevance questions around UAA/Cedar policy mapping, Diego vs. Kubernetes operator deployment models, and overlap with CF's service-binding model.

Checklist

  • Copied research/TEMPLATE.md and filled in required frontmatter (title, author, date, tags, status, sources)
  • Included all four required body sections (Summary, Key findings, CF relevance, Open questions)
  • Validated locally: devbox run -- python .github/scripts/validate_notes.pyOK: 8 research note(s) and 4 idea(s) valid.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant