How to Deploy the Axual MCP Server

This guide shows you how to prepare the Axual Model Context Protocol (MCP) Server values for one tenant, deploy the chart, and verify that OAuth authentication works end to end.

Type

How-to guide

Goal

Get an Axual MCP Server running and authenticating against one tenant of Axual Governance.

Audience

Platform Operator with Helm or Argo CD access to the target namespace.

When to use

Use this guide when adding the MCP Server to an installation, once its Keycloak clients exist.

The MCP Server gives an AI model an interface onto the platform: it calls the Axual API to carry out actions a model initiates in a chat conversation. One server serves one tenant, so a multi-tenant governance installation runs one MCP Server per tenant.

Axual MCP Deployment Architecture

Contents

The sections below cover each task in this guide:

Prerequisites

Confirm the following before you begin.

Access and permissions required

You need the following access and permissions:

  • Helm or Argo CD access to the namespace the MCP Server will run in.

  • Permission to create the Ingress and its TLS Secret.

Tools and versions required

You need the following tools:

  • helm >= 3.12, or an Argo CD application pointing at your values.

Resources that must exist before starting

The following must already exist:

Prepare the values

Decide where the values.yaml will live and, if you deploy through Argo CD, what the application will be called. Then copy the values below and replace every placeholder.

MCP_OAUTH_SERVER_BASE_URL must be the full origin, scheme included, and it must match the redirect URI registered on the mcp-oauth-proxy Keycloak client exactly. Keycloak rejects a redirect URI with no scheme.

Replace every <VALUE> placeholder with your own value before running a command. MCP_OAUTH_CLIENT_SECRET is the secret from the mcp-oauth-proxy client created in the Keycloak guide.
# Copy this file and customise it for your environment

replicaCount: 1

image:
  repository: registry.axual.io/public/axual/mcp-axual
  pullPolicy: Always
  # -- Image tag. Omit to use the chart appVersion, which is the version the chart was tested with.
  tag: "<IMAGE_TAG>"

# Ingress configuration
ingress:
  enabled: true
  className: "nginx"
  hosts:
    - host: mcp-tenant1.example.org
      paths:
        - path: /
          pathType: Prefix
  tls:
    - hosts:
        - "mcp-tenant1.example.org"
      secretName: "secret-name"

# Environment variables (non-sensitive)
envSecrets:
  AXUAL_BASE_URL: https://governance.url
  AXUAL_TENANT: tenant1
  MCP_OAUTH_ENABLED: "true"
  MCP_OAUTH_SERVER_BASE_URL: https://mcp-tenant1.example.org
  MCP_OAUTH_AUTHORIZATION_SERVER: https://governance.url/auth/realms/tenant1
  MCP_OAUTH_CLIENT_ID: mcp-oauth-proxy
  MCP_OAUTH_CLIENT_SECRET: <MCP_OAUTH_CLIENT_SECRET>
  MCP_OAUTH_REQUIRED_SCOPES: mcp:user

# Resource limits and requests
resources:
  limits:
    memory: 512Mi
  requests:
    cpu: 250m
    memory: 256Mi

Deploy the chart

Install the chart with the values file you prepared. Under a GitOps workflow, commit the values instead and let the pipeline apply them; see Deployment Strategy.

helm registry login registry.axual.io --username <YOUR_USERNAME>

helm upgrade --install axual-mcp \
  oci://registry.axual.io/<CHART_PATH>/<CHART_NAME> \
  --version <CHART_VERSION> \
  --namespace <NAMESPACE> \
  --create-namespace \
  -f mcp-values.yaml

helm upgrade --install is idempotent, so it is safe to re-run after changing a value.

Keep MCP_OAUTH_CLIENT_SECRET out of the values file on anything but a trial. The chart reads envSecrets into the pod’s environment, so supply the secret from a Kubernetes Secret or the secret store this installation already uses, and leave the placeholder in the file you commit.

Verify the installation

Test the deployment through a client rather than by checking the pod, because a running pod with a wrong OAuth configuration looks healthy and still refuses every request.

Follow Axual MCP Server - User Guide to connect a client and confirm OAuth authentication succeeds.