mcp-gateway
An envoy-based MCP Gateway that integrates with Istio and policy attachment mechanisms for authN, authZ, rate limiting and more.
File Explorer
Download Latest Version (.zip)- controller-tests.md
- e2e-tests.md
- release.md
- review-with-plan.md
- sync-chart.md
- what-next.md
- maintenance-audit.md
- breaking-changes.md
- crd-changes.md
- e2e-tests.md
- ext-proc-handlers.md
- manual-test-cases.md
- upstream-features.md
- otel-tracing-and-logging.md
- unit_tests.md
- rc-test-matrix.md
- ci-docs.yaml
- ci-node-image.yaml
- code-style.yaml
- conformance.yaml
- contributor-governance.yml
- controller-integration-tests.yaml
- e2e-auth.yaml
- e2e-nightly.yaml
- e2e-on-demand.yaml
- e2e.yaml
- helm-install-test.yaml
- helm-release.yaml
- images.yaml
- issue-triage.yaml
- linkinator-weekly.yaml
- performance-benchmark.yml
- ratchet-check.yaml
- ratchet-update.yaml
- spelling.yaml
- test-images.yaml
- tests.yaml
- verify-crd-sync.yaml
- dependabot.yml
- PULL_REQUEST_TEMPLATE.md
- doc.go
- groupversion_info.go
- mcpgatewayextension_types.go
- types.go
- zz_generated.deepcopy.go
- doc.go
- groupversion_info.go
- mcpgatewayextension_types.go
- mcpgatewayextension_types_test.go
- types.go
- zz_generated.deepcopy.go
- Dockerfile
- auth.mk
- cert-manager.mk
- ci-node.mk
- ci.mk
- cluster.mk
- debug.mk
- deploy.mk
- dev.mk
- e2e.mk
- gateway-api.mk
- helm-test.mk
- info.mk
- inspect.mk
- istio-debug.mk
- istio.mk
- keycloak.mk
- kind.mk
- kuadrant.mk
- metallb.mk
- observability.mk
- olm.mk
- perf.mk
- ports.mk
- setup.mk
- tools.mk
- vault-token-exchange.mk
- mcp-gateway.clusterserviceversion.yaml
- mcp.kuadrant.io_mcpgatewayextensions.yaml
- mcp.kuadrant.io_mcpserverregistrations.yaml
- mcp.kuadrant.io_mcpvirtualservers.yaml
- annotations.yaml
- mcp-gateway-channel-entry.yaml
- mcp.kuadrant.io_mcpgatewayextensions.yaml
- mcp.kuadrant.io_mcpserverregistrations.yaml
- mcp.kuadrant.io_mcpvirtualservers.yaml
- test-connection.yaml
- test-status.yaml
- _helpers.tpl
- deployment-controller.yaml
- gateway-nodeport.yaml
- gateway.yaml
- mcpgatewayextension.yaml
- networkpolicy-broker-router.yaml
- networkpolicy-controller.yaml
- NOTES.txt
- rbac.yaml
- referencegrant.yaml
- serviceaccount.yaml
- .helmignore
- Chart.yaml
- values.yaml
- README.md
- sample_local_helm_setup.sh
- broker.go
- main.go
- main_test.go
- router.go
- main.go
- standard.yaml
- customresourcedefinitions.gen.yaml
- kustomization.yaml
- kustomizeconfig.yaml
- mcp.kuadrant.io_mcpgatewayextensions.yaml
- mcp.kuadrant.io_mcpserverregistrations.yaml
- mcp.kuadrant.io_mcpvirtualservers.yaml
- catalogsource.yaml
- kustomization.yaml
- namespace.yaml
- operatorgroup.yaml
- subscription.yaml
- broker-service.yaml
- serviceentry.yaml
- mcp-auth-policy.yaml
- mcps-auth-policy.yaml
- gateway-1.yaml.template
- gateway-2.yaml.template
- gateway-elicitation.yaml.template
- gateway-shared.yaml.template
- kustomization-kind.yaml
- kustomization-openshift.yaml
- namespace.yaml
- nodeport.yaml
- README.md
- kustomization.yaml
- alloy-values.yaml
- dashboard-values.yaml
- kustomization.yaml
- README.md
- gateway.yaml
- kustomization.yaml
- namespace.yaml
- nodeport.yaml
- referencegrant.yaml
- envoyfilter.yaml
- istio.yaml
- certificate.yaml
- deployment.yaml
- httproute.yaml
- patch-gateway.json
- patch-hostaliases.json
- preflight_envoyfilter.yaml
- realm-import.yaml
- cluster-ci.yaml
- cluster.yaml
- kuadrant.yaml
- kustomization.yaml
- connect_external_server.sh
- destination-rule.yaml
- local-mcp-server.yaml
- service-entry.yaml
- values.yaml
- mcp-gateway.clusterserviceversion.yaml
- kustomization.yaml
- kustomization.yaml
- mcpgatewayextension.yaml
- deployment-controller.yaml
- kustomization.yaml
- rbac-controller.yaml
- kustomization.yaml
- namespace.yaml
- trusted-header-public-key.yaml
- deployment-controller-redis-patch.yaml
- kustomization.yaml
- namespace.yaml
- poll-interval-patch.yaml
- redis-deployment.yaml
- redis-service.yaml
- trusted-header-public-key.yaml
- kustomization.yaml
- broker-service.yaml
- deployment-broker.yaml
- deployment-controller-redis-patch.yaml
- deployment-controller.yaml
- httproute.yaml
- kustomization.yaml
- mcpgatewayextension.yaml
- namespace.yaml
- poll-interval-patch.yaml
- rbac.yaml
- redis-deployment.yaml
- redis-service.yaml
- trusted-header-public-key.yaml
- route.yaml
- .helmignore
- Chart.yaml
- values.yaml
- connectivity-link.yaml
- kustomization.yaml
- mcp-gateway-ingress.yaml
- mcp-gateway.yaml
- service-mesh.yaml
- kustomization.yaml
- kustomization.yaml
- kuadrant.yaml
- kustomization.yaml
- kustomization.yaml
- namespace.yaml
- operatorgroup.yaml
- subscription.yaml
- gatewayclass.yaml
- kustomization.yaml
- kustomization.yaml
- kustomization.yaml
- istio-cni-namespace.yaml
- istio-system-namespace.yaml
- istio.yaml
- istiocni.yaml
- kustomization.yaml
- kustomization.yaml
- subscription.yaml
- deploy_openshift.sh
- deploy_openshift_argocd.sh
- README.md
- mcpgatewayextension_admin_role.yaml
- mcpgatewayextension_editor_role.yaml
- mcpgatewayextension_viewer_role.yaml
- role.yaml
- kustomization.yaml
- token-exchange-secret.yaml
- tools-call-auth.yaml
- tools-list-auth.yaml
- trusted-header-public-key.yaml
- trusted-headers-private-key.yaml
- authpolicy.yaml
- create_resources.sh
- destinationrule.yaml
- httproute.yaml
- mcpserverregistration.yaml
- secret.yaml
- serviceentry.yaml
- config.yaml
- httproute-calendar.yaml
- kustomization.yaml
- mcp_v1_mcpgatewayextension.yaml
- mcpserverregistration-broken-server.yaml
- mcpserverregistration-conformance-server.yaml
- mcpserverregistration-everything-server.yaml
- mcpserverregistration-multiserver.yaml
- mcpserverregistration-test-servers-base.yaml
- mcpserverregistration-test-servers-extended.yaml
- mcpvirtualserver-test1.yaml
- mcpvirtualserver-test2.yaml
- singleserver.yaml
- weather-route.yaml
- conformance-server-deployment.yaml
- conformance-server-httproute.yaml
- conformance-server-service.yaml
- kustomization.yaml
- a2a-server-deployment.yaml
- a2a-server-httproute-ext.yaml
- a2a-server-httproute.yaml
- a2a-server-service.yaml
- api-key-server-deployment.yaml
- api-key-server-httproute-ext.yaml
- api-key-server-httproute.yaml
- api-key-server-secret.yaml
- api-key-server-service.yaml
- broken-server-deployment.yaml
- broken-server-httproute-ext.yaml
- broken-server-httproute.yaml
- broken-server-service.yaml
- CLAUDE.md
- custom-path-server-deployment.yaml
- custom-path-server-httproute.yaml
- custom-response-deployment.yaml
- custom-response-httproute.yaml
- custom-response-service.yaml
- everything-server-deployment.yaml
- everything-server-httproute-ext.yaml
- everything-server-httproute.yaml
- everything-server-service.yaml
- kustomization.yaml
- namespace.yaml
- oidc-server-deployment.yaml
- oidc-server-httproute-ext.yaml
- oidc-server-httproute.yaml
- oidc-server-secret.yaml
- oidc-server-service.yaml
- server1-deployment.yaml
- server1-httproute-ext.yaml
- server1-httproute.yaml
- server1-service.yaml
- server2-deployment.yaml
- server2-httproute-ext.yaml
- server2-httproute.yaml
- server2-service.yaml
- server3-deployment.yaml
- server3-httproute-ext.yaml
- server3-httproute.yaml
- server3-service.yaml
- stateless-server-deployment.yaml
- stateless-server-httproute.yaml
- stateless-server-service.yaml
- tls-server-cert-manager.yaml
- tls-server-deployment.yaml
- user-specific-server-deployment.yaml
- user-specific-server-httproute-ext.yaml
- user-specific-server-httproute.yaml
- user-specific-server-mcpserverregistration.yaml
- deployment.yaml
- kustomization.yaml
- namespace.yaml
- service.yaml
- main.go
- mcpserverregistration-stateless.yaml
- README.md
- authpolicy-callback.yaml
- authpolicy-gateway.yaml
- authpolicy-tokens.yaml
- callback-httproute.yaml
- demo.sh
- mcpserverregistration.yaml
- documentation.md
- e2e_test_cases.md
- tasks.md
- a2a-design.md
- documentation.md
- tasks.md
- test_cases.md
- broker-2026-07-28-design.md
- documentation.md
- e2e_test_cases.md
- tasks.md
- gateway-ca-cert-bundle-design.md
- documentation.md
- e2e_test_cases.md
- tasks.md
- gateway-url-token-elicitation-design.md
- documentation.md
- test_cases.md
- guardrails-design.md
- isolated-gateway.jpg
- mcp-auth-phase1.jpg
- mcp-gateway-routing.jpg
- mcp-gateway.jpg
- MCPgateway-auth.jpg
- operator-deployment.jpg
- token-exchange.jpg
- tools-list.jpg
- metrics-phase3-design.md
- resources-federation-design.md
- broker-2026-scope.md
- tasks.md
- router-2026-07-28-design.md
- streamed-body-processing.md
- documentation.md
- e2e_test_cases.md
- tasks.md
- single-gateway-dual-protocol-design.md
- documentation.md
- e2e_test_cases.md
- tasks.md
- user-specific-list-design.md
- auth-phase-1.md
- auth-phase-2.md
- backend-mcp-management.md
- CLAUDE.md
- flows.md
- isolated-gateway-deployment.md
- notifications.md
- observability.md
- operator-based-install.md
- overview.md
- performance.md
- prompts-federation.md
- protocol-versions.md
- routing.md
- security-architecture.md
- session-mgmt.md
- tool-discovery.md
- virtual-mcp-server-v2.md
- mcp-inspector-1.png
- mcp-inspector-2-connected.png
- mcp-inspector-3-tools.png
- mcp-inspector-4-kube-namespaces.png
- mcp-inspector-5-kube-namespaces-success.png
- a2a-passthrough.md
- auditing.md
- authentication.md
- authorization.md
- binary-install.md
- configure-mcp-gateway-listener-and-router.md
- custom-ca-certificates.md
- external-mcp-server.md
- getting-started.md
- how-to-install-and-configure.md
- isolated-gateway-deployment.md
- kind-cluster-setup.md
- kubernetes-mcp-server.md
- migrating-mcpgatewayextension.md
- multi-protocol-support.md
- observability.md
- olm-install.md
- openshift-local-development.md
- opentelemetry.md
- overview.md
- quick-start.md
- README.md
- register-mcp-servers.md
- scaling.md
- tool-discovery.md
- tool-revocation.md
- troubleshooting.md
- understanding-mcp-gateway-architecture.md
- url-elicitation.md
- user-based-tool-filter.md
- user-specific-tools.md
- vault-integration.md
- vault-token-exchange.md
- virtual-mcp-servers.md
- mcpgatewayextension.md
- mcpserverregistration.md
- mcpvirtualserver.md
- 0.0.8.md
- 0.7.0.md
- 1086-signing-key-length.md
- 1109-api-v1-migration.md
- 1249-gateway-ca-cert-removal.md
- 1376-unserve-v1alpha1.md
- external-mcp-server.md
- CLAUDE.md
- README.md
- grafana-mcp-metrics-dashboard.json
- grafana.yaml
- istio-mcp-metrics.yaml
- istio-telemetry.yaml
- loki.yaml
- namespace.yaml
- otel-collector.yaml
- prometheus.yaml
- README.md
- tempo.yaml
- sync-helm-rbac.sh
- token_form.html
- token_success.html
- hints.go
- hints_test.go
- invalid_tool_policy.go
- manager.go
- manager_test.go
- mcp.go
- mcp_test.go
- notification_watcher.go
- notification_watcher_test.go
- protocol_version_test.go
- status_test.go
- validate.go
- validate_test.go
- version_detection_test.go
- benchmark_test.go
- broker.go
- broker_test.go
- cache_aggregation.go
- cache_aggregation_test.go
- config_change_test.go
- discovery.go
- discovery_scope.go
- discovery_scope_test.go
- discovery_test.go
- elicitation_handler.go
- elicitation_handler_test.go
- errors.go
- filtered_prompts_handler.go
- filtered_prompts_handler_test.go
- filtered_resources_handler.go
- filtered_resources_handler_test.go
- filtered_tools_handler.go
- filtered_tools_handler_test.go
- gateway_server.go
- gateway_server_notify_test.go
- gateway_server_test.go
- harness_test.go
- http_compat.go
- http_compat_test.go
- oauth_protected_resource_handler.go
- oauth_protected_resource_handler_test.go
- protocol_filter.go
- protocol_filter_test.go
- protocol_handler.go
- protocol_handler_2025.go
- protocol_handler_2025_test.go
- protocol_handler_2026.go
- protocol_handler_2026_test.go
- README.md
- resources_test.go
- routing_table.go
- routing_table_test.go
- session_resurrection.go
- session_resurrection_test.go
- status.go
- status_test.go
- tags_handler.go
- tags_handler_test.go
- tokens.go
- tokens_test.go
- tracing.go
- tracing_test.go
- user_specific_tools.go
- user_specific_tools_test.go
- version_test.go
- clients.go
- clients_test.go
- config_test.go
- config_writer.go
- config_writer_test.go
- mcpservers_test.go
- types.go
- broker_router.go
- ca_cert_bundle.go
- ca_cert_bundle_test.go
- CLAUDE.md
- deployment_test.go
- envoyfilter_test.go
- guardrails_config_test.go
- httproute_wrapper.go
- httproute_wrapper_test.go
- keypair.go
- keypair_test.go
- listener_config.go
- mcpgatewayextension.go
- mcpgatewayextension_controller.go
- mcpgatewayextension_controller_test.go
- mcpgatewayextension_test.go
- mcpserverregistration_controller.go
- mcpserverregistration_controller_integration_test.go
- mcpserverregistration_controller_test.go
- mcpvirtualserver_controller.go
- mcpvirtualserver_controller_test.go
- session_signing_key.go
- session_signing_key_test.go
- session_store.go
- suite_test.go
- trusted_headers.go
- trusted_headers_test.go
- inmemory.go
- map.go
- map_test.go
- redis.go
- secret.go
- secret_test.go
- headers.go
- inmemory.go
- map.go
- map_test.go
- redis.go
- decode.go
- decode_test.go
- a2a.go
- a2a_process_test.go
- a2a_test.go
- adapter_test.go
- CLAUDE.md
- elicitation.go
- elicitation_test.go
- ext_proc_adapter.go
- ext_proc_adapter_test.go
- headers.go
- headers_test.go
- README.md
- resource_rewrite.go
- resource_rewrite_test.go
- response_builder.go
- response_builder_test.go
- tracing.go
- config.go
- config_test.go
- logging.go
- logging_test.go
- logs.go
- logs_test.go
- metrics.go
- metrics_test.go
- otel.go
- otel_test.go
- provider.go
- provider_test.go
- resource.go
- version.go
- benchmark_test.go
- mcp_request.go
- mcp_request_test.go
- mem_table.go
- mem_table_test.go
- response.go
- response_test.go
- router.go
- router_202511.go
- router_202607.go
- router_202607_test.go
- router_test.go
- session.go
- table.go
- tracing.go
- cache.go
- cache_test.go
- crypto.go
- jwt.go
- jwt_test.go
- main.go
- server2.go
- server2_test.go
- server.go
- server_test.go
- server.go
- server_test.go
- roundtripper_test.go
- transport.go
- generate-oidc-authpolicies.sh
- quick-start.sh
- set-release-version.sh
- auth_policy_test.go
- builders.go
- ca_cert_bundle_test.go
- CLAUDE.md
- commons.go
- custom_tls_test.go
- dual_protocol_test.go
- elicitation_test.go
- happy_path_test.go
- jwt_helpers.go
- keycloak_helpers.go
- kubectl_helpers.go
- mcp_client.go
- multi_gateway_test.go
- oauth_protected_resource_test.go
- raw_mcp_2026_http.go
- raw_mcp_http.go
- README.md
- resources_federation_test.go
- resources_read_routing_test.go
- suite_test.go
- test_cases.md
- tool_discovery_test.go
- tool_validation_test.go
- user_specific_list_test.go
- verifiers.go
- test-helm-install.sh
- main.go
- ci-benchmark.js
- concurrency-levels.js
- ramp-up.js
- k6-benchmark-job.yaml
- mock-server.yaml
- registration.yaml
- Dockerfile
- go.mod
- go.sum
- main.go
- capture-profiles.sh
- collect-resources.sh
- convert-k6-to-benchmark.sh
- convert-k6-to-benchmark_test.sh
- README.md
- Dockerfile
- go.mod
- main.go
- Dockerfile
- go.mod
- go.sum
- main.go
- README.md
- Dockerfile
- go.mod
- go.sum
- main.go
- README.md
- .dockerignore
- Dockerfile
- README.md
- start.ts
- Dockerfile
- go.mod
- go.sum
- main.go
- Dockerfile
- go.mod
- main.go
- Dockerfile
- README.md
- Dockerfile
- go.mod
- go.sum
- main.go
- README.md
- Dockerfile
- go.mod
- go.sum
- main.go
- main_test.go
- README.md
- Dockerfile
- main.go
- README.md
- .dockerignore
- Dockerfile
- README.md
- server.py
- Dockerfile
- main.go
- Dockerfile
- go.mod
- go.sum
- main.go
- Dockerfile
- main.go
- README.md
- agent.md
- README.md
- ci-node-image-hash.sh
- docker-network-ipaddresspool.sh
- generate-catalog.sh
- generate-placeholder-ca.sh
- patch-authorino-to-keycloak.sh
- resolve_ip.sh
- verify_mcp_connection.sh
- .coderabbit.yaml
- .cspell.json
- .gitattributes
- .gitignore
- .golangci-kube-api-linter.yml
- .golangci.yml
- AGENTS.md
- bundle.Dockerfile
- CLAUDE.md
- CONTRIBUTING.md
- Dockerfile
- Dockerfile.controller
- Dockerfile.k6
- go.mod
- go.sum
- LICENSE
- linkinator.config.json
- Makefile
- PROJECT
- project-words.txt
- README.md
- RELEASING.md
- VISION.md
# Installation Guide
git clone https://github.com/Kuadrant/mcp-gateway
Downloads the entire project code from GitHub to your computer.
cd mcp-gateway
Moves into the project folder you just downloaded.
2. Docker
Easy Recommended- Git Needed to download the project code from GitHub.
- Docker Desktop Needed to build and run containers. Install it and keep it running in the background.
docker build -t mcp-gateway .
Builds a runnable image based on the Dockerfile.
docker run -p 8080:80 mcp-gateway
Runs the built image as an actual container.
3. Go
Mediumgo build ./...
Compiles the Go program into an executable.
go run .
Runs the Go program directly without a separate build step.
4. Make
Medium- Git Needed to download the project code from GitHub.
- Make Usually pre-installed on Linux/macOS. On Windows, install separately (e.g. via MSYS2 or WSL).
make local-env-setup
Compiles the code based on the generated build configuration to produce an executable.
make inspect-gateway
Compiles the code based on the generated build configuration to produce an executable.
make auth-example-setup
Compiles the code based on the generated build configuration to produce an executable.
make run
Compiles the code based on the generated build configuration to produce an executable.
make run-controller
Compiles the code based on the generated build configuration to produce an executable.
Pulled directly from this repo's README.
