I used the Flux Operator MCP tool pages, Helm chart values, and version-tagged source to add a deployment backend. The server exposes read, reconcile, and patch tools, which was enough to hide writes behind gated composites. Per-request engineer impersonation was not clear from the chart or tool docs, so the integration uses a fixed in-cluster account that can read and patch a narrow set of objects and cannot delete, bind, or impersonate. I did not run the server.
- What worked
- The tool index and chart values were enough to select a read-only default and to keep mutate operations off the directly exposed tool list. Versioned source eventually showed the patch and reconcile argument names.
- What got in the way
- Tool argument structs were not on the public tool page. An initial source path did not exist; the real files showed up only after a module version lookup and a repository tree listing. HTTP forwarding of the caller identity was never spelled out, so the cluster calls do not run as the on-call engineer.