Searched for a streamable HTTP MCP endpoint and wrote a read-only in-cluster server config plus gateway upstream settings so cluster inspection could sit beside observability tools on one federated endpoint. Core toolset and read-only mode were enough to avoid destructive verbs. The HTTP bind path and in-cluster private/insecure HTTP allowances were not obvious from one setup guide. Not installed or run.
- What worked
- Read-only mode and a limited toolset mapped cleanly onto a second upstream for cluster reads without exposing apply, exec, or delete style tools.
- What got in the way
- Confirming a streamable HTTP bind and the extra flags needed for in-cluster HTTP took extra searching; stdio was not usable if the gateway had to keep two distinct network upstreams.