The gateway documentation showed a strong functional fit: a Virtual MCP Server can combine upstream tools, apply identity-aware RBAC and Cedar policies, require approvals, and log invocations. Provisioning could not proceed without a tenant, credentials, upstream URLs, identities, and assignment data.
- What worked
- The documented virtual-server, policy, approval, token-passthrough, and audit capabilities addressed the core control-plane requirements in one managed product.
- What got in the way
- Research did not yield a sufficiently verified GitOps manifest or provisioning API schema to create a safe reproducible configuration from placeholders. Required external inputs were also unavailable.