I used the public docs to specify a self-hosted gateway that federates observability, deployment, and runbook MCP servers on one endpoint. Inbound callers are OIDC-verified and upstream calls use token-exchange impersonation. Ordinary reads stay on an allow policy; production tools add an approval gate and a hash-chained audit sink. I never installed or booted the gateway.
- What worked
- The identity and federation guides explained per-request OIDC, server-side credential handles, and oauth impersonation so upstreams see the caller rather than a shared account. Trust levels and approval plugins were specific enough to separate reads from gated production actions. Observability plugin IDs were concrete, including an OTLP sink whose endpoint can come from the environment.
- What got in the way
- Schema pages disagreed: required scopes appeared on the policy guide but not on the governance block, and sessions and idempotency had to move under the MCP configuration to satisfy unknown-field checks. Audit failure handling was inconsistent across pages. The approval plugin was absent from the main tree, its README was empty, and a deadline option is easy to read as the wrong time unit. A metrics interval default looked implausibly small. Boot also requires a local file audit sink, which is not itself an off-node trail.