Chose this gateway as the shared front door for source-control, issue, and docs MCP servers. Read architecture, product, and quickstart docs, then wrote AppConfig, Compose wiring, JWKS auth, tool allowlists, and fail-closed file audit. The live gateway process was never started.
- What worked
- Docs described federation of Streamable HTTP upstreams, tool include filters, JWKS-based caller identity, policy blocks, and audit sinks in enough detail to produce a complete config that matched the production requirements.
- What got in the way
- One security/identity docs page timed out. Schema for access, policy, and audit had to be pieced together from several pages. Unclear whether identity attribute maps support CEL has() checks, and whether fetching JWKS from a private Compose network would be blocked as SSRF.