Skip to content

Feature: reusable OAuth/MCP agent connector with GroundControl deployment tools #81

Description

@teckedd-code2save

Context

RentAWeekend Surface work is currently blocked operationally when the operator is away from a desktop/VPS terminal. GroundControl already owns the VPS/deployment boundary, so expose a narrow, authenticated remote MCP surface that ChatGPT and other MCP clients can connect to using the familiar provider login/consent flow.

This is an enabling layer for RentAWeekend first, not a product-direction change.

Goal

Build a portable agent-connect layer that can later be extracted/bundled for other Serendepify projects. GroundControl is the reference host and RentAWeekend is the first acceptance workload.

Authentication / authorization

  • Preserve the existing GroundControl gc_token login and requireAuth() flow.
  • OAuth Authorization Code + S256 PKCE for delegated clients.
  • Short-lived access tokens, rotating refresh tokens, revocation.
  • RFC 8414 authorization-server metadata.
  • RFC 9728 protected-resource metadata and WWW-Authenticate challenge from /mcp.
  • Support current MCP authorization discovery. Prefer Client ID Metadata Documents (CIMD) for the 2026-07-28 profile; keep standards-compatible fallback registration only where needed for client compatibility.
  • Scope grants to the authenticated GroundControl user and continue enforcing GroundControl RBAC on every operation.
  • Never expose VPS credentials, environment secret values, or unrestricted shell access.

First MCP tool surface

Read:

  • deployment.list
  • deployment.inspect
  • deployment.logs
  • deployment.health

Write:

  • deployment.redeploy

All host operations must go through the existing execOnVps() / deployment abstractions per AGENTS.md.

Acceptance test: RentAWeekend

From ChatGPT/custom MCP client:

  1. Connect GroundControl.
  2. Browser opens GroundControl login/consent.
  3. User authenticates and approves requested scopes.
  4. Client can list/inspect RentAWeekend and read its logs/health.
  5. A redeploy request can deploy latest RentAWeekend main through GroundControl without exposing SSH credentials.
  6. Disconnect/revoke removes future MCP access.
  7. Existing GroundControl browser auth and UI continue to work unchanged.

Portability boundary

Keep OAuth grant/token logic, scope definitions, protected-resource discovery, and MCP bearer validation isolated from GroundControl-specific deployment executors so this can later become a package or sidecar.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions