Skip to content

fix(acedatacloud): share OAuth state across MCP replicas - #963

Merged
Germey merged 2 commits into
mainfrom
codex/mcp-oauth-shared-state-20261007
Oct 7, 2026
Merged

Germey merged 2 commits into
mainfrom
codex/mcp-oauth-shared-state-20261007

Conversation

@acedatacloud-dev

Copy link
Copy Markdown
Member

Summary

Fix AceDataCloud hosted MCP reconnect failures after the service moved to two replicas. Dynamic OAuth clients, pending authorization, and one-time authorization codes now use encrypted Redis state shared by both Pods. Unknown client IDs no longer get a fabricated record with the wrong redirect URI.

The deploy script creates a stable Kubernetes Secret on first rollout, starts a dedicated persistent Redis StatefulSet with restricted ingress, and waits for it before updating the MCP Deployment. It fails if the state Secret disappears while the PVC remains, so an accidental key rotation cannot silently invalidate stored clients.

Validation

  • ruff check . and ruff format --check .
  • mypy core tools contracts
  • pytest --cov=core --cov=tools --cov=contracts --cov-report=term-missing --cov-fail-under=75: 217 passed, 81.97% coverage
  • python scripts/sync_contract_docs.py --check
  • python -m build
  • kubectl apply --dry-run=server -f acedatacloud/deploy/production/oauth-redis.yaml
  • Cross-replica regression test covers DCR, exact callback, callback state, one-time code exchange, and encrypted Redis values.

Rollout

Merge and deploy this PR first. Then deploy the companion AuthBackend PR to rotate previously cached in-memory DCR clients once. Existing active platform tokens remain usable. Previously registered external OAuth clients may need a fresh client registration when they next reconnect; no credential migration from old Pod memory is possible.

If deployment fails, keep the Secret and PVC for recovery. Do not recreate the Secret with a new state key. The existing MCP image can be restored while the new Redis resources remain in place.

@Germey
Germey merged commit 1453745 into main Oct 7, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants