chore: deprecate injected MCP approach in AI Bridge (#23031)

_Disclaimer: implemented by a Coder Agent using Claude Opus 4.6._

Marks the injected MCP approach in AI Bridge as deprecated across the
codebase.

## Changes

- **`codersdk/deployment.go`**: Deprecated `ExternalAuthConfig.MCPURL`,
`.MCPToolAllowRegex`, `.MCPToolDenyRegex` fields; deprecated and hid the
`--aibridge-inject-coder-mcp-tools` server flag; deprecated
`AIBridgeConfig.InjectCoderMCPTools`.
- **`coderd/externalauth/externalauth.go`**: Deprecated `Config.MCPURL`,
`.MCPToolAllowRegex`, `.MCPToolDenyRegex`.
- **`enterprise/aibridgedserver/aibridgedserver.go`**: Added runtime
deprecation warning when `CODER_AIBRIDGE_INJECT_CODER_MCP_TOOLS` is
enabled; deprecated `getCoderMCPServerConfig`.
- **`enterprise/aibridged/mcp.go`**: Deprecated `MCPProxyBuilder`
interface and `MCPProxyFactory` struct.
- **`docs/ai-coder/ai-bridge/mcp.md`**: Added deprecation warning
banner.
This commit is contained in:
Danny Kopping
2026-03-13 16:15:33 +02:00
committed by GitHub
parent df2360f56a
commit 870583224d
13 changed files with 61 additions and 42 deletions
-5
View File
@@ -143,11 +143,6 @@ AI BRIDGE OPTIONS:
--aibridge-enabled bool, $CODER_AIBRIDGE_ENABLED (default: false)
Whether to start an in-memory aibridged instance.
--aibridge-inject-coder-mcp-tools bool, $CODER_AIBRIDGE_INJECT_CODER_MCP_TOOLS (default: false)
Whether to inject Coder's MCP tools into intercepted AI Bridge
requests (requires the "oauth2" and "mcp-server-http" experiments to
be enabled).
--aibridge-max-concurrency int, $CODER_AIBRIDGE_MAX_CONCURRENCY (default: 0)
Maximum number of concurrent AI Bridge requests per replica. Set to 0
to disable (unlimited).
+4 -2
View File
@@ -778,8 +778,10 @@ aibridge:
# https://docs.claude.com/en/docs/claude-code/settings#environment-variables.
# (default: global.anthropic.claude-haiku-4-5-20251001-v1:0, type: string)
bedrock_small_fast_model: global.anthropic.claude-haiku-4-5-20251001-v1:0
# Whether to inject Coder's MCP tools into intercepted AI Bridge requests
# (requires the "oauth2" and "mcp-server-http" experiments to be enabled).
# Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a
# future release. Whether to inject Coder's MCP tools into intercepted AI Bridge
# requests (requires the "oauth2" and "mcp-server-http" experiments to be
# enabled).
# (default: false, type: bool)
inject_coder_mcp_tools: false
# Length of time to retain data such as interceptions and all related records
+4
View File
@@ -12448,6 +12448,7 @@ const docTemplate = `{
"type": "boolean"
},
"inject_coder_mcp_tools": {
"description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "boolean"
},
"max_concurrency": {
@@ -15336,12 +15337,15 @@ const docTemplate = `{
"type": "string"
},
"mcp_tool_allow_regex": {
"description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "string"
},
"mcp_tool_deny_regex": {
"description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "string"
},
"mcp_url": {
"description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "string"
},
"no_refresh": {
+4
View File
@@ -11058,6 +11058,7 @@
"type": "boolean"
},
"inject_coder_mcp_tools": {
"description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "boolean"
},
"max_concurrency": {
@@ -13858,12 +13859,15 @@
"type": "string"
},
"mcp_tool_allow_regex": {
"description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "string"
},
"mcp_tool_deny_regex": {
"description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "string"
},
"mcp_url": {
"description": "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.",
"type": "string"
},
"no_refresh": {
+6
View File
@@ -95,14 +95,20 @@ type Config struct {
// AppInstallationsURL is an API endpoint that returns a list of
// installations for the user. This is used for GitHub Apps.
AppInstallationsURL string
// Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
//
// MCPURL is the endpoint that clients must use to communicate with the associated
// MCP server.
MCPURL string
// Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
//
// MCPToolAllowRegex is a [regexp.Regexp] to match tools which are explicitly allowed to be
// injected into Coder AI Bridge upstream requests.
// In the case of conflicts, [MCPToolDenylistPattern] overrides items evaluated by this list.
// This field can be nil if unspecified in the config.
MCPToolAllowRegex *regexp.Regexp
// Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
//
// MCPToolDenyRegex is a [regexp.Regexp] to match tools which are explicitly NOT allowed to be
// injected into Coder AI Bridge upstream requests.
// In the case of conflicts, items evaluated by this list override [MCPToolAllowRegex].
+19 -14
View File
@@ -970,9 +970,12 @@ type ExternalAuthConfig struct {
ExtraTokenKeys []string `json:"-" yaml:"extra_token_keys"`
DeviceFlow bool `json:"device_flow" yaml:"device_flow"`
DeviceCodeURL string `json:"device_code_url" yaml:"device_code_url"`
MCPURL string `json:"mcp_url" yaml:"mcp_url"`
MCPToolAllowRegex string `json:"mcp_tool_allow_regex" yaml:"mcp_tool_allow_regex"`
MCPToolDenyRegex string `json:"mcp_tool_deny_regex" yaml:"mcp_tool_deny_regex"`
// Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
MCPURL string `json:"mcp_url" yaml:"mcp_url"`
// Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
MCPToolAllowRegex string `json:"mcp_tool_allow_regex" yaml:"mcp_tool_allow_regex"`
// Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
MCPToolDenyRegex string `json:"mcp_tool_deny_regex" yaml:"mcp_tool_deny_regex"`
// Regex allows API requesters to match an auth config by
// a string (e.g. coder.com) instead of by it's type.
//
@@ -3712,13 +3715,14 @@ Write out the current server config as YAML to stdout.`,
},
{
Name: "AI Bridge Inject Coder MCP tools",
Description: "Whether to inject Coder's MCP tools into intercepted AI Bridge requests (requires the \"oauth2\" and \"mcp-server-http\" experiments to be enabled).",
Description: "Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release. Whether to inject Coder's MCP tools into intercepted AI Bridge requests (requires the \"oauth2\" and \"mcp-server-http\" experiments to be enabled).",
Flag: "aibridge-inject-coder-mcp-tools",
Env: "CODER_AIBRIDGE_INJECT_CODER_MCP_TOOLS",
Value: &c.AI.BridgeConfig.InjectCoderMCPTools,
Default: "false",
Group: &deploymentGroupAIBridge,
YAML: "inject_coder_mcp_tools",
Hidden: true,
},
{
Name: "AI Bridge Data Retention Duration",
@@ -3997,16 +4001,17 @@ Write out the current server config as YAML to stdout.`,
}
type AIBridgeConfig struct {
Enabled serpent.Bool `json:"enabled" typescript:",notnull"`
OpenAI AIBridgeOpenAIConfig `json:"openai" typescript:",notnull"`
Anthropic AIBridgeAnthropicConfig `json:"anthropic" typescript:",notnull"`
Bedrock AIBridgeBedrockConfig `json:"bedrock" typescript:",notnull"`
InjectCoderMCPTools serpent.Bool `json:"inject_coder_mcp_tools" typescript:",notnull"`
Retention serpent.Duration `json:"retention" typescript:",notnull"`
MaxConcurrency serpent.Int64 `json:"max_concurrency" typescript:",notnull"`
RateLimit serpent.Int64 `json:"rate_limit" typescript:",notnull"`
StructuredLogging serpent.Bool `json:"structured_logging" typescript:",notnull"`
SendActorHeaders serpent.Bool `json:"send_actor_headers" typescript:",notnull"`
Enabled serpent.Bool `json:"enabled" typescript:",notnull"`
OpenAI AIBridgeOpenAIConfig `json:"openai" typescript:",notnull"`
Anthropic AIBridgeAnthropicConfig `json:"anthropic" typescript:",notnull"`
Bedrock AIBridgeBedrockConfig `json:"bedrock" typescript:",notnull"`
// Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
InjectCoderMCPTools serpent.Bool `json:"inject_coder_mcp_tools" typescript:",notnull"`
Retention serpent.Duration `json:"retention" typescript:",notnull"`
MaxConcurrency serpent.Int64 `json:"max_concurrency" typescript:",notnull"`
RateLimit serpent.Int64 `json:"rate_limit" typescript:",notnull"`
StructuredLogging serpent.Bool `json:"structured_logging" typescript:",notnull"`
SendActorHeaders serpent.Bool `json:"send_actor_headers" typescript:",notnull"`
// Circuit breaker protects against cascading failures from upstream AI
// provider rate limits (429, 503, 529 overloaded).
CircuitBreakerEnabled serpent.Bool `json:"circuit_breaker_enabled" typescript:",notnull"`
+4 -1
View File
@@ -1,5 +1,8 @@
# MCP
> [!WARNING]
> Injected MCP in AI Bridge is deprecated and will be removed in a future release.
[Model Context Protocol (MCP)](https://modelcontextprotocol.io/docs/getting-started/intro) is a mechanism for connecting AI applications to external systems.
AI Bridge can connect to MCP servers and inject tools automatically, enabling you to centrally manage the list of tools you wish to grant your users.
@@ -55,7 +58,7 @@ If a model decides to invoke a tool and it has a `bmcp_` suffix and AI Bridge ha
In contrast, tools which are defined by the client (i.e. the [`Bash` tool](https://docs.claude.com/en/docs/claude-code/settings#tools-available-to-claude) defined by _Claude Code_) cannot be invoked by AI Bridge, and the tool call from the model will be relayed to the client, after which it will invoke the tool.
If you have [Coder MCP Server](../mcp-server.md) enabled, as well as have [`CODER_AIBRIDGE_INJECT_CODER_MCP_TOOLS=true`](../../reference/cli/server#--aibridge-inject-coder-mcp-tools) set, Coder's MCP tools will be injected into intercepted requests.
If you have [Coder MCP Server](../mcp-server.md) enabled, as well as have `CODER_AIBRIDGE_INJECT_CODER_MCP_TOOLS=true` set, Coder's MCP tools will be injected into intercepted requests.
### Troubleshooting
+4 -4
View File
@@ -422,7 +422,7 @@
| `circuit_breaker_max_requests` | integer | false | | |
| `circuit_breaker_timeout` | integer | false | | |
| `enabled` | boolean | false | | |
| `inject_coder_mcp_tools` | boolean | false | | |
| `inject_coder_mcp_tools` | boolean | false | | Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release. |
| `max_concurrency` | integer | false | | |
| `openai` | [codersdk.AIBridgeOpenAIConfig](#codersdkaibridgeopenaiconfig) | false | | |
| `rate_limit` | integer | false | | |
@@ -4151,9 +4151,9 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
| `display_icon` | string | false | | Display icon is a URL to an icon to display in the UI. |
| `display_name` | string | false | | Display name is shown in the UI to identify the auth config. |
| `id` | string | false | | ID is a unique identifier for the auth config. It defaults to `type` when not provided. |
| `mcp_tool_allow_regex` | string | false | | |
| `mcp_tool_deny_regex` | string | false | | |
| `mcp_url` | string | false | | |
| `mcp_tool_allow_regex` | string | false | | Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release. |
| `mcp_tool_deny_regex` | string | false | | Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release. |
| `mcp_url` | string | false | | Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release. |
| `no_refresh` | boolean | false | | |
|`regex`|string|false||Regex allows API requesters to match an auth config by a string (e.g. coder.com) instead of by it's type.
Git clone makes use of this by parsing the URL from: 'Username for "https://github.com":' And sending it to the Coder server to match against the Regex.|
-11
View File
@@ -1813,17 +1813,6 @@ The model to use when making requests to the AWS Bedrock API.
The small fast model to use when making requests to the AWS Bedrock API. Claude Code uses Haiku-class models to perform background tasks. See https://docs.claude.com/en/docs/claude-code/settings#environment-variables.
### --aibridge-inject-coder-mcp-tools
| | |
|-------------|-----------------------------------------------------|
| Type | <code>bool</code> |
| Environment | <code>$CODER_AIBRIDGE_INJECT_CODER_MCP_TOOLS</code> |
| YAML | <code>aibridge.inject_coder_mcp_tools</code> |
| Default | <code>false</code> |
Whether to inject Coder's MCP tools into intercepted AI Bridge requests (requires the "oauth2" and "mcp-server-http" experiments to be enabled).
### --aibridge-retention
| | |
+2
View File
@@ -23,6 +23,7 @@ const (
InternalMCPServerID = "coder"
)
// Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
type MCPProxyBuilder interface {
// Build creates a [mcp.ServerProxier] for the given request initiator.
// At minimum, the Coder MCP server will be proxied.
@@ -34,6 +35,7 @@ type MCPProxyBuilder interface {
var _ MCPProxyBuilder = &MCPProxyFactory{}
// Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
type MCPProxyFactory struct {
logger slog.Logger
tracer trace.Tracer
@@ -105,6 +105,7 @@ func NewServer(lifecycleCtx context.Context, store store, logger slog.Logger, ac
}
if bridgeCfg.InjectCoderMCPTools {
logger.Warn(lifecycleCtx, "inject MCP tools option is deprecated and will be removed in a future release")
coderMCPConfig, err := getCoderMCPServerConfig(experiments, accessURL)
if err != nil {
logger.Warn(lifecycleCtx, "failed to retrieve coder MCP server config, Coder MCP will not be available", slog.Error(err))
@@ -551,6 +552,7 @@ func (s *Server) IsAuthorized(ctx context.Context, in *proto.IsAuthorizedRequest
}, nil
}
// Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
func getCoderMCPServerConfig(experiments codersdk.Experiments, accessURL string) (*proto.MCPServerConfig, error) {
// Both the MCP & OAuth2 experiments are currently required in order to use our
// internal MCP server.
-5
View File
@@ -144,11 +144,6 @@ AI BRIDGE OPTIONS:
--aibridge-enabled bool, $CODER_AIBRIDGE_ENABLED (default: false)
Whether to start an in-memory aibridged instance.
--aibridge-inject-coder-mcp-tools bool, $CODER_AIBRIDGE_INJECT_CODER_MCP_TOOLS (default: false)
Whether to inject Coder's MCP tools into intercepted AI Bridge
requests (requires the "oauth2" and "mcp-server-http" experiments to
be enabled).
--aibridge-max-concurrency int, $CODER_AIBRIDGE_MAX_CONCURRENCY (default: 0)
Maximum number of concurrent AI Bridge requests per replica. Set to 0
to disable (unlimited).
+12
View File
@@ -32,6 +32,9 @@ export interface AIBridgeConfig {
readonly openai: AIBridgeOpenAIConfig;
readonly anthropic: AIBridgeAnthropicConfig;
readonly bedrock: AIBridgeBedrockConfig;
/**
* Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
*/
readonly inject_coder_mcp_tools: boolean;
readonly retention: number;
readonly max_concurrency: number;
@@ -2711,8 +2714,17 @@ export interface ExternalAuthConfig {
readonly scopes: readonly string[];
readonly device_flow: boolean;
readonly device_code_url: string;
/**
* Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
*/
readonly mcp_url: string;
/**
* Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
*/
readonly mcp_tool_allow_regex: string;
/**
* Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
*/
readonly mcp_tool_deny_regex: string;
/**
* Regex allows API requesters to match an auth config by