Uploaded image for project: 'Satellite'
  1. Satellite
  2. SAT-40211

Documentation doesn't give context on MCP transport modes

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Duplicate
    • Icon: Undefined Undefined
    • None
    • None
    • Documentation
    • False
    • Satellite Endeavour Sprint 10
    • sat-endeavour
    • None
    • None
    • None
    • None

      Section 9.2.1. Configuring the MCP server for Foreman https://docs.theforeman.org/nightly/Managing_Hosts/index-katello.html#configuring-the-mcp-server-for-Foreman doesn't give any details or context about best practices for MCP transport modes. It only links to MCP docs on transport modes.

       

      streamable-http is the default transport mode. The `podman run` command in the procedure doesn't specify any transport mode, which means that streamable-http is used by default. However, the stdio transport mode is arguably the more secure option.

       

      Expected result: Documentation briefly explains the context of MCP transport modes and advises users on the risks of streamable-http, or at least hints that the MCP documentation explains that context and potential risks (see for example "Security Warning" in https://modelcontextprotocol.io/specification/2025-03-26/basic/transports )

              apetrova@redhat.com Aneta Šteflová Petrová
              apetrova@redhat.com Aneta Šteflová Petrová
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: