1. Prima di iniziare
Il Model Context Protocol (MCP) è uno standard aperto che consente a modelli e agenti AI di accedere in modo sicuro a strumenti, database e contesto aziendale. Dalla sua introduzione nel 2024, il protocollo è stato ampiamente adottato dai provider di cloud e LLM. La specifica più recente MCP Spec 2026-07-28 (MCP 2.0) definisce un'architettura stateless, trasporti semplificati e una digitazione rigorosa dei risultati, pur rimanendo compatibile con le versioni precedenti.
L'SDK Python MCP ufficiale (mcp>=2.0.0) fornisce MCPServer (mcp.server.mcpserver.MCPServer), che sostituisce FastMCP in MCP 2.0 come framework ad alte prestazioni e facile da usare per gli sviluppatori per creare server MCP pronti per la produzione conformi alla moderna specifica MCP (28/07/2026) con trasporti HTTP e Server-Sent Events (SSE) trasmissibili tramite SSL/TLS.
In questo codelab creerai un server MCP di livello di produzione utilizzando MCPServer dall'SDK Python MCP 2.0 e la gestione delle dipendenze uv. Il server MCP sarà dotato di quattro strumenti Google Cloud (invocazione di Vertex AI Gemini, ispezione di Google Cloud Storage, scrittura di audit di Cloud Logging e controllo dell'integrità delle risorse Google Cloud). Poi, containerizzerai il server ed eseguirai il deployment in due target di runtime Google Cloud: Cloud Run e Google Kubernetes Engine (GKE) Autopilot, e registrerai e utilizzerai il server MCP in Gemini Enterprise Agent Platform.
In questo lab proverai a:
- Crea un
MCPServercon 4 strumenti Google Cloud utilizzando Python 3.12+ euvconforme alla specifica MCP 2026-07-28. - Containerizza il server MCP utilizzando una build Docker multifase.
- Proteggi ed esegui il deployment del server MCP su Cloud Run con autenticazione IAM e SSL/TLS applicate.
- Proteggi e implementa il server MCP in GKE Autopilot utilizzando Workload Identity e l'API Kubernetes Gateway con TLS.
- Registra l'endpoint del server MCP sicuro con Gemini Enterprise Agent Platform utilizzando le intestazioni dei token di autenticazione OIDC.
Che cosa ti serve
- Un progetto Google Cloud con la fatturazione abilitata.
- Google Cloud SDK (interfaccia a riga di comando
gcloud) installato e configurato. - Python 3.12+ e gestore di pacchetti
uvinstallati. dockerinstallato.- Strumento a riga di comando
kubectlinstallato.
2. Configurare l'ambiente Google Cloud
Prima di creare risorse, autentica il tuo ambiente e abilita le API Google Cloud necessarie.
Autenticare gcloud CLI
Accedi al tuo account Google Cloud:
gcloud auth login
Imposta l'ID progetto Google Cloud attivo:
export PROJECT_ID=$(gcloud config get-value project)
gcloud config set project ${PROJECT_ID}
Attiva i servizi Google Cloud
Abilita tutte le API richieste per Cloud Run, GKE, Vertex AI, Artifact Registry, Cloud Build, Cloud Logging, Storage e Compute Engine:
gcloud services enable \
agentregistry.googleapis.com \
run.googleapis.com \
container.googleapis.com \
artifactregistry.googleapis.com \
aiplatform.googleapis.com \
logging.googleapis.com \
storage.googleapis.com \
compute.googleapis.com \
iam.googleapis.com \
cloudbuild.googleapis.com \
--project="${PROJECT_ID}"
Verifica che le API siano state abilitate correttamente:
Operation "operations/..." finished successfully.
Autentica le Credenziali predefinite dell'applicazione
Autentica il tuo ambiente in modo che le librerie client Python possano accedere a Vertex AI e Cloud Storage localmente durante lo sviluppo:
gcloud auth application-default login
3. Crea il server MCP con MCPServer e uv
In questo passaggio, inizializzerai un progetto Python utilizzando uv e creerai un MCPServer che supporta quattro funzionalità di Google Cloud.
Inizializzare il progetto con uv
Crea la directory del server e inizializza uv:
mkdir -p mcp-server/src/mcp_server
cd mcp-server
uv init --lib
Copia il codice nel file pyproject.toml:
[project]
name = "secure-mcp-gcp-server"
version = "0.1.0"
description = "MCP server with Google Cloud tools supporting MCP Spec 2026-07-28 over Streamable HTTP"
readme = "README.md"
requires-python = ">=3.12"
dependencies = [
"mcp>=2.0.0",
"google-genai>=1.0.0",
"google-cloud-storage>=2.14.0",
"google-cloud-logging>=3.11.0",
"google-cloud-resource-manager>=1.12.0",
"uvicorn>=0.30.0",
"httpx2>=0.1.0",
"pydantic>=2.7.0",
]
[build-system]
requires = ["hatchling"]
build-backend = "hatchling.build"
[tool.hatch.build.targets.wheel]
packages = ["src/mcp_server"]
Sincronizza le dipendenze utilizzando uv:
uv sync
Scrivi il codice MCPServer
Crea il file di implementazione del server in src/mcp_server/server.py:
import logging
import os
from typing import Any
from google import genai
from google.cloud import logging as cloud_logging
from google.cloud import storage
from mcp.server.mcpserver import MCPServer
from starlette.requests import Request
from starlette.responses import PlainTextResponse
logging.basicConfig(level=logging.INFO)
logger = logging.getLogger("mcp-gcp-server")
# Initialize MCPServer conforming to MCP Spec 2026-07-28
mcp = MCPServer(
"Google Cloud Production Tools",
instructions="MCP Server conforming to MCP Spec 2026-07-28 for Vertex AI, Cloud Storage, Audit Logging, and Health Inspection.",
)
@mcp.custom_route("/healthz", methods=["GET"])
async def health_check(request: Request) -> PlainTextResponse:
"""Kubernetes readiness and liveness probe health check endpoint."""
return PlainTextResponse("OK")
@mcp.tool(description="Generate content or answer questions using Vertex AI Gemini model.")
def vertex_ai_generate_content(
prompt: str,
model_name: str = "gemini-2.5-flash",
project_id: str | None = None,
location: str = "us-central1",
) -> str:
"""Invokes Vertex AI Gemini API using official google-genai SDK."""
target_project = project_id or os.getenv("GCP_PROJECT") or os.getenv("GOOGLE_CLOUD_PROJECT")
if not target_project:
return "Error: GCP project ID not configured."
try:
client = genai.Client(vertexai=True, project=target_project, location=location)
response = client.models.generate_content(
model=model_name,
contents=prompt,
)
return response.text or "No text returned from Gemini."
except Exception as e:
logger.error("Vertex AI Tool Error: %s", e)
return f"Error executing Vertex AI tool: {e!s}"
@mcp.tool(description="List objects and inspect metadata for a specified Google Cloud Storage bucket.")
def gcs_bucket_inspector(
bucket_name: str,
max_results: int = 10,
prefix: str | None = None,
) -> dict[str, Any]:
"""Inspects GCS bucket content and metadata conforming to MCP Spec 2026-07-28 resultType schema."""
try:
client = storage.Client()
bucket = client.bucket(bucket_name)
blobs = list(client.list_blobs(bucket, max_results=max_results, prefix=prefix))
items = [{"name": b.name, "size_bytes": b.size, "updated": str(b.updated)} for b in blobs]
return {
"resultType": "complete",
"bucket_name": bucket_name,
"object_count_sample": len(items),
"objects": items,
}
except Exception as e:
logger.error("GCS Inspector Error: %s", e)
return {"resultType": "complete", "error": f"Failed to inspect GCS bucket: {e!s}"}
@mcp.tool(description="Write structured operational or security audit log records to Google Cloud Logging.")
def cloud_logging_audit_writer(
log_name: str,
message: str,
severity: str = "INFO",
metadata: dict[str, Any] | None = None,
) -> dict[str, Any]:
"""Sends structured audit entry to Cloud Logging."""
try:
client = cloud_logging.Client()
logger_instance = client.logger(log_name)
payload = {"message": message, "metadata": metadata or {}, "source": "mcp-server-gcp"}
logger_instance.log_struct(payload, severity=severity.upper())
return {
"resultType": "complete",
"status": "success",
"log_name": log_name,
"recorded_message": message,
}
except Exception as e:
logger.error("Cloud Logging Error: %s", e)
return {"resultType": "complete", "error": f"Failed to record audit log: {e!s}"}
@mcp.tool(description="Check health and operational state of Google Cloud project resources.")
def gcp_resource_health_checker(project_id: str | None = None) -> dict[str, Any]:
"""Returns project resource summary and status."""
target_project = project_id or os.getenv("GOOGLE_CLOUD_PROJECT") or "unknown-project"
return {
"resultType": "complete",
"status": "HEALTHY",
"project_id": target_project,
"mcp_spec_version": "2026-07-28",
"_meta": {
"io.modelcontextprotocol/protocolVersion": "2026-07-28",
"io.modelcontextprotocol/serverInfo": {"name": "mcp-gcp-server", "version": "0.1.0"},
},
"transports_enabled": ["Streamable HTTP"],
"ssl_tls_enabled": True,
}
if __name__ == "__main__":
port = int(os.getenv("PORT", "8080"))
logger.info("Starting MCPServer on port %d (Streamable HTTP Transport, Spec 2026-07-28)...", port)
mcp.run(
transport="streamable-http",
host="0.0.0.0",
port=port,
stateless_http=True,
json_response=True,
)
Testare il server MCP localmente
Passaggio 1: avvia il server MCP
Nel terminale principale, avvia il server utilizzando uv:
uv run python -m src.mcp_server.server
Dovresti visualizzare i log di avvio che confermano che il server HTTP Streamable è in ascolto sulla porta 8080:
INFO:mcp-gcp-server:Starting MCPServer on port 8080 (Streamable HTTP Transport, Spec 2026-07-28)... INFO: Started server process [12345] INFO: Waiting for application startup. INFO:mcp.server.streamable_http_manager:StreamableHTTP session manager started INFO: Application startup complete. INFO: Uvicorn running on http://0.0.0.0:8080 (Press CTRL+C to quit)
Tieni aperto e in esecuzione questo terminale.
Passaggio 2: verifica l'endpoint HTTP Streamable utilizzando curl
In MCP 2.0 (MCP Spec 2026-07-28), l'handshake initialize stateful e l'intestazione Mcp-Session-Id vengono sostituiti da richieste stateless. Puoi richiamare tools/list direttamente passando le intestazioni MCP-Protocol-Version e Mcp-Method insieme ai metadati del client in params._meta.
Apri una seconda finestra del terminale e invia una richiesta POST HTTP di Streamable:
cd mcp-server
curl -i -X POST http://localhost:8080/mcp \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-H "MCP-Protocol-Version: 2026-07-28" \
-H "Mcp-Method: tools/list" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/list",
"params": {
"_meta": {
"io.modelcontextprotocol/protocolVersion": "2026-07-28",
"io.modelcontextprotocol/clientInfo": {
"name": "curl-test",
"version": "1.0.0"
},
"io.modelcontextprotocol/clientCapabilities": {}
}
}
}'
MCPServer risponderà con HTTP/1.1 200 OK e restituirà direttamente il risultato JSON-RPC tools/list:
HTTP/1.1 200 OK
date: Wed, 12 Aug 2026 14:55:00 GMT
server: uvicorn
content-type: application/json
{"jsonrpc":"2.0","id":1,"result":{"tools":[{"name":"vertex_ai_generate_content",...},{"name":"gcs_bucket_inspector",...},{"name":"cloud_logging_audit_writer",...},{"name":"gcp_resource_health_checker",...}]}}
Passaggio 3: esegui il client di test MCP
Per testare l'individuazione e l'esecuzione di strumenti sul server locale tramite Streamable HTTP, crea uno script client di test src/mcp_server/test_client.py:
import asyncio
from mcp import Client
from mcp.types import TextContent
async def test_mcp_server() -> None:
"""Connects to the local MCP v2.0 server, lists tools, and invokes health check."""
server_url = "http://localhost:8080/mcp"
print(f"[*] Connecting to local MCPServer at {server_url} (Streamable HTTP)...")
async with Client(server_url) as client:
print(
f"[+] Connected (protocol: {client.protocol_version}, "
f"server: {client.server_info.name if client.server_info else 'unknown'})."
)
# List available tools
tools_response = await client.list_tools()
print("\n[*] Discovered MCP Tools:")
for tool in tools_response.tools:
print(f" - {tool.name}: {tool.description}")
# Invoke gcp_resource_health_checker tool
print("\n[*] Invoking tool: gcp_resource_health_checker...")
health_result = await client.call_tool("gcp_resource_health_checker", {})
print("[+] Result:")
for content in health_result.content:
if isinstance(content, TextContent):
print(content.text)
if __name__ == "__main__":
asyncio.run(test_mcp_server())
Esegui lo script del client di test utilizzando uv:
uv run python src/mcp_server/test_client.py
Dovresti visualizzare un output che dimostra la riuscita della connessione, l'individuazione dello strumento e l'esecuzione dello strumento:
[*] Connecting to local MCPServer at http://localhost:8080/mcp (Streamable HTTP)...
[+] Connected (protocol: 2026-07-28, server: Google Cloud Production Tools).
[*] Discovered MCP Tools:
- vertex_ai_generate_content: Generate content or answer questions using Vertex AI Gemini model.
- gcs_bucket_inspector: List objects and inspect metadata for a specified Google Cloud Storage bucket.
- cloud_logging_audit_writer: Write structured operational or security audit log records to Google Cloud Logging.
- gcp_resource_health_checker: Check health and operational state of Google Cloud project resources.
[*] Invoking tool: gcp_resource_health_checker...
[+] Result:
{"resultType": "complete", "status": "HEALTHY", "project_id": "my-gcp-project", "mcp_spec_version": "2026-07-28", "_meta": {"io.modelcontextprotocol/protocolVersion": "2026-07-28", "io.modelcontextprotocol/serverInfo": {"name": "mcp-gcp-server", "version": "0.1.0"}}, "transports_enabled": ["Streamable HTTP"], "ssl_tls_enabled": true}
Una volta verificato, premi CTRL+C nel terminale principale per arrestare il server locale.
4. Contenere il server MCP
Per eseguire il deployment del server MCP su Cloud Run e GKE Autopilot, inserisci il server in un'immagine container minima utilizzando un Dockerfile multifase basato su uv.
Crea Dockerfile
In mcp-server/Dockerfile:
FROM ghcr.io/astral-sh/uv:python3.12-bookworm-slim AS builder
WORKDIR /app
ENV UV_COMPILE_BYTECODE=1 UV_LINK_MODE=copy
COPY pyproject.toml uv.lock* /app/
RUN uv sync --no-install-project --no-dev
COPY README.md /app/
COPY src /app/src
RUN uv sync --no-dev
FROM python:3.12-slim-bookworm
WORKDIR /app
COPY --from=builder /app /app
ENV PATH="/app/.venv/bin:$PATH"
ENV PORT=8080
ENV PYTHONUNBUFFERED=1
EXPOSE 8080
CMD ["python", "-m", "src.mcp_server.server"]
Crea ed esegui il push dell'immagine in Artifact Registry
Crea un repository Artifact Registry:
gcloud artifacts repositories create mcp-servers \
--repository-format=docker \
--location=us-central1 \
--description="Docker repository for MCP Servers" \
--project="${PROJECT_ID}"
Concedi le autorizzazioni IAM richieste al tuo account utente e all'account di servizio Compute Engine predefinito in modo che Cloud Build possa preparare le origini, scrivere i log e eseguire il push delle immagini in Artifact Registry:
export USER_EMAIL=$(gcloud config get-value account)
gcloud projects add-iam-policy-binding "${PROJECT_ID}" \
--member="user:${USER_EMAIL}" \
--role="roles/cloudbuild.builds.editor"
gcloud projects add-iam-policy-binding "${PROJECT_ID}" \
--member="user:${USER_EMAIL}" \
--role="roles/storage.admin"
export DEFAULT_SA=$(gcloud iam service-accounts list \
--filter="email:compute@developer.gserviceaccount.com" \
--format="value(email)" \
--project="${PROJECT_ID}")
gcloud projects add-iam-policy-binding "${PROJECT_ID}" \
--member="serviceAccount:${DEFAULT_SA}" \
--role="roles/storage.objectViewer"
gcloud projects add-iam-policy-binding "${PROJECT_ID}" \
--member="serviceAccount:${DEFAULT_SA}" \
--role="roles/artifactregistry.writer"
gcloud projects add-iam-policy-binding "${PROJECT_ID}" \
--member="serviceAccount:${DEFAULT_SA}" \
--role="roles/logging.logWriter"
Invia la build dell'immagine utilizzando Cloud Build:
export IMAGE_URI="us-central1-docker.pkg.dev/${PROJECT_ID}/mcp-servers/secure-mcp-server:latest"
gcloud builds submit . --tag="${IMAGE_URI}" --project="${PROJECT_ID}"
Al termine, l'immagine container viene archiviata in modo sicuro in Artifact Registry:
SUCCESS: Image published to us-central1-docker.pkg.dev/.../secure-mcp-server:latest
5. Esegui il deployment in Cloud Run con IAM e HTTPS
Cloud Run fornisce un ambiente serverless completamente gestito con terminazione automatica dei certificati HTTPS / SSL e controllo dell'accesso Cloud IAM granulare.
Crea service account dedicato
Crea un service account Google con privilegi minimi per Cloud Run:
gcloud iam service-accounts create mcp-server-cr-sa \
--display-name="MCP Server Cloud Run SA" \
--project="${PROJECT_ID}"
export SA_EMAIL="mcp-server-cr-sa@${PROJECT_ID}.iam.gserviceaccount.com"
# Grant Vertex AI, Logging, and GCS permissions
gcloud projects add-iam-policy-binding "${PROJECT_ID}" \
--member="serviceAccount:${SA_EMAIL}" \
--role="roles/aiplatform.user"
gcloud projects add-iam-policy-binding "${PROJECT_ID}" \
--member="serviceAccount:${SA_EMAIL}" \
--role="roles/logging.logWriter"
gcloud projects add-iam-policy-binding "${PROJECT_ID}" \
--member="serviceAccount:${SA_EMAIL}" \
--role="roles/storage.objectViewer"
Esegui il deployment del servizio in Cloud Run
Esegui il deployment del container in Cloud Run con l'autenticazione IAM forzata (--no-allow-unauthenticated) e SSL gestito predefinito:
gcloud run deploy secure-mcp-server \
--image="${IMAGE_URI}" \
--platform=managed \
--region=us-central1 \
--service-account="${SA_EMAIL}" \
--set-env-vars="GOOGLE_CLOUD_PROJECT=${PROJECT_ID}" \
--no-allow-unauthenticated \
--ingress=all \
--project="${PROJECT_ID}"
Recupera l'URL HTTPS:
export CLOUD_RUN_URL=$(gcloud run services describe secure-mcp-server --platform=managed --region=us-central1 --format='value(status.url)' --project="${PROJECT_ID}")
echo "Cloud Run HTTPS Endpoint: ${CLOUD_RUN_URL}"
Verificare Endpoint Security
Il tentativo di una richiesta non autorizzata all'endpoint HTTP di Streamable restituirà 403 Forbidden:
curl -i -X POST "${CLOUD_RUN_URL}/mcp" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-H "MCP-Protocol-Version: 2026-07-28" \
-H "Mcp-Method: tools/list" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/list",
"params": {
"_meta": {
"io.modelcontextprotocol/protocolVersion": "2026-07-28",
"io.modelcontextprotocol/clientInfo": {
"name": "curl-test",
"version": "1.0.0"
},
"io.modelcontextprotocol/clientCapabilities": {}
}
}
}'
HTTP/2 403 content-type: text/html; charset=UTF-8 date: Mon, 11 Aug 2026 14:00:00 GMT
Genera un token ID OIDC utilizzando gcloud per verificare la comunicazione autorizzata:
export ID_TOKEN=$(gcloud auth print-identity-token --audiences="${CLOUD_RUN_URL}")
curl -i -X POST "${CLOUD_RUN_URL}/mcp" \
-H "Authorization: Bearer ${ID_TOKEN}" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-H "MCP-Protocol-Version: 2026-07-28" \
-H "Mcp-Method: tools/list" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/list",
"params": {
"_meta": {
"io.modelcontextprotocol/protocolVersion": "2026-07-28",
"io.modelcontextprotocol/clientInfo": {
"name": "curl-test",
"version": "1.0.0"
},
"io.modelcontextprotocol/clientCapabilities": {}
}
}
}'
HTTP/2 200
content-type: application/json
{"jsonrpc":"2.0","id":1,"result":{"tools":[{"name":"vertex_ai_generate_content",...},{"name":"gcs_bucket_inspector",...},{"name":"cloud_logging_audit_writer",...},{"name":"gcp_resource_health_checker",...}]}}
Test dell'esecuzione dello strumento live: Cloud Storage Inspector
Ora che il server MCP remoto è autenticato e risponde, prova a eseguire lo strumento gcs_bucket_inspector sull'infrastruttura Google Cloud.
Passaggio 1: crea un bucket Cloud Storage di test
Crea un bucket di test e carica un file di esempio:
export BUCKET_NAME="${PROJECT_ID}-mcp-demo"
# Create Cloud Storage bucket
gcloud storage buckets create "gs://${BUCKET_NAME}" \
--location=us-central1 \
--project="${PROJECT_ID}"
# Upload sample file
echo "Hello from Secure MCP on Google Cloud!" > sample.txt
gcloud storage cp sample.txt "gs://${BUCKET_NAME}/sample.txt"
Passaggio 2: crea il client di test dello strumento GCS remoto
Crea uno script client di test denominato src/mcp_server/test_gcs_tool.py per l'autenticazione su Cloud Run e richiama lo strumento gcs_bucket_inspector:
import asyncio
import os
import subprocess
import httpx2
from mcp import Client
from mcp.client.streamable_http import streamable_http_client
from mcp.types import TextContent
async def test_gcs_tool() -> None:
"""Authenticates to Cloud Run via OIDC and invokes the gcs_bucket_inspector tool."""
cloud_run_url = os.getenv("CLOUD_RUN_URL")
bucket_name = os.getenv("BUCKET_NAME")
if not cloud_run_url or not bucket_name:
print("[!] Please set both CLOUD_RUN_URL and BUCKET_NAME environment variables.")
return
# Generate Google OIDC ID token for Cloud Run authentication
id_token = subprocess.check_output(
["gcloud", "auth", "print-identity-token", f"--audiences={cloud_run_url.rstrip('/')}"],
text=True,
).strip()
headers = {"Authorization": f"Bearer {id_token}"}
server_url = f"{cloud_run_url.rstrip('/')}/mcp"
print(f"[*] Connecting to remote Cloud Run MCP server at {server_url} (Streamable HTTP)...")
async with httpx2.AsyncClient(
headers=headers,
timeout=httpx2.Timeout(30.0, read=300.0),
) as http_client:
transport = streamable_http_client(server_url, http_client=http_client)
async with Client(transport) as client:
print(
f"[+] Authenticated and connected (protocol: {client.protocol_version})."
)
# List tools
tools_response = await client.list_tools()
print(f"[*] Verified {len(tools_response.tools)} available tools on Cloud Run.")
# Invoke gcs_bucket_inspector tool
print(f"\n[*] Invoking tool: gcs_bucket_inspector on '{bucket_name}'...")
result = await client.call_tool(
"gcs_bucket_inspector", {"bucket_name": bucket_name}
)
print("[+] Response from Cloud Run MCP Server:")
for content in result.content:
if isinstance(content, TextContent):
print(content.text)
if __name__ == "__main__":
asyncio.run(test_gcs_tool())
Passaggio 3: esegui il client di test GCS remoto
Esegui lo script per il test utilizzando uv:
uv run python src/mcp_server/test_gcs_tool.py
Dovresti visualizzare i metadati degli oggetti live restituiti dal server MCP di Cloud Run:
[*] Connecting to remote Cloud Run MCP server at https://secure-mcp-server-...-uc.a.run.app/mcp (Streamable HTTP)...
[+] Authenticated and connected (protocol: 2026-07-28).
[*] Verified 4 available tools on Cloud Run.
[*] Invoking tool: gcs_bucket_inspector on 'my-project-mcp-demo'...
[+] Response from Cloud Run MCP Server:
{"resultType":"complete","bucket_name":"my-project-mcp-demo","object_count_sample":1,"objects":[{"name":"sample.txt","size_bytes":39,"updated":"..."}]}
6. Esegui il deployment su GKE Autopilot con Workload Identity e TLS
Per i carichi di lavoro Kubernetes, GKE Autopilot gestisce il provisioning dei nodi, mentre Workload Identity elimina le chiavi statiche dei service account.
Esegui il provisioning del cluster GKE Autopilot
Esegui il provisioning di un cluster GKE Autopilot:
gcloud container clusters create-auto mcp-gke-cluster \
--location=us-central1 \
--project="${PROJECT_ID}"
gcloud container clusters get-credentials mcp-gke-cluster \
--location=us-central1 \
--project="${PROJECT_ID}"
Configura Workload Identity
Crea un service account Google (GSA) e un service account Kubernetes (KSA), quindi collegali utilizzando Workload Identity:
# 1. Create GSA
gcloud iam service-accounts create mcp-gke-sa \
--display-name="GKE MCP Service Account" \
--project="${PROJECT_ID}"
export GSA_EMAIL="mcp-gke-sa@${PROJECT_ID}.iam.gserviceaccount.com"
# 2. Grant IAM Roles to GSA
gcloud projects add-iam-policy-binding "${PROJECT_ID}" --member="serviceAccount:${GSA_EMAIL}" --role="roles/aiplatform.user"
gcloud projects add-iam-policy-binding "${PROJECT_ID}" --member="serviceAccount:${GSA_EMAIL}" --role="roles/logging.logWriter"
gcloud projects add-iam-policy-binding "${PROJECT_ID}" --member="serviceAccount:${GSA_EMAIL}" --role="roles/storage.objectViewer"
# 3. Create KSA
kubectl create serviceaccount mcp-server-ksa --namespace default
# 4. Annotate KSA
kubectl annotate serviceaccount mcp-server-ksa \
--namespace default \
iam.gke.io/gcp-service-account="${GSA_EMAIL}"
# 5. Bind KSA to GSA
gcloud iam service-accounts add-iam-policy-binding "${GSA_EMAIL}" \
--role="roles/iam.workloadIdentityUser" \
--member="serviceAccount:${PROJECT_ID}.svc.id.goog[default/mcp-server-ksa]" \
--project="${PROJECT_ID}"
Applica il deployment di Kubernetes e l'API Gateway con TLS
Passaggio 1: prenota l'IP statico e fornisci il certificato SSL gestito da Google con nip.io
Riserva un indirizzo IP esterno globale e utilizza il servizio DNS con caratteri jolly nip.io () per stabilire un nome di dominio pubblico valido (MCP_DOMAIN) prima di applicare i manifest Kubernetes:
# Reserve global static IP address for GKE Gateway Load Balancer
gcloud compute addresses create mcp-server-ip \
--global \
--project="${PROJECT_ID}"
export MCP_IP=$(gcloud compute addresses describe mcp-server-ip --global --format="value(address)" --project="${PROJECT_ID}")
export MCP_DOMAIN="mcp.${MCP_IP}.nip.io"
echo "Reserved Static IP: ${MCP_IP}"
echo "Configured nip.io Domain: ${MCP_DOMAIN}"
# Provision Google-managed SSL certificate
gcloud compute ssl-certificates create mcp-server-cert \
--domains="${MCP_DOMAIN}" \
--global \
--project="${PROJECT_ID}"
Non devi attendere il completamento del provisioning del certificato SSL prima di continuare. Infatti, i certificati gestiti da Google rimangono nello stato PROVISIONING finché non vengono collegati al bilanciamento del carico del gateway nel passaggio 3. Procedi immediatamente ai passaggi successivi.
Passaggio 2: crea il manifest del deployment e del servizio
Crea deployment.yaml contenente le definizioni di Deployment e del servizio interno. Poiché MCP 2.0 (MCP Spec 2026-07-28) è stateless, Kubernetes Service non richiede l'affinità di sessione IP client:
apiVersion: apps/v1
kind: Deployment
metadata:
name: mcp-server-deployment
namespace: default
labels:
app: mcp-server
# GKE takes this label and registers the deployment as an MCP server to Agent Registry
registry.gke.io/functional-type: "MCP_SERVER"
annotations:
# Endpoint URL where the GKE controller can access this MCP server
modelcontextprotocol.info/urls: |
- https://MCP_DOMAIN/mcp
# Defines structural capabilities for the MCP server card
modelcontextprotocol.info/capabilities: |
card:
endpoint: "/mcp"
protocol: "HTTP"
spec:
replicas: 2
selector:
matchLabels:
app: mcp-server
template:
metadata:
labels:
app: mcp-server
annotations:
# Workload Identity annotation for identity and access management
iam.gke.io/spiffe-identity-type: agent-identity
spec:
serviceAccountName: mcp-server-ksa
containers:
- name: mcp-server
image: us-central1-docker.pkg.dev/PROJECT_ID/mcp-servers/secure-mcp-server:latest
ports:
- containerPort: 8080
name: http
env:
- name: PORT
value: "8080"
- name: GOOGLE_CLOUD_PROJECT
value: "PROJECT_ID"
resources:
requests:
cpu: "250m"
memory: "512Mi"
limits:
cpu: "1000m"
memory: "1Gi"
readinessProbe:
httpGet:
path: /healthz
port: 8080
initialDelaySeconds: 5
periodSeconds: 10
livenessProbe:
httpGet:
path: /healthz
port: 8080
initialDelaySeconds: 10
periodSeconds: 15
---
apiVersion: v1
kind: Service
metadata:
name: mcp-server-service
namespace: default
labels:
app: mcp-server
spec:
type: ClusterIP
ports:
- port: 80
targetPort: 8080
name: http
selector:
app: mcp-server
Sostituisci MCP_DOMAIN e PROJECT_ID e applica il deployment:
sed -e "s|MCP_DOMAIN|${MCP_DOMAIN}|g" \
-e "s|PROJECT_ID|${PROJECT_ID}|g" \
deployment.yaml | kubectl apply -f -
Passaggio 3: crea il manifest di Gateway API, HealthCheckPolicy e GCPBackendPolicy
Crea gateway.yaml contenente il gateway, HTTPRoute, un HealthCheckPolicy e un GCPBackendPolicy:
HealthCheckPolicy: configura il bilanciatore del carico Google Cloud per eseguire il probe di/healthzsulla porta 8080.GCPBackendPolicy(timeout backend): impostatimeoutSec: 300in modo che corrisponda al timeout di lettura di 300 secondi dell'SDK MCP v2 per i flussi HTTP / SSE riproducibili in streaming (il gateway GKE ha un valore predefinito di 30 secondi se omesso).
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: mcp-gateway
namespace: default
spec:
gatewayClassName: gke-l7-global-external-managed
listeners:
- name: https
protocol: HTTPS
port: 443
tls:
mode: Terminate
options:
networking.gke.io/pre-shared-certs: mcp-server-cert
addresses:
- type: NamedAddress
value: mcp-server-ip
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: mcp-http-route
namespace: default
spec:
parentRefs:
- name: mcp-gateway
hostnames:
- "MCP_DOMAIN"
rules:
- matches:
- path:
type: PathPrefix
value: /
backendRefs:
- name: mcp-server-service
port: 80
---
apiVersion: networking.gke.io/v1
kind: HealthCheckPolicy
metadata:
name: mcp-health-check-policy
namespace: default
spec:
default:
checkIntervalSec: 15
timeoutSec: 5
healthyThreshold: 1
unhealthyThreshold: 2
config:
type: HTTP
httpHealthCheck:
port: 8080
requestPath: /healthz
targetRef:
group: ""
kind: Service
name: mcp-server-service
---
apiVersion: networking.gke.io/v1
kind: GCPBackendPolicy
metadata:
name: mcp-backend-policy
namespace: default
spec:
default:
# Aligns with MCP SDK v2's 300s read timeout for Streamable HTTP / SSE streams
# (GKE Gateway defaults to 30s if omitted)
timeoutSec: 300
targetRef:
group: ""
kind: Service
name: mcp-server-service
Applica Gateway, HTTPRoute, HealthCheckPolicy e GCPBackendPolicy:
sed "s/MCP_DOMAIN/${MCP_DOMAIN}/g" gateway.yaml | kubectl apply -f -
Passaggio 4: verifica il deployment e testa il server MCP utilizzando l'inoltro delle porte
Poiché i certificati SSL gestiti da Google e i bilanciatori del carico delle applicazioni Google Cloud esterni richiedono 5-15 minuti per il provisioning e la configurazione del routing DNS, puoi testare immediatamente i pod GKE in esecuzione utilizzando kubectl port-forward.
Innanzitutto, controlla che i pod e il gateway siano in esecuzione:
kubectl get pods -l app=mcp-server
kubectl get gateway mcp-gateway
NAME READY STATUS RESTARTS AGE mcp-server-deployment-7b8f9495c5-x2n8q 1/1 Running 0 45s mcp-server-deployment-7b8f9495c5-z4k9p 1/1 Running 0 45s NAME CLASS ADDRESS PROGRAMMED AGE mcp-gateway gke-l7-global-external-managed 34.120.x.x True 2m
Successivamente, testa il servizio GKE live in locale utilizzando il port forwarding:
- Nel terminale, inoltra la porta locale
8080al servizio GKE ClusterIP:
kubectl port-forward svc/mcp-server-service 8080:80
- In un secondo terminale, crea uno script client di test denominato
src/mcp_server/test_vertex_tool.pyper richiamare lo strumentovertex_ai_generate_contentsu GKE utilizzando Workload Identity:
import argparse
import asyncio
import os
from mcp import Client
from mcp.types import TextContent
async def test_vertex_tool(server_url: str) -> None:
"""Connects to the MCP v2.0 server and invokes the vertex_ai_generate_content tool."""
print(f"[*] Connecting to MCPServer at {server_url} (Streamable HTTP)...")
async with Client(server_url) as client:
print(
f"[+] Connected (protocol: {client.protocol_version}, "
f"server: {client.server_info.name if client.server_info else 'unknown'})."
)
# List available tools
tools_response = await client.list_tools()
print(f"[*] Discovered {len(tools_response.tools)} MCP Tools:")
for tool in tools_response.tools:
print(f" - {tool.name}")
# Invoke vertex_ai_generate_content tool
prompt = "Explain in 2 sentences why Model Context Protocol (MCP) Streamable HTTP is great for cloud deployments."
print(f"\n[*] Invoking tool: vertex_ai_generate_content with prompt: '{prompt}'...")
result = await client.call_tool(
"vertex_ai_generate_content",
{
"prompt": prompt,
"model_name": "gemini-2.5-flash",
},
)
print("\n[+] Response from Vertex AI Gemini:")
for content in result.content:
if isinstance(content, TextContent):
print(content.text)
if __name__ == "__main__":
parser = argparse.ArgumentParser(description="Test Vertex AI MCP Tool on MCPServer.")
parser.add_argument(
"--host",
default=os.getenv("MCP_URL", "http://localhost:8080/mcp"),
help="MCP Server host or URL (default: http://localhost:8080/mcp or $MCP_URL)",
)
args = parser.parse_args()
# Normalize URL format
url = args.host
if not url.startswith("http://") and not url.startswith("https://"):
url = f"https://{url}"
if not url.endswith("/mcp"):
url = f"{url.rstrip('/')}/mcp"
asyncio.run(test_vertex_tool(url))
- Esegui lo script per il test sull'istanza locale con port forwarding:
uv run python src/mcp_server/test_vertex_tool.py --host="http://localhost:8080/mcp"
[*] Connecting to MCPServer at http://localhost:8080/mcp (Streamable HTTP)... [+] Connected (protocol: 2026-07-28, server: Google Cloud Production Tools). [*] Discovered 4 MCP Tools: - vertex_ai_generate_content - gcs_bucket_inspector - cloud_logging_audit_writer - gcp_resource_health_checker [*] Invoking tool: vertex_ai_generate_content with prompt: 'Explain in 2 sentences why Model Context Protocol (MCP) Streamable HTTP is great for cloud deployments.'... [+] Response from Vertex AI Gemini: MCP Streamable HTTP enables lightweight, stateless HTTP interactions that scale effortlessly across cloud-native platforms like GKE and Cloud Run. It simplifies infrastructure management by using standard HTTP/HTTPS protocols while preserving rich bidirectional streaming for AI agents.
Ciò conferma che i pod GKE sono integri, che Workload Identity esegue l'autenticazione su Vertex AI senza credenziali statiche e che il trasporto HTTP Streamable funziona come previsto.
Passaggio 5: verifica l'endpoint del gateway HTTPS pubblico
Controlla lo stato del provisioning dei certificati con:
gcloud compute ssl-certificates describe mcp-server-cert --global --format="value(managed.status)"
Una volta che il certificato è ACTIVE, testa l'endpoint HTTPS pubblico utilizzando il client di test Python con il flag --host:
uv run python src/mcp_server/test_vertex_tool.py --host="https://${MCP_DOMAIN}/mcp"
[*] Connecting to MCPServer at https://mcp.34.120.x.x.nip.io/mcp (Streamable HTTP)... [+] Connected (protocol: 2026-07-28, server: Google Cloud Production Tools). [*] Discovered 4 MCP Tools: - vertex_ai_generate_content - gcs_bucket_inspector - cloud_logging_audit_writer - gcp_resource_health_checker [*] Invoking tool: vertex_ai_generate_content with prompt: 'Explain in 2 sentences why Model Context Protocol (MCP) Streamable HTTP is great for cloud deployments.'... [+] Response from Vertex AI Gemini: MCP Streamable HTTP enables lightweight, stateless HTTP interactions that scale effortlessly across cloud-native platforms like GKE and Cloud Run. It simplifies infrastructure management by using standard HTTP/HTTPS protocols while preserving rich bidirectional streaming for AI agents.
7. Integra il server MCP con Google Cloud Agent Platform
Ora che il tuo MCPServer è stato implementato in modo sicuro negli endpoint HTTPS su Cloud Run e GKE Autopilot, registra e scopri i tuoi strumenti MCP con Google Cloud Agent Platform (Agent Registry) in modo che gli agenti aziendali e i modelli di AI possano rilevarli e richiamarli in modo dinamico.
1. Registra il server MCP Cloud Run personalizzato in Agent Platform e testalo utilizzando Service Discovery
Passaggio 1: estrai le specifiche dello strumento (toolspec.json)
Per registrare un server MCP esterno o personalizzato in Agent Registry, esegui una query su tools/list sul tuo server MCP 2.0 stateless live, rimuovi i campi _meta a livello di strumento e salva il risultato in toolspec.json in una singola pipeline:
# 1. Generate identity token
export ID_TOKEN=$(gcloud auth print-identity-token --audiences="${CLOUD_RUN_URL}")
# 2. Query, parse, sanitize and save in one single pipeline
curl -s -X POST "${CLOUD_RUN_URL}/mcp" \
-H "Authorization: Bearer ${ID_TOKEN}" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-H "MCP-Protocol-Version: 2026-07-28" \
-H "Mcp-Method: tools/list" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/list",
"params": {
"_meta": {
"io.modelcontextprotocol/protocolVersion": "2026-07-28",
"io.modelcontextprotocol/clientInfo": {
"name": "cli",
"version": "1.0.0"
},
"io.modelcontextprotocol/clientCapabilities": {}
}
}
}' \
| sed -n 's/^data: //p; /^{/p' \
| jq '.result | del(.tools[]._meta)' > toolspec.json
Passaggio 2: registra il servizio in Agent Registry
Utilizza gcloud agent-registry services create per catalogare il server MCP:
export SERVER_NAME="secure-mcp-server"
export DISPLAY_NAME="Google Cloud MCPServer"
export REGION="global"
gcloud agent-registry services create "${SERVER_NAME}" \
--project="${PROJECT_ID}" \
--location="${REGION}" \
--display-name="${DISPLAY_NAME}" \
--mcp-server-spec-type="tool-spec" \
--mcp-server-spec-content=toolspec.json \
--interfaces="url=${CLOUD_RUN_URL}/mcp,protocolBinding=jsonrpc"
Verifica che il servizio sia stato registrato correttamente:
gcloud agent-registry services describe "${SERVER_NAME}" --location="${REGION}"
name: projects/PROJECT_ID/locations/global/services/secure-mcp-server displayName: Google Cloud MCPServer interfaces: - protocolBinding: JSONRPC url: https://secure-mcp-server-xxxx.a.run.app/mcp mcpServerSpec: type: TOOL_SPEC
Passaggio 3: crea ed esegui il client di test Service Discovery
Crea uno script Python denominato src/mcp_server/test_agent_platform.py che risolve dinamicamente l'endpoint dal catalogo mcp-servers di Agent Registry, esegue l'autenticazione con Google Cloud IAM e richiama uno strumento utilizzando httpx2 e MCP 2.0 Client:
import asyncio
import os
import subprocess
import httpx2 # MCP SDK 2.x utilizes httpx2 instead of httpx
from mcp import Client
from mcp.client.streamable_http import streamable_http_client
async def main() -> None:
server_name = os.getenv("SERVER_NAME", "secure-mcp-server")
location = os.getenv("REGION", "global")
# 1. Discover endpoint URL from Google Cloud Agent Registry (mcp-servers catalog)
print(f"[*] Discovering '{server_name}' in '{location}' from Agent Registry...")
url = subprocess.check_output(
[
"gcloud",
"agent-registry",
"mcp-servers",
"list",
f"--location={location}",
f"--filter=displayName='{server_name}' OR mcpServerId ~ ':{server_name}$'",
"--format=value(interfaces[0].url)",
"--limit=1",
],
text=True,
).strip()
if not url:
raise RuntimeError(
f"No endpoint URL found for '{server_name}' in location '{location}'. "
"Verify the server is registered and has an interface URL configured."
)
print(f"[+] Discovered Endpoint: {url}")
# 2. Generate IAM identity token if connecting to Cloud Run
headers: dict[str, str] = {}
if "run.app" in url:
audience = url.split("/mcp")[0]
token = subprocess.check_output(
["gcloud", "auth", "print-identity-token", f"--audiences={audience}"],
text=True,
).strip()
headers["Authorization"] = f"Bearer {token}"
# 3. Configure a custom httpx2 Client with MCP-safe timeouts
# We set read to 300s to ensure the long-lived SSE/GET stream stays open
async with httpx2.AsyncClient(
headers=headers,
timeout=httpx2.Timeout(30.0, read=300.0),
) as http_client:
# 4. Initialize Streamable HTTP Transport (yielding a 2-tuple in MCP v2.x)
transport = streamable_http_client(url, http_client=http_client)
# 5. Connect using the clean high-level Client interface
async with Client(transport) as client:
print("[+] Session active. Connected successfully.")
# Verify tools registered in the catalog (Attributes are snake_case in MCP v2)
tools_response = await client.list_tools()
print(f"[+] Discovered {len(tools_response.tools)} tools:")
for tool in tools_response.tools:
print(f" - {tool.name}")
# Test executing the health check tool
print("\n[*] Invoking tool: gcp_resource_health_checker...")
result = await client.call_tool("gcp_resource_health_checker", {})
print(f"[+] Tool Output from Agent Platform:\n{result.content[0].text}")
if __name__ == "__main__":
asyncio.run(main())
Esegui lo script per il test:
uv run python src/mcp_server/test_agent_platform.py
[*] Discovering 'secure-mcp-server' in 'global' from Agent Registry...
[+] Discovered Endpoint: https://secure-mcp-server-xxxx.a.run.app/mcp
[+] Session active. Connected successfully.
[+] Discovered 4 tools:
- vertex_ai_generate_content
- gcs_bucket_inspector
- cloud_logging_audit_writer
- gcp_resource_health_checker
[*] Invoking tool: gcp_resource_health_checker...
[+] Tool Output from Agent Platform:
{"resultType": "complete", "status": "HEALTHY", "mcp_spec_version": "2026-07-28"}
2. Rilevamento e registrazione automatici del server MCP con GKE
Google Kubernetes Engine (GKE) fornisce l'integrazione automatica con Agent Registry. Etichettando e annotando il manifest di deployment GKE, GKE esegue automaticamente una scansione di introspezione sul server MCP, registra gli strumenti nel catalogo e proietta il servizio sul lato consumer senza dover generare o caricare manualmente un toolspec.json.
Passaggio 1: come funziona il rilevamento automatico di GKE
Quando è stato applicato il tuo deployment.yaml nella sezione precedente, le seguenti configurazioni hanno attivato il rilevamento automatico:
registry.gke.io/functional-type: "MCP_SERVER": indica al controller del cluster GKE di registrare il deployment in Google Cloud Agent Registry.modelcontextprotocol.info/urls: fornisce l'endpoint del gateway HTTPS esterno (https://${MCP_DOMAIN}/mcp) per l'introspezione del controller e il routing dei consumer.modelcontextprotocol.info/capabilities: dichiara l'endpoint di trasporto HTTP (/mcp).iam.gke.io/spiffe-identity-type: agent-identity: configura Workload Identity per la comunicazione agentica.
Passaggio 2: verifica la registrazione automatica di GKE in Agent Registry
Verifica che GKE abbia rilevato e registrato automaticamente il server MCP nel catalogo regionale mcp-servers:
# List the automatically registered GKE MCP server in us-central1
gcloud agent-registry mcp-servers list \
--location=us-central1 \
--format="table(displayName, tools.len():label=TOOLS)"
DISPLAY_NAME TOOLS mcp-server-deployment 4
Passaggio 3: testa il server GKE MCP utilizzando Service Discovery
Testa il deployment di GKE MCP utilizzando lo script di service discovery rispetto al nome del server registrato automaticamente in us-central1:
SERVER_NAME="mcp-server-deployment" \
REGION=us-central1 \
uv run python src/mcp_server/test_agent_platform.py
[*] Discovering 'mcp-server-deployment' in 'us-central1' from Agent Registry...
[+] Discovered Endpoint: https://mcp.34.120.x.x.nip.io/mcp
[+] Session active. Connected successfully.
[+] Discovered 4 tools:
- vertex_ai_generate_content
- gcs_bucket_inspector
- cloud_logging_audit_writer
- gcp_resource_health_checker
[*] Invoking tool: gcp_resource_health_checker...
[+] Tool Output from Agent Platform:
{"resultType": "complete", "status": "HEALTHY", "mcp_spec_version": "2026-07-28"}
8. Libera spazio
Per evitare che al tuo account Google Cloud vengano addebitati costi relativi alle risorse utilizzate in questo codelab, elimina il servizio Cloud Run, il cluster GKE, i service account e il repository di container.
Elimina il servizio Cloud Run
gcloud run services delete secure-mcp-server \
--platform=managed \
--region=us-central1 \
--quiet \
--project="${PROJECT_ID}"
Elimina il cluster GKE Autopilot
gcloud container clusters delete mcp-gke-cluster \
--location=us-central1 \
--quiet \
--project="${PROJECT_ID}"
Elimina service account e associazioni IAM
gcloud iam service-accounts delete "mcp-server-cr-sa@${PROJECT_ID}.iam.gserviceaccount.com" --quiet --project="${PROJECT_ID}"
gcloud iam service-accounts delete "mcp-gke-sa@${PROJECT_ID}.iam.gserviceaccount.com" --quiet --project="${PROJECT_ID}"
Elimina il repository Artifact Registry
gcloud artifacts repositories delete mcp-servers \
--location=us-central1 \
--quiet \
--project="${PROJECT_ID}"
Elimina servizio personalizzato di Agent Registry
gcloud agent-registry services delete secure-mcp-server \
--location=global \
--quiet \
--project="${PROJECT_ID}"
Elimina il bucket Cloud Storage
gcloud storage rm --recursive "gs://${BUCKET_NAME}" --quiet
Elimina IP statico e certificato SSL
gcloud compute ssl-certificates delete mcp-server-cert --global --quiet --project="${PROJECT_ID}"
gcloud compute addresses delete mcp-server-ip --global --quiet --project="${PROJECT_ID}"
Verifica che la pulizia dell'eliminazione sia completata:
Deleted service [secure-mcp-server]. Deleted cluster [mcp-gke-cluster]. Deleted repository [mcp-servers].
9. Complimenti
Complimenti! Hai creato, protetto ed eseguito il deployment di un server MCP 2.0 utilizzando MCPServer dall'SDK Python MCP e uv su Google Cloud.
Argomenti trattati
- È stato creato un
MCPServerche supporta la specifica MCP (28/07/2026) tramite HTTP Streamable stateless. - Ha creato quattro strumenti Google Cloud di produzione integrando Vertex AI Gemini, Cloud Storage, Cloud Logging e Resource Health.
- Deployment di container protetti su Cloud Run con autenticazione IAM e SSL/TLS applicate.
- Autenticazione senza secret configurata su GKE Autopilot con Workload Identity e API Kubernetes Gateway con TLS.
- Endpoint del server MCP registrati e rilevati con Gemini Enterprise Agent Platform (Agent Registry) utilizzando le intestazioni di autorizzazione OIDC.
Passaggi successivi
- Esplora la specifica del Model Context Protocol per risorse avanzate e definizioni dei prompt.
- Scopri di più sull'SDK Python MCP.
- Scopri di più sulla sicurezza di Google Cloud Run e su Workload Identity di GKE.