Skip to content

Proxy runner triggers StatefulSet rolling update on every restart, causing crash loop #4877

Description

@JAORMX

Bug

MCPServers with externalAuthConfigRef (embedded auth server) enter a crash loop where the proxy Deployment and backend StatefulSet are continuously rolled.

Symptoms

  1. The StatefulSet .metadata.generation increments on every proxy restart (observed going from 2 → 51+)
  2. The proxy runner logs show the StatefulSet going from ready_replicas: 1 → ready_replicas: 0 each time it starts
  3. After the 5-minute initialize timeout, the proxy reports "workload started successfully" but the transport immediately dies ("transport is no longer running")
  4. The proxy enters CrashLoopBackOff
waiting for statefulset to be ready... ready_replicas:1, observed_generation:7, desired_generation:8
waiting for statefulset to be ready... ready_replicas:0
Waiting for MCP server to be ready, endpoint: http://localhost:8080/mcp
initialize not successful, but continuing
workload started successfully, press Ctrl+C to stop
transport is no longer running, attempting automatic restart

MCPServers without externalAuthConfigRef do not exhibit this behavior — their StatefulSets stabilize normally.

To reproduce

  1. Create an MCPServer with externalAuthConfigRef pointing to an MCPExternalAuthConfig of type embeddedAuthServer with an OIDC upstream provider
  2. Ensure the required ExternalSecrets (ECDSA signing key, HMAC secret) are synced
  3. Observe that the proxy Deployment pod enters CrashLoopBackOff
  4. Check the StatefulSet generation — it increments on each proxy restart

Environment

  • ToolHive operator v0.20.0
  • Kubernetes (EKS)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions