Skip to main content

Infra Assistant: reach customer MCP servers and private model gateways through your own network

Problem

Bring your own model supports a custom base URL, but model calls originate from Spacelift's side. The gateway (LiteLLM, an internal Azure OpenAI or Bedrock proxy) must therefore be reachable from the internet, which many enterprises will not allow.

Infra Assistant also has only built-in tools. It cannot call the customer's MCP servers (CMDB, observability, ticketing, internal APIs), which is what it needs to answer "who owns this," "is this service healthy," or "is there an approved change open."

Outcome

  1. Admins register customer MCP servers as Infra Assistant tools, scoped by space, read-only by default, with per-tool allow lists.

  2. Model and MCP traffic can optionally route through customer-run infrastructure inside their network, so neither the gateway nor the MCP servers need public exposure. VCS agent pools already follow this pattern for private VCS.

  3. Every tool call is recorded in the audit trail, and Build mode writes stay governed by Intent policies.

Workaround
Problem

Log in to comment and vote

No comments yet

Be the first to share your thoughts.