v2.1.42
Changelog
- Added
bifrost.governance.roles[].access_profilesfor granting multiple access profiles to a role. The plural list takes precedence over the deprecated singularaccess_profile; an explicit empty list removes all profile grants. - Added
bifrost.scim.trustedNetworks— the private IP/CIDR allowlist the SSRF guard consults before the generic provider’s outbound OIDC discovery calls (Discover endpoints / Discover claims), so a self-hosted IdP on10.x,172.16-31.x, or192.168.xis reachable from a declarative install instead of only from the dashboard. Each entry is{ cidr, description }: a bare IP is treated as a single host (/32, or/128for IPv6) and hostnames are rejected. Declaring the key makes Helm own the whole list - it replaces whatever is stored, and an explicittrustedNetworks: []clears dashboard-added ranges - while omitting it leaves them untouched. - Added
mcp.clientConfigs[].perUserHeaderKeys— the header names each caller must individually supply underauthType: per_user_headers(e.g.["Authorization"]). - Added
bifrost.plugins.otel.config.overhead_breakdown_enabled(defaultfalse) andbifrost.plugins.telemetry.config.overhead_breakdown_enabled- exports the per-component overhead histogrambifrost_overhead_component_microseconds, overhead latency split by theoverhead_componentlabel. - Fixed
bifrost.plugins.otel.config.export_overhead_spansnot rendering intoconfig.json. - Added
bifrost.accessProfiles[].virtual_mcpsandbifrost.accessProfiles[].mcp_configs({ mcp_client_id, tools_to_execute }) — the current spelling of a profile’s MCP grants. The values schema previously declared only the retiredmcp_tool_groups/mcp_servers/mcp_tool_overrideskeys underadditionalProperties: false, so a chart using the keys Bifrost actually reads failed schema validation and MCP grants could not be managed declaratively at all.tools_to_executeis["*"]for every tool including future ones,[]for none, or a named list. - Virtual MCPs are now assigned by name:
bifrost.accessProfiles[].virtual_mcps[]andbifrost.governance.projects[].virtual_mcps[]take{ virtual_mcp_name }, matching howmcp_configsnames its MCP client. Resolved on startup; a name matching no Virtual MCP is refused.virtual_mcp_idis still accepted as an alternative and wins when both are set. - Deprecated
bifrost.accessProfiles[].mcp_tool_groups,.mcp_servers, and.mcp_tool_overrides. They still render and Bifrost now folds them intovirtual_mcps/mcp_configsat load time with a warning in the startup logs, instead of dropping them silently.mcp_tool_groupsis ignored whenvirtual_mcpsis present;mcp_serversbecomes a["*"]allowlist except for clientsmcp_configsalready names.

