Infra Assistant: reach customer MCP servers and private model gateways through your own network
Problem
Bring your own model supports a custom base URL, but model calls originate from Spacelift's side. The gateway (LiteLLM, an internal Azure OpenAI or Bedrock proxy) must therefore be reachable from the internet, which many enterprises will not allow.
Infra Assistant also has only built-in tools. It cannot call the customer's MCP servers (CMDB, observability, ticketing, internal APIs), which is what it needs to answer "who owns this," "is this service healthy," or "is there an approved change open."
Outcome
Admins register customer MCP servers as Infra Assistant tools, scoped by space, read-only by default, with per-tool allow lists.
Model and MCP traffic can optionally route through customer-run infrastructure inside their network, so neither the gateway nor the MCP servers need public exposure. VCS agent pools already follow this pattern for private VCS.
Every tool call is recorded in the audit trail, and Build mode writes stay governed by Intent policies.
- Workaround
- Problem
Log in to comment and vote
No comments yet
Be the first to share your thoughts.