---
title: "Connect Codefresh to ChatGPT: Orchestrate CI/CD and Clusters"
slug: connect-codefresh-to-chatgpt-orchestrate-ci-cd-and-clusters
date: 2026-10-01
author: Roopendra Talekar
categories: ["AI & Agents"]
excerpt: "Learn how to connect Codefresh to ChatGPT using a managed MCP server. Automate CI/CD pipelines, GitOps workflows, and Kubernetes clusters with AI agents."
tldr: "Connect Codefresh to ChatGPT via Truto's managed MCP server to orchestrate CI/CD pipelines and clusters. Discover how to generate tools, execute deployments, and secure AI agent access."
canonical: https://truto.one/blog/connect-codefresh-to-chatgpt-orchestrate-ci-cd-and-clusters/
---

# Connect Codefresh to ChatGPT: Orchestrate CI/CD and Clusters


If you need to connect Codefresh to ChatGPT to automate CI/CD workflows, manage Kubernetes clusters, or orchestrate GitOps deployments, you need a [Model Context Protocol (MCP) server](https://truto.one/what-is-mcp-and-mcp-servers-and-how-do-they-work/). This server acts as the translation layer between ChatGPT's tool calls and Codefresh's REST APIs. You can either [build and maintain this infrastructure yourself](https://truto.one/auto-generated-mcp-tools-for-ai-agents-a-2026-architecture-guide/), or use a managed integration platform like Truto to dynamically generate a secure, authenticated MCP server URL.

If your team uses Claude, check out our guide on [connecting Codefresh to Claude](https://truto.one/connect-codefresh-to-claude-streamline-devops-and-governance/) or explore our broader architectural overview on [connecting Codefresh to AI Agents](https://truto.one/connect-codefresh-to-ai-agents-manage-release-cycles-and-images/).

Giving a Large Language Model (LLM) read and write access to a complex CI/CD and GitOps platform like Codefresh is a massive engineering challenge. You have to handle opaque Kubernetes proxy endpoints, URL-encoded resource identifiers, and deeply nested Argo CD application manifests. Every time a developer adds a new pipeline or cluster, your custom server code must interpret those changes securely. 

This guide breaks down exactly how to use Truto to generate a secure, managed MCP server for Codefresh, connect it natively to ChatGPT, and execute complex deployment workflows using natural language.

::cta{buttonText="Talk to us" buttonUrl="/book-a-demo/"}
Stop writing boilerplate API integration code. Let Truto generate secure, managed MCP servers for your AI agents in seconds.
:::

## The Engineering Reality of the Codefresh API

A [custom MCP server](https://truto.one/what-is-mcp-and-mcp-servers-and-how-do-they-work/) is a self-hosted integration layer. While the [open MCP standard](https://truto.one/what-is-mcp-and-mcp-servers-and-how-do-they-work/) provides a predictable way for models to discover tools, implementing it against Codefresh's highly specific deployment API is exceptionally painful. 

If you decide to build a custom MCP server for Codefresh, you own the entire API lifecycle. Here are the specific integration challenges that break standard CRUD assumptions when working with Codefresh:

### Opaque Kubernetes Proxy Endpoints
Unlike standard SaaS platforms with predictable JSON schemas, Codefresh heavily utilizes proxy paths (e.g., `/api/clusters/*` and `/api/kubernetes/*`) to communicate directly with connected Kubernetes clusters. These endpoints act as pass-through mechanisms. If an LLM calls a proxy endpoint to retrieve a deployment status, the response schema is completely opaque to Codefresh - it depends entirely on the specific Kubernetes provider and version being queried. Hardcoding static MCP tool schemas for these endpoints is impossible, requiring your server to dynamically interpret varying Kubernetes API responses on the fly.

### Deeply Nested GitOps Manifests
Codefresh's GitOps functionality (powered by Argo CD) is managed via the Environments V2 API. When creating or updating a GitOps application, the API requires a complex, multi-layered Kubernetes Application manifest nested inside a JSON payload containing `kind`, `metadata`, and `spec` objects. If you rely on an LLM to generate this payload from scratch without strict schema guardrails, it will inevitably hallucinate fields, leading to failed deployments or misconfigured clusters. Your MCP server must heavily validate these manifests before passing them upstream.

### URL-Encoded Resource Identifiers
Codefresh has a unique routing quirk: many endpoints addressing pipelines or projects accept either a MongoDB object ID or an escaped full name. For example, addressing a pipeline often requires formatting the identifier as `projectName%2FpipelineName`. If an LLM attempts to pass `projectName/pipelineName` without properly URL-encoding the slash, the API router will misinterpret the path and drop a 404 Not Found error. Your custom MCP server must implement a middleware layer specifically to detect and encode these specific Codefresh identifiers.

### Factual Note on Rate Limits
When orchestrating high-volume CI/CD tasks, API rate limits are a reality. It is important to note that Truto does not retry, throttle, or apply backoff on rate limit errors. When the upstream Codefresh API returns an HTTP 429 Too Many Requests, Truto passes that error directly to the caller. Truto normalizes upstream rate limit info into standardized headers (`ratelimit-limit`, `ratelimit-remaining`, `ratelimit-reset`) per the IETF specification. The caller (your LLM client or orchestrator) is entirely responsible for retry and backoff logic.

## Generating a Codefresh MCP Server

Truto handles the authentication, schema generation, and routing by generating a secure, tokenized MCP server scoped to a single connected Codefresh account. You can create this server using either the Truto UI or the REST API.

### Method 1: Via the Truto UI

For teams who prefer a visual setup, generating an MCP server takes just a few clicks:

1. Log into your Truto account and navigate to your connected **Integrated Accounts**.
2. Select your connected Codefresh account to open its detail page.
3. Click the **MCP Servers** tab.
4. Click the **Create MCP Server** button.
5. Select your desired configuration (e.g., restrict to read-only methods or filter by tags like `pipelines` or `clusters`).
6. Copy the generated MCP server URL. Treat this URL like a secure credential - it contains a cryptographic token that authenticates requests to this specific Codefresh workspace.

### Method 2: Via the Truto API

For engineering teams automating their infrastructure, you can generate MCP servers programmatically. This is ideal for provisioning ephemeral agents for specific deployment tasks.

Make a POST request to `/integrated-account/:id/mcp` using your Truto API token:

```bash
curl -X POST https://api.truto.one/integrated-account/$INTEGRATED_ACCOUNT_ID/mcp \
  -H "Authorization: Bearer $TRUTO_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Codefresh DevOps Agent",
    "config": {
      "methods": ["read", "write", "custom"],
      "tags": ["pipelines", "clusters", "environments"]
    }
  }'
```

The API returns a payload containing the unique server URL:

```json
{
  "id": "mcp_abc123",
  "name": "Codefresh DevOps Agent",
  "config": { ... },
  "expires_at": null,
  "url": "https://api.truto.one/mcp/a1b2c3d4e5f67890"
}
```

## Connecting the MCP Server to ChatGPT

Once you have your Truto MCP URL, you can connect it directly to ChatGPT so your AI agent can begin discovering tools and interacting with Codefresh.

### Method 1: Via the ChatGPT UI

If you are using ChatGPT via the web interface (requires a Pro, Plus, Business, Enterprise, or Education seat with Developer mode enabled):

1. In ChatGPT, navigate to **Settings -> Apps -> Advanced settings**.
2. Enable **Developer mode**.
3. Under **MCP servers / Custom connectors**, click to add a new server.
4. Set the **Name** to something descriptive (e.g., "Codefresh CI/CD").
5. Paste the Truto MCP URL into the **Server URL** field.
6. Click **Add** or **Save**.

ChatGPT will immediately perform a handshake with the Truto server, fetch the allowed tools, and make them available to the model.

### Method 2: Via Manual Configuration File

If you are running your own local agent, using Claude Desktop, or using an IDE like Cursor, you can connect the MCP server using a JSON configuration file and the standard Server-Sent Events (SSE) transport.

Add the following configuration to your `mcp.json` or respective configuration file:

```json
{
  "mcpServers": {
    "codefresh_devops": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-sse",
        "--url",
        "https://api.truto.one/mcp/a1b2c3d4e5f67890"
      ]
    }
  }
}
```

## Codefresh Hero Tools for ChatGPT

Truto automatically derives tool schemas from the Codefresh API documentation, handling the conversion into JSON-RPC formats. Here are the highest-leverage tools your ChatGPT agent can use to orchestrate CI/CD workflows.

### list_all_codefresh_pipelines

**Description:** Retrieves a list of pipelines in the Codefresh account, optionally filtered by project, labels, or execution context. Returns pipeline metadata, triggers, steps, and last-executed timestamps.

**Usage Notes:** This is the primary discovery tool for an AI agent to figure out which pipelines exist before attempting to run or modify them. Agents can use this to map out the CI/CD landscape.

> "List all the pipelines in the 'production-deployments' project and tell me when they were last executed."

### create_a_codefresh_pipelines_run

**Description:** Triggers a run of a Codefresh pipeline to start a new build. Can also be used to restart a previous build by passing its ID in the `previousWorkflow` parameter.

**Usage Notes:** The core execution tool. The agent can inject environment variables into the run by formatting them in the request body, allowing dynamic deployments based on conversational context.

> "Trigger the 'frontend-release' pipeline, and pass the variable 'VERSION=v2.4.1' into the build context."

### list_all_codefresh_workflows

**Description:** Lists Codefresh workflow builds in a paginated way. Returns the build ID, status (e.g., success, error, running), start/finish timestamps, branches, and executed steps.

**Usage Notes:** After triggering a pipeline, the agent uses this tool to poll for status updates or investigate why a recent deployment failed by inspecting the step statuses.

> "Check the status of the most recent workflows for the backend service. Did any of them fail at the integration testing step?"

### list_all_codefresh_clusters

**Description:** Retrieves a list of all Kubernetes clusters connected to the Codefresh account. Returns a JSON payload detailing cluster names, providers, and integration statuses.

**Usage Notes:** Essential for GitOps and infrastructure agents. It allows the LLM to verify that a target cluster is healthy and accessible before attempting to deploy a Helm chart or Argo application to it.

> "List all connected Kubernetes clusters and confirm if the 'aws-us-east-prod' cluster is actively responding."

### list_all_codefresh_gitops_applications

**Description:** Lists Codefresh GitOps (Argo CD) applications. Returns the application manifest including `kind`, `metadata`, and `spec` details.

**Usage Notes:** Allows the agent to audit current GitOps states. Because GitOps apps define the desired state of the cluster, the LLM can compare this output against actual cluster health to detect configuration drift.

> "Retrieve the GitOps application manifest for the 'payment-gateway' service and show me which target revision it is synced to."

### create_a_codefresh_install_helm_3

**Description:** Installs a Helm 3 chart in Codefresh by triggering the internal pipeline that executes the Helm release. Returns the ID of the running pipeline.

**Usage Notes:** A powerful orchestration tool. The agent requires the cluster selector and target namespace. This abstracts away manual `helm install` commands into an automated, trackable Codefresh pipeline execution.

> "Install the standard Redis Helm 3 chart into the 'data-layer' namespace on the staging cluster."

To see the complete list of available operations, schemas, and required parameters, visit the [Codefresh integration page](https://truto.one/integrations/detail/codefresh).

## Workflows in Action

By chaining these tools together, ChatGPT can act as a fully autonomous Site Reliability Engineer (SRE), investigating failures and rolling out fixes.

### Scenario 1: Debugging and Restarting a Failed Build

When a critical CI pipeline breaks, developers usually have to context-switch into the Codefresh dashboard, find the logs, determine the failure point, and manually restart the build. ChatGPT can automate this entirely.

> "Find the most recent failed build for the 'auth-service' pipeline. Tell me which step caused the failure, and if it looks like a transient network issue, trigger a rebuild."

1. **`list_all_codefresh_workflows`:** The agent queries recent builds, filtering for the `auth-service` pipeline and looking for a `status` of `error`.
2. **Analysis:** The LLM inspects the `steps` array in the returned payload. It identifies that a step named `push-to-ecr` failed due to a timeout.
3. **`get_single_codefresh_builds_rebuild_by_id`:** Since the failure matches a transient network pattern, the agent calls the rebuild tool, passing the ID of the failed workflow to trigger an exact retry.

**Result:** The user receives a concise summary of why the build failed and confirmation that a retry is already in progress, saving several minutes of manual investigation.

### Scenario 2: Deploying a Helm Chart to Production

Platform teams often rely on manual CLI commands or complex UI navigation to deploy infrastructure components via Helm. ChatGPT can orchestrate this through natural language.

> "Deploy the new ingress-nginx Helm chart to the production cluster. Once you trigger it, monitor the workflow until it succeeds."

```mermaid
sequenceDiagram
  participant User as User
  participant GPT as ChatGPT
  participant Truto as Truto MCP Server
  participant Codefresh as Codefresh API
  User->>GPT: Deploy Helm chart to production cluster
  GPT->>Truto: call list_all_codefresh_clusters
  Truto->>Codefresh: GET /api/clusters
  Codefresh-->>Truto: Return cluster list
  Truto-->>GPT: Identify 'prod-cluster' selector
  GPT->>Truto: call create_a_codefresh_install_helm_3
  Truto->>Codefresh: POST /api/kubernetes/helm/install
  Codefresh-->>Truto: Return pipeline ID
  Truto-->>GPT: Pipeline ID received
  GPT->>Truto: call list_all_codefresh_workflows
  Truto->>Codefresh: GET /api/builds
  Codefresh-->>Truto: Return running status
  Truto-->>GPT: Status evaluated
  GPT-->>User: Deployment triggered. Status is Running.
```

1. **`list_all_codefresh_clusters`:** The agent first validates that the production cluster exists and retrieves its specific selector string.
2. **`create_a_codefresh_install_helm_3`:** The agent submits the Helm install payload targeting the production selector and capturing the returned pipeline ID.
3. **`list_all_codefresh_workflows`:** The agent polls the workflow endpoint using the pipeline ID to verify the Helm chart was successfully deployed.

**Result:** The LLM abstracts the complexity of cluster selectors and pipeline triggers, providing a conversational interface to infrastructure deployment.

## Security and Access Control

Giving an AI agent access to your CI/CD pipelines and production clusters requires strict governance. Truto provides several mechanisms to lock down your Codefresh MCP servers:

*   **Method Filtering (`methods`):** Restrict an MCP server to only perform safe actions. Set `methods: ["read"]` to allow the LLM to inspect builds and clusters without the ability to trigger deployments or delete resources.
*   **Tag Filtering (`tags`):** Limit the scope of available tools based on resource tags. For example, setting `tags: ["pipelines"]` ensures the agent can interact with CI workflows but completely hides GitOps and Helm operations.
*   **API Token Auth (`require_api_token_auth`):** By default, the Truto MCP URL acts as a bearer token. By enabling this flag, the client must also pass a valid Truto API token in the `Authorization` header, adding a required secondary layer of authentication.
*   **Auto-Expiration (`expires_at`):** Generate short-lived servers for temporary contractors or specific deployment windows. Once the ISO datetime is reached, the server and its underlying KV storage are automatically destroyed.

## Orchestrate Codefresh with Truto

Building a custom integration layer to translate LLM tool calls into Codefresh's unique proxy endpoints and Kubernetes payloads is an expensive distraction from building your core product. 

By leveraging Truto's dynamically generated MCP servers, you can instantly give ChatGPT secure, strongly-typed access to your pipelines, clusters, and GitOps deployments. Stop worrying about schema drift, authentication refreshes, and API routing.

::cta{buttonText="Talk to us" buttonUrl="/book-a-demo/"}
Ready to connect Codefresh to your AI agents? Talk to our engineering team to see Truto's MCP servers in action.
:::
