Connect Codefresh to ChatGPT: Orchestrate CI/CD and Clusters
Learn how to connect Codefresh to ChatGPT using a managed MCP server. Automate CI/CD pipelines, GitOps workflows, and Kubernetes clusters with AI agents.
If you need to connect Codefresh to ChatGPT to automate CI/CD workflows, manage Kubernetes clusters, or orchestrate GitOps deployments, you need a Model Context Protocol (MCP) server. This server acts as the translation layer between ChatGPT's tool calls and Codefresh's REST APIs. You can either build and maintain this infrastructure yourself, or use a managed integration platform like Truto to dynamically generate a secure, authenticated MCP server URL.
If your team uses Claude, check out our guide on connecting Codefresh to Claude or explore our broader architectural overview on connecting Codefresh to AI Agents.
Giving a Large Language Model (LLM) read and write access to a complex CI/CD and GitOps platform like Codefresh is a massive engineering challenge. You have to handle opaque Kubernetes proxy endpoints, URL-encoded resource identifiers, and deeply nested Argo CD application manifests. Every time a developer adds a new pipeline or cluster, your custom server code must interpret those changes securely.
This guide breaks down exactly how to use Truto to generate a secure, managed MCP server for Codefresh, connect it natively to ChatGPT, and execute complex deployment workflows using natural language.
Stop writing boilerplate API integration code. Let Truto generate secure, managed MCP servers for your AI agents in seconds. :::
The Engineering Reality of the Codefresh API
A custom MCP server is a self-hosted integration layer. While the open MCP standard provides a predictable way for models to discover tools, implementing it against Codefresh's highly specific deployment API is exceptionally painful.
If you decide to build a custom MCP server for Codefresh, you own the entire API lifecycle. Here are the specific integration challenges that break standard CRUD assumptions when working with Codefresh:
Opaque Kubernetes Proxy Endpoints
Unlike standard SaaS platforms with predictable JSON schemas, Codefresh heavily utilizes proxy paths (e.g., /api/clusters/* and /api/kubernetes/*) to communicate directly with connected Kubernetes clusters. These endpoints act as pass-through mechanisms. If an LLM calls a proxy endpoint to retrieve a deployment status, the response schema is completely opaque to Codefresh - it depends entirely on the specific Kubernetes provider and version being queried. Hardcoding static MCP tool schemas for these endpoints is impossible, requiring your server to dynamically interpret varying Kubernetes API responses on the fly.
Deeply Nested GitOps Manifests
Codefresh's GitOps functionality (powered by Argo CD) is managed via the Environments V2 API. When creating or updating a GitOps application, the API requires a complex, multi-layered Kubernetes Application manifest nested inside a JSON payload containing kind, metadata, and spec objects. If you rely on an LLM to generate this payload from scratch without strict schema guardrails, it will inevitably hallucinate fields, leading to failed deployments or misconfigured clusters. Your MCP server must heavily validate these manifests before passing them upstream.
URL-Encoded Resource Identifiers
Codefresh has a unique routing quirk: many endpoints addressing pipelines or projects accept either a MongoDB object ID or an escaped full name. For example, addressing a pipeline often requires formatting the identifier as projectName%2FpipelineName. If an LLM attempts to pass projectName/pipelineName without properly URL-encoding the slash, the API router will misinterpret the path and drop a 404 Not Found error. Your custom MCP server must implement a middleware layer specifically to detect and encode these specific Codefresh identifiers.
Factual Note on Rate Limits
When orchestrating high-volume CI/CD tasks, API rate limits are a reality. It is important to note that Truto does not retry, throttle, or apply backoff on rate limit errors. When the upstream Codefresh API returns an HTTP 429 Too Many Requests, Truto passes that error directly to the caller. Truto normalizes upstream rate limit info into standardized headers (ratelimit-limit, ratelimit-remaining, ratelimit-reset) per the IETF specification. The caller (your LLM client or orchestrator) is entirely responsible for retry and backoff logic.
Generating a Codefresh MCP Server
Truto handles the authentication, schema generation, and routing by generating a secure, tokenized MCP server scoped to a single connected Codefresh account. You can create this server using either the Truto UI or the REST API.
Method 1: Via the Truto UI
For teams who prefer a visual setup, generating an MCP server takes just a few clicks:
- Log into your Truto account and navigate to your connected Integrated Accounts.
- Select your connected Codefresh account to open its detail page.
- Click the MCP Servers tab.
- Click the Create MCP Server button.
- Select your desired configuration (e.g., restrict to read-only methods or filter by tags like
pipelinesorclusters). - Copy the generated MCP server URL. Treat this URL like a secure credential - it contains a cryptographic token that authenticates requests to this specific Codefresh workspace.
Method 2: Via the Truto API
For engineering teams automating their infrastructure, you can generate MCP servers programmatically. This is ideal for provisioning ephemeral agents for specific deployment tasks.
Make a POST request to /integrated-account/:id/mcp using your Truto API token:
curl -X POST https://api.truto.one/integrated-account/$INTEGRATED_ACCOUNT_ID/mcp \
-H "Authorization: Bearer $TRUTO_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "Codefresh DevOps Agent",
"config": {
"methods": ["read", "write", "custom"],
"tags": ["pipelines", "clusters", "environments"]
}
}'The API returns a payload containing the unique server URL:
{
"id": "mcp_abc123",
"name": "Codefresh DevOps Agent",
"config": { ... },
"expires_at": null,
"url": "https://api.truto.one/mcp/a1b2c3d4e5f67890"
}Connecting the MCP Server to ChatGPT
Once you have your Truto MCP URL, you can connect it directly to ChatGPT so your AI agent can begin discovering tools and interacting with Codefresh.
Method 1: Via the ChatGPT UI
If you are using ChatGPT via the web interface (requires a Pro, Plus, Business, Enterprise, or Education seat with Developer mode enabled):
- In ChatGPT, navigate to Settings -> Apps -> Advanced settings.
- Enable Developer mode.
- Under MCP servers / Custom connectors, click to add a new server.
- Set the Name to something descriptive (e.g., "Codefresh CI/CD").
- Paste the Truto MCP URL into the Server URL field.
- Click Add or Save.
ChatGPT will immediately perform a handshake with the Truto server, fetch the allowed tools, and make them available to the model.
Method 2: Via Manual Configuration File
If you are running your own local agent, using Claude Desktop, or using an IDE like Cursor, you can connect the MCP server using a JSON configuration file and the standard Server-Sent Events (SSE) transport.
Add the following configuration to your mcp.json or respective configuration file:
{
"mcpServers": {
"codefresh_devops": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-sse",
"--url",
"https://api.truto.one/mcp/a1b2c3d4e5f67890"
]
}
}
}Codefresh Hero Tools for ChatGPT
Truto automatically derives tool schemas from the Codefresh API documentation, handling the conversion into JSON-RPC formats. Here are the highest-leverage tools your ChatGPT agent can use to orchestrate CI/CD workflows.
list_all_codefresh_pipelines
Description: Retrieves a list of pipelines in the Codefresh account, optionally filtered by project, labels, or execution context. Returns pipeline metadata, triggers, steps, and last-executed timestamps.
Usage Notes: This is the primary discovery tool for an AI agent to figure out which pipelines exist before attempting to run or modify them. Agents can use this to map out the CI/CD landscape.
"List all the pipelines in the 'production-deployments' project and tell me when they were last executed."
create_a_codefresh_pipelines_run
Description: Triggers a run of a Codefresh pipeline to start a new build. Can also be used to restart a previous build by passing its ID in the previousWorkflow parameter.
Usage Notes: The core execution tool. The agent can inject environment variables into the run by formatting them in the request body, allowing dynamic deployments based on conversational context.
"Trigger the 'frontend-release' pipeline, and pass the variable 'VERSION=v2.4.1' into the build context."
list_all_codefresh_workflows
Description: Lists Codefresh workflow builds in a paginated way. Returns the build ID, status (e.g., success, error, running), start/finish timestamps, branches, and executed steps.
Usage Notes: After triggering a pipeline, the agent uses this tool to poll for status updates or investigate why a recent deployment failed by inspecting the step statuses.
"Check the status of the most recent workflows for the backend service. Did any of them fail at the integration testing step?"
list_all_codefresh_clusters
Description: Retrieves a list of all Kubernetes clusters connected to the Codefresh account. Returns a JSON payload detailing cluster names, providers, and integration statuses.
Usage Notes: Essential for GitOps and infrastructure agents. It allows the LLM to verify that a target cluster is healthy and accessible before attempting to deploy a Helm chart or Argo application to it.
"List all connected Kubernetes clusters and confirm if the 'aws-us-east-prod' cluster is actively responding."
list_all_codefresh_gitops_applications
Description: Lists Codefresh GitOps (Argo CD) applications. Returns the application manifest including kind, metadata, and spec details.
Usage Notes: Allows the agent to audit current GitOps states. Because GitOps apps define the desired state of the cluster, the LLM can compare this output against actual cluster health to detect configuration drift.
"Retrieve the GitOps application manifest for the 'payment-gateway' service and show me which target revision it is synced to."
create_a_codefresh_install_helm_3
Description: Installs a Helm 3 chart in Codefresh by triggering the internal pipeline that executes the Helm release. Returns the ID of the running pipeline.
Usage Notes: A powerful orchestration tool. The agent requires the cluster selector and target namespace. This abstracts away manual helm install commands into an automated, trackable Codefresh pipeline execution.
"Install the standard Redis Helm 3 chart into the 'data-layer' namespace on the staging cluster."
To see the complete list of available operations, schemas, and required parameters, visit the Codefresh integration page.
Workflows in Action
By chaining these tools together, ChatGPT can act as a fully autonomous Site Reliability Engineer (SRE), investigating failures and rolling out fixes.
Scenario 1: Debugging and Restarting a Failed Build
When a critical CI pipeline breaks, developers usually have to context-switch into the Codefresh dashboard, find the logs, determine the failure point, and manually restart the build. ChatGPT can automate this entirely.
"Find the most recent failed build for the 'auth-service' pipeline. Tell me which step caused the failure, and if it looks like a transient network issue, trigger a rebuild."
list_all_codefresh_workflows: The agent queries recent builds, filtering for theauth-servicepipeline and looking for astatusoferror.- Analysis: The LLM inspects the
stepsarray in the returned payload. It identifies that a step namedpush-to-ecrfailed due to a timeout. get_single_codefresh_builds_rebuild_by_id: Since the failure matches a transient network pattern, the agent calls the rebuild tool, passing the ID of the failed workflow to trigger an exact retry.
Result: The user receives a concise summary of why the build failed and confirmation that a retry is already in progress, saving several minutes of manual investigation.
Scenario 2: Deploying a Helm Chart to Production
Platform teams often rely on manual CLI commands or complex UI navigation to deploy infrastructure components via Helm. ChatGPT can orchestrate this through natural language.
"Deploy the new ingress-nginx Helm chart to the production cluster. Once you trigger it, monitor the workflow until it succeeds."
sequenceDiagram participant User as User participant GPT as ChatGPT participant Truto as Truto MCP Server participant Codefresh as Codefresh API User->>GPT: Deploy Helm chart to production cluster GPT->>Truto: call list_all_codefresh_clusters Truto->>Codefresh: GET /api/clusters Codefresh-->>Truto: Return cluster list Truto-->>GPT: Identify 'prod-cluster' selector GPT->>Truto: call create_a_codefresh_install_helm_3 Truto->>Codefresh: POST /api/kubernetes/helm/install Codefresh-->>Truto: Return pipeline ID Truto-->>GPT: Pipeline ID received GPT->>Truto: call list_all_codefresh_workflows Truto->>Codefresh: GET /api/builds Codefresh-->>Truto: Return running status Truto-->>GPT: Status evaluated GPT-->>User: Deployment triggered. Status is Running.
list_all_codefresh_clusters: The agent first validates that the production cluster exists and retrieves its specific selector string.create_a_codefresh_install_helm_3: The agent submits the Helm install payload targeting the production selector and capturing the returned pipeline ID.list_all_codefresh_workflows: The agent polls the workflow endpoint using the pipeline ID to verify the Helm chart was successfully deployed.
Result: The LLM abstracts the complexity of cluster selectors and pipeline triggers, providing a conversational interface to infrastructure deployment.
Security and Access Control
Giving an AI agent access to your CI/CD pipelines and production clusters requires strict governance. Truto provides several mechanisms to lock down your Codefresh MCP servers:
- Method Filtering (
methods): Restrict an MCP server to only perform safe actions. Setmethods: ["read"]to allow the LLM to inspect builds and clusters without the ability to trigger deployments or delete resources. - Tag Filtering (
tags): Limit the scope of available tools based on resource tags. For example, settingtags: ["pipelines"]ensures the agent can interact with CI workflows but completely hides GitOps and Helm operations. - API Token Auth (
require_api_token_auth): By default, the Truto MCP URL acts as a bearer token. By enabling this flag, the client must also pass a valid Truto API token in theAuthorizationheader, adding a required secondary layer of authentication. - Auto-Expiration (
expires_at): Generate short-lived servers for temporary contractors or specific deployment windows. Once the ISO datetime is reached, the server and its underlying KV storage are automatically destroyed.
Orchestrate Codefresh with Truto
Building a custom integration layer to translate LLM tool calls into Codefresh's unique proxy endpoints and Kubernetes payloads is an expensive distraction from building your core product.
By leveraging Truto's dynamically generated MCP servers, you can instantly give ChatGPT secure, strongly-typed access to your pipelines, clusters, and GitOps deployments. Stop worrying about schema drift, authentication refreshes, and API routing.
Ready to connect Codefresh to your AI agents? Talk to our engineering team to see Truto's MCP servers in action. :::
FAQ
- Can I restrict ChatGPT to read-only access in Codefresh?
- Yes. When generating the MCP server via Truto, you can configure method filters to only allow 'read' operations. This ensures the LLM can list pipelines and check build statuses, but cannot trigger deployments or alter cluster configurations.
- How does Truto handle Codefresh API rate limits?
- Truto does not automatically retry or absorb rate limit errors. If the Codefresh API returns a 429 Too Many Requests, Truto passes the error back to the caller while normalizing the rate limit data into standard IETF headers. The caller must implement their own retry and backoff logic.
- How do MCP tools handle complex GitOps Argo CD manifests?
- Truto dynamically derives tool schemas from Codefresh's API documentation. For GitOps endpoints, Truto generates strict JSON schemas for the required Kubernetes Application manifests, ensuring the LLM understands exactly what fields are required before making a deployment request.
- Can I connect the Codefresh MCP server to other LLM frameworks besides ChatGPT?
- Yes. Because Truto outputs standard JSON-RPC 2.0 endpoints compliant with the Model Context Protocol, you can connect the server to Claude Desktop, Cursor, LangChain, or any custom AI agent framework that supports MCP.