Skip to content

Connect Codefresh to ChatGPT: Orchestrate CI/CD and Clusters

Learn how to connect Codefresh to ChatGPT using a managed MCP server. Automate CI/CD pipelines, GitOps workflows, and Kubernetes clusters with AI agents.

Roopendra Talekar Roopendra Talekar · · 10 min read
Connect Codefresh to ChatGPT: Orchestrate CI/CD and Clusters

If you need to connect Codefresh to ChatGPT to automate CI/CD workflows, manage Kubernetes clusters, or orchestrate GitOps deployments, you need a Model Context Protocol (MCP) server. This server acts as the translation layer between ChatGPT's tool calls and Codefresh's REST APIs. You can either build and maintain this infrastructure yourself, or use a managed integration platform like Truto to dynamically generate a secure, authenticated MCP server URL.

If your team uses Claude, check out our guide on connecting Codefresh to Claude or explore our broader architectural overview on connecting Codefresh to AI Agents.

Giving a Large Language Model (LLM) read and write access to a complex CI/CD and GitOps platform like Codefresh is a massive engineering challenge. You have to handle opaque Kubernetes proxy endpoints, URL-encoded resource identifiers, and deeply nested Argo CD application manifests. Every time a developer adds a new pipeline or cluster, your custom server code must interpret those changes securely.

This guide breaks down exactly how to use Truto to generate a secure, managed MCP server for Codefresh, connect it natively to ChatGPT, and execute complex deployment workflows using natural language.

Stop writing boilerplate API integration code. Let Truto generate secure, managed MCP servers for your AI agents in seconds. :::

The Engineering Reality of the Codefresh API

A custom MCP server is a self-hosted integration layer. While the open MCP standard provides a predictable way for models to discover tools, implementing it against Codefresh's highly specific deployment API is exceptionally painful.

If you decide to build a custom MCP server for Codefresh, you own the entire API lifecycle. Here are the specific integration challenges that break standard CRUD assumptions when working with Codefresh:

Opaque Kubernetes Proxy Endpoints

Unlike standard SaaS platforms with predictable JSON schemas, Codefresh heavily utilizes proxy paths (e.g., /api/clusters/* and /api/kubernetes/*) to communicate directly with connected Kubernetes clusters. These endpoints act as pass-through mechanisms. If an LLM calls a proxy endpoint to retrieve a deployment status, the response schema is completely opaque to Codefresh - it depends entirely on the specific Kubernetes provider and version being queried. Hardcoding static MCP tool schemas for these endpoints is impossible, requiring your server to dynamically interpret varying Kubernetes API responses on the fly.

Deeply Nested GitOps Manifests

Codefresh's GitOps functionality (powered by Argo CD) is managed via the Environments V2 API. When creating or updating a GitOps application, the API requires a complex, multi-layered Kubernetes Application manifest nested inside a JSON payload containing kind, metadata, and spec objects. If you rely on an LLM to generate this payload from scratch without strict schema guardrails, it will inevitably hallucinate fields, leading to failed deployments or misconfigured clusters. Your MCP server must heavily validate these manifests before passing them upstream.

URL-Encoded Resource Identifiers

Codefresh has a unique routing quirk: many endpoints addressing pipelines or projects accept either a MongoDB object ID or an escaped full name. For example, addressing a pipeline often requires formatting the identifier as projectName%2FpipelineName. If an LLM attempts to pass projectName/pipelineName without properly URL-encoding the slash, the API router will misinterpret the path and drop a 404 Not Found error. Your custom MCP server must implement a middleware layer specifically to detect and encode these specific Codefresh identifiers.

Factual Note on Rate Limits

When orchestrating high-volume CI/CD tasks, API rate limits are a reality. It is important to note that Truto does not retry, throttle, or apply backoff on rate limit errors. When the upstream Codefresh API returns an HTTP 429 Too Many Requests, Truto passes that error directly to the caller. Truto normalizes upstream rate limit info into standardized headers (ratelimit-limit, ratelimit-remaining, ratelimit-reset) per the IETF specification. The caller (your LLM client or orchestrator) is entirely responsible for retry and backoff logic.

Generating a Codefresh MCP Server

Truto handles the authentication, schema generation, and routing by generating a secure, tokenized MCP server scoped to a single connected Codefresh account. You can create this server using either the Truto UI or the REST API.

Method 1: Via the Truto UI

For teams who prefer a visual setup, generating an MCP server takes just a few clicks:

  1. Log into your Truto account and navigate to your connected Integrated Accounts.
  2. Select your connected Codefresh account to open its detail page.
  3. Click the MCP Servers tab.
  4. Click the Create MCP Server button.
  5. Select your desired configuration (e.g., restrict to read-only methods or filter by tags like pipelines or clusters).
  6. Copy the generated MCP server URL. Treat this URL like a secure credential - it contains a cryptographic token that authenticates requests to this specific Codefresh workspace.

Method 2: Via the Truto API

For engineering teams automating their infrastructure, you can generate MCP servers programmatically. This is ideal for provisioning ephemeral agents for specific deployment tasks.

Make a POST request to /integrated-account/:id/mcp using your Truto API token:

curl -X POST https://api.truto.one/integrated-account/$INTEGRATED_ACCOUNT_ID/mcp \
  -H "Authorization: Bearer $TRUTO_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Codefresh DevOps Agent",
    "config": {
      "methods": ["read", "write", "custom"],
      "tags": ["pipelines", "clusters", "environments"]
    }
  }'

The API returns a payload containing the unique server URL:

{
  "id": "mcp_abc123",
  "name": "Codefresh DevOps Agent",
  "config": { ... },
  "expires_at": null,
  "url": "https://api.truto.one/mcp/a1b2c3d4e5f67890"
}

Connecting the MCP Server to ChatGPT

Once you have your Truto MCP URL, you can connect it directly to ChatGPT so your AI agent can begin discovering tools and interacting with Codefresh.

Method 1: Via the ChatGPT UI

If you are using ChatGPT via the web interface (requires a Pro, Plus, Business, Enterprise, or Education seat with Developer mode enabled):

  1. In ChatGPT, navigate to Settings -> Apps -> Advanced settings.
  2. Enable Developer mode.
  3. Under MCP servers / Custom connectors, click to add a new server.
  4. Set the Name to something descriptive (e.g., "Codefresh CI/CD").
  5. Paste the Truto MCP URL into the Server URL field.
  6. Click Add or Save.

ChatGPT will immediately perform a handshake with the Truto server, fetch the allowed tools, and make them available to the model.

Method 2: Via Manual Configuration File

If you are running your own local agent, using Claude Desktop, or using an IDE like Cursor, you can connect the MCP server using a JSON configuration file and the standard Server-Sent Events (SSE) transport.

Add the following configuration to your mcp.json or respective configuration file:

{
  "mcpServers": {
    "codefresh_devops": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-sse",
        "--url",
        "https://api.truto.one/mcp/a1b2c3d4e5f67890"
      ]
    }
  }
}

Codefresh Hero Tools for ChatGPT

Truto automatically derives tool schemas from the Codefresh API documentation, handling the conversion into JSON-RPC formats. Here are the highest-leverage tools your ChatGPT agent can use to orchestrate CI/CD workflows.

list_all_codefresh_pipelines

Description: Retrieves a list of pipelines in the Codefresh account, optionally filtered by project, labels, or execution context. Returns pipeline metadata, triggers, steps, and last-executed timestamps.

Usage Notes: This is the primary discovery tool for an AI agent to figure out which pipelines exist before attempting to run or modify them. Agents can use this to map out the CI/CD landscape.

"List all the pipelines in the 'production-deployments' project and tell me when they were last executed."

create_a_codefresh_pipelines_run

Description: Triggers a run of a Codefresh pipeline to start a new build. Can also be used to restart a previous build by passing its ID in the previousWorkflow parameter.

Usage Notes: The core execution tool. The agent can inject environment variables into the run by formatting them in the request body, allowing dynamic deployments based on conversational context.

"Trigger the 'frontend-release' pipeline, and pass the variable 'VERSION=v2.4.1' into the build context."

list_all_codefresh_workflows

Description: Lists Codefresh workflow builds in a paginated way. Returns the build ID, status (e.g., success, error, running), start/finish timestamps, branches, and executed steps.

Usage Notes: After triggering a pipeline, the agent uses this tool to poll for status updates or investigate why a recent deployment failed by inspecting the step statuses.

"Check the status of the most recent workflows for the backend service. Did any of them fail at the integration testing step?"

list_all_codefresh_clusters

Description: Retrieves a list of all Kubernetes clusters connected to the Codefresh account. Returns a JSON payload detailing cluster names, providers, and integration statuses.

Usage Notes: Essential for GitOps and infrastructure agents. It allows the LLM to verify that a target cluster is healthy and accessible before attempting to deploy a Helm chart or Argo application to it.

"List all connected Kubernetes clusters and confirm if the 'aws-us-east-prod' cluster is actively responding."

list_all_codefresh_gitops_applications

Description: Lists Codefresh GitOps (Argo CD) applications. Returns the application manifest including kind, metadata, and spec details.

Usage Notes: Allows the agent to audit current GitOps states. Because GitOps apps define the desired state of the cluster, the LLM can compare this output against actual cluster health to detect configuration drift.

"Retrieve the GitOps application manifest for the 'payment-gateway' service and show me which target revision it is synced to."

create_a_codefresh_install_helm_3

Description: Installs a Helm 3 chart in Codefresh by triggering the internal pipeline that executes the Helm release. Returns the ID of the running pipeline.

Usage Notes: A powerful orchestration tool. The agent requires the cluster selector and target namespace. This abstracts away manual helm install commands into an automated, trackable Codefresh pipeline execution.

"Install the standard Redis Helm 3 chart into the 'data-layer' namespace on the staging cluster."

To see the complete list of available operations, schemas, and required parameters, visit the Codefresh integration page.

Workflows in Action

By chaining these tools together, ChatGPT can act as a fully autonomous Site Reliability Engineer (SRE), investigating failures and rolling out fixes.

Scenario 1: Debugging and Restarting a Failed Build

When a critical CI pipeline breaks, developers usually have to context-switch into the Codefresh dashboard, find the logs, determine the failure point, and manually restart the build. ChatGPT can automate this entirely.

"Find the most recent failed build for the 'auth-service' pipeline. Tell me which step caused the failure, and if it looks like a transient network issue, trigger a rebuild."

  1. list_all_codefresh_workflows: The agent queries recent builds, filtering for the auth-service pipeline and looking for a status of error.
  2. Analysis: The LLM inspects the steps array in the returned payload. It identifies that a step named push-to-ecr failed due to a timeout.
  3. get_single_codefresh_builds_rebuild_by_id: Since the failure matches a transient network pattern, the agent calls the rebuild tool, passing the ID of the failed workflow to trigger an exact retry.

Result: The user receives a concise summary of why the build failed and confirmation that a retry is already in progress, saving several minutes of manual investigation.

Scenario 2: Deploying a Helm Chart to Production

Platform teams often rely on manual CLI commands or complex UI navigation to deploy infrastructure components via Helm. ChatGPT can orchestrate this through natural language.

"Deploy the new ingress-nginx Helm chart to the production cluster. Once you trigger it, monitor the workflow until it succeeds."

sequenceDiagram
  participant User as User
  participant GPT as ChatGPT
  participant Truto as Truto MCP Server
  participant Codefresh as Codefresh API
  User->>GPT: Deploy Helm chart to production cluster
  GPT->>Truto: call list_all_codefresh_clusters
  Truto->>Codefresh: GET /api/clusters
  Codefresh-->>Truto: Return cluster list
  Truto-->>GPT: Identify 'prod-cluster' selector
  GPT->>Truto: call create_a_codefresh_install_helm_3
  Truto->>Codefresh: POST /api/kubernetes/helm/install
  Codefresh-->>Truto: Return pipeline ID
  Truto-->>GPT: Pipeline ID received
  GPT->>Truto: call list_all_codefresh_workflows
  Truto->>Codefresh: GET /api/builds
  Codefresh-->>Truto: Return running status
  Truto-->>GPT: Status evaluated
  GPT-->>User: Deployment triggered. Status is Running.
  1. list_all_codefresh_clusters: The agent first validates that the production cluster exists and retrieves its specific selector string.
  2. create_a_codefresh_install_helm_3: The agent submits the Helm install payload targeting the production selector and capturing the returned pipeline ID.
  3. list_all_codefresh_workflows: The agent polls the workflow endpoint using the pipeline ID to verify the Helm chart was successfully deployed.

Result: The LLM abstracts the complexity of cluster selectors and pipeline triggers, providing a conversational interface to infrastructure deployment.

Security and Access Control

Giving an AI agent access to your CI/CD pipelines and production clusters requires strict governance. Truto provides several mechanisms to lock down your Codefresh MCP servers:

  • Method Filtering (methods): Restrict an MCP server to only perform safe actions. Set methods: ["read"] to allow the LLM to inspect builds and clusters without the ability to trigger deployments or delete resources.
  • Tag Filtering (tags): Limit the scope of available tools based on resource tags. For example, setting tags: ["pipelines"] ensures the agent can interact with CI workflows but completely hides GitOps and Helm operations.
  • API Token Auth (require_api_token_auth): By default, the Truto MCP URL acts as a bearer token. By enabling this flag, the client must also pass a valid Truto API token in the Authorization header, adding a required secondary layer of authentication.
  • Auto-Expiration (expires_at): Generate short-lived servers for temporary contractors or specific deployment windows. Once the ISO datetime is reached, the server and its underlying KV storage are automatically destroyed.

Orchestrate Codefresh with Truto

Building a custom integration layer to translate LLM tool calls into Codefresh's unique proxy endpoints and Kubernetes payloads is an expensive distraction from building your core product.

By leveraging Truto's dynamically generated MCP servers, you can instantly give ChatGPT secure, strongly-typed access to your pipelines, clusters, and GitOps deployments. Stop worrying about schema drift, authentication refreshes, and API routing.

Ready to connect Codefresh to your AI agents? Talk to our engineering team to see Truto's MCP servers in action. :::

FAQ

Can I restrict ChatGPT to read-only access in Codefresh?
Yes. When generating the MCP server via Truto, you can configure method filters to only allow 'read' operations. This ensures the LLM can list pipelines and check build statuses, but cannot trigger deployments or alter cluster configurations.
How does Truto handle Codefresh API rate limits?
Truto does not automatically retry or absorb rate limit errors. If the Codefresh API returns a 429 Too Many Requests, Truto passes the error back to the caller while normalizing the rate limit data into standard IETF headers. The caller must implement their own retry and backoff logic.
How do MCP tools handle complex GitOps Argo CD manifests?
Truto dynamically derives tool schemas from Codefresh's API documentation. For GitOps endpoints, Truto generates strict JSON schemas for the required Kubernetes Application manifests, ensuring the LLM understands exactly what fields are required before making a deployment request.
Can I connect the Codefresh MCP server to other LLM frameworks besides ChatGPT?
Yes. Because Truto outputs standard JSON-RPC 2.0 endpoints compliant with the Model Context Protocol, you can connect the server to Claude Desktop, Cursor, LangChain, or any custom AI agent framework that supports MCP.

More from our Blog