On Tanzu Platform 10.3, the documented MCP service-publisher pattern runs an MCP server as an application, keeps it on the internal apps.internal domain, and exposes it to approved consumers through Tanzu Gateway. Teams create and bind a marketplace service; the application receives its gateway URL and API key through VCAP_SERVICES. This guide covers that workflow and the implementation and security choices around it.
Understand the Tanzu MCP gateway pattern
The service-publisher capability described by VMware Tanzu was introduced in Tanzu Platform 10.3. In this design, the MCP server is an application published as a Cloud Foundry Marketplace service, rather than a generic gateway product or a custom service broker. A Spring Cloud Gateway provides the consumer-facing route, while the MCP server remains internally routed on apps.internal. Network policy allows the gateway to reach the server, so consumers access it through the gateway rather than directly.
The flow has three distinct controls: internal routing limits where the server is reachable; network policy restricts the path to the gateway; and platform service access and binding determine which organizations and applications can use the published service. The Tanzu article describes the pattern and workflow in its January 23, 2026 article on building an enterprise MCP server marketplace.
Confirm your Tanzu release and prerequisites
Before implementing this workflow, confirm that the target installation is Tanzu Platform 10.3 or later and that the service-publisher capability is available under its entitlements and configuration. The cited Tanzu article links to a more detailed Broadcom technical guide, but the available source does not establish a complete prerequisite checklist or patch-level support matrix. Use the official documentation and Cloud Foundry CLI reference that match your installed platform version; do not assume every command or setting is identical across releases.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
Build and publish the MCP server application
The gateway does not implement MCP tools for you. First deploy an application that implements the MCP server and an appropriate transport. The Tanzu example publishes a service definition containing a name, description, and plans, including a standard plan. Its example command is:
cf publish-service customer-data-tools -f service.yaml
Treat this as the example syntax from the Tanzu article and validate it against the CLI and platform version in use. The pattern does not require writing custom service-broker code, but it does require the server application and its service definition.
Keep the MCP server on internal routing
In the described architecture, the server route uses the internal apps.internal domain. A Spring Cloud Gateway is provisioned alongside the published service, and network policy permits the gateway—not arbitrary external clients—to communicate with the MCP server. This is a platform-specific service-publisher design, not a universal behavior of every product called an MCP gateway.
Plan the boundary deliberately: decide whether the server should be internal-only, which organizations should be able to consume it, and how the gateway’s network path is constrained. Do not treat an API key by itself as proof of end-user authorization; the documented workflow also relies on Tanzu organization and space permissions.
Grant access to intended organizations
Published services are disabled by default in the described workflow. A platform administrator reviews the service and explicitly enables access for an intended organization, for example:
Rank #2
cf enable-service-access customer-data-tools -o product-team
This is an administrative approval step. Organization and space permissions determine who can create service instances and bind them to applications, so grant access only where the service is intended to be used.
Create an instance, bind it, and read its credentials
After access is enabled, a consumer creates a service instance and binds it to the application that needs MCP access:
cf create-service customer-data-tools standard my-customer-tools
cf bind-service my-agent-app my-customer-tools
In the Tanzu workflow, Gateway provisions a route and API key for the consumer. Restart the bound application so the binding values are made available to it. The gateway URL and credentials are injected in the application’s VCAP_SERVICES environment variable. Read the binding from the application runtime rather than embedding the API key in source code.
Choose an MCP server transport and Spring AI version
Select a transport compatible with both the MCP client and deployment topology. The Spring AI reference lists server starters for STDIO and HTTP transports, including SSE, Streamable-HTTP, and stateless Streamable-HTTP options, with choices depending on starter and configuration. STDIO and HTTP are not interchangeable deployment choices: select the mode the client supports and that fits how the server is hosted.
The Spring AI reference identifies itself as version 2.0.1. Spring AI 2.0 moved Spring-specific WebFlux and WebMVC MCP transports into the Spring AI project, changing Maven group IDs and Java packages for some transports. Older samples may therefore need dependency and import updates. For a Spring AI 2.0 application using the BOM or current starters, explicit versions for listed artifacts may not be necessary; verify the reference for the dependency set actually selected. See the Spring AI MCP server starter documentation.
Rank #3
A separate 2025 Broadcom Community example shows a Spring AI MCP server exposing Tanzu Application Catalog chart listing, metadata, and README tools. It is an implementation example, not a prerequisite for the gateway workflow: Building an MCP server for Tanzu Application Catalog.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Consider tool discovery for large tool sets
If an agent has many available tools, dynamic discovery can reduce the tool definitions sent up front. Spring reported preliminary token reductions of 34%–64% in tests using a 28-tool demo setup, comparing search-assisted tool selection with sending all tool definitions. The tests covered Gemini, OpenAI, and Anthropic models, but Spring’s author described the runs as manual, few, unaveraged, and illustrative rather than representative. These results are not a general performance guarantee, and tool discovery is not a security boundary. Details and qualifications are in Spring’s December 11, 2025 Tool Search Tool article.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsDisable access and retire the service
When deprecating a published service, the Tanzu article gives these lifecycle commands:
cf disable-service-access customer-data-tools
cf unpublish-service customer-data-tools
The described sequence disables new service access first; existing consumers may continue to use their bindings. Unpublishing removes the service from the marketplace. Check the behavior and impact on existing consumers against the installed platform release before making a production change.
Operational checks before rollout
- Release and capability: verify the installed Tanzu Platform release, entitlements, and version-matched service-publisher instructions.
- Server and transport: confirm the application implements the tools required and that its MCP transport matches the client and hosting topology.
- Network path: confirm the server is internally routed and the intended gateway is permitted to reach it.
- Access boundary: verify service access is enabled only for intended organizations and that org/space permissions match the consumers.
- Binding behavior: restart the consuming app after binding and confirm the gateway URL and credentials appear in
VCAP_SERVICES; keep credentials out of application source. - Retirement plan: identify existing consumers before disabling access or unpublishing, and validate release-specific effects.
- Dependency compatibility: check Spring AI version, artifact coordinates, and Java package names rather than copying an older sample unchanged.
A 2020 VMware Tanzu Team article discusses gateway configuration concepts such as client-certificate authorization, CORS allowed origins, header limits, timeouts, Application Security Groups, and isolation segments. It predates the Tanzu Platform 10.3 service-publisher workflow and does not establish current support or identical configuration syntax: Spring Cloud Gateway for VMware Tanzu configuration options.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

