general MCP Server
Kubernetes-native AI platform for building, deploying, governing, and improving AI agents and ML models
Discovered via github-topic:mcp and last synced 3mo ago.
Install instructions not detected yet
Check the source repository for the latest setup steps.
Multi-tenant isolation with resource quotas
Purpose
Reusable agent templates
What it does
RBAC + ABAC policies
Agents discover and communicate with each other
Token and compute spend limits with alerts
What it shows
Real-time streaming from agent to UI via SSE
Agent configuration — model, skills, memory, guardrails, sandbox
Training and evaluation datasets
Environment promotion: dev → staging → prod
~3
Model registry — provider, version, routing
Input/output filtering and safety rules
Platform-wide defaults and configuration
Skill catalog with versioning
kagent
External data source connections
None built-in
RAG knowledge base configuration
A/B testing and canary rollouts for agents
Not supported
Scheduled backups with retention
What's in it
--- ## Project Structure ``` arcana/ ├── cmd/ # 19 Go service entrypoints │ ├── engine/ # Agent orchestration (LangGraph) │ ├── operator/ # Kubernetes CRD controller │ ├── mesh/ # A2A + ACP mesh gateway │ ├── api/ # REST/GraphQL API gateway │ ├── agui/ # AG-UI SSE streaming │ ├── codex-*/ # RAG pipeline services │ └── ... ├── pkg/ # Shared Go packages ├── services/ # Non-Go services │ ├── skills/ # Skill engine (Python/FastAPI) │ ├── ward/ # Guardrails pipeline (Python/FastAPI) │ ├── studio/ # Web UI (React + PatternFly 6) │ └── ... ├── deploy/ │ ├── crds/ # 16 CRD manifests │ ├── helm/ # Helm chart per service │ ├── compose/ # Backing services (Compose) │ └── kind/ # Local dev cluster config ├── examples/ # Ready-to-deploy agent configs ├── docs/ # Architecture, deployment, security ├── e2e/ # Playwright end-to-end tests └── Makefile # 25+ dev/build/test/deploy targets ``` ## Quick Reference
Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS
Reduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.
Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.
Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators
ToolJet is the open-source foundation of ToolJet AI - the enterprise app generation platform for building internal tools, dashboard, business applications, workflows and AI agents 🚀
Secure, Fast, and Extensible Sandbox runtime for AI agents.
Next Generation Agentic Proxy for AI Agents and MCP servers
Learn Agentic AI using Dapr Agentic Cloud Ascent (DACA) Design Pattern and Agent-Native Cloud Technologies: OpenAI Agents SDK, Memory, MCP, A2A, Knowledge Graphs, Dapr, Rancher Desktop, and Kubernetes.
Learn how to use the docker-kubernetes Claude skill. Complete guide with installation instructions and examples.
Learn how to use the implementing-container-network-policies-with-calico Claude skill. Complete guide with installation instructions and examples.
Learn how to use the detecting-container-escape-attempts Claude skill. Complete guide with installation instructions and examples.