devops-infra MCP Server
Model Context Protocol (MCP) server for Kubernetes and OpenShift
Discovered via github-topic:mcp and last synced 3mo ago.
1. Install the package
npx -y kubernetes-mcp-server@latest
2. Add to claude_desktop_config.json
{
"mcpServers": {
"kubernetes-mcp-server": {
"command": "npx",
"args": [
"kubernetes-mcp-server"
]
}
}
}Config file location: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) / %APPDATA%\Claude\claude_desktop_config.json (Windows)
(`string`) - End time for traces in microseconds since epoch (optional, defaults to 10 minutes after startMicros if not provided, only used when traceId is not provided)
List all available targets
(`string`) **(required)** - Container Image to run in the Pod
(`string`) - Time duration to fetch logs from (e.g., '5m', '1h', '30s'). If not provided, returns recent logs
Get the logs of a Kubernetes Pod in the current or provided namespace with the provided name
(`string`) - Name of the resource to get traces for. Required if traceId is not provided.
(`string`) - Start time for traces in microseconds since epoch (optional, defaults to 10 minutes before current time if not provided, only used when traceId is not provided)
(`string`) **(required)** - Chart reference to install (for example: stable/grafana, oci://ghcr.io/nginxinc/charts/nginx-ingress)
(`string`) - Type of resource to get traces for (app, service, workload). Required if traceId is not provided.
Gets traces for a specific resource (app, service, workload) in a namespace, or gets detailed information for a specific trace by its ID. If traceId is provided, it returns detailed trace information and other parameters are not required.
(`string`) - JSON string of tags to filter traces (optional, only used when traceId is not provided)
(`string`) - JSON data to apply or create the object
(`object`) - Values to pass to the Helm chart (Optional)
(`string`) **(required)** - Name or path of the workspace to describe
Get logs for a specific workload's pods in a namespace. Only requires namespace and workload name - automatically discovers pods and containers. Optionally filter by container name, time range, and other parameters. Container is auto-detected if not specified.
Returns the topology of a specific namespaces, health, status of the mesh and namespaces. Includes a mesh health summary overview with aggregated counts of healthy, degraded, and failing apps, workloads, and services. Use this for high-level overviews
(`integer`) - Minimum trace duration in microseconds (optional, only used when traceId is not provided)
Read-only Istio config: list or get objects. For action 'list', returns an array of objects with {name, namespace, type, validation}. For create, patch, or delete use manage_istio_config.
List the resource consumption (CPU and memory) as recorded by the Kubernetes Metrics Server for the specified Kubernetes Pods in the all namespaces, the provided namespace, or the current namespace
List all the Kubernetes namespaces in the current cluster
(`string`) **(required)** - Name of the TaskRun to get logs from
(`string`) - Namespace of the TaskRun
List the resource consumption (CPU and memory) as recorded by the Kubernetes Metrics Server for the specified Kubernetes Nodes or all nodes in the cluster
Get a Kubernetes Pod in the current or provided namespace with the provided name
Retrieves the high-level health, topology, and environment details of the Istio service mesh. Returns multi-cluster control plane status (istiod), data plane namespace health (including ambient mesh status), observability stack health (Prometheus, Grafana...), and component connectivity. Use this tool as the first step to diagnose mesh-wide issues, verify Istio/Kiali versions, or check overall health before drilling into specific workloads.
Get the current Kubernetes configuration content as a kubeconfig YAML
(`number`) - TCP/IP port to expose from the Pod container (Optional, no port exposed if not provided)
Create a KubeVirt VirtualMachine in the cluster with the specified configuration, automatically resolving instance types, preferences, and container disk images. VM will be created in Halted state by default; use autostart parameter to start it immediately.
List Kubernetes events (warnings, errors, state changes) for debugging and troubleshooting in the current cluster from all namespaces
List all available context names and associated server urls from the kubeconfig file
(`string`) - Optional workload size hint for the VM (e.g., 'small', 'medium', 'large', 'xlarge'). Used to auto-select an appropriate instance type if not explicitly specified.
(`integer`) - Number of lines to retrieve from the end of the logs (Optional, 0 means all logs)
Create or update a Kubernetes resource in the current cluster by providing a YAML or JSON representation of the resource
List all the Kubernetes pods in the current cluster from all namespaces
(`string`) - Complete JSON or YAML data to apply or create the object. Required for create and patch actions. You MUST provide a COMPLETE and VALID manifest with ALL required fields for the resource type. Arrays (like servers, http, etc.) are REPLACED entirely, so you must include ALL required fields within each array element.
Get the logs from a Tekton TaskRun by resolving its underlying pod
List Kubernetes resources and objects in the current cluster by providing their apiVersion and kind and optionally the namespace and label selector
List all available kcp workspaces in the current cluster
(`string`) - Time window used to compute CPU rate (Prometheus duration like '5m', '10m', '1h', '1d'). Defaults to '10m'.
(`string`) - Optional severity filter applied client-side. Accepts 'ERROR', 'WARN' or combinations like 'ERROR,WARN'.
(`string`) - Rate interval for metrics (e.g., '1m', '5m'). Optional, defaults to '10m'
(`string`) **(required)** - The name for the new cloned virtual machine
(`boolean`) - Return a minified version of the configuration. If set to true, keeps only the current-context and the relevant pieces of the configuration for that context. If set to false, all contexts, clusters, auth-infos, and users are returned in the configuration. (Optional, default true)
Get a Kubernetes resource in the current cluster by providing its apiVersion, kind, optionally the namespace, and its name
(`integer`) - Optional duration in seconds before the object should be deleted. Value must be non-negative integer. The value zero indicates delete immediately. If this value is nil, the default grace period for the specified type will be used
(`integer`) - Optional scale to update the resources scale to. If not provided, will return the current scale of the resource, and not update it
Uninstall a Helm release in the current or provided namespace
(`string`) - Comma-separated list of namespaces to query (e.g., 'bookinfo' or 'bookinfo,default'). If not provided, it will query across all accessible namespaces.
(`boolean`) - If true, only consider traces that contain errors. Default false.
(`string`) - Traffic direction. Optional, defaults to 'outbound'
>
Get logs from a Kubernetes node (kubelet, kube-proxy, or other system logs). This accesses node logs through the Kubernetes API proxy to the kubelet
Execute a command in a Kubernetes Pod (shell access, run commands in container) in the current or provided namespace with the provided name and command
(`string`) **(required)** - API group of the Istio object
Fetches a single distributed trace by trace_id and returns its call hierarchy (service tree with duration, status, and nested calls). Use this after list_traces to drill into a specific trace.
Get the logs of a Kubernetes Pod (or workload name that will be resolved to a pod) in a namespace. Output is plain text, matching kubernetes-mcp-server pods_log. The line_count field tells you the total number of log lines returned. Analyze ALL of them, but summarize the results unless the user explicitly asks for the raw output. Do not omit any error or warning lines.
List all the Kubernetes pods in the specified namespace in the current cluster
(`string`) - Granularity of the graph. 'app' aggregates by app name, 'versionedApp' separates by versions, 'workload' maps specific pods/deployments. Default: versionedApp.
(`string`) **(required)** - Name of the Istio object
List all the OpenShift projects in the current cluster
(`string`) **(required)** - apiVersion of the resource (examples of valid apiVersion are apps/v1)
Get or update the scale of a Kubernetes resource in the current cluster by providing its apiVersion, kind, name, and optionally the namespace. If the scale is set in the tool call, the scale will be updated to that value. Always returns the current scale of the resource
Get detailed information about a specific kcp workspace
(`string`) **(required)** - Service name to search traces for (required). Returns multiple traces up to limit.
(`string`) - Kubernetes Workload name (e.g. Deployment/StatefulSet/etc). Tool will look up the workload and pick one of its Pods. If not found, it will fall back to treating this value as a podName.
(`string`) - Metrics reporter(s). Comma-separated list of: 'source', 'destination', 'waypoint', or the special value 'both' (no reporter filter). Optional, defaults to 'source'. Example: 'source,waypoint'
(`string`) - Optional storage size for the VM's root disk when using DataSources (e.g., '30Gi', '50Gi', '100Gi'). Defaults to 30Gi. Ignored when using container disks.
(`string`) - Kubernetes label selector (e.g. 'app=myapp,env=prod' or 'app in (myapp,yourapp)'), use this option when you want to filter the pods by label (Optional, only applicable when name is not provided)
(`string`) - Optional. Name of the Pod container to get the logs from.
Run a Kubernetes Pod in the current or provided namespace with the provided container image and optional name
(`string`) - Optional Kubernetes label selector (e.g. 'app=myapp,env=prod' or 'app in (myapp,yourapp)'), use this option when you want to filter the resources by label
Delete a Kubernetes resource in the current cluster by providing its apiVersion, kind, optionally the namespace, and its name
(`boolean`) - If true, lists all Helm releases in all namespaces ignoring the namespace argument (Optional)
Lists distributed traces for a service in a namespace. Returns a summary (namespace, service, total_found, avg_duration_ms) and a list of traces with id, duration_ms, spans_count, root_op, slowest_service, has_errors. Use get_trace_details with a trace id to get full hierarchy.
Returns a human-readable text summary with current Pod CPU/memory usage (from Prometheus) compared to Kubernetes requests/limits (from the Pod spec). Useful to answer questions like 'Is this workload using too much memory?'
Install (deploy) a Helm chart to create a release in the current or provided namespace
(`string`) **(required)** - API version. Use 'v1' for VirtualService, DestinationRule, and Gateway.
(`integer`) - Maximum number of traces to return. Default 10.
(`string`) - Kubernetes Pod name. If workloadName is provided, the tool will attempt to resolve a Pod from that workload first.
Manage KubeVirt VirtualMachine lifecycle: start, stop, or restart a VM
Delete a Kubernetes Pod in the current or provided namespace with the provided name
(`array`) **(required)** - Command to execute in the Pod container. The first item is the command to be run, and the rest are the arguments to that command. Example: ["ls", "-l", "/tmp"]
(`integer`) - Number of lines to retrieve from the end of the logs (Optional, default: 100)
(`string`) **(required)** - A JSON or YAML containing a representation of the Kubernetes resource. Should include top-level fields such as apiVersion,kind,metadata, and spec
(`string`) **(required)** - Kind of the Istio object (e.g., 'VirtualService', 'DestinationRule').
List all the Helm releases in the current or provided namespace (or in all namespaces if specified)
Returns service-to-service traffic topology, dependencies, and network metrics (throughput, response time, mTLS) for the specified namespaces. Use this to diagnose routing issues, latency, or find upstream/downstream dependencies.
(`string`) **(required)** - Trace ID to fetch and summarize. If provided, namespace/service_name are ignored.
(`string`) - Cluster name to get metrics from. Optional, defaults to the cluster name in the Kiali configuration (KubeConfig)
Returns a compact JSON summary of Istio metrics (latency quantiles, traffic trends, throughput, payload sizes) for the given resource.
(`string`) **(required)** - Name of the resource to get metrics for
(`string`) - Optional instance type name for the VM (e.g., 'u1.small', 'u1.medium', 'u1.large')
Get guest operating system information from a VirtualMachine's QEMU guest agent. Requires the guest agent to be installed and running inside the VM. Provides detailed information about the OS, filesystems, network interfaces, and logged-in users.
Create, patch, or delete Istio config. For list and get (read-only) use manage_istio_config_read.
(`integer`) - How far back to search. Default 600 (10m).
(`string`) - Optional end timestamp (RFC3339) for the query. Defaults to now.
(`boolean`) - Optional. Return previous terminated container logs
(`string`) - Comma-separated list of quantiles for histogram metrics (e.g., '0.5,0.95,0.99'). Optional
(`string`) - Optional preference name for the VM
(`string`) **(required)** - The lifecycle action to perform: 'start' (changes runStrategy to Always), 'stop' (changes runStrategy to Halted), or 'restart' (stops then starts the VM)
(`string`) - Step between data points in seconds (e.g., '15'). Optional, defaults to 15 seconds
(`object`) - Parameter values to pass to the Task. Keys are parameter names; values can be a string, an array of strings, or an object (map of string to string) depending on the parameter type defined in the Task spec
(`string`) - The workload for the VM. Accepts OS names (e.g., 'fedora' (default), 'ubuntu', 'centos', 'centos-stream', 'debian', 'rhel', 'opensuse', 'opensuse-tumbleweed', 'opensuse-leap') or full container disk image URLs
(`string`) - Filter by request protocol (e.g., 'http', 'grpc', 'tcp'). Optional
(`boolean`) - Optional flag to automatically start the VM after creation (sets runStrategy to Always instead of Halted). Defaults to false.
Start a Tekton Pipeline by creating a PipelineRun that references it
>
(`string`) - Comma-separated list of labels to group metrics by (e.g., 'source_workload,destination_service'). Optional
(`string`) - Type of information to retrieve: 'all' (default - all available info), 'os' (operating system details), 'filesystem' (disk and filesystem info), 'users' (logged-in users), 'network' (network interfaces and IPs)
Restart a Tekton TaskRun by creating a new TaskRun with the same spec
Clone a KubeVirt VirtualMachine by creating a VirtualMachineClone resource. This creates a copy of the source VM with a new name using the KubeVirt Clone API
Restart a Tekton PipelineRun by creating a new PipelineRun with the same spec
Start a Tekton Task by creating a TaskRun that references it
(`string`) - Optional Kubernetes field selector to filter resources by field values (e.g. 'status.phase=Running', 'metadata.name=myresource'). Supported fields vary by resource type. For Pods: metadata.name, metadata.namespace, spec.nodeName, spec.restartPolicy, spec.schedulerName, spec.serviceAccountName, status.phase (Pending/Running/Succeeded/Failed/Unknown), status.podIP, status.nominatedNodeName. See https://kubernetes.io/docs/concepts/overview/working-with-objects/field-selectors/
(`string`) **(required)** - query specifies services(s) or files from which to return logs (required). Example: "kubelet" to fetch kubelet logs, "/<log-file-name>" to fetch a specific log file from the node (e.g., "/var/log/kubelet.log" or "/var/log/kube-proxy.log")
Get detailed resource usage statistics from a Kubernetes node via the kubelet's Summary API. Provides comprehensive metrics including CPU, memory, filesystem, and network usage at the node, pod, and container levels. On systems with cgroup v2 and kernel 4.20+, also includes PSI (Pressure Stall Information) metrics that show resource pressure for CPU, memory, and I/O. See https://kubernetes.io/docs/reference/instrumentation/understand-psi-metrics/ for details on PSI metrics
Fetches a list of resources OR retrieves detailed data for a specific resource. If 'resourceName' is omitted, it returns a list. If 'resourceName' is provided, it returns details for that specific resource.
(`string`) **(required)** - Type of resource to get metrics
(`string`) - Output formatting for chat. 'codeblock' wraps logs in ~~~ fences (recommended). 'plain' returns raw text like kubernetes-mcp-server pods_log.
(`array`) - Optional secondary network interfaces to attach to the VM. Each item specifies a Multus NetworkAttachmentDefinition to attach. Accepts either simple strings (NetworkAttachmentDefinition names) or objects with 'name' (interface name in VM) and 'networkName' (NetworkAttachmentDefinition name) properties. Each network creates a bridge interface on the VM.
(`string`) - Optional performance family hint for the VM instance type (e.g., 'u1' for general-purpose, 'o1' for overcommitted, 'c1' for compute-optimized, 'm1' for memory-optimized). Defaults to 'u1' (general-purpose) if not specified.
Detect and prevent privilege escalation in Kubernetes pods by monitoring security contexts, capabilities, and syscall patterns with Falco and OPA policies.
Detect container escape attempts in real-time using Falco runtime security rules that monitor syscalls, file access, and privilege escalation.
Detect unauthorized modifications to running containers by monitoring for binary execution drift, file system changes, and configuration deviations from the original container image.
Reduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.
ToolJet is the open-source foundation of ToolJet AI - the enterprise app generation platform for building internal tools, dashboard, business applications, workflows and AI agents 🚀
Secure, Fast, and Extensible Sandbox runtime for AI agents.
Next Generation Agentic Proxy for AI Agents and MCP servers
Learn Agentic AI using Dapr Agentic Cloud Ascent (DACA) Design Pattern and Agent-Native Cloud Technologies: OpenAI Agents SDK, Memory, MCP, A2A, Knowledge Graphs, Dapr, Rancher Desktop, and Kubernetes.
Learn how to use the docker-kubernetes Claude skill. Complete guide with installation instructions and examples.
Learn how to use the implementing-container-network-policies-with-calico Claude skill. Complete guide with installation instructions and examples.
Learn how to use the detecting-container-escape-attempts Claude skill. Complete guide with installation instructions and examples.