mcp-kubernetes
A Model Context Protocol (MCP) server that enables AI assistants to interact with Kubernetes clusters. It serves as a bridge between AI tools (like Claude, Cursor, and GitHub Copilot) and Kubernetes
Documentation
mcp-kubernetes
The mcp-kubernetes is a Model Context Protocol (MCP) server that enables AI assistants to interact with Kubernetes clusters. It serves as a bridge between AI tools (like Claude, Cursor, and GitHub Copilot) and Kubernetes, translating natural language requests into Kubernetes operations and returning the results in a format the AI tools can understand.
It allows AI tools to:
- Query Kubernetes resources
- Execute kubectl commands
- Manage Kubernetes clusters through natural language interactions
- Diagnose and interpret the states of Kubernetes resources
How it works

How to install
Container images are no longer produced or supported. Install a released binary locally and configure your MCP client to run it as a stdio subprocess.
Local
Install kubectl
Install kubectl if it's not installed yet and add it to your PATH, e.g.
# For Linux
curl -LO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl"
# For MacOS
curl -LO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/darwin/arm64/kubectl"Install helm
Install helm if it's not installed yet and add it to your PATH, e.g.
curl -sSL https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bashConfig your MCP servers in Claude Desktop, Cursor, ChatGPT Copilot, Github Copilot and other supported AI clients, e.g.
{
"mcpServers": {
"kubernetes": {
"command": "",
"args": ["--transport", "stdio"],
"env": {
"KUBECONFIG": ""
}
}
}
}Options
Environment variables:
- `KUBECONFIG`: Path to your kubeconfig file, e.g. `/home//.kube/config`.
- `USE_LEGACY_TOOLS`: Set to `true` to use multiple specialized kubectl tools instead of the unified `call_kubectl` tool (default: `false`).
Command line arguments:
Usage of ./mcp-kubernetes:
--access-level string Access level (readonly, readwrite, or admin) (default "readonly")
--additional-tools string Comma-separated list of additional tools to support (kubectl is always enabled). Available: helm,cilium,hubble
--allow-namespaces string Comma-separated list of namespaces to allow (empty means all allowed)
--otlp-endpoint string OTLP endpoint for OpenTelemetry traces (e.g. localhost:4317, default "")
--timeout int Timeout for command execution in seconds, default is 60s (default 60)
--transport string Transport mechanism to use (stdio only) (default "stdio")Unified vs Legacy Tools
By default, mcp-kubernetes uses a single unified `call_kubectl` tool that consolidates all kubectl operations into one tool interface. This significantly reduces context consumption while maintaining full functionality.
To use the legacy mode with multiple specialized tools (6-7 separate tools), set the environment variable:
{
"mcpServers": {
"kubernetes": {
"command": "mcp-kubernetes",
"env": {
"USE_LEGACY_TOOLS": "true"
}
}
}
}Access Levels
The `--access-level` flag controls what operations are allowed:
- `readonly` (default): Only read operations are allowed (get, describe, logs, etc.)
- `readwrite`: Read and write operations are allowed (create, delete, apply, etc.)
- `admin`: All operations are allowed, including admin operations (cordon, drain, taint, etc.)
Tools and operations are filtered at registration time based on the access level, so AI assistants only see operations they can actually use.
Example configurations:
// Read-only access (default)
{
"mcpServers": {
"kubernetes": {
"command": "mcp-kubernetes"
}
}
}
// Read-write access
{
"mcpServers": {
"kubernetes": {
"command": "mcp-kubernetes",
"args": ["--access-level", "readwrite"]
}
}
}
// Admin access
{
"mcpServers": {
"kubernetes": {
"command": "mcp-kubernetes",
"args": ["--access-level", "admin"]
}
}
}Usage
Ask any questions about Kubernetes cluster in your AI client. The MCP tools make it easier for AI assistants to understand and use kubectl operations.
Example Queries
What is the status of my Kubernetes cluster?
What is wrong with my nginx pod?
Show me all deployments in the production namespace
Scale my web deployment to 5 replicas
Check if I have permission to create pods
What is my current kubectl context?
List all available kubectl contexts
Switch to the production contextAvailable Tools
Unified Tool (Default)
By default, mcp-kubernetes uses a single unified `call_kubectl` tool that handles all kubectl operations. This approach significantly reduces context consumption compared to the legacy multi-tool approach.
call_kubectl - Execute kubectl commands
- Available in: All access levels (operations filtered by access level)
- Parameters:
- `command`: The full kubectl command to execute including 'kubectl' prefix (e.g., "kubectl get pods -n default", "kubectl apply -f deployment.yaml")
- Examples:
# Get pods
command: "kubectl get pods -n default"
# Apply configuration
command: "kubectl apply -f deployment.yaml"
# Scale deployment
command: "kubectl scale deployment nginx --replicas=3"Legacy Tools (Optional)
When `USE_LEGACY_TOOLS=true`, the mcp-kubernetes server provides multiple specialized kubectl tools that group related operations together. Tools are automatically filtered based on your access level.
Kubectl Tools
kubectl_resources - Manage Kubernetes resources
Available in: readonly, readwrite, admin
Handles CRUD operations on Kubernetes resources and node management. In readonly mode, only supports `get` and `describe` operations. Node operations (cordon, uncordon, drain, taint) are available in admin mode only.
Parameters:
- `operation`: The operation to perform (get, describe, create, delete, apply, patch, replace, cordon, uncordon, drain, taint)
- `resource`: The resource type (e.g., pods, deployments, services, nodes) or empty for file-based operations
- `args`: Additional arguments like resource names, namespaces, and flags
Examples:
# Get all pods
operation: "get"
resource: "pods"
args: "--all-namespaces"
# Apply a configuration
operation: "apply"
resource: ""
args: "-f deployment.yaml"
# Drain a node (admin only)
operation: "drain"
resource: "node"
args: "worker-1 --ignore-daemonsets"
# Add a taint (admin only)
operation: "taint"
resource: "nodes"
args: "worker-1 key=value:NoSchedule"kubectl_workloads - Manage workload deployments
Available in: readwrite, admin
Manages deployment lifecycle operations including scaling and rollouts.
Parameters:
- `operation`: The operation to perform (run, expose, scale, autoscale, rollout)
- `resource`: For rollout operations, the subcommand (status, history, undo, restart, pause, resume)
- `args`: Additional arguments
Examples:
# Scale a deployment
operation: "scale"
resource: "deployment"
args: "nginx --replicas=3"
# Check rollout status
operation: "rollout"
resource: "status"
args: "deployment/nginx"kubectl_metadata - Manage resource metadata
Available in: readwrite, admin
Updates labels, annotations, and other metadata on resources.
Parameters:
- `operation`: The operation to perform (label, annotate, set)
- `resource`: The resource type
- `args`: Resource name and metadata changes
Examples:
# Add a label
operation: "label"
resource: "pods"
args: "nginx-pod app=web"
# Set image
operation: "set"
resource: "image"
args: "deployment/nginx nginx=nginx:latest"kubectl_diagnostics - Debug and monitor resources
Available in: readonly, readwrite, admin
Provides debugging and monitoring capabilities.
Parameters:
- `operation`: The operation to perform (logs, events, top, exec, cp)
- `resource`: The resource type or specific resource
- `args`: Additional arguments
Examples:
# View logs
operation: "logs"
resource: ""
args: "nginx-pod -f"
# Execute command in pod
operation: "exec"
resource: ""
args: "nginx-pod -- ls /app"kubectl_cluster - View cluster information
Available in: readonly, readwrite, admin
Provides cluster-level information and API discovery.
Parameters:
- `operation`: The operation to perform (cluster-info, api-resources, api-versions, explain)
- `resource`: For explain operation, the resource to document
- `args`: Additional flags
Examples:
# Get cluster info
operation: "cluster-info"
resource: ""
args: ""
# Explain pod spec
operation: "explain"
resource: "pod.spec"
args: "--recursive"kubectl_config - Configuration and security
Available in: readonly, readwrite, admin
Handles configuration validation, security operations, and kubectl context management. In readonly mode, supports `diff`, `auth can-i`, and read-only config operations.
Parameters:
- `operation`: The operation to perform (diff, auth, certificate, config)
- `resource`: Subcommand for auth/certificate/config operations
- `args`: Operation-specific arguments
Examples:
# Check permissions
operation: "auth"
resource: "can-i"
args: "create pods"
# Approve certificate
operation: "certificate"
resource: "approve"
args: "csr-name"
# Get current context
operation: "config"
resource: "current-context"
args: ""
# List all contexts
operation: "config"
resource: "get-contexts"
args: ""
# Switch context (readwrite/admin only)
operation: "config"
resource: "use-context"
args: "my-cluster-context"Config Operations:
- `current-context`: Display the current context (readonly, readwrite, admin)
- `get-contexts`: List all available contexts (readonly, readwrite, admin)
- `use-context`: Switch to a different context (readwrite, admin only)
Additional Tools
call_helm - Helm package manager
Available when: `--additional-tools=helm` is specified
Run Helm commands for managing Kubernetes applications.
Parameters:
- `command`: The helm command to execute
Example:
command: "list --all-namespaces"call_cilium - Cilium CNI commands
Available when: `--additional-tools=cilium` is specified
Run Cilium commands for network policies and observability.
Parameters:
- `command`: The cilium command to execute
Example:
command: "status"call_hubble - Hubble observability commands
Available when: `--additional-tools=hubble` is specified
Run Hubble commands for network monitoring and debugging in Cilium-enabled clusters.
Parameters:
- `command`: The hubble command to execute
Example:
command: "status"
command: "observe observe --namespace backend-jobs --from-label 'app=web'"
command: "list nodes"Telemetry
Telemetry collection is on by default.
To opt out, set the environment variable `KUBERNETES_MCP_COLLECT_TELEMETRY=false`.
OpenTelemetry Support
The mcp-kubernetes server supports exporting telemetry data using OpenTelemetry Protocol (OTLP). You can configure an OTLP endpoint to send traces to any OpenTelemetry-compatible backend:
{
"mcpServers": {
"kubernetes": {
"command": "mcp-kubernetes",
"args": ["--otlp-endpoint", "localhost:4317"]
}
}
}Development
How to inspect MCP server requests and responses:
npx @modelcontextprotocol/inspectorContributing
This project welcomes contributions and suggestions. Most contributions require you to agree to a Contributor License Agreement (CLA) declaring that you have the right to, and actually do, grant us the rights to use your contribution. For details, visit https://cla.opensource.microsoft.com.
When you submit a pull request, a CLA bot will automatically determine whether you need to provide a CLA and decorate the PR appropriately (e.g., status check, comment). Simply follow the instructions provided by the bot. You will only need to do this once across all repos using our CLA.
This project has adopted the Microsoft Open Source Code of Conduct. For more information see the Code of Conduct FAQ or contact opencode@microsoft.com with any additional questions or comments.
Trademarks
This project may contain trademarks or logos for projects, products, or services. Authorized use of Microsoft trademarks or logos is subject to and must follow Microsoft's Trademark & Brand Guidelines. Use of Microsoft trademarks or logos in modified versions of this project must not cause confusion or imply Microsoft sponsorship. Any use of third-party trademarks or logos are subject to those third-party's policies.
Frequently asked questions
What is mcp-kubernetes?
mcp-kubernetes is A Model Context Protocol (MCP) server that enables AI assistants to interact with Kubernetes clusters. It serves as a bridge between AI tools (like Claude, Cursor, and GitHub Copilot) and Kubernetes
How do I install mcp-kubernetes?
Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.
Is mcp-kubernetes open source?
Yes — it is hosted on GitHub at https://github.com/Azure/mcp-kubernetes and has 61 stars.
Related MCP tools
The missing open-source Kubernetes UI with a built-in MCP server for AI agents. See what's broken, why, and what changed. Issues, Topology, event timeline, Helm, GitOps, live service traffic, and cluster audits - all in one Go binary.
mcp-language-server gives MCP enabled clients access semantic tools like get definition, references, rename, and diagnostics.
One place to manage & connect to all your MCP servers
eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via MCP and humans via dashboard.
Run MATLAB® using AI applications with the official MATLAB MCP Server from MathWorks®. This MCP server for MATLAB supports a wide range of coding agents like Claude Code® and Visual Studio® Code.
ToolHive makes deploying MCP servers easy, secure and fun Go-based implementation. Trusted by 1300+ developers. Trusted by 1300+ developers.
Run your own MCP server? See who uses it and what to fix.
Measure it with TrackMCP