ECC
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
npx ecc-install --profile fullThe agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
npx ecc-install --profile fullFair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
npx n8nAn open-source AI agent that brings the power of Gemini directly into your terminal.
npx @google/gemini-cliSupports Claude Code, Cursor, Mcp
Carries strong trust indicators from repository metadata
1784 GitHub stars recorded
The Kubernetes MCP server supports enabling or disabling specific groups of tools and functionalities (tools, resources, prompts, and so on) via the --toolsets command-line flag or toolsets configuration option.
This allows you to control which Kubernetes functionalities are available to your AI tools.
Enabling only the toolsets you need can help reduce the context size and improve the LLM's tool selection accuracy.
The following CNCF and Kubernetes ecosystem projects are covered by
automated evaluation scenarios in evals/tasks. Most scenarios
work with just the core toolset. The dedicated toolsets below are optional
and only needed for the project-specific scenarios noted.
| Project | Optional toolset(s) | Eval scenarios |
|---|---|---|
| Helm | helm | 3 |
| Istio | kiali | 5 |
| Kiali | kiali | 16 |
| Kubernetes | - | 32 |
| KubeVirt | kubevirt, tekton | 19 |
| Tekton | tekton | 9 |
The following sets of tools are available (toolsets marked with β in the Default column are enabled by default):
| Toolset | Description | Default |
|---|---|---|
| config | View and manage the current local Kubernetes configuration (kubeconfig) | β |
| core | Most common tools for Kubernetes management (Pods, Generic Resources, Events, etc.) | β |
| helm | Tools for managing Helm charts and releases | |
| kcp | Manage kcp workspaces and multi-tenancy features | |
| kiali | Most common tools for managing Kiali, check the Kiali documentation for more details. | |
| kubevirt | KubeVirt virtual machine management tools, check the KubeVirt documentation for more details. | |
| tekton | Tekton pipeline management tools for Pipelines, PipelineRuns, Tasks, and TaskRuns. |
In case multi-cluster support is enabled (default) and you have access to multiple clusters, all applicable tools will include an additional context argument to specify the Kubernetes context (cluster) to use for that operation.
configuration_contexts_list - List all available context names and associated server urls from the kubeconfig file
targets_list - List all available targets
configuration_view - Get the current Kubernetes configuration content as a kubeconfig YAML
minified (boolean) - Return a minified version of the configuration. If set to true, keeps only the current-context and the relevant pieces of the configuration for that context. If set to false, all contexts, clusters, auth-infos, and users are returned in the configuration. (Optional, default true)events_list - List Kubernetes events (warnings, errors, state changes) for debugging and troubleshooting in the current cluster from all namespaces
fieldSelector (string) - Optional Kubernetes field selector to filter events by field values (e.g. 'type=Warning', 'involvedObject.name=my-pod'). Supported fields: involvedObject.kind, involvedObject.name, involvedObject.namespace, involvedObject.uid, involvedObject.apiVersion, involvedObject.resourceVersion, involvedObject.fieldPath, reason, reportingComponent, source, type. See https://kubernetes.io/docs/concepts/overview/working-with-objects/field-selectors/namespace (string) - Optional Namespace to retrieve the events from. If not provided, will list events from all namespacesnamespaces_list - List all the Kubernetes namespaces in the current cluster
fieldSelector (string) - Optional Kubernetes field selector to filter namespaces by field values (e.g. 'metadata.name=default', 'status.phase=Active'). Supported fields: metadata.name, status.phase. See https://kubernetes.io/docs/concepts/overview/working-with-objects/field-selectors/projects_list - List all the OpenShift projects in the current cluster
nodes_log - Get logs from a Kubernetes node (kubelet, kube-proxy, or other system logs). This accesses node logs through the Kubernetes API proxy to the kubelet
name (string) (required) - Name of the node to get logs fromhelm_install - Install (deploy) a Helm chart to create a release in the current or provided namespace
chart (string) (required) - Chart reference to install (for example: stable/grafana, oci://ghcr.io/nginxinc/charts/nginx-ingress)name (string) - Name of the Helm release (Optional, random name if not provided)namespace (string) - Namespace to install the Helm chart in (Optional, current namespace if not provided)values (object) - Values to pass to the Helm chart (Optional)helm_list - List all the Helm releases in the current or provided namespace (or in all namespaces if specified)
all_namespaces (boolean) - If true, lists all Helm releases in all namespaces ignoring the namespace argument (Optional)namespace (string) - Namespace to list Helm releases from (Optional, all namespaces if not provided)helm_uninstall - Uninstall a Helm release in the current or provided namespace
name (string) (required) - Name of the Helm release to uninstallnamespace (string) - Namespace to uninstall the Helm release from (Optional, current namespace if not provided)kcp_workspaces_list - List all available kcp workspaces in the current cluster
kcp_workspace_describe - Get detailed information about a specific kcp workspace
workspace (string) (required) - Name or path of the workspace to describekiali_get_mesh_traffic_graph - Returns service-to-service traffic topology, dependencies, and network metrics (throughput, response time, mTLS) for the specified namespaces. Use this to diagnose routing issues, latency, or find upstream/downstream dependencies.
clusterName (string) - Optional cluster name to include in the graph. Default is the cluster name in the Kiali configuration (KubeConfig).graphType (string) - Granularity of the graph. 'app' aggregates by app name, 'versionedApp' separates by versions, 'workload' maps specific pods/deployments. Default: versionedApp.namespaces (string) (required) - Comma-separated list of namespaces to mapkiali_get_mesh_status - Retrieves the high-level health, topology, and environment details of the Istio service mesh. Returns multi-cluster control plane status (istiod), data plane namespace health (including ambient mesh status), observability stack health (Prometheus, Grafana...), and component connectivity. Use this tool as the first step to diagnose mesh-wide issues, verify Istio/Kiali versions, or check overall health before drilling into specific workloads.
kiali_manage_istio_config_read - Read-only Istio config: list or get objects. For action 'list', returns an array of objects with {name, namespace, type, validation}. For create, patch, or delete use manage_istio_config.
action (string) (required) - Action to perform (read-only)clusterName (string) - Optional cluster name. Defaults to the cluster name in the Kiali configuration.group (string) - API group of the Istio object. Required for 'get' action.vm_clone - Clone a KubeVirt VirtualMachine by creating a VirtualMachineClone resource. This creates a copy of the source VM with a new name using the KubeVirt Clone API
name (string) (required) - The name of the source virtual machine to clonenamespace (string) (required) - The namespace of the source virtual machinetargetName (string) (required) - The name for the new cloned virtual machinevm_create - Create a KubeVirt VirtualMachine in the cluster with the specified configuration, automatically resolving instance types, preferences, and container disk images. VM will be created in Halted state by default; use autostart parameter to start it immediately.
autostart (boolean) - Optional flag to automatically start the VM after creation (sets runStrategy to Always instead of Halted). Defaults to false.instancetype (string) - Optional instance type name for the VM (e.g., 'u1.small', 'u1.medium', 'u1.large')name (string) (required) - The name of the virtual machinenamespace (string) (required) - The namespace for the virtual machinenetworks (array) - Optional secondary network interfaces to attach to the VM. Each item specifies a Multus NetworkAttachmentDefinition to attach. Accepts either simple strings (NetworkAttachmentDefinition names) or objects with 'name' (interface name in VM) and 'networkName' (NetworkAttachmentDefinition name) properties. Each network creates a bridge interface on the VM.tekton_pipeline_start - Start a Tekton Pipeline by creating a PipelineRun that references it
name (string) (required) - Name of the Pipeline to startnamespace (string) - Namespace of the Pipelineparams (object) - Parameter values to pass to the Pipeline. Keys are parameter names; values can be a string, an array of strings, or an object (map of string to string) depending on the parameter type defined in the Pipeline spectekton_pipelinerun_restart - Restart a Tekton PipelineRun by creating a new PipelineRun with the same spec
name (string) (required) - Name of the PipelineRun to restartnamespace (string) - Namespace of the PipelineRuntekton_task_start - Start a Tekton Task by creating a TaskRun that references it
name (string) (required) - Name of the Task to startnamespace (string) - Namespace of the Taskparams (object) - Parameter values to pass to the Task. Keys are parameter names; values can be a string, an array of strings, or an object (map of string to string) depending on the parameter type defined in the Task specnamespace (string) - Optional namespace to limit health check scope (default: all namespaces)check_events (string) - Include recent warning/error events (true/false, default: true)mesh-list-applications - List applications in the mesh namespaces
namespace (string) - Optional namespace to filter applications (default: all namespaces)list-istio-config - List Istio configuration resources in the mesh namespaces
namespace (string) - Optional namespace to filter Istio configuration (default: all namespaces)mesh-list-namespaces - List all namespaces with their sidecar injection status and Istio labels
mesh-list-services - List services in the mesh namespaces
namespace (string) - Optional namespace to filter services (default: all namespaces)mesh-list-workloads - List workloads in the mesh namespaces
namespace (string) - Optional namespace to filter workloads (default: all namespaces)mesh-health-check - Perform a comprehensive health assessment of the Istio service mesh including control plane and data plane status
namespace (string) - Optional namespace to focus the health check on (default: all namespaces)mesh-topology - Show the mesh topology including control plane components and cluster connectivity
traffic-topology - Analyze the service mesh traffic topology showing service dependencies, traffic flow, and communication patterns
namespaces (string) - Comma-separated list of namespaces to include in the graph, or 'all' to include all accessible mesh namespacesvm-troubleshoot - Generate a step-by-step troubleshooting guide for diagnosing KubeVirt VirtualMachine issues
namespace (string) (required) - The namespace of the VirtualMachine to troubleshootname (string) (required) - The name of the VirtualMachine to troubleshootwindows-golden-image - Guides creation of a Windows golden image via the KubeVirt windows-efi-installer Tekton pipeline
winImageDownloadURL (string) (required) - Microsoft Windows ISO download URL (must be https://)namespace (string) - Target namespace for the PipelineRunwindowsVersion (string) - Windows version: 10, 11, 2k22 (default), or 2k25pipelineVersion (string) - Pipeline version (default: latest). Use specific version like 0.25.0 if neededA powerful and flexible Kubernetes Model Context Protocol (MCP) server implementation with support for Kubernetes and OpenShift.
.kube/config or in-cluster configuration.querystringtailLines (integer) - Number of lines to retrieve from the end of the logs (Optional, 0 means all logs)nodes_stats_summary - Get detailed resource usage statistics from a Kubernetes node via the kubelet's Summary API. Provides comprehensive metrics including CPU, memory, filesystem, and network usage at the node, pod, and container levels. On systems with cgroup v2 and kernel 4.20+, also includes PSI (Pressure Stall Information) metrics that show resource pressure for CPU, memory, and I/O. See https://kubernetes.io/docs/reference/instrumentation/understand-psi-metrics/ for details on PSI metrics
name (string) (required) - Name of the node to get stats fromnodes_top - List the resource consumption (CPU and memory) as recorded by the Kubernetes Metrics Server for the specified Kubernetes Nodes or all nodes in the cluster
label_selector (string) - Kubernetes label selector (e.g. 'node-role.kubernetes.io/worker=') to filter nodes by label (Optional, only applicable when name is not provided)name (string) - Name of the Node to get the resource consumption from (Optional, all Nodes if not provided)pods_list - List all the Kubernetes pods in the current cluster from all namespaces
fieldSelector (string) - Optional Kubernetes field selector to filter pods by field values (e.g. 'status.phase=Running', 'spec.nodeName=node1'). Supported fields: metadata.name, metadata.namespace, spec.nodeName, spec.restartPolicy, spec.schedulerName, spec.serviceAccountName, status.phase (Pending/Running/Succeeded/Failed/Unknown), status.podIP, status.nominatedNodeName. Note: CrashLoopBackOff is a container state, not a pod phase, so it cannot be filtered directly. See https://kubernetes.io/docs/concepts/overview/working-with-objects/field-selectors/labelSelector (string) - Optional Kubernetes label selector (e.g. 'app=myapp,env=prod' or 'app in (myapp,yourapp)'), use this option when you want to filter the pods by labelpods_list_in_namespace - List all the Kubernetes pods in the specified namespace in the current cluster
fieldSelector (string) - Optional Kubernetes field selector to filter pods by field values (e.g. 'status.phase=Running', 'spec.nodeName=node1'). Supported fields: metadata.name, metadata.namespace, spec.nodeName, spec.restartPolicy, spec.schedulerName, spec.serviceAccountName, status.phase (Pending/Running/Succeeded/Failed/Unknown), status.podIP, status.nominatedNodeName. Note: CrashLoopBackOff is a container state, not a pod phase, so it cannot be filtered directly. See https://kubernetes.io/docs/concepts/overview/working-with-objects/field-selectors/labelSelector (string) - Optional Kubernetes label selector (e.g. 'app=myapp,env=prod' or 'app in (myapp,yourapp)'), use this option when you want to filter the pods by labelnamespace (string) (required) - Namespace to list pods frompods_get - Get a Kubernetes Pod in the current or provided namespace with the provided name
name (string) (required) - Name of the Podnamespace (string) - Namespace to get the Pod frompods_delete - Delete a Kubernetes Pod in the current or provided namespace with the provided name
name (string) (required) - Name of the Pod to deletenamespace (string) - Namespace to delete the Pod frompods_top - List the resource consumption (CPU and memory) as recorded by the Kubernetes Metrics Server for the specified Kubernetes Pods in the all namespaces, the provided namespace, or the current namespace
all_namespaces (boolean) - If true, list the resource consumption for all Pods in all namespaces. If false, list the resource consumption for Pods in the provided namespace or the current namespacelabel_selector (string) - Kubernetes label selector (e.g. 'app=myapp,env=prod' or 'app in (myapp,yourapp)'), use this option when you want to filter the pods by label (Optional, only applicable when name is not provided)name (string) - Name of the Pod to get the resource consumption from (Optional, all Pods in the namespace if not provided)namespace (string) - Namespace to get the Pods resource consumption from (Optional, current namespace if not provided and all_namespaces is false)pods_exec - Execute a command in a Kubernetes Pod (shell access, run commands in container) in the current or provided namespace with the provided name and command
command (array) (required) - Command to execute in the Pod container. The first item is the command to be run, and the rest are the arguments to that command. Example: ["ls", "-l", "/tmp"]container (string) - Name of the Pod container where the command will be executed (Optional)name (string) (required) - Name of the Pod where the command will be executednamespace (string) - Namespace of the Pod where the command will be executedpods_log - Get the logs of a Kubernetes Pod in the current or provided namespace with the provided name
container (string) - Name of the Pod container to get the logs from (Optional)name (string) (required) - Name of the Pod to get the logs fromnamespace (string) - Namespace to get the Pod logs fromprevious (boolean) - Return previous terminated container logs (Optional)tail (integer) - Number of lines to retrieve from the end of the logs (Optional, default: 100)pods_run - Run a Kubernetes Pod in the current or provided namespace with the provided container image and optional name
image (string) (required) - Container Image to run in the Podname (string) - Name of the Pod (Optional, random name if not provided)namespace (string) - Namespace to run the Pod inport (number) - TCP/IP port to expose from the Pod container (Optional, no port exposed if not provided)resources_list - List Kubernetes resources and objects in the current cluster by providing their apiVersion and kind and optionally the namespace and label selector (common apiVersion and kind include: v1 Pod, v1 Service, v1 Node, apps/v1 Deployment, networking.k8s.io/v1 Ingress, route.openshift.io/v1 Route)
apiVersion (string) (required) - apiVersion of the resources (examples of valid apiVersion are: v1, apps/v1, networking.k8s.io/v1)fieldSelector (string) - Optional Kubernetes field selector to filter resources by field values (e.g. 'status.phase=Running', 'metadata.name=myresource'). Supported fields vary by resource type. For Pods: metadata.name, metadata.namespace, spec.nodeName, spec.restartPolicy, spec.schedulerName, spec.serviceAccountName, status.phase (Pending/Running/Succeeded/Failed/Unknown), status.podIP, status.nominatedNodeName. See https://kubernetes.io/docs/concepts/overview/working-with-objects/field-selectors/kind (string) (required) - kind of the resources (examples of valid kind are: Pod, Service, Deployment, Ingress)labelSelector (string) - Optional Kubernetes label selector (e.g. 'app=myapp,env=prod' or 'app in (myapp,yourapp)'), use this option when you want to filter the resources by labelnamespace (string) - Optional Namespace to retrieve the namespaced resources from (ignored in case of cluster scoped resources). If not provided, will list resources from all namespacesresources_get - Get a Kubernetes resource in the current cluster by providing its apiVersion, kind, optionally the namespace, and its name (common apiVersion and kind include: v1 Pod, v1 Service, v1 Node, apps/v1 Deployment, networking.k8s.io/v1 Ingress, route.openshift.io/v1 Route)
apiVersion (string) (required) - apiVersion of the resource (examples of valid apiVersion are: v1, apps/v1, networking.k8s.io/v1)kind (string) (required) - kind of the resource (examples of valid kind are: Pod, Service, Deployment, Ingress)name (string) (required) - Name of the resourcenamespace (string) - Optional Namespace to retrieve the namespaced resource from (ignored in case of cluster scoped resources). If not provided, will get resource from configured namespaceresources_create_or_update - Create or update a Kubernetes resource via Server-Side Apply. The manifest is the complete desired state: any field this tool previously set and the new manifest omits is removed. To edit an existing resource, fetch it with resources_get, modify it, then re-apply the full resource. (common apiVersion and kind include: v1 Pod, v1 Service, v1 Node, apps/v1 Deployment, networking.k8s.io/v1 Ingress, route.openshift.io/v1 Route)
resource (string) (required) - Complete YAML or JSON representation of the Kubernetes resource (full desired state, not a partial patch). Include apiVersion, kind, metadata, and the full spec.resources_delete - Delete a Kubernetes resource in the current cluster by providing its apiVersion, kind, optionally the namespace, and its name (common apiVersion and kind include: v1 Pod, v1 Service, v1 Node, apps/v1 Deployment, networking.k8s.io/v1 Ingress, route.openshift.io/v1 Route)
apiVersion (string) (required) - apiVersion of the resource (examples of valid apiVersion are: v1, apps/v1, networking.k8s.io/v1)gracePeriodSeconds (integer) - Optional duration in seconds before the object should be deleted. Value must be non-negative integer. The value zero indicates delete immediately. If this value is nil, the default grace period for the specified type will be usedkind (string) (required) - kind of the resource (examples of valid kind are: Pod, Service, Deployment, Ingress)name (string) (required) - Name of the resourcenamespace (string) - Optional Namespace to delete the namespaced resource from (ignored in case of cluster scoped resources). If not provided, will delete resource from configured namespaceresources_scale - Get or update the scale of a Kubernetes resource in the current cluster by providing its apiVersion, kind, name, and optionally the namespace. If the scale is set in the tool call, the scale will be updated to that value. Always returns the current scale of the resource
apiVersion (string) (required) - apiVersion of the resource (examples of valid apiVersion are apps/v1)kind (string) (required) - kind of the resource (examples of valid kind are: StatefulSet, Deployment)name (string) (required) - Name of the resourcenamespace (string) - Optional Namespace to get/update the namespaced resource scale from (ignored in case of cluster scoped resources). If not provided, will get/update resource scale from configured namespacescale (integer) - Optional scale to update the resources scale to. If not provided, will return the current scale of the resource, and not update itkind (string) - Kind of the Istio object. Required for 'get' action.namespace (string) - Namespace containing the Istio object. For 'list', if not provided, returns objects across all namespaces. For 'get', required.object (string) - Name of the Istio object. Required for 'get' action.serviceName (string) - Filter Istio configurations (VirtualServices, DestinationRules, and their referenced Gateways) that affect a specific service. Only applicable for 'list' actionversion (string) - API version. Use 'v1' for VirtualService, DestinationRule, and Gateway. Required for 'get' action.kiali_manage_istio_config - Create, patch, or delete Istio config. For list and get (read-only) use manage_istio_config_read.
action (string) (required) - Action to perform (write)clusterName (string) - Optional cluster name. Defaults to the cluster name in the Kiali configuration.data (string) - Complete JSON or YAML data to apply or create the object. Required for create and patch actions. You MUST provide a COMPLETE and VALID manifest with ALL required fields for the resource type. Arrays (like servers, http, etc.) are REPLACED entirely, so you must include ALL required fields within each array element.group (string) (required) - API group of the Istio objectkind (string) (required) - Kind of the Istio object (e.g., 'VirtualService', 'DestinationRule').namespace (string) (required) - Namespace containing the Istio objectobject (string) (required) - Name of the Istio objectversion (string) (required) - API version. Use 'v1' for VirtualService, DestinationRule, and Gateway.kiali_get_resource_details - Fetches a list of resources OR retrieves detailed data for a specific resource. If 'resourceName' is omitted, it returns a list. If 'resourceName' is provided, it returns details for that specific resource.
clusterName (string) - Optional. Name of the cluster to get resources from. If not provided, will use the default cluster name in the Kiali KubeConfignamespaces (string) - Comma-separated list of namespaces to query (e.g., 'bookinfo' or 'bookinfo,default'). If not provided, it will query across all accessible namespaces.resourceName (string) - Optional. The specific name of the resource. If left empty, the tool returns a list of all resources of the specified type. If provided, the tool returns deep details for this specific resource.resourceType (string) (required) - The type of resource to query. Use 'app' for Kiali applications (grouped by the Kubernetes 'app' label). Use 'argoapp' for ArgoCD Application CRDs (requires ArgoCD installed and the Kiali service account must have read permissions on applications.argoproj.io).kiali_list_traces - Lists distributed traces for a service in a namespace. Returns a summary (namespace, service, total_found, avg_duration_ms) and a list of traces with id, duration_ms, spans_count, root_op, slowest_service, has_errors. Use get_trace_details with a trace id to get full hierarchy.
clusterName (string) - Optional cluster name. Defaults to the cluster name in the Kiali configuration.errorOnly (boolean) - If true, only consider traces that contain errors. Default false.limit (integer) - Maximum number of traces to return. Default 10.lookbackSeconds (integer) - How far back to search. Default 600 (10m).namespace (string) (required) - Kubernetes namespace of the service.serviceName (string) (required) - Service name to search traces for (required). Returns multiple traces up to limit.kiali_get_trace_details - Fetches a single distributed trace by trace_id and returns its call hierarchy (service tree with duration, status, and nested calls). Use this after list_traces to drill into a specific trace.
traceId (string) (required) - Trace ID to fetch and summarize. If provided, namespace/service_name are ignored.kiali_get_pod_performance - Returns a human-readable text summary with current Pod CPU/memory usage (from Prometheus) compared to Kubernetes requests/limits (from the Pod spec). Useful to answer questions like 'Is this workload using too much memory?'
clusterName (string) - Optional. Name of the cluster to get resources from. If not provided, will use the default cluster name in the Kiali KubeConfignamespace (string) (required) - Kubernetes namespace of the Pod.podName (string) - Kubernetes Pod name. If workloadName is provided, the tool will attempt to resolve a Pod from that workload first.queryTime (string) - Optional end timestamp (RFC3339) for the query. Defaults to now.timeRange (string) - Time window used to compute CPU rate (Prometheus duration like '5m', '10m', '1h', '1d'). Defaults to '10m'.workloadName (string) - Kubernetes Workload name (e.g. Deployment/StatefulSet/etc). Tool will look up the workload and pick one of its Pods. If not found, it will fall back to treating this value as a podName.kiali_get_logs - Get the logs of a Kubernetes Pod (or workload name that will be resolved to a pod) in a namespace. Output is plain text, matching kubernetes-mcp-server pods_log. The line_count field tells you the total number of log lines returned. Analyze ALL of them, but summarize the results unless the user explicitly asks for the raw output. Do not omit any error or warning lines.
clusterName (string) - Optional. Name of the cluster to get the logs from. If not provided, will use the default cluster name in the Kiali KubeConfigcontainer (string) - Optional. Name of the Pod container to get the logs from.format (string) - Output formatting for chat. 'codeblock' wraps logs in ~~~ fences (recommended). 'plain' returns raw text like kubernetes-mcp-server pods_log.name (string) (required) - Name of the Pod to get the logs from. If it does not exist, it will be treated as a workload name and a running pod will be selected.namespace (string) (required) - Namespace to get the Pod logs fromprevious (boolean) - Optional. Return previous terminated container logsseverity (string) - Optional severity filter applied client-side. Accepts 'ERROR', 'WARN' or combinations like 'ERROR,WARN'.tail (integer) - Number of lines to retrieve from the end of the logs (Optional, defaults to 50). Cannot exceed 200 lines.workload (string) - Optional. Workload name override (used when name lookup fails).kiali_get_metrics - Returns a compact JSON summary of Istio metrics (latency quantiles, traffic trends, throughput, payload sizes) for the given resource.
byLabels (string) - Comma-separated list of labels to group metrics by (e.g., 'source_workload,destination_service'). OptionalclusterName (string) - Cluster name to get metrics from. Optional, defaults to the cluster name in the Kiali configuration (KubeConfig)direction (string) - Traffic direction. Optional, defaults to 'outbound'namespace (string) (required) - Namespace to get metrics fromquantiles (string) - Comma-separated list of quantiles for histogram metrics (e.g., '0.5,0.95,0.99'). OptionalrateInterval (string) - Rate interval for metrics (e.g., '1m', '5m'). Optional, defaults to '10m'reporter (string) - Metrics reporter(s). Comma-separated list of: 'source', 'destination', 'waypoint', or the special value 'both' (no reporter filter). Optional, defaults to 'source'. Example: 'source,waypoint'requestProtocol (string) - Filter by request protocol (e.g., 'http', 'grpc', 'tcp'). OptionalresourceName (string) (required) - Name of the resource to get metrics forresourceType (string) (required) - Type of resource to get metricsstep (string) - Step between data points in seconds (e.g., '15'). Optional, defaults to 15 secondsperformance (string) - Optional performance family hint for the VM instance type (e.g., 'u1' for general-purpose, 'o1' for overcommitted, 'c1' for compute-optimized, 'm1' for memory-optimized). Defaults to 'u1' (general-purpose) if not specified.preference (string) - Optional preference name for the VMsize (string) - Optional workload size hint for the VM (e.g., 'small', 'medium', 'large', 'xlarge'). Used to auto-select an appropriate instance type if not explicitly specified.storage (string) - Optional storage size for the VM's root disk when using DataSources (e.g., '30Gi', '50Gi', '100Gi'). Defaults to 30Gi. Ignored when using container disks.workload (string) - The workload for the VM. Accepts OS names (e.g., 'fedora' (default), 'ubuntu', 'centos', 'centos-stream', 'debian', 'rhel', 'opensuse', 'opensuse-tumbleweed', 'opensuse-leap') or full container disk image URLsvm_guest_info - Get guest operating system information from a VirtualMachine's QEMU guest agent. Requires the guest agent to be installed and running inside the VM. Provides detailed information about the OS, filesystems, network interfaces, and logged-in users.
info_type (string) - Type of information to retrieve: 'all' (default - all available info), 'os' (operating system details), 'filesystem' (disk and filesystem info), 'users' (logged-in users), 'network' (network interfaces and IPs)name (string) (required) - The name of the virtual machinenamespace (string) (required) - The namespace of the virtual machinevm_lifecycle - Manage KubeVirt VirtualMachine lifecycle: start, stop, or restart a VM
action (string) (required) - The lifecycle action to perform: 'start' (changes runStrategy to Always), 'stop' (changes runStrategy to Halted), or 'restart' (stops then starts the VM)name (string) (required) - The name of the virtual machinenamespace (string) (required) - The namespace of the virtual machinetekton_taskrun_restart - Restart a Tekton TaskRun by creating a new TaskRun with the same spec
name (string) (required) - Name of the TaskRun to restartnamespace (string) - Namespace of the TaskRuntekton_taskrun_logs - Get the logs from a Tekton TaskRun by resolving its underlying pod
name (string) (required) - Name of the TaskRun to get logs fromnamespace (string) - Namespace of the TaskRuntail (integer) - Number of lines to retrieve from the end of the logs (Optional, default: 100)service-troubleshoot - Investigate service errors using logs, traces, and Istio configuration to identify root causes
namespace (string) (required) - Namespace where the service is deployedservice (string) (required) - Name of the service to troubleshootworkload (string) - Optional workload or pod name to fetch logs from (if omitted, uses the service name)trace-analysis - Investigate distributed traces for a service to identify latency bottlenecks, error sources, and slow spans
namespace (string) (required) - Namespace where the service is deployedservice (string) (required) - Name of the service to investigate traces foristio-config-review - Review and validate Istio configuration in a namespace, checking for misconfigurations and best practice violations
namespace (string) (required) - Namespace to review Istio configuration for/stats endpoint for real-time statistics. See OTEL.md.Unlike other Kubernetes MCP server implementations, this IS NOT just a wrapper around kubectl or helm command-line tools.
It is a Go-based native implementation that interacts directly with the Kubernetes API server.
There is NO NEED for external dependencies or tools to be installed on the system. If you're using the native binaries you don't need to have Node or Python installed on your system.
--config-dir | (Optional) Path to drop-in configuration directory. Files are loaded in lexical (alphabetical) order. Defaults to conf.d relative to the main config file if --config is specified. See Configuration Reference for details. |
--kubeconfig | Path to the Kubernetes configuration file. If not provided, it will try to resolve the configuration (in-cluster, default location, etc.). |
--list-output | Output format for resource list operations (one of: yaml, table) (default "table") |
--read-only | If set, the MCP server will run in read-only mode, meaning it will not allow any write operations (create, update, delete) on the Kubernetes cluster. This is useful for debugging or inspecting the cluster without making changes. |
--disable-destructive | If set, the MCP server will disable all destructive operations (delete, update, etc.) on the Kubernetes cluster. This is useful for debugging or inspecting the cluster without accidentally making changes. This option has no effect when --read-only is used. |
--stateless | If set, the MCP server will run in stateless mode, disabling tool and prompt change notifications. This is useful for container deployments, load balancing, and serverless environments where maintaining client state is not desired. |
--toolsets | Comma-separated list of toolsets to enable. Check the π οΈ Tools and Functionalities section for more information. |
--disable-multi-cluster | If set, the MCP server will disable multi-cluster support and will only use the current context from the kubeconfig file. This is useful if you want to restrict the MCP server to a single cluster. |
--cluster-provider | Cluster provider strategy to use (one of: kubeconfig, in-cluster, kcp, disabled). If not set, the server will auto-detect based on the environment. |
Note: Most CLI options have equivalent TOML configuration fields. The
--disable-multi-clusterflag is equivalent to settingcluster_provider_strategy = "disabled"in TOML. See the Configuration Reference for all TOML options.
For complex or persistent configurations, use TOML configuration files instead of CLI arguments:
kubernetes-mcp-server --config /etc/kubernetes-mcp-server/config.toml
Example configuration:
log_level = 2
read_only = true
toolsets = ["core", "config", "helm", "kubevirt"]
# Deny access to sensitive resources
[[denied_resources]]
group = ""
version = "v1"
kind = "Secret"
[telemetry]
endpoint = "http://localhost:4317"
For comprehensive TOML configuration documentation, including:
See the Configuration Reference.