Gives Claude read-only access to your Kubernetes clusters through kubectl-style operations: list resources, describe objects, tail logs, check events, and pull metrics from metrics-server. Built in Go over stdio. Secrets are automatically masked before they reach the model, and the server locks to whatever kubeconfig context is active at startup, so prompt injection can't make Claude pivot to production. Responses are token-efficient, returning only diagnostic fields instead of full API objects. When Claude wants to mutate something, it prints the kubectl command for you to run manually. If you troubleshoot Kubernetes incidents with an AI and want guardrails that work even when you're tired, this handles the inspection layer safely.
A read-only MCP server that gives Claude access to Kubernetes clusters. Built in Go, it communicates over stdio using the MCP protocol.
get, describe, logs, and top style operations. No create, update, or delete. If a mutating operation is needed, the server prints the equivalent kubectl command for you to run manually. Safe to use while on-call at night: Claude can never accidentally mutate your cluster, even under prompt fatigue.| Object/Field | Reason |
|---|---|
| Secret.data | Secret leak prevention |
| Secret.stringData | Secret leak prevention |
| CertificateSigningRequest.spec.request | Large base64 PEM blob, no diagnostic value, saves tokens |
| Certificate (cert-manager) .spec.keystores | Cert chain PEM blobs, no diagnostic value, saves tokens |
| Certificate (cert-manager) status.conditions[].message | Cert chain PEM blobs, no diagnostic value, saves tokens |
| *.managedFields | No diagnostic value, saves tokens |
| Tool | Description |
|---|---|
k8s_list_resources | List any resource type by name — pods, deployments, CRDs, etc. Accepts optional namespace filter. Returns name, status, readiness, restarts, node, IP, and more depending on resource kind. |
k8s_describe_resource | Return the full YAML of a single resource. Secret data is masked. |
k8s_list_resource_types | List all available resource types via the discovery API. Accepts optional API group filter. |
k8s_get_logs | Fetch pod logs. Supports container selector, tail lines, and --previous for crashed containers. |
k8s_get_events | List Kubernetes events for a namespace or the whole cluster, sorted by most recent. |
k8s_top_pods | CPU and memory usage per pod, with per-container breakdown. Requires metrics-server. |
k8s_top_nodes | CPU and memory usage per node, with percentage of allocatable capacity. Requires metrics-server. |
| Environment variable | Default | Description |
|---|---|---|
KUBECONFIG | ~/.kube/config | Path to kubeconfig file |
claude mcp add --scope user --transport stdio k8s-ro \
-- docker run --rm -i -v ~/.kube:/home/nonroot/.kube:ro ghcr.io/your-ko/mcp-k8s-ro:latest
Pinning a specific version (check the latest release ) is recommended for production use:
claude mcp add --scope user --transport stdio k8s-ro \
-- docker run --rm -i -v ~/.kube:/home/nonroot/.kube:ro ghcr.io/your-ko/mcp-k8s-ro:1.1.0
Download a pre-built binary from GitHub Releases:
# macOS Apple Silicon — change ARCH for other platforms: darwin-amd64, linux-amd64, linux-arm64
ARCH=darwin-arm64
VERSION=$(curl -fsSL https://api.github.com/repos/your-ko/mcp-k8s-ro/releases/latest | grep tag_name | cut -d'"' -f4)
curl -fsSL "https://github.com/your-ko/mcp-k8s-ro/releases/download/${VERSION}/mcp-k8s-ro-${VERSION}-${ARCH}" -o ~/.local/bin/mcp-k8s-ro
chmod +x ~/.local/bin/mcp-k8s-ro
xattr -d com.apple.quarantine ~/.local/bin/mcp-k8s-ro 2>/dev/null # macOS only: remove Gatekeeper quarantine
claude mcp add --scope user --transport stdio k8s-ro ~/.local/bin/mcp-k8s-ro
macOS Gatekeeper: The binary is not code-signed, so macOS will block it. The
xattrcommand above removes the quarantine flag. Alternatively, go to System Settings → Privacy & Security and click "Allow Anyway" after the first blocked attempt.
Or build from source:
make build
claude mcp add --scope user --transport stdio k8s-ro ./bin/mcp-k8s-ro
If your kubeconfig is not at ~/.kube/config, set the KUBECONFIG environment variable:
# Binary
claude mcp add --scope user --transport stdio -e KUBECONFIG=/path/to/kubeconfig k8s-ro ~/.local/bin/mcp-k8s-ro
# Docker
claude mcp add --scope user --transport stdio k8s-ro \
-- docker run --rm -i -e KUBECONFIG=/config/kubeconfig -v /path/to/kubeconfig:/config/kubeconfig:ro ghcr.io/your-ko/mcp-k8s-ro:latest
The server intentionally operates on one kubeconfig context and provides no tool to switch clusters at runtime. The reasons are:
To point the server at a different cluster, stop the server, switch context, and restart:
kubectl config use-context my-other-cluster
# then restart the MCP server / reload Claude Desktop
To work with multiple clusters simultaneously, register a separate server instance per cluster in your MCP config:
{
"mcpServers": {
"k8s-staging": {
"type": "stdio",
"command": "/path/to/bin/mcp-k8s-ro",
"env": { "KUBECONFIG": "/path/to/.kube/config" }
},
"k8s-prod": {
"type": "stdio",
"command": "/path/to/bin/mcp-k8s-ro",
"env": { "KUBECONFIG": "/path/to/.kube/config-prod" }
}
}
}
Claude will address each server by name and each instance only ever sees its own cluster.
This server is published on registry.modelcontextprotocol.io
KUBECONFIGPath to the kubeconfig file. Defaults to ~/.kube/config.
silenceper/mcp-k8s
azure/containerization-assist
io.github.evozim/aws-builder
reza-gholizade/k8s-mcp-server
flux159/mcp-server-kubernetes