AI-powered Kubernetes diagnostics, RBAC analysis, security checks, and app deployment via MCP
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
AI-powered multi-cluster Kubernetes tools for Claude Code.
Single-cluster UX for multi-cluster reality - work with your apps, not your clusters.
kubestellar-mcp is the AI entry point to the KubeStellar platform — a CNCF Sandbox ecosystem for multi-cluster Kubernetes orchestration.
| Sub-project | Role |
|---|---|
| kubestellar | Core engine — BindingPolicy, WDS, ITS, WEC workload propagation |
| console | Web dashboard — 300+ cards, AI missions, GPU and LLM-d monitoring |
| console-marketplace | 153+ community card presets (GPU/AI/ML, ArgoCD, OPA, Falco, security) |
| console-kb | AI knowledge base — community missions and operational runbooks |
| kubestellar-mcp | This repo — MCP server for Claude, Cursor, Windsurf, VS Code |
kubestellar-mcp lets AI agents inspect and operate clusters through natural language. For visual dashboards and AI missions, see KubeStellar Console.
| Binary | Description |
|---|---|
| kubestellar-ops | Multi-cluster diagnostics, RBAC analysis, security checks |
| kubestellar-deploy | App-centric deployment, GitOps, smart workload placement |
Additional documentation lives in docs/:
docs/index.md - expanded setup, plugin workflow, CLI usage, and operational guidancedocs/ARCHITECTURE.md - architecture overview and contributor guide for the two MCP servers, request lifecycle, and how to add new toolsIf you are contributing new MCP capabilities, start with docs/ARCHITECTURE.md; it is the best guide to how the servers are organized and where new tools should be added.
docs/slo.md - Service Level Objectives and Indicatorsdocs/alerts/ - importable Prometheus alert rules aligned with the SLOsdocs/dashboards/ - importable Grafana dashboardrunbooks/ - operational runbooks (startup/shutdown, cluster discovery failures, credential rotation, connectivity loss, release rollback)docs/postmortem-template.md - incident postmortem templatedocs/severity-levels.md - P1-P4 incident severity scale used by the incident template and postmortem requirementDownload from GitHub Releases.
Prerequisites: Go 1.26+ (go version to verify)
In Claude Code, run:
Or:
/plugin → Marketplaces tab → click Update on kubestellar marketplace/plugin → Discover tab → Install kubestellar-ops and/or kubestellar-deployRun /mcp in Claude Code - you should see:
Add to ~/.claude/settings.json:
Or run in Claude Code:
You can run either binary as a generic MCP stdio server with kubestellar-ops --mcp-server or kubestellar-deploy --mcp-server. Any MCP-compatible client can use the binary over stdio.
Create .vscode/mcp.json:
Create .cursor/mcp.json:
Add to ~/.codeium/windsurf/mcp_config.json:
OpenCode is an open-source AI coding agent.
Add the following to your project's opencode.json or opencode.jsonc:
After adding, run opencode mcp list and verify both servers show as connected.
For your AI agent — Copy and paste this message into your OpenCode session to have it configure the MCP tools automatically:
The MCP binaries use your active kubeconfig by default. If you run them in-cluster, bind the same permissions to the pod ServiceAccount.
| Use case | Typical permissions |
|---|---|
| kubestellar-ops read-only | get, list, watch on namespaces, nodes, pods, pods/log, services, endpoints, deployments, replica sets, statefulsets, daemonsets, jobs, cronjobs, events, resourcequotas, limitranges, roles, rolebindings, clusterroles, and clusterrolebindings |
| kubestellar-deploy write | Everything above, plus create, update, patch, and delete on the resource types you plan to manage |
Example read-only ClusterRole:
For write workflows, add create, update, patch, and delete to the resource rules you actually need.
which kubestellar-ops.kubectl auth can-i --list to see what your current identity can access.kubectl config current-context.KUBECONFIG is set and points to the kubeconfig file you expect.No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/kubestellar-mcp)<a href="https://allmcps.com/mcp/kubestellar-mcp"><img src="https://allmcps.com/api/badge/kubestellar-mcp?style=directory" alt="KubeStellar MCP on AllMCPs" /></a>