The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the KubeStellar MCP listing page.
AI-powered multi-cluster Kubernetes tools for Claude Code.
Single-cluster UX for multi-cluster reality - work with your apps, not your clusters.
kubestellar-mcp is the AI entry point to the KubeStellar platform — a CNCF Sandbox ecosystem for multi-cluster Kubernetes orchestration.
| Sub-project | Role |
|---|---|
| kubestellar | Core engine — BindingPolicy, WDS, ITS, WEC workload propagation |
| console | Web dashboard — 300+ cards, AI missions, GPU and LLM-d monitoring |
| console-marketplace | 153+ community card presets (GPU/AI/ML, ArgoCD, OPA, Falco, security) |
| console-kb | AI knowledge base — community missions and operational runbooks |
| kubestellar-mcp | This repo — MCP server for Claude, Cursor, Windsurf, VS Code |
kubestellar-mcp lets AI agents inspect and operate clusters through natural language. For visual dashboards and AI missions, see KubeStellar Console.
| Binary | Description |
|---|---|
| kubestellar-ops | Multi-cluster diagnostics, RBAC analysis, security checks |
| kubestellar-deploy | App-centric deployment, GitOps, smart workload placement |
Additional documentation lives in docs/:
docs/index.md - expanded setup, plugin workflow, CLI usage, and operational guidancedocs/ARCHITECTURE.md - architecture overview and contributor guide for the two MCP servers, request lifecycle, and how to add new toolsIf you are contributing new MCP capabilities, start with docs/ARCHITECTURE.md; it is the best guide to how the servers are organized and where new tools should be added.
docs/slo.md - Service Level Objectives and Indicatorsdocs/alerts/ - importable Prometheus alert rules aligned with the SLOsdocs/dashboards/ - importable Grafana dashboardrunbooks/ - operational runbooks (startup/shutdown, cluster discovery failures, credential rotation, connectivity loss, release rollback)docs/postmortem-template.md - incident postmortem templatedocs/severity-levels.md - P1-P4 incident severity scale used by the incident template and postmortem requirementDownload from GitHub Releases.
Prerequisites: Go 1.26+ (go version to verify)
In Claude Code, run:
Or:
/plugin → Marketplaces tab → click Update on kubestellar marketplace/plugin → Discover tab → Install kubestellar-ops and/or kubestellar-deployRun /mcp in Claude Code - you should see:
Add to ~/.claude/settings.json:
Or run in Claude Code:
You can run either binary as a generic MCP stdio server with kubestellar-ops --mcp-server or kubestellar-deploy --mcp-server. Any MCP-compatible client can use the binary over stdio.
Create .vscode/mcp.json:
Create .cursor/mcp.json:
Add to ~/.codeium/windsurf/mcp_config.json:
OpenCode is an open-source AI coding agent.
Add the following to your project's opencode.json or opencode.jsonc:
After adding, run opencode mcp list and verify both servers show as connected.
For your AI agent — Copy and paste this message into your OpenCode session to have it configure the MCP tools automatically:
The MCP binaries use your active kubeconfig by default. If you run them in-cluster, bind the same permissions to the pod ServiceAccount.
| Use case | Typical permissions |
|---|---|
| kubestellar-ops read-only | get, list, watch on namespaces, nodes, pods, pods/log, services, endpoints, deployments, replica sets, statefulsets, daemonsets, jobs, cronjobs, events, resourcequotas, limitranges, roles, rolebindings, clusterroles, and clusterrolebindings |
| kubestellar-deploy write | Everything above, plus create, update, patch, and delete on the resource types you plan to manage |
Example read-only ClusterRole:
For write workflows, add create, update, patch, and delete to the resource rules you actually need.
which kubestellar-ops.kubectl auth can-i --list to see what your current identity can access.kubectl config current-context.KUBECONFIG is set and points to the kubeconfig file you expect.Update the CLI tools via Homebrew:
Update the plugins in Claude Code:
Multi-cluster Kubernetes diagnostics, RBAC analysis, and security checks.
| Category | Tools |
|---|---|
| Cluster | list_clusters, get_cluster_health, get_nodes, audit_kubeconfig |
| Workloads | get_pods, get_deployments, get_services, get_events, describe_pod, get_pod_logs |
| RBAC | get_roles, get_cluster_roles, get_role_bindings, can_i, analyze_subject_permissions |
| Diagnostics | find_pod_issues, find_deployment_issues, check_resource_limits, check_security_issues |
| Gatekeeper | check_gatekeeper, install_ownership_policy, list_ownership_violations |
| Upgrades | detect_cluster_type, get_cluster_version_info, check_helm_release_upgrades |
| GitOps | detect_drift |
| Command | Description |
|---|---|
/k8s-health | Check health of all clusters |
/k8s-issues | Find pod and deployment issues |
/k8s-security | Check for security misconfigurations |
/k8s-rbac | Analyze RBAC permissions |
/k8s-analyze | Comprehensive namespace analysis |
/k8s-audit-kubeconfig | Audit kubeconfig clusters and recommend cleanup |
/k8s-ownership | Manage ownership tracking with OPA Gatekeeper |
/k8s-upgrade-check | Check for available upgrades |
/k8s-upgrade | Upgrade cluster (master and nodes) |
App-centric multi-cluster deployment and operations.
| Category | Tools |
|---|---|
| App Discovery | get_app_instances, get_app_status, get_app_logs |
| Deployment | deploy_app, scale_app, patch_app |
| Placement | list_cluster_capabilities, find_clusters_for_workload |
| GitOps | sync_from_git, detect_drift, reconcile, preview_changes |
| Helm | helm_install, helm_uninstall, helm_list, helm_rollback |
| Kustomize | kustomize_build, kustomize_apply, kustomize_delete |
| Resources | kubectl_apply, delete_resource |
| Labels | add_labels, remove_labels |
| Command | Description |
|---|---|
/app-status | Show status of an app across all clusters |
/app-logs | Get aggregated logs from an app |
/deploy | Deploy or update an app |
/gitops-sync | Sync clusters from git |
/gitops-drift | Check for drift from git |
"Where is my app running?"
"Deploy to GPU clusters"
"Check for drift"
"Install nginx-ingress with Helm"
"Apply kustomize overlay"
"Delete the test deployment"
kubestellar-deploy does not currently expose standalone deployment subcommands. Outside MCP server mode, the CLI only provides informational commands such as version, completion, and help. App deployment, GitOps, Helm, kubectl, kustomize, and labeling workflows are available through the MCP tool server started with --mcp-server. To target a different Kubernetes environment, point KUBECONFIG at the desired kubeconfig (or switch the active context in that kubeconfig) before starting the binary.
| Variable | Used by | Description |
|---|---|---|
KUBECONFIG | kubestellar-ops, kubestellar-deploy | Path to the kubeconfig file to use instead of the default Kubernetes client lookup path |
ANTHROPIC_API_KEY | kubestellar-ops | Required for the query command and natural-language cluster queries backed by Claude |
kubestellar-ops also inherits the standard Kubernetes client flags from kubectl, so contributors can override cluster selection and request behavior at runtime without additional environment variables. Common examples include:
--context to select a kubeconfig context--namespace to scope namespaced operations--request-timeout to override API request timeouts--cluster, --user, --server, --token, and TLS flags for advanced auth/connection overrides--all-clusters, --target-cluster, and --mcp-server for KubeStellar-specific behaviorkubestellar-deploy currently exposes --mcp-server as its runtime flag and does not require any additional environment variables beyond Kubernetes client configuration.
Contributions are welcome! Please read our contributing guidelines.
Apache License 2.0 - see LICENSE for details.