The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the MCP K8s Ro listing page.
A read-only MCP server that gives Claude access to Kubernetes clusters. Built in Go, it communicates over stdio using the MCP protocol.
get, describe, logs, and top style operations. No create, update, or delete. If a mutating operation is needed, the server prints the equivalent kubectl command for you to run manually. Safe to use while on-call at night: Claude can never accidentally mutate your cluster, even under prompt fatigue.| Object/Field | Reason |
|---|---|
| Secret.data | Secret leak prevention |
| Secret.stringData | Secret leak prevention |
| CertificateSigningRequest.spec.request | Large base64 PEM blob, no diagnostic value, saves tokens |
| Certificate (cert-manager) .spec.keystores | Cert chain PEM blobs, no diagnostic value, saves tokens |
| Certificate (cert-manager) status.conditions[].message | Cert chain PEM blobs, no diagnostic value, saves tokens |
| *.managedFields | No diagnostic value, saves tokens |
| Tool | Description |
|---|---|
k8s_list_resources | List any resource type by name — pods, deployments, CRDs, etc. Accepts optional namespace filter. Returns name, status, readiness, restarts, node, IP, and more depending on resource kind. |
k8s_describe_resource | Return the full YAML of a single resource. Secret data is masked. |
k8s_list_resource_types | List all available resource types via the discovery API. Accepts optional API group filter. |
k8s_get_logs | Fetch pod logs. Supports container selector, tail lines, and --previous for crashed containers. |
k8s_get_events | List Kubernetes events for a namespace or the whole cluster, sorted by most recent. |
k8s_top_pods | CPU and memory usage per pod, with per-container breakdown. Requires metrics-server. |
k8s_top_nodes | CPU and memory usage per node, with percentage of allocatable capacity. Requires metrics-server. |
| Environment variable | Default | Description |
|---|---|---|
KUBECONFIG | ~/.kube/config | Path to kubeconfig file |
Pinning a specific version (check the latest release ) is recommended for production use:
Download a pre-built binary from GitHub Releases:
macOS Gatekeeper: The binary is not code-signed, so macOS will block it. The
xattrcommand above removes the quarantine flag. Alternatively, go to System Settings → Privacy & Security and click "Allow Anyway" after the first blocked attempt.
Or build from source:
If your kubeconfig is not at ~/.kube/config, set the KUBECONFIG environment variable:
The server intentionally operates on one kubeconfig context and provides no tool to switch clusters at runtime. The reasons are:
To point the server at a different cluster, stop the server, switch context, and restart:
To work with multiple clusters simultaneously, register a separate server instance per cluster in your MCP config:
Claude will address each server by name and each instance only ever sees its own cluster.
This server is published on registry.modelcontextprotocol.io