The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the VMware VKS listing page.
Author: Wei Zhou, VMware by Broadcom — wei-wz.zhou@broadcom.com This is a community-driven project by a VMware engineer, not an official VMware product. For official VMware developer tools see developer.broadcom.com.
MCP Skill + CLI for VMware vSphere Kubernetes Service (VKS) management — Supervisor clusters, vSphere Namespaces, and VKS Cluster lifecycle. 23 MCP tools.
Part of the VMware MCP Skills family. Each skill handles a distinct domain — install only what you need.
| Skill | Scope | Tools | Install |
|---|---|---|---|
| vmware-aiops ⭐ entry point | VM lifecycle, deployment, guest ops, clusters | 49 | uv tool install vmware-aiops |
| vmware-monitor | Read-only monitoring, alarms, events, VM info | 27 | uv tool install vmware-monitor |
| vmware-storage | Datastores, iSCSI, vSAN | 11 | uv tool install vmware-storage |
| vmware-nsx | NSX networking: segments, gateways, NAT, IPAM | 33 | uv tool install vmware-nsx-mgmt |
| vmware-nsx-security | DFW microsegmentation, security groups, Traceflow | 21 | uv tool install vmware-nsx-security |
| vmware-aria | Aria Ops metrics, alerts, capacity planning | 28 | uv tool install vmware-aria |
uv tool installRun vmware-vks check after setup to verify all requirements are met.
This project uses the modern PEP 517 build system (hatchling), so there is no
setup.py by design — that is expected, not a missing file. If you cloned the
source and hit ERROR: File "setup.py" or "setup.cfg" not found ... editable mode currently requires a setuptools-based build, your pip is older than 21.3 and
cannot do an editable (-e) install with a non-setuptools backend. Editable
mode is a developer convenience, not needed to run the tool — do one of:
For a truly air-gapped host, build the wheels on a connected machine and copy them over — the target then needs no network:
vmware-vks checkvmware-vks tkc versions -n devvmware-vks namespace create dev --cluster domain-c1 --storage-policy <policy-id> --cpu 16000 --memory 32768 --apply (get the policy ID from vmware-vks supervisor storage-policies)vmware-vks tkc create dev-cluster -n dev --version v1.28.4+vmware.1 --control-plane 1 --workers 3 --vm-class best-effort-large --applyvmware-vks kubeconfig get dev-cluster -n devvmware-vks tkc get dev-cluster -n devvmware-vks tkc scale dev-cluster -n dev --workers 6vmware-vks tkc get dev-cluster -n dev (watch phase)vmware-vks namespace listvmware-vks storage -n devvmware-vks namespace update dev --cpu 32000 --memory 65536| Tool | Description | Type |
|---|---|---|
check_vks_compatibility | vCenter version check + WCP status | Read |
get_supervisor_status | Supervisor cluster status and K8s API endpoint | Read |
list_supervisor_storage_policies | vCenter storage policies (policy ID, name, description) | Read |
| Tool | Description | Type |
|---|---|---|
list_namespaces | All vSphere Namespaces with status | Read |
get_namespace | Namespace detail (quotas, storage, roles) | Read |
create_namespace | Create Namespace with dry-run preview | Write |
update_namespace | Modify quotas and storage policy | Write |
delete_namespace | Delete with TKC guard (rejects if clusters exist) | Write |
list_vm_classes | Available VM classes for TKC sizing | Read |
| Tool | Description | Type |
|---|---|---|
list_tkc_clusters | TanzuKubernetesCluster list with status | Read |
get_tkc_cluster | Cluster detail (nodes, health, conditions) | Read |
get_tkc_available_versions | Supported K8s versions on Supervisor | Read |
create_tkc_cluster | Create TKC with YAML plan + dry-run default | Write |
scale_tkc_cluster | Scale worker node count | Write |
upgrade_tkc_cluster | Upgrade K8s version | Write |
delete_tkc_cluster | Delete with workload guard | Write |
| Tool | Description | Type |
|---|---|---|
get_supervisor_kubeconfig | Supervisor kubeconfig YAML | Read |
get_tkc_kubeconfig | TKC kubeconfig (stdout or file) | Write |
get_harbor_info | Embedded Harbor registry info (id, cluster, version, URL, health, storage used) | Read |
list_namespace_storage_usage | PVC list and capacity stats | Read |
After uv tool install vmware-vks, start the MCP server with one command (v1.5.15+):
Add to your AI agent's MCP config:
Behind a corporate TLS proxy? uvx may fail with
invalid peer certificate: UnknownIssuer. Use the recommendedvmware-vks mcpform above (no network needed), or setUV_NATIVE_TLS=true.
| Feature | Description |
|---|---|
| Read-heavy | 15/23 tools are read-only |
| Dry-run default | create_namespace, create_tkc_cluster, delete_namespace, delete_tkc_cluster all default to dry_run=True |
| TKC guard | delete_namespace rejects if TKC clusters exist inside |
| Workload guard | delete_tkc_cluster rejects if Deployments/StatefulSets are running |
| Credential safety | Passwords only from environment variables (.env file), never in config.yaml |
| In-memory kubeconfig | Supervisor/TKC kubeconfig (with vCenter session bearer token) is built as an in-memory dict and loaded via load_kube_config_from_dict() — never written to a temp file on disk (v1.5.18+) |
| Audit logging | All write operations logged to ~/.vmware-vks/audit.log |
| stdio transport | No network listener; MCP runs over stdio only |
Workload Management must be enabled in vCenter. Check: vCenter UI -> Workload Management. Requires vSphere 8.x+ with Enterprise Plus or VCF license.
The namespace, storage-policy and Supervisor-status tools authenticate against
the vSphere Automation REST API with a session id from POST /api/session —
not the pyVmomi SOAP session key, which that API never issued and always
rejects. A 401 is refreshed automatically once; if it persists, check whether a
proxy between you and vCenter strips the vmware-api-session-id header. An
account short of Workload Management permissions gets a 403, not a 401.
List policies first: vmware-vks supervisor storage-policies, then pass the Policy ID column value (not the display name) as --storage-policy.
Check Supervisor events in vCenter. Common causes: insufficient resources on ESXi hosts, network issues with NSX-T, or storage policy not available on target datastore.
Supervisor API endpoint must be reachable from the machine running vmware-vks. Check firewall rules for port 6443.
Verify the cluster is in "Running" phase before scaling. Clusters in "Creating" or "Updating" phase reject scale operations.
The namespace delete guard prevents deletion when TKC clusters exist inside. Delete all TKC clusters in the namespace first, then retry.
| vSphere / VCF | Support | Notes |
|---|---|---|
| 9.0 / 9.1 | ⚠ Not yet verified | Workload Management (Supervisor / WCP) API surface in vSphere 9 has not been tested by maintainers. Existing vSphere 8.x code paths should work but no guarantees until a lab run is completed — basic CRUD likely works, corner cases may need testing. File issues with check_vks_compatibility output if you run this on VCF 9. |
| 8.0+ | Full | Workload Management APIs available |
| 7.x | Not supported | WCP API surface is different; use vSphere 8.x |
| Skill | Scope | Tools | Install |
|---|---|---|---|
| vmware-aiops ⭐ entry point | VM lifecycle, deployment, guest ops, clusters | 49 | uv tool install vmware-aiops |
| vmware-monitor | Read-only monitoring, alarms, events, VM info | 27 | uv tool install vmware-monitor |
| vmware-storage | Datastores, iSCSI, vSAN | 11 | uv tool install vmware-storage |
| vmware-nsx | NSX networking: segments, gateways, NAT, IPAM | 33 | uv tool install vmware-nsx-mgmt |
| vmware-nsx-security | DFW microsegmentation, security groups, Traceflow | 21 | uv tool install vmware-nsx-security |
| vmware-aria | Aria Ops metrics, alerts, capacity planning | 28 | uv tool install vmware-aria |