Control Plane

Official SSE

by Control Plane

352 downloads Not rated yet

About

Deploy and operate workloads, secrets, and networking across AWS, GCP, Azure, and private clouds.

Details

Transport
SSE

Explore

- Deploy and operate serverless, standard, cron, stateful, and VM workloads.
- Create and reference secrets for AWS, GCP, Azure, Docker, ECR, and more.
- Grant workloads credential-free cloud access via identity and policy.
- Map custom domains with automatic TLS; configure firewalls, CORS, CDN, and rate limiting.
- Provision volume sets, snapshots, and HA databases for stateful workloads.
- Query logs, metrics, traces, audit events; exec into running replicas.

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Control Plane
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

{
  "mcpServers": {
    "control-plane": {
      "type": "http",
      "url": "https://mcp.cpln.io/mcp"
    }
  }
}

add_domain_port

Add a new port listener to a domain. Minimal port is {number, protocol}; routes, cors, and tls are optional. Errors if a listener for that port number already exists — use the route/CORS/TLS tools to modify an existing listener instead. Recommended reading before first use: get_cpln_skill("domain") — the runbook for this tool family (read once per session).

add_domain_route

Append a route entry to an existing port listener. Minimal route is {workloadLink}; omit prefix/regex to match /. Routes are matched by prefix (default) or regex; the new route must not collide with an existing one. Use update_domain_route to replace an existing entry. Recommended reading before first use: get_cpln_skill("domain") — the runbook for this tool family (read once per session).

browse_templates

List the Control Plane Template Catalog — production-ready stacks (Postgres, Redis, Kafka, MongoDB, nginx, …) you can install instead of hand-authoring resources. Returns each template’s name, category, latest version, and whether it creates its own GVC. Reach for this first whenever the user wants a database, cache, queue, or other common service. Pass `filter` to narrow. Then call get_template for versions and the example values.yaml.

clear_domain_tls

Remove the TLS configuration from a port listener; the listener reverts to platform defaults. NOTE: on 443 with http/http2 the platform re-injects a default TLS block — TLS cannot be disabled there, only reset.

convert_to_terraform

Convert a Control Plane resource manifest (YAML or JSON) into the equivalent Terraform (HCL). The manifest is first DRY-RUN VALIDATED against the API (no resource is created) — if it fails validation you get the error instead of HCL, so the returned Terraform always corresponds to a schema-valid resource. Pass `gvc` when the kind is GVC-scoped (workload, identity, volumeset). Set `generateImports` to also return ready-to-run `terraform import` commands. To convert an EXISTING resource instead…

create_domain

Provision a Control Plane domain, map routes to workloads, and capture DNS records required for validation. Minimal port item is {number, protocol}; route items minimally need workloadLink and may omit prefix/regex to match /. Run this in the organization that will own the domain. Recommended reading before first use: get_cpln_skill("domain") — the runbook for this tool family (read once per session).

create_gvc

Create a new GVC (Global Virtual Cloud) — the deployment scope workloads live in. Set `locations` in this call: a GVC without locations cannot run workloads. If the user did not name the location(s), ASK first (list_resources kind="location" shows the options) — never guess a region and never create an empty GVC. Custom domains are configured with the Domain resource (create_domain), not on the GVC.

create_identity

Create a new identity in a GVC. Optionally seed networkResources (agent-based) and nativeNetworkResources (PrivateLink / PSC). Identities are assigned to workloads via spec.identityLink. Recommended reading before first use: get_cpln_skill("access-control") — the runbook for this tool family (read once per session).

create_policy

Create a new policy with target kind, exactly one target scope (targetAll/targetLinks/targetQuery), and principal bindings (addPermissions plus at least one principal list — one without the other is an error). Recommended reading before first use: get_cpln_skill("access-control") — the runbook for this tool family (read once per session).

create_secret_dictionary

Create a dictionary secret. A map of arbitrary key→value string pairs. Provide the typed fields below; the server assembles the secret data.

create_secret_docker

Create a docker secret. A Docker registry pull secret (the docker config JSON). Provide the typed fields below; the server assembles the secret data.

create_secret_ecr

Create a ecr secret. An ECR pull secret (AWS creds scoped to one or more ECR repos). Provide the typed fields below; the server assembles the secret data.

create_secret_opaque

Create a opaque secret. A single freeform value (the most common type). Provide the typed fields below; the server assembles the secret data.

create_secret_tls

Create a tls secret. A TLS certificate (and optional private key / chain). Provide the typed fields below; the server assembles the secret data.

create_volumeset

Create a new volumeset in a GVC with explicit performance class, filesystem type, initial capacity, snapshot policy, and (optional) autoscaling. Performance class and filesystem type are IMMUTABLE — choose carefully. xfs/ext4 support snapshots; shared is read-write-many but cannot be snapshotted. Snapshot defaults injected when omitted: createFinalSnapshot=true, retentionDuration "7d". customEncryption (customer-managed KMS keys) cannot be set here — apply a full manifest with the CLI (`cpln …

create_workload

Create a serverless/standard/stateful workload — or a SCHEDULED JOB by setting `type: "cron"`. Define the container(s) in the typed `containers[]` array (the only way — there are no flat image/cpu/port fields) and scaling in the single `autoscaling` block. For a cron workload set `type: "cron"` and a required `schedule` (plus optional job policy); autoscaling/capacityAI/timeoutSeconds/debug do not apply to cron and are rejected. Decide reachability IN THIS CALL: a user-facing service needs `p…

delete_resource

Delete one Control Plane resource by `kind` + `name` — the single delete tool for every deletable kind. Deletes on the call (your client confirms the write first). Before calling, read the resource and tell the user what the deletion removes and which dependents break, and proceed only on their explicit approval. Deletion is permanent. Never invent a name.

expand_volumeset

Increase the storage capacity of a volume in a volumeset. Live operation — no downtime, no data loss. Throttled: expansion is throttled to 4 per volume per rolling 24 hours — an HTTP 429 means the rolling window is exhausted (waiting briefly will NOT help; wait for the oldest expansion to age out). Available for all filesystem types (ext4, xfs, shared). Recommended reading before first use: get_cpln_skill("stateful-storage") — the runbook for this tool family (read once per session).

export_terraform

Generate Terraform (HCL) for EXISTING Control Plane resources from a self link. Single resource (`/org/acme/gvc/prod/workload/api`) or bulk by path depth — `/org/acme` exports the whole org, `/org/acme/gvc/prod/workload` exports every workload in a GVC. Set `generateImports` to get ready-to-run `terraform import` commands for adopting the resources into Terraform state, and `includeDependencies` to pull in referenced resources. Exported secrets embed their REVEALED plaintext values — without …

get_cpln_rules

Returns the Control Plane operating guide — the resource model, how secrets/images/workloads/domains fit together, production-grade defaults, how to verify a change landed, and how to handle failures. Read it once per session before the first create/update/delete, and any time a multi-resource task spans unfamiliar ground.

get_cpln_skill

Returns the runbook for one Control Plane task family — how to use the feature correctly, the platform constraints that are easy to miss, when it is the WRONG tool, and what to do with the result. Tools that belong to a family name their skill as recommended reading; read it once per session before the first such operation.

get_installed_template

Show an installed release’s current status, revision, and the Control Plane resources it created (kind, name, link). Requires the token to have secret `reveal` permission (release state is stored in a helm-release secret).

get_permissions

Fetch available permissions for a resource kind from the /-schema/permissions endpoint. Recommended reading before first use: get_cpln_skill("access-control") — the runbook for this tool family (read once per session).

get_resource

Fetch one Control Plane resource by `kind` + `name` (no `name` for kind="org"). Returns a summary plus the full JSON. The single read-one tool for every resource kind. Secret values are masked — use reveal_secret to read them. Call this before any update or delete to capture current state.

get_resource_schema

Return the exact object schema and REST API endpoints for a Control Plane resource kind, so you can author an accurate manifest for `cpln apply` or call the API directly. ALWAYS call this FIRST whenever you are about to write a cpln apply YAML/JSON file, set up CI/CD that applies Control Plane resources, or build a request body for the REST API — do not hand-write a manifest or guess field names from memory. Pick a `kind` and pass `org` (and `gvc` for workload/identity/volumeset). Large schem…

get_template

Show a catalog template’s available versions, prerequisites, whether it creates its own GVC, and the EXAMPLE values.yaml for the chosen (or latest) version. Read this before install_template — copy and edit the example values to configure the deployment.

get_workload_events

Fetch event log for a workload to diagnose readiness/liveness probe issues and errors. Use after a deploy fails — pair with list_deployments and get_workload_logs to triangulate the failure. Recommended reading before first use: get_cpln_skill("workload-troubleshooting") — the runbook for this tool family (read once per session).

get_workload_logs

Query workload logs from a GVC. Provide structured params (gvc, workload, container, location, filter) OR a raw LogQL `query` — a raw query REPLACES the structured params, so it must embed ALL labels itself. Available labels: gvc, workload, container, location, provider, replica, stream — replica and stream are only reachable via a raw query. `filter` is a literal substring match (|=), not regex; for regex use a raw query with |~. Cron workload? Get jobExecutions via list_deployments (with `l…

install_template

Install a catalog template as a new release. Provide `name` (release name), `template`, optional `version` (defaults to latest), the `values` YAML (from get_template), and `gvc` unless the template creates its own. Validate first where available: preview_template (full profile; same inputs) dry-runs the render and catches values mistakes before anything is created. Deployment is asynchronous — verify with get_installed_template afterwards. Recommended reading before first use: get_cpln_skill(…

list_deployments

A workload's deployments — its per-location rollout status. This is the PRIMARY readiness check after create_workload/update_workload: poll it (without `location`) until ready, then report the canonical endpoint as the public URL — never construct a URL by hand. Without `location`: every location with readiness, endpoints, and the canonical URL. With `location`: that single deployment in full detail — version chain, per-container readiness/restarts/messages, full JSON. For cron workloads, per…

list_installed_templates

List the template releases installed in an org (name, template, version, GVC, revision). Use get_installed_template for the resources and status of a specific release.

list_metrics

Discover what metrics you can query before calling `query_metrics`, so you never guess a metric name or label. Returns the documented Control Plane default metrics (with type and a correct PromQL template each), PLUS the metrics actually present in the org right now — including CUSTOM metrics your workloads expose and kube_/node_ families. Pass `filter` to narrow by substring. Pass `metric` to see that metric’s REAL label dimensions and values (workload, gvc, location, …) from live data so yo…

list_resources

List Control Plane resources of one `kind` as a summary table. The single read-list tool for every resource kind — pass `kind` (e.g. "workload", "secret", "gvc"), `org`, and `gvc` for GVC-scoped kinds. For a single item's full JSON use get_resource. Workload deployments are not a kind here — use list_deployments.

list_workload_replicas

List the names of the running replicas (pods) of a workload in a location. Read-only. Use this before workload_exec to target a specific replica with its `replica` argument; without it, exec uses the first replica. Recommended reading before first use: get_cpln_skill("workload-troubleshooting") — the runbook for this tool family (read once per session).

mount_volumeset_to_workload

Attach a volumeset to a workload — mounts into the FIRST container only. Creates the volumeset when missing; size/fileSystemType/performanceClass apply ONLY on that create path and are ignored when the volumeset already exists. Workload-type rule: ext4/xfs (read-write-once) volumesets require a stateful or vm workload and bind to ONE workload; shared-filesystem volumesets mount on any workload type. Workload types are immutable — switching requires deleting and recreating the workload (plan d…

query_audit_events

Query the Control Plane audit trail for mutations on one or more resources of the same kind. Omit `name` and `names` to fetch every event for that kind in the org. Supply `names` to audit multiple resources in one call (events are merged and sorted newest-first). Supports filtering by subject, audit context, and time range. Platform events live in the built-in `cpln` context.

query_metrics

Run a PromQL query against Control Plane metrics (Prometheus-compatible). Default is a range query over the last hour at 60s step — pass `resolution: "instant"` for a point-in-time query, `since` / `from` / `to` to adjust the window, and `step` to control resolution. Results are sliced to the first 50 series in prose; the full Prometheus response is included as JSON. If you already know the metric, just query it: gauges like `cpu_used`, `mem_used`, `replica_count` are used bare — as are the p…

remove_domain_port

Remove a port listener from a domain. Live traffic on that port stops immediately and any routed workloads become unreachable through this domain on that port.

remove_domain_route

Delete a single route entry from a port listener. Traffic that matched this route returns 404 on the affected listener until a new matching route is configured.

reveal_secret

Reveal the actual secret data (break-glass access; audited). Call ONLY when the user explicitly asked to see the plaintext value — workloads consume secrets via cpln://secret/NAME references without ever revealing them. The result prints the plaintext into the conversation context — do not persist it anywhere (no files, no specs, no logs). Requires reveal permission on the secret.

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "control plane": {
            "control-plane": {
                "type": "http",
                "url": "https://mcp.cpln.io/mcp"
            }
        }
    }
}

McpServers

{
    "control-plane": {
        "type": "http",
        "url": "https://mcp.cpln.io/mcp"
    }
}

Control Plane is a platform for running cloud-native workloads across multiple clouds and regions from a single control plane. Its remote MCP server lets assistants inspect and manage workloads, GVCs, and related infrastructure resources in a Control Plane organization directly from conversation.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.