Kubectl MCP Tool
About
Enables AI assistants to interact with Kubernetes clusters using natural language.
Details
- License
- MIT
Explore
- π€ 253 Powerful Tools - Complete Kubernetes management from pods to security
- π― 8 AI Workflow Prompts - Pre-built workflows for common operations
- π 8 MCP Resources - Browsable Kubernetes data exposure
- π¨ 6 Interactive Dashboards - HTML UI tools for visual cluster management
- π 26 Browser Tools - Web automation with cloud provider support
- π 107 Ecosystem Tools - GitOps, Cert-Manager, Policy, Backup, KEDA, Cilium, Rollouts, CAPI, KubeVirt, Istio, vCluster
- β‘ Multi-Transport - stdio, SSE, HTTP, streamable-http
- π Security First - Non-destructive mode, secret masking, RBAC validation
- π₯ Advanced Diagnostics - AI-powered troubleshooting and cost optimization
- βΈοΈ Multi-Cluster - Target any cluster via context parameter in every tool
- π‘ Full Helm v3 - Complete chart lifecycle management
- π§ Powerful CLI - Shell-friendly tool discovery and direct calling
- π³ Cloud Native - Deploy in-cluster with kMCP or kagent
- Structured errors: Actionable error messages with suggestions
- Colorized output: Human-readable with JSON mode for scripting (--json)
- NO_COLOR support: Respects NO_COLOR environment variable
- Stdin support: Pipe JSON arguments to commands
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
Kubectl MCP ToolCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
- Python 3.9+ (for pip installation)
- Node.js 14+ (for npx installation)
- kubectl installed and configured
- Access to a Kubernetes cluster
npx -y kubectl-mcp-server
npm install -g kubectl-mcp-server
pip install kubectl-mcp-server
bash
pip install https://github.com/rohitg00/kubectl-mcp-server/releases/download/v{VERSION}/kubectl_mcp_server-{VERSION}-py3-none-any.whl
pip install https://github.com/rohitg00/kubectl-mcp-server/releases/download/v1.19.0/kubectl_mcp_server-1.19.0-py3-none-any.whl
pip install git+https://github.com/rohitg00/kubectl-mcp-server.git
kubectl cluster-info
Core Settings:
| Variable | Description | Default |
|----------|-------------|---------|
| KUBECONFIG | Path to kubeconfig file | ~/.kube/config |
| MCP_DEBUG | Enable verbose logging | false |
| MCP_LOG_FILE | Log file path | None (stdout) |
Authentication (Enterprise):
| Variable | Description | Default |
|----------|-------------|---------|
| MCP_AUTH_ENABLED | Enable OAuth 2.1 authentication | false |
| MCP_AUTH_ISSUER | OAuth 2.0 Authorization Server URL | - |
| MCP_AUTH_JWKS_URI | JWKS endpoint URL | Auto-derived |
| MCP_AUTH_AUDIENCE | Expected token audience | kubectl-mcp-server |
| MCP_AUTH_REQUIRED_SCOPES | Required OAuth scopes | mcp:tools |
Browser Automation (Optional):
| Variable | Description | Default |
|----------|-------------|---------|
| MCP_BROWSER_ENABLED | Enable browser automation tools | false |
| MCP_BROWSER_PROVIDER | Cloud provider (browserbase/browseruse) | None |
| MCP_BROWSER_PROFILE | Persistent profile path | None |
| MCP_BROWSER_CDP_URL | Remote CDP WebSocket URL | None |
| MCP_BROWSER_PROXY | Proxy server URL | None |
pip install kubectl-mcp-server[ui]
6 Dashboard Tools:
- π show_pods_dashboard_ui - Real-time pod status table
- π show_pod_logs_ui - Interactive log viewer with search
- π― show_cluster_overview_ui - Complete cluster dashboard
- β‘ show_events_timeline_ui - Events timeline with filtering
- π show_resource_yaml_ui - YAML viewer with syntax highlighting
- πΈ render_k8s_dashboard_screenshot - Export dashboards as PNG
Features:
- π¨ Dark theme optimized for terminals (Catppuccin)
- π Graceful fallback to JSON for incompatible clients
- πΌοΈ Screenshot rendering for universal compatibility
- π Zero external dependencies
Works With: Goose, LibreChat, Nanobot (full HTML UI) | Claude Desktop, Cursor, others (JSON + screenshots)
npm install -g agent-browser
agent-browser install
npx kubectl-mcp-app
Claude Desktop Configuration:
json{
"mcpServers": {
"kubectl-app": {
"command": "npx",
"args": ["kubectl-mcp-app"]
}
}
}
8 Interactive UI Tools:
| Tool | Description |
| ---- | ----------- |
| k8s-pods | Interactive pod viewer with filtering, sorting, status indicators |
| k8s-logs | Real-time log viewer with syntax highlighting and search |
| k8s-deploy | Deployment dashboard with rollout status, scaling, rollback |
| k8s-helm | Helm release manager with upgrade/rollback actions |
| k8s-cluster | Cluster overview with node health and resource metrics |
| k8s-cost | Cost analyzer with waste detection and recommendations |
| k8s-events | Events timeline with type filtering and grouping |
| k8s-network | Network topology graph showing Services/Pods/Ingress |
Features:
- π¨ Dark/light theme support
- π Real-time data visualization
- π±οΈ Interactive actions (scale, restart, delete)
- π Seamless integration with kubectl-mcp-server
More Info: See kubectl-mcp-app/README.md for full documentation.
Secure your MCP server with OAuth 2.1 authentication (RFC 9728).
bashexport MCP_AUTH_ENABLED=true
export MCP_AUTH_ISSUER=https://your-idp.example.com
export MCP_AUTH_AUDIENCE=kubectl-mcp-server
kubectl-mcp-server --transport http --port 8000
Supported Identity Providers: Okta, Auth0, Keycloak, Microsoft Entra ID, Google OAuth, and any OIDC-compliant provider.
Use Case: Multi-tenant environments, compliance requirements, audit logging.
curl -fsSL https://raw.githubusercontent.com/agentregistry-dev/agentregistry/main/scripts/install.sh | bash
arctl mcp install io.github.rohitg00/kubectl-mcp-server
Available via: PyPI (uvx), npm (npx), OCI (docker.io/rohitghumare64/kubectl-mcp-server)
cat > gateway.yaml <<EOF
binds:
- port: 3000
listeners:
- routes:
- backends:
- mcp:
targets:
- name: kubectl-mcp-server
mcp:
host: http://localhost:8000/mcp
EOF
curl -fsSL https://raw.githubusercontent.com/kagent-dev/kmcp/refs/heads/main/scripts/get-kmcp.sh | bash
kmcp install
kmcp deploy package --deployment-name kubectl-mcp-server \
--manager npx --args kubectl-mcp-server
Category
Tools
kubectl-mcp-server call get_pods '{"namespace": "kube-system"}'
| Category | Tools |
|----------|-------|
| Pods | get_pods, get_logs, get_pod_events, check_pod_health, exec_in_pod, cleanup_pods, get_pod_conditions, get_previous_logs |
| Deployments | get_deployments, create_deployment, scale_deployment, kubectl_rollout, restart_deployment |
| Workloads | get_statefulsets, get_daemonsets, get_jobs, get_replicasets |
| Services & Networking | get_services, get_ingress, get_endpoints, diagnose_network_connectivity, check_dns_resolution, trace_service_chain |
| Storage | get_persistent_volumes, get_pvcs, get_storage_classes |
| Config | get_configmaps, get_secrets, get_resource_quotas, get_limit_ranges |
| Cluster | get_nodes, get_namespaces, get_cluster_info, get_cluster_version, health_check, get_node_metrics, get_pod_metrics |
| RBAC & Security | get_rbac_roles, get_cluster_roles, get_service_accounts, audit_rbac_permissions, check_secrets_security, get_pod_security_info, get_admission_webhooks |
| CRDs | get_crds, get_priority_classes |
| Helm Releases | helm_list, helm_status, helm_history, helm_get_values, helm_get_manifest, helm_get_notes, helm_get_hooks, helm_get_all |
| Helm Charts | helm_show_chart, helm_show_values, helm_show_readme, helm_show_crds, helm_show_all, helm_search_repo, helm_search_hub |
| Helm Repos | helm_repo_list, helm_repo_add, helm_repo_remove, helm_repo_update |
| Helm Operations | install_helm_chart, upgrade_helm_chart, uninstall_helm_chart, helm_rollback, helm_test, helm_template, helm_template_apply |
| Helm Development | helm_create, helm_lint, helm_package, helm_pull, helm_dependency_list, helm_dependency_update, helm_dependency_build, helm_version, helm_env |
| Context | get_current_context, switch_context, list_contexts, list_kubeconfig_contexts |
| Diagnostics | diagnose_pod_crash, detect_pending_pods, get_evicted_pods, compare_namespaces |
| Operations | kubectl_apply, kubectl_create, kubectl_describe, kubectl_patch, delete_resource, kubectl_cp, backup_resource, label_resource, annotate_resource, taint_node, wait_for_condition |
| Autoscaling | get_hpa, get_pdb |
| Cost Optimization | get_resource_recommendations, get_idle_resources, get_resource_quotas_usage, get_cost_analysis, get_overprovisioned_resources, get_resource_trends, get_namespace_cost_allocation, optimize_resource_requests |
| Advanced | kubectl_generic, kubectl_explain, get_api_resources, port_forward, get_resource_usage, node_management |
| UI Dashboards | show_pod_logs_ui, show_pods_dashboard_ui, show_resource_yaml_ui, show_cluster_overview_ui, show_events_timeline_ui, render_k8s_dashboard_screenshot |
| GitOps (Flux/Argo) | gitops_apps_list, gitops_app_get, gitops_app_sync, gitops_app_status, gitops_sources_list, gitops_source_get, gitops_detect_engine |
| Cert-Manager | certs_list, certs_get, certs_issuers_list, certs_issuer_get, certs_renew, certs_status_explain, certs_challenges_list, certs_requests_list, certs_detect |
| Policy (Kyverno/Gatekeeper) | policy_list, policy_get, policy_violations_list, policy_explain_denial, policy_audit, policy_detect |
| Backup (Velero) | backup_list, backup_get, backup_create, backup_delete, restore_list, restore_create, restore_get, backup_locations_list, backup_schedules_list, backup_schedule_create, backup_detect |
| KEDA Autoscaling | keda_scaledobjects_list, keda_scaledobject_get, keda_scaledjobs_list, keda_triggerauths_list, keda_triggerauth_get, keda_hpa_list, keda_detect |
| Cilium/Hubble | cilium_policies_list, cilium_policy_get, cilium_endpoints_list, cilium_identities_list, cilium_nodes_list, cilium_status, hubble_flows_query, cilium_detect |
| Argo Rollouts/Flagger | rollouts_list, rollout_get, rollout_status, rollout_promote, rollout_abort, rollout_retry, rollout_restart, analysis_runs_list, flagger_canaries_list, flagger_canary_get, rollouts_detect |
| Cluster API | capi_clusters_list, capi_cluster_get, capi_machines_list, capi_machine_get, capi_machinedeployments_list, capi_machinedeployment_scale, capi_machinesets_list, capi_machinehealthchecks_list, capi_clusterclasses_list, capi_cluster_kubeconfig, capi_detect |
| KubeVirt VMs | kubevirt_vms_list, kubevirt_vm_get, kubevirt_vmis_list, kubevirt_vm_start, kubevirt_vm_stop, kubevirt_vm_restart, kubevirt_vm_pause, kubevirt_vm_unpause, kubevirt_vm_migrate, kubevirt_datasources_list, kubevirt_instancetypes_list, kubevirt_datavolumes_list, kubevirt_detect |
| Istio/Kiali | istio_virtualservices_list, istio_virtualservice_get, istio_destinationrules_list, istio_gateways_list, istio_peerauthentications_list, istio_authorizationpolicies_list, istio_proxy_status, istio_analyze, istio_sidecar_status, istio_detect |
| vCluster (vind) | vind_detect_tool, vind_list_clusters_tool, vind_status_tool, vind_get_kubeconfig_tool, vind_logs_tool, vind_create_cluster_tool, vind_delete_cluster_tool, vind_pause_tool, vind_resume_tool, vind_connect_tool, vind_disconnect_tool, vind_upgrade_tool, vind_describe_tool, vind_platform_start_tool |
| kind (K8s in Docker) | kind_detect_tool, kind_version_tool, kind_list_clusters_tool, kind_get_nodes_tool, kind_get_kubeconfig_tool, kind_export_logs_tool, kind_cluster_info_tool, kind_node_labels_tool, kind_create_cluster_tool, kind_delete_cluster_tool, kind_delete_all_clusters_tool, kind_load_image_tool, kind_load_image_archive_tool, kind_build_node_image_tool, kind_set_kubeconfig_tool |
kubectl-mcp-server call get_pods '{"namespace": "kube-system"}'
Get beautiful HTML dashboards for visual cluster management.
Installation:
bash
Automate web-based Kubernetes operations with agent-browser integration.
Quick Setup:
export MCP_BROWSER_ENABLED=true
kubectl-mcp-server
What You Can Do:
- π Test deployed apps via Ingress URLs
- πΈ Screenshot Grafana, ArgoCD, or any K8s dashboard
- βοΈ Automate cloud console operations (EKS, GKE, AKS)
- π₯ Health check web applications
- π Export monitoring dashboards as PDF
- π Test authentication flows with persistent sessions
26 Available Tools: browser_open, browser_screenshot, browser_click, browser_fill, browser_test_ingress, browser_screenshot_grafana, browser_health_check, and 19 more
Advanced Features:
- Cloud providers: Browserbase, Browser Use
- Persistent browser profiles
- Remote CDP connections
- Session management
Works with Docker MCP Toolkit:
docker mcp server add kubectl-mcp-server mcp/kubectl-mcp-server:latest
docker mcp server configure kubectl-mcp-server --volume "$HOME/.kube:/root/.kube:ro"
docker mcp server enable kubectl-mcp-server
docker mcp client connect claude
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"kubectl mcp tool": {
"kubectl-mcp-server": {
"command": "npx",
"args": [
"-y",
"kubectl-mcp-server"
]
}
}
}
}
McpServers
{
"kubectl-mcp-server": {
"command": "npx",
"args": [
"-y",
"kubectl-mcp-server"
]
}
}
Install kubectl-mcp-server
arctl mcp install io.github.rohitg00/kubectl-mcp-server
Available via: PyPI (uvx), npm (npx), OCI (docker.io/rohitghumare64/kubectl-mcp-server)
agentgateway
Route to multiple MCP servers through agentgateway:
bashSign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



