Manage Kubernetes Resources Programmatically
mcp-k8s-go gives AI assistants full Kubernetes cluster access: resources, pods, logs, and exec, with readonly and context guards.
Why it matters
Connect to and manage your Kubernetes clusters programmatically. View, monitor, and modify resources like pods, services, and deployments with fine-grained control.
Outcomes
What it gets done
List and manage Kubernetes contexts and namespaces
Interact with Kubernetes resources (pods, services, deployments)
Retrieve pod logs and execute commands within pods
Securely manage access with read-only modes and context restrictions
Install
Add it to your toolbox
Run in your project directory:
curl -fsSL https://spark.entire.vc/get/vb-mcp-k8s-go | bash Capabilities
Tools your agent gets
List Kubernetes contexts available in the cluster configuration.
List Kubernetes namespaces in the cluster.
List, get, create, and modify any Kubernetes resources.
List Kubernetes nodes in the cluster.
Get Kubernetes events from the cluster.
Get logs from Kubernetes pods.
Execute commands in Kubernetes pods.
Overview
mcp-k8s-go MCP Server
mcp-k8s-go gives an AI assistant Kubernetes cluster access - resources, pods, logs, events, and pod exec - through MCP, with readonly and context-restriction flags. Use it when an AI assistant needs to inspect or operate on a Kubernetes cluster, with write access and context scope deliberately restricted.
What it does
mcp-k8s-go is a Golang-based MCP server that connects an AI assistant to Kubernetes, exposing cluster contexts, namespaces, resources, nodes, pods, events, logs, and the ability to run commands inside a pod as MCP prompts, resources, and tools.
When to use - and when NOT to
Use it when you want an AI assistant to inspect or operate on a Kubernetes cluster: listing contexts and namespaces, listing, getting, creating, or modifying resources including pods, services, and deployments, checking pod logs for errors, or running a command inside a running pod. Because it can create and modify cluster resources and execute commands in pods, run it with --readonly to disable any tool that can write changes, and use --allowed-contexts to restrict which Kubernetes contexts are reachable at all, rather than exposing every context in your kubeconfig by default. Secrets are masked in output by default, so you'd have to deliberately disable that to see raw secret values.
Capabilities
Resource operations cover listing, getting, creating, and modifying any Kubernetes resource, with custom mappings for common types like pods, services, and deployments. Cluster visibility tools list contexts, namespaces, nodes, and pods, and can fetch Kubernetes events. Pod-level tools get pod logs and can run a command inside a pod directly. Configuration is controlled via the KUBECONFIG environment variable, defaulting to ~/.kube/config, and command-line flags: --allowed-contexts to restrict which contexts are usable, --readonly to disable write-capable tools, and --mask-secrets, on by default, to redact secret values from output.
How to install
Several installation paths are available depending on your prerequisites. Via Smithery, which requires Node.js and auto-configures Claude:
npx -y @smithery/cli install @strowk/mcp-k8s --client claude
Via mcp-get, also Node.js, also auto-configuring Claude:
npx @michaellatman/mcp-get@latest install @strowk/mcp-k8s
Prebuilt npm packages and GitHub release binaries are also available for manual Claude configuration, Docker images are provided, and it can be built from source if you have Golang installed. Configure Claude Desktop by pointing the mcpServers entry at the mcp-k8s binary with your chosen flags, for example --allowed-contexts=dev,prod --readonly to scope access to two contexts and disable write operations.
You can also browse the server directly with the MCP Inspector to see its resources and tools before wiring it into a client: npx @modelcontextprotocol/inspector npx @strowk/mcp-k8s.
Who it's for
Platform and SRE teams who want an AI assistant to inspect and, if explicitly enabled, operate on a Kubernetes cluster - resources, pods, logs, and events - with context and write-access restrictions to keep the blast radius contained.
Source README
Golang-based MCP server connecting to Kubernetes
MCP K8S Go
Features ⚙ Browse With Inspector ⚙ Use With Claude ⚙ Contributing ↗ ⚙ About MCP ↗
Features
MCP 💬 prompt 🗂️ resource 🤖 tool
- 🗂️🤖 List Kubernetes contexts
- 💬🤖 List Kubernetes namespaces
- 🤖 List, get, create and modify any Kubernetes resources
- includes custom mappings for resources like pods, services, deployments
- 🤖 List Kubernetes nodes
- 💬 List Kubernetes pods
- 🤖 Get Kubernetes events
- 🤖 Get Kubernetes pod logs
- 🤖 Run command in Kubernetes pod
Browse With Inspector
To use latest published version with Inspector you can run this:
npx @modelcontextprotocol/inspector npx @strowk/mcp-k8s
Use With Claude
Demo Usage
Following chat with Claude Desktop demonstrates how it looks when selected particular context as a resource and then asked to check pod logs for errors in kube-system namespace:
To use this MCP server with Claude Desktop (or any other client) you might need to choose which way of installation to use.
You have multiple options:
| Smithery | mcp-get | Pre-built NPM | Pre-built in Github | From sources | Using Docker | |
|---|---|---|---|---|---|---|
| Claude Setup | Auto | Auto | Manual | Manual | Manual | Manual |
| Prerequisite | Node.js | Node.js | Node.js | None | Golang | Docker |
Using Smithery
To install MCP K8S Go for Claude Desktop automatically via Smithery:
npx -y @smithery/cli install @strowk/mcp-k8s --client claude
Using mcp-get
To install MCP K8S Go for Claude Desktop automatically via mcp-get:
npx @michaellatman/mcp-get@latest install @strowk/mcp-k8s
Manually with prebuilt binaries
Prebuilt from npm
Use this if you have npm installed and want to use pre-built binaries:
npm install -g @strowk/mcp-k8s
Then check version by running mcp-k8s --version and if this printed installed version, you can proceed to add configuration to claude_desktop_config.json file:
{
"mcpServers": {
"mcp_k8s": {
"command": "mcp-k8s",
"args": []
}
}
}
, or using npx with any client:
npx @strowk/mcp-k8s
For example for Claude:
{
"mcpServers": {
"mcp_k8s": {
"command": "npx",
"args": [
"@strowk/mcp-k8s"
]
}
}
}
From GitHub releases
Head to GitHub releases and download the latest release for your platform.
Unpack the archive, which would contain binary named mcp-k8s-go, put that binary somewhere in your PATH and then add the following configuration to the claude_desktop_config.json file:
{
"mcpServers": {
"mcp_k8s": {
"command": "mcp-k8s-go",
"args": []
}
}
}
Building from source
You would need Golang installed to build this project:
go get github.com/strowk/mcp-k8s-go
go install github.com/strowk/mcp-k8s-go
, and then add the following configuration to the claude_desktop_config.json file:
{
"mcpServers": {
"mcp_k8s_go": {
"command": "mcp-k8s-go",
"args": []
}
}
}
Using Docker
This server is built and published to Docker Hub since 0.3.1-beta.2 release with multi-arch images available for linux/amd64 and linux/arm64 architectures.
You can use latest tag f.e like this:
docker run -i -v ~/.kube/config:/home/nonroot/.kube/config --rm mcpk8s/server:latest
Windows users might need to replace ~/.kube/config with //c/Users/<username>/.kube/config at least in Git Bash.
For Claude:
{
"mcpServers": {
"mcp_k8s_go": {
"command": "docker",
"args": [
"run",
"-i",
"-v",
"~/.kube/config:/home/nonroot/.kube/config",
"--rm",
"mcpk8s/server:latest"
]
}
}
}
Environment Variables and Command-line Options
The following environment variables are used by the MCP server:
KUBECONFIG: Path to your Kubernetes configuration file (optional, defaults to ~/.kube/config)
The following command-line options are supported:
--allowed-contexts=<ctx1,ctx2,...>: Comma-separated list of allowed Kubernetes contexts that users can access. If not specified, all contexts are allowed.--readonly: Disables any tool which can write changes to the cluster--help: Display help information--version: Display version information--mask-secrets: Mask secrets in the output (default: true). Use--mask-secrets=falseto disable masking
For example if you are configuring Claude Desktop, you can add the following configuration to claude_desktop_config.json file:
{
"mcpServers": {
"mcp_k8s": {
"command": "mcp-k8s",
"args": [
"--allowed-contexts=dev,prod",
"--readonly"
]
}
}
}
, which would allow only dev and prod contexts to be used and would disable any tool which can write changes to the cluster.
FAQ
Common questions
Discussion
Questions & comments · 0
Sign In Sign in to leave a comment.