← Back to directory
K

Kubernetes MCP Server

Community
MCP server for interacting with Kubernetes clusters via kubectl
Category
Dev Tools #108 of 438
Stars
★ 1.6k Very popular
Transport
stdio (local process)
Runtime
Node.js
Credentials
No credential needed
License
MIT
Last commit
Tools
23
61FMRS · C

The server is powerful but requires caution, especially in production. It is advised to enable non-destructive mode to reduce risk.

Strongest · Documentation 17/20 Weakest · Security and permissions 3/20

Reliability
10/20
Security and permissions
3/20
Maintenance
16/20
Documentation
17/20
Setup experience
15/20
Why each score
Reliability 10/20
The README indicates a mature npm package (v2.9.4) with many declared tools (kubectl_*, Helm, port-forward, cleanup, diagnose) and a CI badge; tests are mentioned (`bun run test`), but no committed test files or CI workflows were supplied in the source material, so execution cannot be verified. Deductions are made for lack of executable evidence, thin error-handling documentation, and minor README inconsistencies (duplicated kubectl_get listing, mixed helm tool naming).
Security and permissions 3/20
Cluster credentials are read from kubeconfig via path or YAML/JSON environment variables, and secret masking in responses is documented; an opt-in read-only/non-destructive mode exists. However, the default configuration exposes destructive tools (kubectl_delete, cleanup_pods, node_management drain, uninstall_helm_chart) and `kubectl_generic` (arbitrary kubectl command execution) with no server-side confirmation mechanism described. This triggers the red line for irreversible delete/remote-command defaults without confirmation, so the score is limited to 0-4; set to 3 because mitigations exist but are not the default.
Maintenance 16/20
MIT license, 1,519 stars, 6 open issues, not archived, documented release workflow, CI badge, CONTRIBUTING page, and versioned npm releases indicate sustained maintenance. Deductions are made for absence of an explicit security-response channel, lack of visible dependency-update evidence, and maintainer ownership being conveyed only through citation rather than a dedicated maintainers file.
Documentation 17/20
The README provides installation examples for Claude Code, Codex, Claude Desktop, VS Code, Cursor, and mcp-chat; it explains kubeconfig loading, non-destructive mode, observability, and architecture, and links to ADVANCED_README and the docs directory. It is missing per-tool parameter schemas, explicit limitations, and a general troubleshooting section; setup assumes user familiarity with kubectl/kubeconfig. After these deductions, the score is 17.
Setup experience 15/20
Installation is essentially `npx mcp-server-kubernetes` with explicit configuration snippets for six mainstream clients; prerequisites (kubectl, kubeconfig, cluster, optional Helm) are stated and a verification command is provided. The static calibration caps setup at 15 because no CI/test execution evidence was supplied; platform-specific issues and runtime verification are not covered, so the score is 15.

Static review · not runListed 2026-08-07

Read the FMRS scoring method →

Fit and risk

What it can accessRuns commands or codeUses the network

Best for

  • Developers and operators managing Kubernetes clusters via AI assistants
  • Scenarios requiring quick troubleshooting and diagnosis of K8s issues
  • Users integrating with MCP clients like Claude Desktop, Codex CLI

Not for

  • Users needing a GUI for Kubernetes management
  • Environments without kubectl or kubeconfig
  • Production environments where fine-grained RBAC control is trusted to AI assistants

Required permissions

  • Read and modify Kubernetes resources (possibly restricted by configuration)
  • Execute kubectl commands (including creating, deleting, updating resources)
  • Access kubeconfig file to connect to clusters
  • May perform port forwarding and node draining operations

Risks and side effects

  • Accidental deletion or modification of resources (mitigated by non-destructive mode)
  • Exposure of sensitive information (e.g., secrets, mitigated by secrets masking)
  • Overly broad permissions can lead to cluster misconfiguration or failures
  • Unauthorized access if kubeconfig is leaked

Setup

Before you start

Runtime:Node.js

Other optional settings (12)
ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS optional Set to true to enable non-destructive mode, disabling delete operations.
ALLOW_ONLY_READONLY_TOOLS optional Set to true to enable read-only mode.
ALLOWED_TOOLS optional Comma-delimited list of allowed tools to restrict availability.
MASK_SECRETS optional Set to false to disable automatic secrets masking in responses.
ENABLE_UNSAFE_STREAMABLE_HTTP_TRANSPORT optional Enables Streamable HTTP transport.
ENABLE_UNSAFE_SSE_TRANSPORT optional Enables SSE transport.
KUBECONFIG_YAML optional Provide kubeconfig as a YAML string.
KUBECONFIG_JSON optional Provide kubeconfig as a JSON string.
KUBECONFIG_PATH optional Path to kubeconfig file, defaults to ~/.kube/config.
ENABLE_TELEMETRY optional Set to true to enable OpenTelemetry observability.
OTEL_EXPORTER_OTLP_ENDPOINT optional OTLP endpoint for exporting traces, e.g. a local Jaeger.
OTEL_TRACES_SAMPLER optional Trace sampling strategy, e.g. always_on.
  1. Ensure kubectl is installed and a valid kubeconfig is configured.
  2. Add the server using npx or client integration: e.g., npx mcp-server-kubernetes.
  3. Configure the mcpServers entry in your client (e.g., Claude Desktop, VS Code).
.mcp.json
{
  "mcpServers": {
    "kubernetes": {
      "command": "npx",
      "args": [
        "mcp-server-kubernetes"
      ]
    }
  }
}

Shown for Claude Code. Other clients may use a different file or key (VS Code uses "servers") — the configurator below converts it.

.vscode/mcp.json
{
  "servers": {
    "kubernetes": {
      "command": "npx",
      "args": [
        "mcp-server-kubernetes"
      ]
    }
  }
}

Goes in your project's .vscode/mcp.json (VS Code uses a "servers" key).

Terminal
claude mcp add kubernetes -- npx mcp-server-kubernetes

Run it in a terminal; replace any <…> placeholders with your own values first.

Check that it works

Confirm the kubernetes server appears in your client's tool list with tools like kubectl_get and ping, then ask the AI to list your pods — a successful response proves the cluster connection works.

Troubleshooting

  1. Run kubectl get pods to verify connection
  2. Check that the kubeconfig path is correct
  3. Ensure kubectl is in PATH
  4. Check server logs for error messages
  5. Ensure environment variables (e.g., KUBECONFIG_PATH) are set correctly

Things to try

Once connected, you can ask your AI assistant things like:

  • List all pods in the current namespace
  • Create and apply an nginx deployment for me
  • Show me the logs for my-pod and diagnose why it is in CrashLoopBackOff
  • Scale my-deployment to 3 replicas

Tools 23

kubectl_get read-only
Get or list Kubernetes resources (e.g., pods, deployments, services)
kubectl_describe read-only
Describe Kubernetes resources in detail
kubectl_create writes
Create Kubernetes resources
kubectl_apply writes
Apply YAML manifests to create or update resources
kubectl_delete destructive
Delete Kubernetes resources
kubectl_logs read-only
Get logs from pods
kubectl_context read-only
Manage kubectl contexts (view, switch, set current context)
explain_resource read-only
Explain fields and structure of Kubernetes resources
Show 15 more tools
list_api_resources read-only
List API resources supported by the cluster
kubectl_scale writes
Scale resources (e.g., deployments)
kubectl_patch writes
Update fields of a resource
kubectl_rollout writes
Manage deployment rollouts (status, restart, rollback)
kubectl_generic writes
Execute any kubectl command
ping read-only
Verify connection to the cluster
port_forward writes
Forward local ports to pods or services
stop_port_forward writes
Stop port forwarding
install_helm_chart writes
Install a Helm chart
upgrade_helm_chart writes
Upgrade a Helm chart
uninstall_helm_chart destructive
Uninstall a Helm chart
helm_template_apply writes
Apply Helm chart via template rendering (bypasses auth issues)
helm_template_uninstall destructive
Uninstall Helm chart via template rendering (bypasses auth issues)
cleanup_pods destructive
Clean up problematic pods (e.g., Evicted, Error, CrashLoopBackOff)
node_management writes
Node management operations (cordon, drain, uncordon)

Use cases

Manage Kubernetes resources through natural language
Automate cluster troubleshooting
Install, upgrade, and uninstall Helm charts
Perform node maintenance operations
Port forward to access services within the cluster

Supported clients

Claude Code
Claude Desktop
Codex
Cursor
VS Code

Listed from the project's documentation, not tested by this site.

Overview

mcp-server-kubernetes is an MCP server that enables AI assistants to interact with Kubernetes clusters via kubectl. It supports loading kubeconfig from multiple sources and offers a rich set of tools for managing resources, performing Helm operations, port forwarding, node management, and more. The server supports non-destructive and read-only modes, and includes secrets masking for enhanced security.

Similar servers

Context7 80 · B

Upstash's official server providing up-to-date third-party library docs for AI coding assistants

★ 62.9k · Tools 2 Compare with this →

Source revision 3d71add20401 Data synced 2026-10-11 Read the FMRS scoring method