MCP server for Kuadrant API Gateway management, providing tools to create and configure Kubernetes Gateway API resources, DNS policies, TLS policies, rate limiting, authentication, and access to Kuadrant documentation
Static source inference · medium confidence · detected: Logging
Deprecated protocol patterns detected
Summary
The Kuadrant MCP server defines 6 Kubernetes management tools with GO struct-based schemas and parameter descriptions. However, the implementation has critical gaps: (1) All descriptions are present but very generic/brief (17-77 chars), falling below the 50-200 char optimal range for LLM reasoning. (2) Schemas exist in Go struct tags but lack critical constraints, no enums for required fields like gatewayClassName, issuerRef, or targetRef that accept specific Kubernetes resource types. (3) Parameter descriptions are minimal; many lack guidance on expected format, required structure, or dependency relationships (e.g., targetRef is just 'Reference to the target Gateway', no hint it's a Kubernetes ObjectReference with group/kind/name fields). (4) Output schemas are completely undocumented, tools return YAML strings with no structured response definition, forcing LLMs to parse text. (5) Error handling is minimal, handlers return string errors with no categorization or recovery guidance. (6) No idempotency guarantees, confirmation steps, or dry-run support for destructive Kubernetes writes. (7) Tool names are clear (create_*), but lack dependency hints and prerequisites documentation. Overall, this is a 'write-only' CRUD wrapper around Kuadrant APIs with minimal LLM-friendliness, typical of auto-generated or first-draft tool integrations.
Tools (6)
create_authpolicywritesource verified46/100
Create a Kuadrant AuthPolicy resource for authentication and authorization configuration
create_dnspolicywritesource verified47/100
Create a Kuadrant DNSPolicy resource for DNS and load balancing configuration
create_gatewaywritesource verified50/100
Create a Kubernetes Gateway resource for API Gateway management
create_httproutewritesource verified46/100
Create a Kubernetes HTTPRoute resource for defining HTTP routing rules
create_ratelimitpolicywritesource verified50/100
Create a Kuadrant RateLimitPolicy resource for rate limiting configuration
create_tlspolicywritesource verified47/100
Create a Kuadrant TLSPolicy resource for TLS/certificate management
Parameter descriptions are too brief (avg 25 - 27 chars) and generic, lacking format guidance, nested object structure, enum constraints, or dependency hints, well below the 50 - 200 char optimal range for LLM reasoning
Complex nested structures (e.g., listeners, parentRefs, rules, conditions) are typed as []interface{} or map[string]interface{} with no inline documentation of required/optional fields, validation rules, or Kubernetes conventions
create_gatewaycreate_httproute
Recommendations
Expand tool descriptions to 50 - 200 chars. Example for create_gateway: 'Create a Kubernetes Gateway for routing external traffic to backend services. Requires valid gatewayClassName (istio, nginx, or custom). Kuadrant policies can only attach to Gateways created with kuadrantEnabled=true. Returns YAML manifest for operator to apply. Prerequisites: Gateway CRD installed, target namespace exists.'
Add inline documentation for all complex/nested parameters. Example for create_httproute → parentRefs: 'Array of Kubernetes ObjectReferences to Gateway resources in same/other namespaces. Each reference: {"group":"gateway.networking.k8s.io", "kind":"Gateway", "name":"<gateway-name>", "namespace":"<namespace>"}. At least one required.'
Replace untyped []interface{} and map[string]interface{} with either (a) concrete Go structs with jsonschema tags, or (b) explicit documentation of nested object schemas in parameter descriptions. Document required vs optional fields within nested objects.
Add enum constraints via jsonschema tags. Example for gatewayClassName: jsonschema:"enum=istio|nginx|kong" and update description to list valid options.
Document output schema for each tool. Example for create_gateway: 'Returns object with fields: {manifest: string (YAML), apiVersion: string, kind: string, metadata: {name, namespace}, status: {ready: bool, message: string (if error)}'.
Implement structured error responses. Instead of bare strings, return objects with {code: string, message: string, recoverable: bool, next_step?: string}. Example: 'Namespace "default" does not exist. Call create_namespace first or use an existing namespace.'
Spec posture evidence
Inferred effective spec: <=2025-11-25.
Relies on Logging (deprecated) - log to stderr or use OpenTelemetry
No idempotency guarantees, dry-run support, or confirmation steps for destructive Kubernetes writes, agents could accidentally recreate or overwrite resources
Mutual exclusivity (e.g., providerRef vs providerRefs in DNSPolicy) is documented inline but not enforced; LLMs will pass both, causing ambiguous failures
No guidance on Kubernetes namespace isolation, RBAC, or permission scopes, agents have no visibility into what resources they can/cannot create in given namespaces
Add 'dry_run' parameter (boolean, default false) to all create_* tools. When true, return the manifest without applying it to the cluster. This gives LLMs a safe way to preview changes.
Document tool sequencing and prerequisites in descriptions. Example for create_ratelimitpolicy: 'Prerequisite: HTTPRoute or Gateway already exists. RateLimitPolicy attaches via targetRef, create the target resource first.'
Clarify targetRef format across all policy tools. Standardize on single description: 'Kubernetes ObjectReference pointing to the target resource (Gateway or HTTPRoute). Format: {"group": "gateway.networking.k8s.io", "kind": "Gateway|HTTPRoute", "name": "<resource-name>", "namespace": "<namespace>"}'.
For create_dnspolicy: explicitly forbid setting both providerRef and providerRefs; document priority order or mutual exclusivity rule in parameter descriptions.
Add per-tool permission/scope declarations. Example: 'Required permissions: create gateways, create httproutes. Affected namespaces: any namespace specified in tool parameters.'
Document rate limiting and retry behavior. Example: 'Tool rate-limits Kubernetes API calls to 100 req/min. Retryable errors: timeout, 429, transient API unavailability. Non-retryable: validation errors, forbidden namespaces.'
For duration/renewBefore fields in create_tlspolicy, add format constraints. Example: 'duration string format: ^\\d+(s|m|h|d)$ e.g. 90d, 2160h. Must be >= 1 day.'
Return metadata that enables tool chaining. E.g., create_gateway should return {manifest: ..., name: ..., namespace: ..., gatewayClassName: ...} so create_httproute can immediately reference the created Gateway.
Add examples to descriptions (but not sample values LLMs might copy). Example for create_gateway: 'Typical usage: Create an Istio Gateway on port 443 with TLS, then attach HTTPRoutes to define request routing. Use kuadrantEnabled=true if Kuadrant policies will be applied.'