An MCP server that provides tools for analyzing and validating Linkerd service mesh configuration, health, connectivity policies, and traffic metrics
The Linkerd MCP server provides 9 read-only tools for Kubernetes mesh introspection. All tools have basic descriptions (80-180 chars) and structured input schemas with type definitions. However, critical gaps prevent a higher score: (1) Output schemas are completely undocumented, no tool description specifies what fields or structure callers should expect; (2) Parameter descriptions lack actionable detail (e.g., 'time_range' says '5m', '1h', '24h' but doesn't state if these are the ONLY valid options or if arbitrary durations work); (3) No error handling guidance, tools fail silently or return opaque errors with no recovery hints; (4) Most tools cluster around similar functions (analyze_connectivity, get_allowed_targets, get_allowed_sources) with subtle naming differences that could confuse LLM selection. Tool names follow verb-noun convention (get_, list_, check_, analyze_, validate_) which is a positive baseline. All tools are read-only (low risk), but lack the richness expected of production-grade Kubernetes introspection tools.
Analyzes Linkerd policies to determine allowed connectivity between services
Analyze traffic metrics between two services
Checks the health status of the Linkerd service mesh in the cluster
Find all services that can communicate with a given target service based on Linkerd authorization policies
Find all services that a given source service can communicate with based on Linkerd authorization policies
Get health summary for all services in a namespace based on metrics
Get traffic metrics for a service (request rate, latency, success rate)
Output schemas completely undocumented for all 9 tools. LLMs cannot plan downstream logic, extract required fields for chaining, or validate responses.
Semantic overlap: analyze_connectivity, get_allowed_targets, get_allowed_sources all retrieve policy-based connectivity info with subtle differences. Lack of clear differentiation forces LLM to guess which to call.
No error handling or recovery guidance. Tools provide no description of failure modes, invalid input guidance, or actionable error messages. LLM cannot self-correct on failures.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 60 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 54 | - | v1 |
Lists all services that are part of the Linkerd mesh
Validate Linkerd service mesh configuration
Pagination entirely absent. list_meshed_services and get_service_health_summary return results with no limit, page, offset, or cursor parameters. Large Kubernetes clusters will overflow context windows.
Parameter descriptions lack actionable constraints. time_range describes examples ('5m', '1h', '24h') but doesn't state if these are enums or if arbitrary durations (e.g. '30s', '90d') are valid. resource_type in validate_mesh_config hints at enum but is not formally declared as one.
No tool composition guidance. No description explains what subsequent tools to call after results are returned, or what IDs/names the responses provide for chaining.