An MCP server for managing and interacting with Kubernetes clusters via kubectl commands and Kubernetes Python API clients.
25 tools with mostly complete schemas and descriptions, but significant gaps in error handling, output documentation, and parameter validation. Tool naming follows verb_noun conventions well (list_*, get_*, delete_*, scale_*, restart_*). Descriptions are present and detailed (averaging 150-250 chars), exceeding minimum thresholds. However, most tools lack documented output schemas, parameter constraints (enums, ranges), and actionable error guidance. Several tools expose dangerous operations (run_kubectl_command, delete_pod) without confirmation patterns or destructive operation safeguards. Parameter descriptions are generic ('The namespace where...') without format constraints or validation rules. No pagination support despite list_* tools potentially returning hundreds of items.
Delete a specific pod from a Kubernetes cluster. This tool deletes a pod from the specified namespace. The pod will be terminated and if it's part of a deployment or other controller, it will be recreated.
Get detailed information about a specific pod. This tool returns comprehensive details about a pod including its current state, resource usage, events, and configuration.
List all ConfigMaps in a specific namespace (or all namespaces if namespace is 'all'). This tool returns a list of all ConfigMaps with their keys and sizes.
List all CronJobs in a specific namespace (or all namespaces if namespace is 'all'). This tool returns a list of all CronJobs with their schedule and current status.
Get the current context that the MCP server is using. This tool returns the current context stored in the global variable, which should match the context set by switch_context().
List all DaemonSets in a specific namespace (or all namespaces if namespace is 'all'). This tool returns a list of all DaemonSets with their current status and scheduling information.
No output schemas documented for any tool. LLMs cannot determine what fields to expect in responses, forcing them to guess what data is available and how to chain tools together. All 25 tools lack explicit return type documentation.
Destructive operations (run_kubectl_command, delete_pod) lack confirmation patterns, dry-run support, or pre-execution safeguards. An LLM could accidentally delete all pods in production without warning. These DESTRUCTIVE-risk tools need explicit confirmation requests before execution.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 47 | <=2025-11-25 | v2 |
List all deployments in a specific namespace (or all namespaces if namespace is 'all'). This tool returns a list of all Kubernetes deployments with their current status, including replica information and other metadata.
List all ingresses in a specific namespace (or all namespaces if namespace is 'all'). This tool returns a list of all Kubernetes ingresses with their rules, backends, and other configuration details.
List all Jobs in a specific namespace (or all namespaces if namespace is 'all'). This tool returns a list of all Jobs with their completion status and other relevant information.
List all namespaces in the Kubernetes cluster. This tool returns a list of all namespaces currently defined in the cluster, including their names and status.
List all nodes in the Kubernetes cluster. This tool returns a list of all nodes in the cluster with their status, resource capacity, and other relevant information.
Get logs from a specific pod in a Kubernetes cluster. This tool retrieves the stdout/stderr logs from a running or stopped pod.
Get CPU and memory metrics for a specific pod. This tool retrieves the current CPU and memory usage metrics for a running pod. Note: This requires the Kubernetes metrics server to be installed in the cluster.
List all pods in a specific namespace (or all namespaces if namespace is 'all'). This tool returns detailed information about pods in the specified namespace, including their names, statuses, and other metadata.
List all PersistentVolumes (PVs) in the cluster. This tool returns a list of all PersistentVolumes with their status, capacity, and access modes.
List all PersistentVolumeClaims (PVCs) in a specific namespace (or all namespaces if namespace is 'all'). This tool returns a list of all PVCs with their status, storage class, and capacity information.
List all secrets in a specific namespace (or all namespaces if namespace is 'all'). This tool returns a list of all secrets with their types and metadata. Note: The actual secret values are not displayed for security reasons.
List all services in a specific namespace (or all namespaces if namespace is 'all'). This tool returns a list of all Kubernetes services with their ClusterIP, external IPs, ports, and other relevant metadata.
List all StatefulSets in a specific namespace (or all namespaces if namespace is 'all'). This tool returns a list of all StatefulSets with their current status and replica information.
List all available Kubernetes clusters and contexts from your kubeconfig file. This tool retrieves all configured Kubernetes contexts from your kubeconfig file, showing both the context names and their associated cluster information. It also indicates which context is currently active.
Restart all pods in a deployment by rolling them out. This tool performs a rolling restart of all pods in a deployment, which can be useful for applying configuration changes or troubleshooting.
Execute any kubectl command with full privileges (use with caution). This tool allows execution of any kubectl command, including potentially destructive operations like delete, update, patch, apply, etc. It provides complete access to your Kubernetes cluster with the same permissions as your kubectl configuration. WARNING: This tool can perform destructive operations. Use run_kubectl_command_ro() for safe, read-only operations when you only need to gather information.
Execute safe, read-only kubectl commands. This tool allows execution of kubectl commands that only read data from your Kubernetes cluster and cannot perform destructive operations. It's safe to use for gathering information about your cluster's state.
Scale a deployment to a specific number of replicas. This tool updates the number of replicas for a deployment, scaling it up or down as needed.
Switch the active Kubernetes context to connect to a different cluster. This tool changes the current Kubernetes context to the specified one, allowing you to switch between different clusters or namespaces. After switching, all subsequent kubectl commands and API calls will be directed to the new context. The Kubernetes API clients are automatically reinitialized for the new context.
No parameter validation or constraint documentation. Parameters lack enums (e.g., namespace could validate against list_namespaces result), min/max for numeric parameters, or format specifications. LLMs will pass invalid namespace names or replica counts causing silent failures.
No error recovery guidance or error classification. Tools return bare Exception strings (e.g., 'Error: ...') without actionable recovery steps. When 'context not found', the error is clear, but most tool errors lack guidance on what to try next or whether the error is retryable.
List tools (get_pods, get_deployments, get_services, etc.) lack pagination support. No limit, offset, page_size, or cursor parameters documented. Large result sets will exceed context windows and degrade LLM reasoning; spec advises pagination for lists.
run_kubectl_command tool is a foot-gun. It accepts arbitrary kubectl commands with DESTRUCTIVE risk classification but no validation, quota, or permission gates. A malicious or confused agent could rm -rf / the cluster. This violates least-privilege design, split into granular, specific operations or add a confirmation gate.
Parameter descriptions are boilerplate and generic. 'The namespace to list pods from' does not explain what happens if namespace doesn't exist, whether 'all' is a valid literal string or a placeholder, or what the default behavior is. Descriptions should be LLM-optimized and include constraints and edge cases.
Inconsistent parameter naming and no type suffixes. 'container' parameter in get_pod_logs lacks a suffix like 'container_name' to clarify it's a name, not an ID. Some tools accept namespace='all', others may not, this should be normalized and documented in a shared parameter definition.
Tool get_pod_logs does not document the expected format of returned logs (plaintext, structured JSON lines, etc.). Absent documentation, LLMs cannot parse or summarize logs reliably.
Missing tool descriptions for output fields that enable chaining. For example, list_clusters returns 'cluster' field but downstream switch_context expects 'context', no documentation explains the mapping. Tools should document which output fields correspond to input parameters of follow-up tools.