MCP server for Kubernetes, Helm, ArgoCD, and FluxCD validation
The server defines 12 tools with generally good naming conventions (verb_noun pattern: select_, list_, flux_, kustomize_, helm_, kubeconform_, yaml_, argocd_). All tools have clear, substantive descriptions (194-280 chars average, well above baseline 34 minimum). However, schema completeness and parameter descriptions vary significantly. All tools shown have explicit input schemas with proper JSON Schema format and type definitions. Parameter descriptions are present and context-aware (e.g., 'Path to YAML file or directory containing manifests (required)'). Output schemas are NOT documented in the source code, no return type specifications are visible. Error handling guidance is minimal; tools do not return actionable recovery messages. Tools like kustomize_dryrun, helm_dryrun, flux_dryrun have prerequisites ('Requires select_kube_context to be called first') documented in descriptions, which is good. No security-sensitive parameters are exposed (no API keys, tokens). The dependency on select_kube_context before most tools is clearly signaled but creates a composition concern: agents must call list_kube_contexts → select_kube_context before useful work. This is documented but not enforced programmatically.
Show the difference between the live cluster state and the desired state for an ArgoCD application.
Get detailed status of a single ArgoCD application including sync status, health, and resources.
List all ArgoCD applications with sync and health status. Uses --core mode (kubeconfig only, no ArgoCD server auth needed). Requires select_kube_context to be called first.
Run 'flux check' to verify Flux installation and components health. Requires select_kube_context to be called first.
Validate FluxCD manifests with kubectl dry-run (client + server). ALWAYS use this before committing Flux YAML files to prevent GitOps reconciliation failures. Requires select_kube_context to be called first.
Get Flux reconciliation status for all resources across namespaces. Requires select_kube_context to be called first.
No output schemas documented. Return types for all 12 tools are not visible in source code. LLMs cannot predict downstream field structure or plan chained calls.
Insufficient error handling guidance. Tools do not indicate what to do if validation fails, context selection fails, or prerequisites are unmet. Descriptions mention prerequisites but do not guide recovery (e.g., 'If select_kube_context was not called, call it first').
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 68 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 58 | - | v1 |
Validate Helm chart by rendering and running kubectl dry-run (client + server). ALWAYS use this before committing Helm chart changes to prevent deployment failures. Requires select_kube_context to be called first.
Validate Kubernetes manifests against JSON schemas offline using kubeconform. Catches invalid fields, type mismatches, and missing required fields without a live cluster. Does NOT require select_kube_context.
Validate Kustomize overlay by building and running kubectl dry-run (client + server). ALWAYS use this before committing Kustomize overlay changes to prevent deployment failures. Requires select_kube_context to be called first.
List available kubectl contexts. Use this to see available contexts, then ALWAYS present the list to the user and ask them which context they want to use before calling select_kube_context. NEVER automatically select a context without user confirmation.
Select the Kubernetes context for all subsequent operations. MUST be called before using any other tool. Does NOT mutate global kubeconfig — context is held in memory only. IMPORTANT: Do NOT call this automatically. Always list contexts first and ask the user which context to use.
Validate YAML syntax of Kubernetes manifest files. Catches syntax errors, duplicate keys, and tab indentation. Use this as a first-pass check before kubeconform or dry-run. Does NOT require select_kube_context.
Stateful context selection via _selected_context global variable. Tools depend on prior calls to select_kube_context, but this dependency is not enforced at the tool level. An agent calling flux_dryrun without select_kube_context first will likely fail with a generic error rather than a clear guidance message.
Minor parameter description gaps. argocd_app_get and argocd_app_diff have minimal descriptions ('Get detailed status...', 'Show the difference...') relative to other tools. Shorter descriptions (70 chars) are below baseline guidance (194 chars average for A+ tools).
No idempotency or dry-run guarantees documented. Tools like flux_dryrun, kustomize_dryrun, helm_dryrun are inherently read-only (dryrun implies no mutation), but this is not signaled via tool annotations (readOnlyHint) in the schema. Agents cannot determine which tools are safe to retry.