Back to Browse

Kubeview MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Read-only Model Context Protocol MCP server enabling code-driven AI analysis of Kubernetes clusters.

About

Read-only Model Context Protocol MCP server enabling code-driven AI analysis of Kubernetes clusters.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (4 strong, 3 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry. Trust signals: 3 highly-trusted packages.

4 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Path to kubeconfig file; defaults to ~/.kube/config if unset.Optional

Environment variable: KUBECONFIG

Transport mode: 'stdio' (default) or 'http'. The published package metadata still targets stdio by default.Optional

Environment variable: MCP_TRANSPORT

Server mode: 'code' (default), compatibility alias 'all', or direct 'tools'.Optional

Environment variable: MCP_MODE

Comma-separated configurable denials inside run_code. Environment overrides JSON; an empty value enables all configurable capabilities.Optional

Environment variable: MCP_CODE_MODE_DISABLED_TOOLS

Argo Workflows capability override: auto, on, or off. Auto uses Kubernetes API discovery.Optional

Environment variable: MCP_ARGO_TOOLS

Argo CD capability override: auto, on, or off. Auto uses Kubernetes API discovery or explicit remote configuration.Optional

Environment variable: MCP_ARGOCD_TOOLS

Logging level: 'error', 'warn', 'info' (default), or 'debug'.Optional

Environment variable: MCP_LOG_LEVEL

Kubernetes context name to use. If unset, uses the current context from kubeconfig.Optional

Environment variable: MCP_KUBE_CONTEXT

Skip TLS certificate verification for Kubernetes API (use 'true' or '1'). Not recommended for production.Optional

Environment variable: MCP_K8S_SKIP_TLS_VERIFY

Enable global sensitive data masking. Set to 'true' or '1' to mask sensitive values in responses.Optional

Environment variable: MCP_HIDE_SENSITIVE

Default timeout in milliseconds for operations. If unset, uses plugin-specific defaults.Optional

Environment variable: MCP_TIMEOUT

HTTP bind host when MCP_TRANSPORT=http. Defaults to 127.0.0.1.Optional

Environment variable: MCP_HTTP_HOST

HTTP port when MCP_TRANSPORT=http. Defaults to 3000.Optional

Environment variable: MCP_HTTP_PORT

HTTP endpoint path when MCP_TRANSPORT=http. Defaults to /mcp.Optional

Environment variable: MCP_HTTP_PATH

Prefer JSON responses over SSE in HTTP mode. Set to 'true' or '1' to enable.Optional

Environment variable: MCP_HTTP_JSON_RESPONSE

Shared secret of at least 32 bytes for signing approval state. Required in HTTP mode and identical across replicas.Required

Environment variable: MCP_APPROVAL_STATE_SECRET

Absolute directory on writable storage shared by every HTTP replica, used to atomically prevent approval replay.Optional

Environment variable: MCP_APPROVAL_REPLAY_DIR

Comma-separated Host allowlist for HTTP mode. Required when binding to 0.0.0.0 or ::.Optional

Environment variable: MCP_ALLOWED_HOSTS

Comma-separated Origin allowlist for HTTP mode.Optional

Environment variable: MCP_ALLOWED_ORIGINS

Force the standalone code-mode runtime to use node:vm instead of isolated-vm. Set to '1' to enable.Optional

Environment variable: KUBE_MCP_FORCE_VM_SANDBOX

Disable Kubernetes plugin. Set to 'true' or '1' to disable.Optional

Environment variable: MCP_DISABLE_KUBERNETES_PLUGIN

Disable Helm plugin. Set to 'true' or '1' to disable.Optional

Environment variable: MCP_DISABLE_HELM_PLUGIN

Deprecated alias for MCP_ARGO_TOOLS=off.Optional

Environment variable: MCP_DISABLE_ARGO_PLUGIN

Deprecated alias for MCP_ARGOCD_TOOLS=off.Optional

Environment variable: MCP_DISABLE_ARGOCD_PLUGIN

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-mikhae1-kubeview": {
      "env": {
        "MCP_MODE": "your-mcp-mode-here",
        "KUBECONFIG": "your-kubeconfig-here",
        "MCP_TIMEOUT": "your-mcp-timeout-here",
        "MCP_HTTP_HOST": "your-mcp-http-host-here",
        "MCP_HTTP_PATH": "your-mcp-http-path-here",
        "MCP_HTTP_PORT": "your-mcp-http-port-here",
        "MCP_LOG_LEVEL": "your-mcp-log-level-here",
        "MCP_TRANSPORT": "your-mcp-transport-here",
        "MCP_ARGO_TOOLS": "your-mcp-argo-tools-here",
        "MCP_ARGOCD_TOOLS": "your-mcp-argocd-tools-here",
        "MCP_KUBE_CONTEXT": "your-mcp-kube-context-here",
        "MCP_ALLOWED_HOSTS": "your-mcp-allowed-hosts-here",
        "MCP_HIDE_SENSITIVE": "your-mcp-hide-sensitive-here",
        "MCP_ALLOWED_ORIGINS": "your-mcp-allowed-origins-here",
        "MCP_HTTP_JSON_RESPONSE": "your-mcp-http-json-response-here",
        "MCP_APPROVAL_REPLAY_DIR": "your-mcp-approval-replay-dir-here",
        "MCP_DISABLE_ARGO_PLUGIN": "your-mcp-disable-argo-plugin-here",
        "MCP_DISABLE_HELM_PLUGIN": "your-mcp-disable-helm-plugin-here",
        "MCP_K8S_SKIP_TLS_VERIFY": "your-mcp-k8s-skip-tls-verify-here",
        "KUBE_MCP_FORCE_VM_SANDBOX": "your-kube-mcp-force-vm-sandbox-here",
        "MCP_APPROVAL_STATE_SECRET": "your-mcp-approval-state-secret-here",
        "MCP_DISABLE_ARGOCD_PLUGIN": "your-mcp-disable-argocd-plugin-here",
        "MCP_CODE_MODE_DISABLED_TOOLS": "your-mcp-code-mode-disabled-tools-here",
        "MCP_DISABLE_KUBERNETES_PLUGIN": "your-mcp-disable-kubernetes-plugin-here"
      },
      "args": [
        "-y",
        "kubeview-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

KubeView MCP

npm version License: MIT Node.js TypeScript Default tools MCP

Read-only Model Context Protocol server for Kubernetes diagnostics. Agents get two public tools, load schemas on demand, and run multi-step cluster workflows in a single execution pass — so Kubernetes, Helm, Argo Workflows, and Argo CD stay reachable without saturating the context window.

Background: Evicting MCP tool calls from your Kubernetes cluster

How it works

v2 publishes exactly two public tools: run_code and approval-gated kube_pod_exec. Everything else is discovered inside the sandbox via tools.list(), tools.search(), and tools.help()progressive discovery + programmatic calling.

run_code executes bounded TypeScript with top-level await. One call can list workloads, correlate events, fetch logs, and diff Helm state without shipping intermediate payloads back through the model:

const pods = await tools.kubernetes.list({ namespace: 'payments' });
const unhealthy = pods.items.filter((p) => p.status?.phase !== 'Running');

return Promise.all(
  unhealthy.map(async (pod) => ({
    pod: pod.metadata?.name,
    logs: await tools.kubernetes.logs({
      namespace: 'payments',
      podName: pod.metadata?.name,
      tailLines: 100,
    }),
  })),
);
  • Sensitive isolationkube_pod_exec is unreachable from sandboxed code. Top-level exec requires MCP elicitation, is bound to the argument digest, expires after 10 minutes, and fails closed. kube_port_forward is never a top-level tool and is denied inside code mode by default. tools.disabled() reports which policy blocked a capability and whether that denial is configurable.
  • API-driven discovery — Argo Workflows and Argo CD are detected from the Kubernetes API, scoped to the active kube context, cached for 60 s. An unavailable optional API never blocks startup.
  • Native reads — resources, metrics, logs, events, and network probes go through the Kubernetes API. Helm releases are parsed from cluster Secrets or ConfigMaps; a local helm binary is a fallback, not a prerequisite.

Quick start

Prerequisites: Node.js ≥ 22 and access to a cluster (KUBECONFIG or in-cluster service account).

npx -y kubeview-mcp

# Claude Code
claude mcp add kubernetes -- npx kubeview-mcp
{
  "mcpServers": {
    "kubeview": {
      "command": "npx",
      "args": ["-y", "kubeview-mcp"]
    }
  }
}

In Cursor, /kubeview/code-mode injects the typed API into context.

Configuration

Cluster

VariableDescriptionDefault
KUBECONFIGKubeconfig path~/.kube/config
MCP_KUBE_CONTEXTKubernetes context; defaults to the active contextunset
MCP_K8S_SKIP_TLS_VERIFYSkip TLS verification for the Kubernetes API (true/1)false
MCP_TIMEOUTDefault operation timeout in msplugin default
MCP_HIDE_SENSITIVEMask sensitive data globallyfalse
MCP_DISABLE_KUBERNETES_PLUGINDisable the Kubernetes plugin (true/1)unset
MCP_DISABLE_HELM_PLUGINDisable the Helm plugin (true/1)unset

Mode and capabilities

VariableDescriptionDefault
MCP_MODEcode (default), all (alias), or toolscode
MCP_CODE_MODE_DISABLED_TOOLSComma-separated code-mode denials; empty enables allJSON/default
MCP_ARGO_TOOLSArgo override: auto, on, offauto
MCP_ARGOCD_TOOLSArgo CD override: auto, on, offauto
MCP_LOG_LEVELerror, warn, info, debuginfo
KUBE_MCP_FORCE_VM_SANDBOXForce node:vm in the standalone runtimeunset

HTTP transport

VariableDescriptionDefault
MCP_TRANSPORTstdio or httpstdio
MCP_HTTP_HOST / _PORTHTTP bind (when MCP_TRANSPORT=http)127.0.0.1:3000
MCP_HTTP_PATHStreamable HTTP endpoint path/mcp
MCP_HTTP_JSON_RESPONSEPrefer JSON over SSE (drops mid-call notifications)false
MCP_ALLOWED_HOSTSHost allowlist (required when binding to 0.0.0.0/::)local defaults
MCP_ALLOWED_ORIGINSOrigin allowlist for HTTPunset
MCP_APPROVAL_STATE_SECRETShared 32+ byte signing secret; required for HTTP approvalsephemeral (stdio)
MCP_APPROVAL_REPLAY_DIRAbsolute shared-volume directory for one-time HTTP approvalsunset
mkdir -p /tmp/kubeview-mcp-approvals
MCP_APPROVAL_STATE_SECRET='replace-with-at-least-32-random-bytes' \
MCP_APPROVAL_REPLAY_DIR=/tmp/kubeview-mcp-approvals \
MCP_TRANSPORT=http MCP_HTTP_HOST=127.0.0.1 MCP_HTTP_PORT=3000 npx -y kubeview-mcp

Endpoint: http://127.0.0.1:3000/mcp. HTTP follows the MCP 2026-07-28 stateless core: a fresh server per request, no initialize, no Mcp-Session-Id. Each request carries protocol version, client identity, and capabilities in _meta; modern requests add Mcp-Method/Mcp-Name for gateway routing. 2025-era clients use the SDK's stateless fallback on the same endpoint. State that must survive across calls has to be passed as tool arguments or handles.

HTTP mode refuses to start without both approval variables. Multi-replica deployments need the same secret and a shared writable replay directory; the /tmp example is for a single process only. The published MCP registry entry still targets stdio.

Tool surfaces

MCP_MODEExposed tools
unset / code / allrun_code, kube_pod_exec
toolskube_list, kube_get, kube_logs, helm, kube_pod_exec, plus detected argo and argocd

Domain tools use an operation discriminator:

  • helmlist | get | debug
  • argolist | get | logs | cron_list (when Workflow or CronWorkflow is discoverable)
  • argocdlist | get | resources | logs | history | status (when Application is discoverable, or with ARGOCD_SERVER + ARGOCD_AUTH_TOKEN)

Discovery is cached per kube context for 60 s. Missing optional APIs are omitted, not fatal.

Code mode

Code mode is the default (MCP_MODE=code). The agent writes short TypeScript against a typed tools global instead of calling dozens of MCP tools.

Inside run_code:

  • Typed tools namespaces for Kubernetes, Helm, and any detected Argo capabilities, generated from live schemas so parameters cannot be hallucinated.
  • Progressive discovery: tools.list(), tools.search(), tools.help(), and tools.disabled() (the last reports why a capability was blocked).
  • A locked-down runtime with only console and tools in scope — no filesystem, no network, no process.
CapabilityInside run_codeTop-level tool
kube_pod_execNever availableRequires per-call user approval (10 min, argument-bound)
kube_port_forwardDenied by default (configurable)Never exposed
Everything elseAvailableOnly when MCP_MODE=tools

Pod exec approval uses MCP elicitation and fails closed. The standalone npm run code-mode launcher has no trusted approval UI, so it always denies pod exec.

Customizing denials

MCP_CODE_MODE_DISABLED_TOOLS (comma-separated) controls which capabilities are blocked inside run_code. Resolution order:

  1. MCP_CODE_MODE_DISABLED_TOOLS env var
  2. disabledTools in kube-mcp.code-mode.json
  3. Default: ["kube_port_forward"]

An empty env value clears the list. kube_pod_exec cannot be added — it is permanently blocked.

Protocol

MCP 2026-07-28:

  • JSON Schema 2020-12 in/out contracts with server-side validation
  • Machine-readable structuredContent with text fallback
  • Accurate read-only, destructive, idempotent, open-world annotations
  • Deterministic tool ordering with cache hints for fixed vs. discovery-dependent surfaces
  • Stateless HTTP with discovery and header-based routing (Mcp-Method, Mcp-Name)
  • Execution failures returned as tool errors; protocol errors reserved for malformed requests

Local development

git clone https://github.com/mikhae1/kubeview-mcp.git
cd kubeview-mcp && npm install

npm run build      # compile
npm start          # build + run
npm test           # jest suite
npm run typecheck  # tsc --noEmit

# Invoke a tool directly
npm run command -- kube_list --namespace=default

Protocol tests pin the SDK v2 client to 2026-07-28 and route through the server handler in-process (no open ports):

npm test -- --runInBand \
  tests/server/StreamableHttpTransport.integration.test.ts \
  tests/server/StreamableHttpRuntime.test.ts \
  tests/server/TransportConfig.test.ts \
  tests/compat/McpSdkCompatibility.test.ts

Contributing

Contributions are welcome! Please feel free to submit an issue or a pull request.

License

MIT © mikhae1

Reviews

No reviews yet

Be the first to review this server!