Cloud ops#Cloud

Kubernetes MCP Server: native cluster access, no kubectl

A Go-native MCP server for Kubernetes and OpenShift that calls the API server directly, ships as one binary, and supports multiple clusters and read-only mode.

Project and installation docs

View project

https://github.com/containers/kubernetes-mcp-server

Many Kubernetes MCP servers are wrappers around kubectl and helm: install those first, then let the model assemble commands and parse text output. Kubernetes MCP Server is written in Go and talks to the Kubernetes API server directly, with no command-line tools to install. It ships as a single native binary, plus npm and Python packages and a container image. It lives under the containers organization, supports OpenShift as well, and had about 2.1k stars as of 2026-10-06.

What it does

  • Generic resource CRUD: create, update, get, list and delete any Kubernetes or OpenShift resource.
  • Pods: list, get and delete pods, read logs, check usage with top, exec commands in a container, and run an image with an optional service.
  • Events and namespaces: view events across namespaces and list namespaces and OpenShift projects.
  • Opt-in toolsets: helm installs, lists and uninstalls Helm releases, and Tekton, KubeVirt, Kiali and kcp toolsets are available too; none of these load by default.
  • Multi-cluster: works with every cluster in your kubeconfig at once and picks up configuration changes automatically.

Who it’s for

  • Developers asking a coding agent why a deployment won’t come up or a pod keeps restarting.
  • Platform engineers running several clusters who want quick answers about events and logs.

Setup

You need access to a cluster. Run it with npx; for Claude Desktop and similar clients:

{
  "mcpServers": {
    "kubernetes": {
      "command": "npx",
      "args": ["-y", "kubernetes-mcp-server@latest"]
    }
  }
}

Claude Code has its own getting-started guide in the project docs. Runtime settings go in a TOML file passed with --config.

Our take

There are many Kubernetes MCP servers. This one wins by skipping the CLI wrapper: direct API calls mean low latency, structured output and no kubectl on the machine. Toolsets are sensibly grouped, with only core and config on by default and Helm, Tekton or KubeVirt added when needed. Be clear about the risk: it can delete resources, exec into pods and install Helm charts. Against production, set read_only = true in the config and use denied_resources to hide Secrets and other sensitive kinds; the README also recommends a dedicated read-only ServiceAccount, described in its Kubernetes setup guide. Licensed Apache-2.0.