Repository files navigation

Kai Logo

Kai - Kubernetes MCP Server

A Model Context Protocol (MCP) server for managing Kubernetes clusters from MCP-compatible clients like Claude Desktop, Cursor, and Continue.

Overview

Kai exposes Kubernetes operations as MCP tools, letting an LLM client manage your cluster through natural language — workloads, networking, config, storage, RBAC, custom resources, and raw manifests.

Features

Core Workloads

  • Pods - Create, list, get, delete, and stream logs
  • Deployments - Create, list, describe, and update
  • Jobs - Batch workload management (create, get, list, delete)
  • CronJobs - Scheduled batch workloads (create, get, list, delete)

Networking

  • Services - Create, get, list, and delete
  • Ingress - HTTP/HTTPS routing, TLS configuration (create, get, list, update, delete)

Configuration

  • ConfigMaps - Configuration management (create, get, list, update, delete)
  • Secrets - Secret management (create, get, list, update, delete)
  • Namespaces - Namespace management (create, get, list, delete)

Cluster Operations

  • Context Management - Switch contexts, list contexts, rename, delete
  • Nodes - Node monitoring, cordoning, and draining (list, get, cordon, uncordon, drain)
  • Cluster Health - Cluster status and resource metrics (cluster health, node/pod metrics)

Storage

  • Persistent Volumes - PV management (list, get, delete) and PVC management (create, list, get, delete)
  • Storage Classes - Storage class operations (list, get)

Security

  • RBAC - Roles, RoleBindings, ClusterRoles, ClusterRoleBindings, and ServiceAccounts (list, get)

Utilities

  • Port Forwarding - Forward ports to pods and services (start, stop, list sessions)

Advanced

  • Apply/Delete Manifests - Apply or delete raw YAML/JSON, multi-document and any kind including CRDs (apply_yaml, delete_yaml)
  • Custom Resources - CRD and custom resource operations (list/get CRDs, list/get/delete custom resources)
  • Events - Event listing and filtering (by namespace, type, involved object)
  • API Discovery - API resource exploration (list_api_resources)

Requirements

The server connects to your current kubectl context by default. Ensure you have access to a Kubernetes cluster configured for kubectl (e.g., minikube, Rancher Desktop, kind, EKS, GKE, AKS).

Installation

go install github.com/basebandit/kai/cmd/kai@latest

Container image

A multi-arch image (linux/amd64, linux/arm64) is published on Docker Hub:

docker pull cyclon/kai:v1.0.0
docker run --rm cyclon/kai:v1.0.0 -version

CLI Options

kai [options]
Options:
-kubeconfig string Path to kubeconfig file (default "~/.kube/config")
-context string Name for the loaded context (default "local")
-in-cluster Use in-cluster config (when running inside a pod)
-transport string stdio (default), streamable-http, or sse-legacy
-sse-addr string HTTP listen address for streamable-http/sse-legacy (default ":8080")
-tls-cert string Path to TLS certificate (enables HTTPS)
-tls-key string Path to TLS private key (enables HTTPS)
-request-timeout duration Timeout for Kubernetes API requests (default 30s)
-metrics Expose Prometheus metrics at /metrics (default true)
-log-format string json (default) or text
-log-level string debug, info, warn, error (default "info")
-version Show version information

Logs are written to stderr in structured JSON format by default, making them easy to parse:

{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"kubeconfig loaded","path":"/home/user/.kube/config","context":"local"}
{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"starting server","transport":"stdio"}

Configuration

Claude Desktop

Edit your Claude Desktop configuration:

# macOS
code ~/Library/Application\ Support/Claude/claude_desktop_config.json
# Linux
code ~/.config/Claude/claude_desktop_config.json

Add the server configuration:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

With custom kubeconfig:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai",
"args": ["-kubeconfig", "/path/to/custom/kubeconfig"]
}
}
}

Cursor

Add to your Cursor MCP settings:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

Continue

Add to your Continue configuration (~/.continue/config.json):

{
"experimental": {
"modelContextProtocolServers": [
{
"transport": {
"type": "stdio",
"command": "/path/to/kai"
}
}
]
}
}

HTTP Mode (web clients, remote use)

For non-stdio clients, run the streamable HTTP transport:

kai -transport=streamable-http -sse-addr=:8080

The MCP endpoint is http://localhost:8080/mcp. Health probes are at /healthz and /readyz, and Prometheus metrics at /metrics. The legacy SSE transport (-transport=sse-legacy, endpoint /sse) still works but is deprecated.

Custom Kubeconfig

By default, Kai uses ~/.kube/config. You can specify a different kubeconfig:

kai -kubeconfig=/path/to/custom/kubeconfig -context=my-cluster

Running Inside a Kubernetes Cluster

When deploying Kai inside a Kubernetes cluster, use the -in-cluster flag to automatically use the pod's service account credentials:

kai -in-cluster -transport=streamable-http -sse-addr=:8080

The recommended way to run Kai in-cluster is with kmcp (from kagent), which manages MCP servers as MCPServer resources:

apiVersion: kagent.dev/v1alpha1kind: MCPServermetadata:
name: kaispec:
transportType: httphttpTransport:
targetPort: 8080path: /mcpdeployment:
image: cyclon/kai:v1.0.0port: 8080cmd: /kaiargs: ["-in-cluster", "-transport=streamable-http", "-sse-addr=:8080"]serviceAccountName: kai

kmcp creates the Deployment and Service for you. The service account needs RBAC for the resources Kai manages — broad get/list/watch, plus create/update/delete where you use mutating tools. See the kmcp deploy guide.

Runnable example: deploy/kagent/kai.example.yaml (test-only — grants cluster-admin; scope down for real use).

Usage Examples

Once configured, you can interact with your cluster using natural language:

  • "List all pods in the default namespace"
  • "Create a deployment named nginx with 3 replicas using the nginx:latest image"
  • "Show me the logs for pod my-app"
  • "Delete the service named backend"
  • "Create a cronjob that runs every 5 minutes"
  • "Create an ingress for my-app with TLS enabled"
  • "Port forward service nginx on port 8080:80"
  • "Apply this manifest: "

Contributing

Contributions are welcome! Please see our contributing guidelines for more information.

License

This project is licensed under the MIT License.


Kubernetes MCP Server

About

An MCP Server for Kubernetes

Topics

Resources

Code of conduct

Contributing

Stars

20 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

Kai Logo

Kai - Kubernetes MCP Server

A Model Context Protocol (MCP) server for managing Kubernetes clusters from MCP-compatible clients like Claude Desktop, Cursor, and Continue.

Overview

Kai exposes Kubernetes operations as MCP tools, letting an LLM client manage your cluster through natural language — workloads, networking, config, storage, RBAC, custom resources, and raw manifests.

Features

Core Workloads

  • Pods - Create, list, get, delete, and stream logs
  • Deployments - Create, list, describe, and update
  • Jobs - Batch workload management (create, get, list, delete)
  • CronJobs - Scheduled batch workloads (create, get, list, delete)

Networking

  • Services - Create, get, list, and delete
  • Ingress - HTTP/HTTPS routing, TLS configuration (create, get, list, update, delete)

Configuration

  • ConfigMaps - Configuration management (create, get, list, update, delete)
  • Secrets - Secret management (create, get, list, update, delete)
  • Namespaces - Namespace management (create, get, list, delete)

Cluster Operations

  • Context Management - Switch contexts, list contexts, rename, delete
  • Nodes - Node monitoring, cordoning, and draining (list, get, cordon, uncordon, drain)
  • Cluster Health - Cluster status and resource metrics (cluster health, node/pod metrics)

Storage

  • Persistent Volumes - PV management (list, get, delete) and PVC management (create, list, get, delete)
  • Storage Classes - Storage class operations (list, get)

Security

  • RBAC - Roles, RoleBindings, ClusterRoles, ClusterRoleBindings, and ServiceAccounts (list, get)

Utilities

  • Port Forwarding - Forward ports to pods and services (start, stop, list sessions)

Advanced

  • Apply/Delete Manifests - Apply or delete raw YAML/JSON, multi-document and any kind including CRDs (apply_yaml, delete_yaml)
  • Custom Resources - CRD and custom resource operations (list/get CRDs, list/get/delete custom resources)
  • Events - Event listing and filtering (by namespace, type, involved object)
  • API Discovery - API resource exploration (list_api_resources)

Requirements

The server connects to your current kubectl context by default. Ensure you have access to a Kubernetes cluster configured for kubectl (e.g., minikube, Rancher Desktop, kind, EKS, GKE, AKS).

Installation

go install github.com/basebandit/kai/cmd/kai@latest

Container image

A multi-arch image (linux/amd64, linux/arm64) is published on Docker Hub:

docker pull cyclon/kai:v1.0.0
docker run --rm cyclon/kai:v1.0.0 -version

CLI Options

kai [options]
Options:
-kubeconfig string Path to kubeconfig file (default "~/.kube/config")
-context string Name for the loaded context (default "local")
-in-cluster Use in-cluster config (when running inside a pod)
-transport string stdio (default), streamable-http, or sse-legacy
-sse-addr string HTTP listen address for streamable-http/sse-legacy (default ":8080")
-tls-cert string Path to TLS certificate (enables HTTPS)
-tls-key string Path to TLS private key (enables HTTPS)
-request-timeout duration Timeout for Kubernetes API requests (default 30s)
-metrics Expose Prometheus metrics at /metrics (default true)
-log-format string json (default) or text
-log-level string debug, info, warn, error (default "info")
-version Show version information

Logs are written to stderr in structured JSON format by default, making them easy to parse:

{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"kubeconfig loaded","path":"/home/user/.kube/config","context":"local"}
{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"starting server","transport":"stdio"}

Configuration

Claude Desktop

Edit your Claude Desktop configuration:

# macOS
code ~/Library/Application\ Support/Claude/claude_desktop_config.json
# Linux
code ~/.config/Claude/claude_desktop_config.json

Add the server configuration:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

With custom kubeconfig:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai",
"args": ["-kubeconfig", "/path/to/custom/kubeconfig"]
}
}
}

Cursor

Add to your Cursor MCP settings:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

Continue

Add to your Continue configuration (~/.continue/config.json):

{
"experimental": {
"modelContextProtocolServers": [
{
"transport": {
"type": "stdio",
"command": "/path/to/kai"
}
}
]
}
}

HTTP Mode (web clients, remote use)

For non-stdio clients, run the streamable HTTP transport:

kai -transport=streamable-http -sse-addr=:8080

The MCP endpoint is http://localhost:8080/mcp. Health probes are at /healthz and /readyz, and Prometheus metrics at /metrics. The legacy SSE transport (-transport=sse-legacy, endpoint /sse) still works but is deprecated.

Custom Kubeconfig

By default, Kai uses ~/.kube/config. You can specify a different kubeconfig:

kai -kubeconfig=/path/to/custom/kubeconfig -context=my-cluster

Running Inside a Kubernetes Cluster

When deploying Kai inside a Kubernetes cluster, use the -in-cluster flag to automatically use the pod's service account credentials:

kai -in-cluster -transport=streamable-http -sse-addr=:8080

The recommended way to run Kai in-cluster is with kmcp (from kagent), which manages MCP servers as MCPServer resources:

apiVersion: kagent.dev/v1alpha1kind: MCPServermetadata:
name: kaispec:
transportType: httphttpTransport:
targetPort: 8080path: /mcpdeployment:
image: cyclon/kai:v1.0.0port: 8080cmd: /kaiargs: ["-in-cluster", "-transport=streamable-http", "-sse-addr=:8080"]serviceAccountName: kai

kmcp creates the Deployment and Service for you. The service account needs RBAC for the resources Kai manages — broad get/list/watch, plus create/update/delete where you use mutating tools. See the kmcp deploy guide.

Runnable example: deploy/kagent/kai.example.yaml (test-only — grants cluster-admin; scope down for real use).

Usage Examples

Once configured, you can interact with your cluster using natural language:

  • "List all pods in the default namespace"
  • "Create a deployment named nginx with 3 replicas using the nginx:latest image"
  • "Show me the logs for pod my-app"
  • "Delete the service named backend"
  • "Create a cronjob that runs every 5 minutes"
  • "Create an ingress for my-app with TLS enabled"
  • "Port forward service nginx on port 8080:80"
  • "Apply this manifest: "

Contributing

Contributions are welcome! Please see our contributing guidelines for more information.

License

This project is licensed under the MIT License.


Kubernetes MCP Server

About

An MCP Server for Kubernetes

Topics

Resources

Code of conduct

Contributing

Stars

20 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Kai Logo

Kai - Kubernetes MCP Server

A Model Context Protocol (MCP) server for managing Kubernetes clusters from MCP-compatible clients like Claude Desktop, Cursor, and Continue.

Overview

Kai exposes Kubernetes operations as MCP tools, letting an LLM client manage your cluster through natural language — workloads, networking, config, storage, RBAC, custom resources, and raw manifests.

Features

Core Workloads

  • Pods - Create, list, get, delete, and stream logs
  • Deployments - Create, list, describe, and update
  • Jobs - Batch workload management (create, get, list, delete)
  • CronJobs - Scheduled batch workloads (create, get, list, delete)

Networking

  • Services - Create, get, list, and delete
  • Ingress - HTTP/HTTPS routing, TLS configuration (create, get, list, update, delete)

Configuration

  • ConfigMaps - Configuration management (create, get, list, update, delete)
  • Secrets - Secret management (create, get, list, update, delete)
  • Namespaces - Namespace management (create, get, list, delete)

Cluster Operations

  • Context Management - Switch contexts, list contexts, rename, delete
  • Nodes - Node monitoring, cordoning, and draining (list, get, cordon, uncordon, drain)
  • Cluster Health - Cluster status and resource metrics (cluster health, node/pod metrics)

Storage

  • Persistent Volumes - PV management (list, get, delete) and PVC management (create, list, get, delete)
  • Storage Classes - Storage class operations (list, get)

Security

  • RBAC - Roles, RoleBindings, ClusterRoles, ClusterRoleBindings, and ServiceAccounts (list, get)

Utilities

  • Port Forwarding - Forward ports to pods and services (start, stop, list sessions)

Advanced

  • Apply/Delete Manifests - Apply or delete raw YAML/JSON, multi-document and any kind including CRDs (apply_yaml, delete_yaml)
  • Custom Resources - CRD and custom resource operations (list/get CRDs, list/get/delete custom resources)
  • Events - Event listing and filtering (by namespace, type, involved object)
  • API Discovery - API resource exploration (list_api_resources)

Requirements

The server connects to your current kubectl context by default. Ensure you have access to a Kubernetes cluster configured for kubectl (e.g., minikube, Rancher Desktop, kind, EKS, GKE, AKS).

Installation

go install github.com/basebandit/kai/cmd/kai@latest

Container image

A multi-arch image (linux/amd64, linux/arm64) is published on Docker Hub:

docker pull cyclon/kai:v1.0.0
docker run --rm cyclon/kai:v1.0.0 -version

CLI Options

kai [options]
Options:
-kubeconfig string Path to kubeconfig file (default "~/.kube/config")
-context string Name for the loaded context (default "local")
-in-cluster Use in-cluster config (when running inside a pod)
-transport string stdio (default), streamable-http, or sse-legacy
-sse-addr string HTTP listen address for streamable-http/sse-legacy (default ":8080")
-tls-cert string Path to TLS certificate (enables HTTPS)
-tls-key string Path to TLS private key (enables HTTPS)
-request-timeout duration Timeout for Kubernetes API requests (default 30s)
-metrics Expose Prometheus metrics at /metrics (default true)
-log-format string json (default) or text
-log-level string debug, info, warn, error (default "info")
-version Show version information

Logs are written to stderr in structured JSON format by default, making them easy to parse:

{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"kubeconfig loaded","path":"/home/user/.kube/config","context":"local"}
{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"starting server","transport":"stdio"}

Configuration

Claude Desktop

Edit your Claude Desktop configuration:

# macOS
code ~/Library/Application\ Support/Claude/claude_desktop_config.json
# Linux
code ~/.config/Claude/claude_desktop_config.json

Add the server configuration:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

With custom kubeconfig:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai",
"args": ["-kubeconfig", "/path/to/custom/kubeconfig"]
}
}
}

Cursor

Add to your Cursor MCP settings:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

Continue

Add to your Continue configuration (~/.continue/config.json):

{
"experimental": {
"modelContextProtocolServers": [
{
"transport": {
"type": "stdio",
"command": "/path/to/kai"
}
}
]
}
}

HTTP Mode (web clients, remote use)

For non-stdio clients, run the streamable HTTP transport:

kai -transport=streamable-http -sse-addr=:8080

The MCP endpoint is http://localhost:8080/mcp. Health probes are at /healthz and /readyz, and Prometheus metrics at /metrics. The legacy SSE transport (-transport=sse-legacy, endpoint /sse) still works but is deprecated.

Custom Kubeconfig

By default, Kai uses ~/.kube/config. You can specify a different kubeconfig:

kai -kubeconfig=/path/to/custom/kubeconfig -context=my-cluster

Running Inside a Kubernetes Cluster

When deploying Kai inside a Kubernetes cluster, use the -in-cluster flag to automatically use the pod's service account credentials:

kai -in-cluster -transport=streamable-http -sse-addr=:8080

The recommended way to run Kai in-cluster is with kmcp (from kagent), which manages MCP servers as MCPServer resources:

apiVersion: kagent.dev/v1alpha1kind: MCPServermetadata:
name: kaispec:
transportType: httphttpTransport:
targetPort: 8080path: /mcpdeployment:
image: cyclon/kai:v1.0.0port: 8080cmd: /kaiargs: ["-in-cluster", "-transport=streamable-http", "-sse-addr=:8080"]serviceAccountName: kai

kmcp creates the Deployment and Service for you. The service account needs RBAC for the resources Kai manages — broad get/list/watch, plus create/update/delete where you use mutating tools. See the kmcp deploy guide.

Runnable example: deploy/kagent/kai.example.yaml (test-only — grants cluster-admin; scope down for real use).

Usage Examples

Once configured, you can interact with your cluster using natural language:

  • "List all pods in the default namespace"
  • "Create a deployment named nginx with 3 replicas using the nginx:latest image"
  • "Show me the logs for pod my-app"
  • "Delete the service named backend"
  • "Create a cronjob that runs every 5 minutes"
  • "Create an ingress for my-app with TLS enabled"
  • "Port forward service nginx on port 8080:80"
  • "Apply this manifest: "

Contributing

Contributions are welcome! Please see our contributing guidelines for more information.

License

This project is licensed under the MIT License.


Kubernetes MCP Server

About

An MCP Server for Kubernetes

Topics

Resources

Code of conduct

Contributing

Stars

20 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Kai Logo

Kai - Kubernetes MCP Server

A Model Context Protocol (MCP) server for managing Kubernetes clusters from MCP-compatible clients like Claude Desktop, Cursor, and Continue.

Overview

Kai exposes Kubernetes operations as MCP tools, letting an LLM client manage your cluster through natural language — workloads, networking, config, storage, RBAC, custom resources, and raw manifests.

Features

Core Workloads

  • Pods - Create, list, get, delete, and stream logs
  • Deployments - Create, list, describe, and update
  • Jobs - Batch workload management (create, get, list, delete)
  • CronJobs - Scheduled batch workloads (create, get, list, delete)

Networking

  • Services - Create, get, list, and delete
  • Ingress - HTTP/HTTPS routing, TLS configuration (create, get, list, update, delete)

Configuration

  • ConfigMaps - Configuration management (create, get, list, update, delete)
  • Secrets - Secret management (create, get, list, update, delete)
  • Namespaces - Namespace management (create, get, list, delete)

Cluster Operations

  • Context Management - Switch contexts, list contexts, rename, delete
  • Nodes - Node monitoring, cordoning, and draining (list, get, cordon, uncordon, drain)
  • Cluster Health - Cluster status and resource metrics (cluster health, node/pod metrics)

Storage

  • Persistent Volumes - PV management (list, get, delete) and PVC management (create, list, get, delete)
  • Storage Classes - Storage class operations (list, get)

Security

  • RBAC - Roles, RoleBindings, ClusterRoles, ClusterRoleBindings, and ServiceAccounts (list, get)

Utilities

  • Port Forwarding - Forward ports to pods and services (start, stop, list sessions)

Advanced

  • Apply/Delete Manifests - Apply or delete raw YAML/JSON, multi-document and any kind including CRDs (apply_yaml, delete_yaml)
  • Custom Resources - CRD and custom resource operations (list/get CRDs, list/get/delete custom resources)
  • Events - Event listing and filtering (by namespace, type, involved object)
  • API Discovery - API resource exploration (list_api_resources)

Requirements

The server connects to your current kubectl context by default. Ensure you have access to a Kubernetes cluster configured for kubectl (e.g., minikube, Rancher Desktop, kind, EKS, GKE, AKS).

Installation

go install github.com/basebandit/kai/cmd/kai@latest

Container image

A multi-arch image (linux/amd64, linux/arm64) is published on Docker Hub:

docker pull cyclon/kai:v1.0.0
docker run --rm cyclon/kai:v1.0.0 -version

CLI Options

kai [options]
Options:
-kubeconfig string Path to kubeconfig file (default "~/.kube/config")
-context string Name for the loaded context (default "local")
-in-cluster Use in-cluster config (when running inside a pod)
-transport string stdio (default), streamable-http, or sse-legacy
-sse-addr string HTTP listen address for streamable-http/sse-legacy (default ":8080")
-tls-cert string Path to TLS certificate (enables HTTPS)
-tls-key string Path to TLS private key (enables HTTPS)
-request-timeout duration Timeout for Kubernetes API requests (default 30s)
-metrics Expose Prometheus metrics at /metrics (default true)
-log-format string json (default) or text
-log-level string debug, info, warn, error (default "info")
-version Show version information

Logs are written to stderr in structured JSON format by default, making them easy to parse:

{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"kubeconfig loaded","path":"/home/user/.kube/config","context":"local"}
{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"starting server","transport":"stdio"}

Configuration

Claude Desktop

Edit your Claude Desktop configuration:

# macOS
code ~/Library/Application\ Support/Claude/claude_desktop_config.json
# Linux
code ~/.config/Claude/claude_desktop_config.json

Add the server configuration:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

With custom kubeconfig:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai",
"args": ["-kubeconfig", "/path/to/custom/kubeconfig"]
}
}
}

Cursor

Add to your Cursor MCP settings:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

Continue

Add to your Continue configuration (~/.continue/config.json):

{
"experimental": {
"modelContextProtocolServers": [
{
"transport": {
"type": "stdio",
"command": "/path/to/kai"
}
}
]
}
}

HTTP Mode (web clients, remote use)

For non-stdio clients, run the streamable HTTP transport:

kai -transport=streamable-http -sse-addr=:8080

The MCP endpoint is http://localhost:8080/mcp. Health probes are at /healthz and /readyz, and Prometheus metrics at /metrics. The legacy SSE transport (-transport=sse-legacy, endpoint /sse) still works but is deprecated.

Custom Kubeconfig

By default, Kai uses ~/.kube/config. You can specify a different kubeconfig:

kai -kubeconfig=/path/to/custom/kubeconfig -context=my-cluster

Running Inside a Kubernetes Cluster

When deploying Kai inside a Kubernetes cluster, use the -in-cluster flag to automatically use the pod's service account credentials:

kai -in-cluster -transport=streamable-http -sse-addr=:8080

The recommended way to run Kai in-cluster is with kmcp (from kagent), which manages MCP servers as MCPServer resources:

apiVersion: kagent.dev/v1alpha1kind: MCPServermetadata:
name: kaispec:
transportType: httphttpTransport:
targetPort: 8080path: /mcpdeployment:
image: cyclon/kai:v1.0.0port: 8080cmd: /kaiargs: ["-in-cluster", "-transport=streamable-http", "-sse-addr=:8080"]serviceAccountName: kai

kmcp creates the Deployment and Service for you. The service account needs RBAC for the resources Kai manages — broad get/list/watch, plus create/update/delete where you use mutating tools. See the kmcp deploy guide.

Runnable example: deploy/kagent/kai.example.yaml (test-only — grants cluster-admin; scope down for real use).

Usage Examples

Once configured, you can interact with your cluster using natural language:

  • "List all pods in the default namespace"
  • "Create a deployment named nginx with 3 replicas using the nginx:latest image"
  • "Show me the logs for pod my-app"
  • "Delete the service named backend"
  • "Create a cronjob that runs every 5 minutes"
  • "Create an ingress for my-app with TLS enabled"
  • "Port forward service nginx on port 8080:80"
  • "Apply this manifest: "

Contributing

Contributions are welcome! Please see our contributing guidelines for more information.

License

This project is licensed under the MIT License.


Kubernetes MCP Server

About

An MCP Server for Kubernetes

Topics

Resources

Code of conduct

Contributing

Stars

20 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

Kai Logo

Kai - Kubernetes MCP Server

A Model Context Protocol (MCP) server for managing Kubernetes clusters from MCP-compatible clients like Claude Desktop, Cursor, and Continue.

Overview

Kai exposes Kubernetes operations as MCP tools, letting an LLM client manage your cluster through natural language — workloads, networking, config, storage, RBAC, custom resources, and raw manifests.

Features

Core Workloads

  • Pods - Create, list, get, delete, and stream logs
  • Deployments - Create, list, describe, and update
  • Jobs - Batch workload management (create, get, list, delete)
  • CronJobs - Scheduled batch workloads (create, get, list, delete)

Networking

  • Services - Create, get, list, and delete
  • Ingress - HTTP/HTTPS routing, TLS configuration (create, get, list, update, delete)

Configuration

  • ConfigMaps - Configuration management (create, get, list, update, delete)
  • Secrets - Secret management (create, get, list, update, delete)
  • Namespaces - Namespace management (create, get, list, delete)

Cluster Operations

  • Context Management - Switch contexts, list contexts, rename, delete
  • Nodes - Node monitoring, cordoning, and draining (list, get, cordon, uncordon, drain)
  • Cluster Health - Cluster status and resource metrics (cluster health, node/pod metrics)

Storage

  • Persistent Volumes - PV management (list, get, delete) and PVC management (create, list, get, delete)
  • Storage Classes - Storage class operations (list, get)

Security

  • RBAC - Roles, RoleBindings, ClusterRoles, ClusterRoleBindings, and ServiceAccounts (list, get)

Utilities

  • Port Forwarding - Forward ports to pods and services (start, stop, list sessions)

Advanced

  • Apply/Delete Manifests - Apply or delete raw YAML/JSON, multi-document and any kind including CRDs (apply_yaml, delete_yaml)
  • Custom Resources - CRD and custom resource operations (list/get CRDs, list/get/delete custom resources)
  • Events - Event listing and filtering (by namespace, type, involved object)
  • API Discovery - API resource exploration (list_api_resources)

Requirements

The server connects to your current kubectl context by default. Ensure you have access to a Kubernetes cluster configured for kubectl (e.g., minikube, Rancher Desktop, kind, EKS, GKE, AKS).

Installation

go install github.com/basebandit/kai/cmd/kai@latest

Container image

A multi-arch image (linux/amd64, linux/arm64) is published on Docker Hub:

docker pull cyclon/kai:v1.0.0
docker run --rm cyclon/kai:v1.0.0 -version

CLI Options

kai [options]
Options:
-kubeconfig string Path to kubeconfig file (default "~/.kube/config")
-context string Name for the loaded context (default "local")
-in-cluster Use in-cluster config (when running inside a pod)
-transport string stdio (default), streamable-http, or sse-legacy
-sse-addr string HTTP listen address for streamable-http/sse-legacy (default ":8080")
-tls-cert string Path to TLS certificate (enables HTTPS)
-tls-key string Path to TLS private key (enables HTTPS)
-request-timeout duration Timeout for Kubernetes API requests (default 30s)
-metrics Expose Prometheus metrics at /metrics (default true)
-log-format string json (default) or text
-log-level string debug, info, warn, error (default "info")
-version Show version information

Logs are written to stderr in structured JSON format by default, making them easy to parse:

{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"kubeconfig loaded","path":"/home/user/.kube/config","context":"local"}
{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"starting server","transport":"stdio"}

Configuration

Claude Desktop

Edit your Claude Desktop configuration:

# macOS
code ~/Library/Application\ Support/Claude/claude_desktop_config.json
# Linux
code ~/.config/Claude/claude_desktop_config.json

Add the server configuration:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

With custom kubeconfig:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai",
"args": ["-kubeconfig", "/path/to/custom/kubeconfig"]
}
}
}

Cursor

Add to your Cursor MCP settings:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

Continue

Add to your Continue configuration (~/.continue/config.json):

{
"experimental": {
"modelContextProtocolServers": [
{
"transport": {
"type": "stdio",
"command": "/path/to/kai"
}
}
]
}
}

HTTP Mode (web clients, remote use)

For non-stdio clients, run the streamable HTTP transport:

kai -transport=streamable-http -sse-addr=:8080

The MCP endpoint is http://localhost:8080/mcp. Health probes are at /healthz and /readyz, and Prometheus metrics at /metrics. The legacy SSE transport (-transport=sse-legacy, endpoint /sse) still works but is deprecated.

Custom Kubeconfig

By default, Kai uses ~/.kube/config. You can specify a different kubeconfig:

kai -kubeconfig=/path/to/custom/kubeconfig -context=my-cluster

Running Inside a Kubernetes Cluster

When deploying Kai inside a Kubernetes cluster, use the -in-cluster flag to automatically use the pod's service account credentials:

kai -in-cluster -transport=streamable-http -sse-addr=:8080

The recommended way to run Kai in-cluster is with kmcp (from kagent), which manages MCP servers as MCPServer resources:

apiVersion: kagent.dev/v1alpha1kind: MCPServermetadata:
name: kaispec:
transportType: httphttpTransport:
targetPort: 8080path: /mcpdeployment:
image: cyclon/kai:v1.0.0port: 8080cmd: /kaiargs: ["-in-cluster", "-transport=streamable-http", "-sse-addr=:8080"]serviceAccountName: kai

kmcp creates the Deployment and Service for you. The service account needs RBAC for the resources Kai manages — broad get/list/watch, plus create/update/delete where you use mutating tools. See the kmcp deploy guide.

Runnable example: deploy/kagent/kai.example.yaml (test-only — grants cluster-admin; scope down for real use).

Usage Examples

Once configured, you can interact with your cluster using natural language:

  • "List all pods in the default namespace"
  • "Create a deployment named nginx with 3 replicas using the nginx:latest image"
  • "Show me the logs for pod my-app"
  • "Delete the service named backend"
  • "Create a cronjob that runs every 5 minutes"
  • "Create an ingress for my-app with TLS enabled"
  • "Port forward service nginx on port 8080:80"
  • "Apply this manifest: "

Contributing

Contributions are welcome! Please see our contributing guidelines for more information.

License

This project is licensed under the MIT License.


Kubernetes MCP Server

About

An MCP Server for Kubernetes

Topics

Resources

Code of conduct

Contributing

Stars

20 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Kai Logo

Kai - Kubernetes MCP Server

A Model Context Protocol (MCP) server for managing Kubernetes clusters from MCP-compatible clients like Claude Desktop, Cursor, and Continue.

Overview

Kai exposes Kubernetes operations as MCP tools, letting an LLM client manage your cluster through natural language — workloads, networking, config, storage, RBAC, custom resources, and raw manifests.

Features

Core Workloads

  • Pods - Create, list, get, delete, and stream logs
  • Deployments - Create, list, describe, and update
  • Jobs - Batch workload management (create, get, list, delete)
  • CronJobs - Scheduled batch workloads (create, get, list, delete)

Networking

  • Services - Create, get, list, and delete
  • Ingress - HTTP/HTTPS routing, TLS configuration (create, get, list, update, delete)

Configuration

  • ConfigMaps - Configuration management (create, get, list, update, delete)
  • Secrets - Secret management (create, get, list, update, delete)
  • Namespaces - Namespace management (create, get, list, delete)

Cluster Operations

  • Context Management - Switch contexts, list contexts, rename, delete
  • Nodes - Node monitoring, cordoning, and draining (list, get, cordon, uncordon, drain)
  • Cluster Health - Cluster status and resource metrics (cluster health, node/pod metrics)

Storage

  • Persistent Volumes - PV management (list, get, delete) and PVC management (create, list, get, delete)
  • Storage Classes - Storage class operations (list, get)

Security

  • RBAC - Roles, RoleBindings, ClusterRoles, ClusterRoleBindings, and ServiceAccounts (list, get)

Utilities

  • Port Forwarding - Forward ports to pods and services (start, stop, list sessions)

Advanced

  • Apply/Delete Manifests - Apply or delete raw YAML/JSON, multi-document and any kind including CRDs (apply_yaml, delete_yaml)
  • Custom Resources - CRD and custom resource operations (list/get CRDs, list/get/delete custom resources)
  • Events - Event listing and filtering (by namespace, type, involved object)
  • API Discovery - API resource exploration (list_api_resources)

Requirements

The server connects to your current kubectl context by default. Ensure you have access to a Kubernetes cluster configured for kubectl (e.g., minikube, Rancher Desktop, kind, EKS, GKE, AKS).

Installation

go install github.com/basebandit/kai/cmd/kai@latest

Container image

A multi-arch image (linux/amd64, linux/arm64) is published on Docker Hub:

docker pull cyclon/kai:v1.0.0
docker run --rm cyclon/kai:v1.0.0 -version

CLI Options

kai [options]
Options:
-kubeconfig string Path to kubeconfig file (default "~/.kube/config")
-context string Name for the loaded context (default "local")
-in-cluster Use in-cluster config (when running inside a pod)
-transport string stdio (default), streamable-http, or sse-legacy
-sse-addr string HTTP listen address for streamable-http/sse-legacy (default ":8080")
-tls-cert string Path to TLS certificate (enables HTTPS)
-tls-key string Path to TLS private key (enables HTTPS)
-request-timeout duration Timeout for Kubernetes API requests (default 30s)
-metrics Expose Prometheus metrics at /metrics (default true)
-log-format string json (default) or text
-log-level string debug, info, warn, error (default "info")
-version Show version information

Logs are written to stderr in structured JSON format by default, making them easy to parse:

{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"kubeconfig loaded","path":"/home/user/.kube/config","context":"local"}
{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"starting server","transport":"stdio"}

Configuration

Claude Desktop

Edit your Claude Desktop configuration:

# macOS
code ~/Library/Application\ Support/Claude/claude_desktop_config.json
# Linux
code ~/.config/Claude/claude_desktop_config.json

Add the server configuration:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

With custom kubeconfig:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai",
"args": ["-kubeconfig", "/path/to/custom/kubeconfig"]
}
}
}

Cursor

Add to your Cursor MCP settings:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

Continue

Add to your Continue configuration (~/.continue/config.json):

{
"experimental": {
"modelContextProtocolServers": [
{
"transport": {
"type": "stdio",
"command": "/path/to/kai"
}
}
]
}
}

HTTP Mode (web clients, remote use)

For non-stdio clients, run the streamable HTTP transport:

kai -transport=streamable-http -sse-addr=:8080

The MCP endpoint is http://localhost:8080/mcp. Health probes are at /healthz and /readyz, and Prometheus metrics at /metrics. The legacy SSE transport (-transport=sse-legacy, endpoint /sse) still works but is deprecated.

Custom Kubeconfig

By default, Kai uses ~/.kube/config. You can specify a different kubeconfig:

kai -kubeconfig=/path/to/custom/kubeconfig -context=my-cluster

Running Inside a Kubernetes Cluster

When deploying Kai inside a Kubernetes cluster, use the -in-cluster flag to automatically use the pod's service account credentials:

kai -in-cluster -transport=streamable-http -sse-addr=:8080

The recommended way to run Kai in-cluster is with kmcp (from kagent), which manages MCP servers as MCPServer resources:

apiVersion: kagent.dev/v1alpha1kind: MCPServermetadata:
name: kaispec:
transportType: httphttpTransport:
targetPort: 8080path: /mcpdeployment:
image: cyclon/kai:v1.0.0port: 8080cmd: /kaiargs: ["-in-cluster", "-transport=streamable-http", "-sse-addr=:8080"]serviceAccountName: kai

kmcp creates the Deployment and Service for you. The service account needs RBAC for the resources Kai manages — broad get/list/watch, plus create/update/delete where you use mutating tools. See the kmcp deploy guide.

Runnable example: deploy/kagent/kai.example.yaml (test-only — grants cluster-admin; scope down for real use).

Usage Examples

Once configured, you can interact with your cluster using natural language:

  • "List all pods in the default namespace"
  • "Create a deployment named nginx with 3 replicas using the nginx:latest image"
  • "Show me the logs for pod my-app"
  • "Delete the service named backend"
  • "Create a cronjob that runs every 5 minutes"
  • "Create an ingress for my-app with TLS enabled"
  • "Port forward service nginx on port 8080:80"
  • "Apply this manifest: "

Contributing

Contributions are welcome! Please see our contributing guidelines for more information.

License

This project is licensed under the MIT License.


Kubernetes MCP Server

About

An MCP Server for Kubernetes

Topics

Resources

Code of conduct

Contributing

Stars

20 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Kai Logo

Kai - Kubernetes MCP Server

A Model Context Protocol (MCP) server for managing Kubernetes clusters from MCP-compatible clients like Claude Desktop, Cursor, and Continue.

Overview

Kai exposes Kubernetes operations as MCP tools, letting an LLM client manage your cluster through natural language — workloads, networking, config, storage, RBAC, custom resources, and raw manifests.

Features

Core Workloads

  • Pods - Create, list, get, delete, and stream logs
  • Deployments - Create, list, describe, and update
  • Jobs - Batch workload management (create, get, list, delete)
  • CronJobs - Scheduled batch workloads (create, get, list, delete)

Networking

  • Services - Create, get, list, and delete
  • Ingress - HTTP/HTTPS routing, TLS configuration (create, get, list, update, delete)

Configuration

  • ConfigMaps - Configuration management (create, get, list, update, delete)
  • Secrets - Secret management (create, get, list, update, delete)
  • Namespaces - Namespace management (create, get, list, delete)

Cluster Operations

  • Context Management - Switch contexts, list contexts, rename, delete
  • Nodes - Node monitoring, cordoning, and draining (list, get, cordon, uncordon, drain)
  • Cluster Health - Cluster status and resource metrics (cluster health, node/pod metrics)

Storage

  • Persistent Volumes - PV management (list, get, delete) and PVC management (create, list, get, delete)
  • Storage Classes - Storage class operations (list, get)

Security

  • RBAC - Roles, RoleBindings, ClusterRoles, ClusterRoleBindings, and ServiceAccounts (list, get)

Utilities

  • Port Forwarding - Forward ports to pods and services (start, stop, list sessions)

Advanced

  • Apply/Delete Manifests - Apply or delete raw YAML/JSON, multi-document and any kind including CRDs (apply_yaml, delete_yaml)
  • Custom Resources - CRD and custom resource operations (list/get CRDs, list/get/delete custom resources)
  • Events - Event listing and filtering (by namespace, type, involved object)
  • API Discovery - API resource exploration (list_api_resources)

Requirements

The server connects to your current kubectl context by default. Ensure you have access to a Kubernetes cluster configured for kubectl (e.g., minikube, Rancher Desktop, kind, EKS, GKE, AKS).

Installation

go install github.com/basebandit/kai/cmd/kai@latest

Container image

A multi-arch image (linux/amd64, linux/arm64) is published on Docker Hub:

docker pull cyclon/kai:v1.0.0
docker run --rm cyclon/kai:v1.0.0 -version

CLI Options

kai [options]
Options:
-kubeconfig string Path to kubeconfig file (default "~/.kube/config")
-context string Name for the loaded context (default "local")
-in-cluster Use in-cluster config (when running inside a pod)
-transport string stdio (default), streamable-http, or sse-legacy
-sse-addr string HTTP listen address for streamable-http/sse-legacy (default ":8080")
-tls-cert string Path to TLS certificate (enables HTTPS)
-tls-key string Path to TLS private key (enables HTTPS)
-request-timeout duration Timeout for Kubernetes API requests (default 30s)
-metrics Expose Prometheus metrics at /metrics (default true)
-log-format string json (default) or text
-log-level string debug, info, warn, error (default "info")
-version Show version information

Logs are written to stderr in structured JSON format by default, making them easy to parse:

{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"kubeconfig loaded","path":"/home/user/.kube/config","context":"local"}
{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"starting server","transport":"stdio"}

Configuration

Claude Desktop

Edit your Claude Desktop configuration:

# macOS
code ~/Library/Application\ Support/Claude/claude_desktop_config.json
# Linux
code ~/.config/Claude/claude_desktop_config.json

Add the server configuration:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

With custom kubeconfig:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai",
"args": ["-kubeconfig", "/path/to/custom/kubeconfig"]
}
}
}

Cursor

Add to your Cursor MCP settings:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

Continue

Add to your Continue configuration (~/.continue/config.json):

{
"experimental": {
"modelContextProtocolServers": [
{
"transport": {
"type": "stdio",
"command": "/path/to/kai"
}
}
]
}
}

HTTP Mode (web clients, remote use)

For non-stdio clients, run the streamable HTTP transport:

kai -transport=streamable-http -sse-addr=:8080

The MCP endpoint is http://localhost:8080/mcp. Health probes are at /healthz and /readyz, and Prometheus metrics at /metrics. The legacy SSE transport (-transport=sse-legacy, endpoint /sse) still works but is deprecated.

Custom Kubeconfig

By default, Kai uses ~/.kube/config. You can specify a different kubeconfig:

kai -kubeconfig=/path/to/custom/kubeconfig -context=my-cluster

Running Inside a Kubernetes Cluster

When deploying Kai inside a Kubernetes cluster, use the -in-cluster flag to automatically use the pod's service account credentials:

kai -in-cluster -transport=streamable-http -sse-addr=:8080

The recommended way to run Kai in-cluster is with kmcp (from kagent), which manages MCP servers as MCPServer resources:

apiVersion: kagent.dev/v1alpha1kind: MCPServermetadata:
name: kaispec:
transportType: httphttpTransport:
targetPort: 8080path: /mcpdeployment:
image: cyclon/kai:v1.0.0port: 8080cmd: /kaiargs: ["-in-cluster", "-transport=streamable-http", "-sse-addr=:8080"]serviceAccountName: kai

kmcp creates the Deployment and Service for you. The service account needs RBAC for the resources Kai manages — broad get/list/watch, plus create/update/delete where you use mutating tools. See the kmcp deploy guide.

Runnable example: deploy/kagent/kai.example.yaml (test-only — grants cluster-admin; scope down for real use).

Usage Examples

Once configured, you can interact with your cluster using natural language:

  • "List all pods in the default namespace"
  • "Create a deployment named nginx with 3 replicas using the nginx:latest image"
  • "Show me the logs for pod my-app"
  • "Delete the service named backend"
  • "Create a cronjob that runs every 5 minutes"
  • "Create an ingress for my-app with TLS enabled"
  • "Port forward service nginx on port 8080:80"
  • "Apply this manifest: "

Contributing

Contributions are welcome! Please see our contributing guidelines for more information.

License

This project is licensed under the MIT License.


Kubernetes MCP Server

About

An MCP Server for Kubernetes

Topics

Resources

Code of conduct

Contributing

Stars

20 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

Kai Logo

Kai - Kubernetes MCP Server

A Model Context Protocol (MCP) server for managing Kubernetes clusters from MCP-compatible clients like Claude Desktop, Cursor, and Continue.

Overview

Kai exposes Kubernetes operations as MCP tools, letting an LLM client manage your cluster through natural language — workloads, networking, config, storage, RBAC, custom resources, and raw manifests.

Features

Core Workloads

  • Pods - Create, list, get, delete, and stream logs
  • Deployments - Create, list, describe, and update
  • Jobs - Batch workload management (create, get, list, delete)
  • CronJobs - Scheduled batch workloads (create, get, list, delete)

Networking

  • Services - Create, get, list, and delete
  • Ingress - HTTP/HTTPS routing, TLS configuration (create, get, list, update, delete)

Configuration

  • ConfigMaps - Configuration management (create, get, list, update, delete)
  • Secrets - Secret management (create, get, list, update, delete)
  • Namespaces - Namespace management (create, get, list, delete)

Cluster Operations

  • Context Management - Switch contexts, list contexts, rename, delete
  • Nodes - Node monitoring, cordoning, and draining (list, get, cordon, uncordon, drain)
  • Cluster Health - Cluster status and resource metrics (cluster health, node/pod metrics)

Storage

  • Persistent Volumes - PV management (list, get, delete) and PVC management (create, list, get, delete)
  • Storage Classes - Storage class operations (list, get)

Security

  • RBAC - Roles, RoleBindings, ClusterRoles, ClusterRoleBindings, and ServiceAccounts (list, get)

Utilities

  • Port Forwarding - Forward ports to pods and services (start, stop, list sessions)

Advanced

  • Apply/Delete Manifests - Apply or delete raw YAML/JSON, multi-document and any kind including CRDs (apply_yaml, delete_yaml)
  • Custom Resources - CRD and custom resource operations (list/get CRDs, list/get/delete custom resources)
  • Events - Event listing and filtering (by namespace, type, involved object)
  • API Discovery - API resource exploration (list_api_resources)

Requirements

The server connects to your current kubectl context by default. Ensure you have access to a Kubernetes cluster configured for kubectl (e.g., minikube, Rancher Desktop, kind, EKS, GKE, AKS).

Installation

go install github.com/basebandit/kai/cmd/kai@latest

Container image

A multi-arch image (linux/amd64, linux/arm64) is published on Docker Hub:

docker pull cyclon/kai:v1.0.0
docker run --rm cyclon/kai:v1.0.0 -version

CLI Options

kai [options]
Options:
-kubeconfig string Path to kubeconfig file (default "~/.kube/config")
-context string Name for the loaded context (default "local")
-in-cluster Use in-cluster config (when running inside a pod)
-transport string stdio (default), streamable-http, or sse-legacy
-sse-addr string HTTP listen address for streamable-http/sse-legacy (default ":8080")
-tls-cert string Path to TLS certificate (enables HTTPS)
-tls-key string Path to TLS private key (enables HTTPS)
-request-timeout duration Timeout for Kubernetes API requests (default 30s)
-metrics Expose Prometheus metrics at /metrics (default true)
-log-format string json (default) or text
-log-level string debug, info, warn, error (default "info")
-version Show version information

Logs are written to stderr in structured JSON format by default, making them easy to parse:

{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"kubeconfig loaded","path":"/home/user/.kube/config","context":"local"}
{"time":"2024-01-15T10:30:00Z","level":"INFO","msg":"starting server","transport":"stdio"}

Configuration

Claude Desktop

Edit your Claude Desktop configuration:

# macOS
code ~/Library/Application\ Support/Claude/claude_desktop_config.json
# Linux
code ~/.config/Claude/claude_desktop_config.json

Add the server configuration:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

With custom kubeconfig:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai",
"args": ["-kubeconfig", "/path/to/custom/kubeconfig"]
}
}
}

Cursor

Add to your Cursor MCP settings:

{
"mcpServers": {
"kubernetes": {
"command": "/path/to/kai"
}
}
}

Continue

Add to your Continue configuration (~/.continue/config.json):

{
"experimental": {
"modelContextProtocolServers": [
{
"transport": {
"type": "stdio",
"command": "/path/to/kai"
}
}
]
}
}

HTTP Mode (web clients, remote use)

For non-stdio clients, run the streamable HTTP transport:

kai -transport=streamable-http -sse-addr=:8080

The MCP endpoint is http://localhost:8080/mcp. Health probes are at /healthz and /readyz, and Prometheus metrics at /metrics. The legacy SSE transport (-transport=sse-legacy, endpoint /sse) still works but is deprecated.

Custom Kubeconfig

By default, Kai uses ~/.kube/config. You can specify a different kubeconfig:

kai -kubeconfig=/path/to/custom/kubeconfig -context=my-cluster

Running Inside a Kubernetes Cluster

When deploying Kai inside a Kubernetes cluster, use the -in-cluster flag to automatically use the pod's service account credentials:

kai -in-cluster -transport=streamable-http -sse-addr=:8080

The recommended way to run Kai in-cluster is with kmcp (from kagent), which manages MCP servers as MCPServer resources:

apiVersion: kagent.dev/v1alpha1kind: MCPServermetadata:
name: kaispec:
transportType: httphttpTransport:
targetPort: 8080path: /mcpdeployment:
image: cyclon/kai:v1.0.0port: 8080cmd: /kaiargs: ["-in-cluster", "-transport=streamable-http", "-sse-addr=:8080"]serviceAccountName: kai

kmcp creates the Deployment and Service for you. The service account needs RBAC for the resources Kai manages — broad get/list/watch, plus create/update/delete where you use mutating tools. See the kmcp deploy guide.

Runnable example: deploy/kagent/kai.example.yaml (test-only — grants cluster-admin; scope down for real use).

Usage Examples

Once configured, you can interact with your cluster using natural language:

  • "List all pods in the default namespace"
  • "Create a deployment named nginx with 3 replicas using the nginx:latest image"
  • "Show me the logs for pod my-app"
  • "Delete the service named backend"
  • "Create a cronjob that runs every 5 minutes"
  • "Create an ingress for my-app with TLS enabled"
  • "Port forward service nginx on port 8080:80"
  • "Apply this manifest: "

Contributing

Contributions are welcome! Please see our contributing guidelines for more information.

License

This project is licensed under the MIT License.


Kubernetes MCP Server

About

An MCP Server for Kubernetes

Topics

Resources

Code of conduct

Contributing

Stars

20 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages