Kubernetes ManagerBLOCK
MCP Server for kubernetes management commands
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/yourusername/mcp-server-kubernetes/actions/workflows/ci.yml) [](https://github.com/yourusername/mcp-server-kubernetes) [](https://kubernetes.io/) [](https://www.docker.com/) [](https://github.com/Flux159/mcp-server-kubernetes/stargazers) [](https://github.com/Flux159/mcp-server-kubernetes/issues) [](https://github.com/Flux159/mcp-server-kubernetes/pulls) [](https://github.com/Flux159/mcp-server-kubernetes/commits/main)
MCP Server that can connect to a Kubernetes cluster and manage it. Supports loading kubeconfig from multiple sources in priority order.
https://github.com/user-attachments/assets/f25f8f4e-4d04-479b-9ae0-5dac452dd2ed
Installation & Usage
Prerequisites
Before using this MCP server with any tool, make sure you have:
- kubectl installed and in your PATH
- A valid kubeconfig file with contexts configured
- Access to a Kubernetes cluster configured for kubectl (e.g. minikube, Rancher Desktop, GKE, etc.)
- Helm v3 installed and in your PATH (no Tiller required). Optional if you don't plan to use Helm.
You can verify your connection by running kubectl get pods in a termina
85489fe48a8dOBSERVED · 2026-09-24Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-server-kubernetes --env K8S_TOKEN=${K8S_TOKEN} --env MASK_SECRETS=${MASK_SECRETS} --env MCP_AUTH_TOKEN=${MCP_AUTH_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"mcp-server-kubernetes": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"K8S_TOKEN": "${K8S_TOKEN}",
"MASK_SECRETS": "${MASK_SECRETS}",
"MCP_AUTH_TOKEN": "${MCP_AUTH_TOKEN}"
}
}
}
}Exposed tools (28)
17 read · 9 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
cleanup | read | Cleanup all managed resources |
create_deployment | write | Create a new Kubernetes deployment |
exec_in_pod | write | Execute a command in a Kubernetes pod or container and return the output. Command must be an array of strings where the first element is the executable and remaining elements are arguments. This executes directly without shell interpretation for security. |
explain_resource | read | Get documentation for a Kubernetes resource or field |
install_helm_chart | write | Install a Helm chart with support for both standard and template-based installation |
k8s-diagnose | read | Diagnose Kubernetes Resources. |
keyword | read | A keyword to search pod/node names. |
kubectl_apply | write | Apply a Kubernetes YAML manifest from a string or file |
kubectl_context | write | Manage Kubernetes contexts - list, get, or set the current context |
kubectl_create | write | Create Kubernetes resources using various methods (from file or using subcommands) |
kubectl_delete | destructive | Delete Kubernetes resources by resource type, name, labels, or from a manifest file |
kubectl_describe | read | Describe Kubernetes resources by resource type, name, and optionally namespace |
kubectl_generic | write | Execute any kubectl command with the provided arguments and flags |
kubectl_get | read | Get or list Kubernetes resources by resource type, name, and optionally namespace |
kubectl_logs | read | Get logs from Kubernetes resources like pods, deployments, or jobs |
kubectl_patch | write | Update field(s) of a resource using strategic merge patch, JSON merge patch, or JSON patch |
kubectl_reconnect | read | Reconnect to the Kubernetes API server by recreating all API clients. Use this after cluster upgrades (e.g., EKS control plane upgrades that rotate ENIs/IPs) to force fresh DNS resolution and new TCP connections. |
kubectl_rollout | read | Manage the rollout of a resource (e.g., deployment, daemonset, statefulset) |
kubectl_scale | read | Scale a Kubernetes deployment |
list_api_resources | read | List the API resources available in the cluster |
list_namespaces | read | List all namespaces |
namespace | read | Optional: Specify a namespace to narrow down the search. |
node_management | read | Manage Kubernetes nodes with cordon, drain, and uncordon operations |
ping | read | Verify that the counterpart is still responsive and the connection is alive. |
port_forward | read | Forward a local port to a port on a Kubernetes resource |
stop_port_forward | write | Stop a port-forward process |
uninstall_helm_chart | destructive | Uninstall a Helm chart release |
upgrade_helm_chart | read | Upgrade an existing Helm chart release |
Trust audit
BLOCKgrade D · trust 68/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
const parsed = yaml.load(output);
# - "199.36.153.8/30" # metadata.google.internal
# Cloud provider metadata service (AWS/GCP use same IP: 169.254.169.254)
bun.lockb
`act on the MCP server's own host, which would allow exfiltration of ` +
vault-token: "your-vault-token-here"
token: "your-service-account-token"
kubectl_delete, uninstall_helm_chart
.mcpbignore
AGENTS.md
sed -i 's|https://192.168.49.2:8443|http://localhost:8080|g' ~/.kube/config
grep "server:" ~/.kube/config
sed -i 's|http://localhost:8080|https://192.168.49.2:8443|g' ~/.kube/config
sed -i 's|https://192.168.49.2:8443|http://localhost:8080|g' ~/.kube/config
grep "server:" ~/.kube/config
cidr: 169.254.169.254/32 # AWS metadata service
cidr: 169.254.169.254/32 # GCP metadata service
# - Metadata services (169.254.169.254)
server: "https://127.0.0.1:19001",
assertSafeArgv(["get", "pods", "-Ashttp://127.0.0.1:59999"])
name: "--server=https://127.0.0.1:19012",
resourceType: "--server=https://127.0.0.1:19099",
# kubectl exec -it deployment/mcp-server -- curl -k https://kubernetes.default/api
test("rejects --insecure-skip-tls-verify", () => {test("rejects --insecure-skip-tls-verify=true in args", () => {Gates applied: no_behavioural_pass.
85489fe48a8dfull audit observations/trust-audit/mcp-server/flux159__kubernetes-manager.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-24 | 85489fe48a8d | BLOCK | D | 68 | first audit |
Questions
What is the Kubernetes Manager MCP server?
MCP Server for kubernetes management commands
What tools does Kubernetes Manager expose?
28 in total: 17 read-only, 9 that write, and 2 that can delete or overwrite (kubectl_delete, uninstall_helm_chart). Every one is listed on this page with its risk.
Is Kubernetes Manager safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (68/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Kubernetes Manager need?
It reads K8S_TOKEN, MASK_SECRETS and MCP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Kubernetes Manager run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-server-kubernetes at 4.1.7.
How current is this page?
The grade is for one exact copy of the source (85489fe48a8d), read on 2026-09-24. The repository is watched and re-audited when it changes.