Skip to main content
Version: 1.0

Configuration

Environment Variables​

The MCP server reads all backend service URLs from environment variables at startup. Every one of them defaults to http://localhost:<port> in the code itself — that default is what makes the server usable out of the box against services reached via kubectl port-forward during local development, and it's why the in-cluster example further down explicitly overrides every single one rather than relying on defaults.

Service URLs​

VariableDefaultService
K8S_MONITOR_BASE_URLhttp://localhost:8085k8s-monitor — health, cost, metrics
SECURITY_API_BASE_URLhttp://localhost:8086security-api — posture, vulnerabilities
CICD_GATEWAY_BASE_URLhttp://localhost:8087cicd-gateway — pipeline run history
KUBEOPERA_API_BASE_URLhttp://localhost:8080kubeopera-api — apps, deployments, pipelines, builds
ANOMALY_DETECTOR_BASE_URLhttp://localhost:8088anomaly-detector — anomaly events
PREDICTIVE_SCALER_BASE_URLhttp://localhost:8089predictive-scaler — forecasts and scaling
INCIDENT_MANAGER_BASE_URLhttp://localhost:8090incident-manager — incidents and runbooks
OBSERVABILITY_AGENT_SRV_BASE_URLhttp://localhost:8092observability-agent — telemetry
ANALYSIS_AGENT_SRV_BASE_URLhttp://localhost:8093analysis-agent — analysis results
ACTION_AGENT_SRV_BASE_URLhttp://localhost:8094action-agent — action log
FEEDBACK_AGENT_SRV_BASE_URLhttp://localhost:8095feedback-agent — feedback signals
RECOMMENDATION_AGENT_SRV_BASE_URLhttp://localhost:8096recommendation-agent — AI recommendations
AGENT_RUNTIME_BASE_URLhttp://localhost:8111agent-runtime — agent launcher
NODES_MANAGER_BASE_URLhttp://localhost:8115nodes-manager — node lifecycle, Karpenter
LOG_GATEWAY_BASE_URLhttp://localhost:3100log-gateway — pod/deployment logs
SLO_MANAGER_BASE_URLhttp://localhost:9090slo-manager — SLO compliance, error budgets
APM_GATEWAY_BASE_URLhttp://localhost:9090apm-gateway — application performance metrics
TRACING_GATEWAY_BASE_URLhttp://localhost:16686tracing-gateway — distributed traces
RCA_ENGINE_BASE_URLhttp://localhost:8116rca-engine — root-cause analysis
KUBEOPERA_AI_BASE_URLhttp://localhost:8113Optimizer — health/optimize/troubleshoot
APP_ADVISOR_BASE_URLhttp://localhost:8105app-advisor-srv — per-app domain profile and advice

The four GitOps tools (sync_argocd_app, get_argocd_app_status, push_gitops_patch, trigger_flux_reconcile) read a separate set of variables — ARGOCD_API_URL, ARGOCD_TOKEN, FLUX_WEBHOOK_URL, FLUX_WEBHOOK_TOKEN, GITOPS_REPO_API_URL, GITOPS_REPO_TOKEN — since they talk to Argo CD and a Git hosting API directly rather than to another KubeOpera backend service.

Other Variables​

The MCP server itself has no other required environment variables. The Anthropic API key is used by agent-runtime, not the MCP server.


Claude Desktop Configuration​

Add the following to your Claude Desktop configuration file.

macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json

Minimal (read-only tools, k8s-monitor only)​

{
"mcpServers": {
"kubeopera": {
"command": "/path/to/kubeopera-mcp-server",
"args": ["--toolsets", "kubeopera"],
"env": {
"K8S_MONITOR_BASE_URL": "http://k8s-monitor:8085"
}
}
}
}

Full Platform (all 49 tools)​

{
"mcpServers": {
"kubeopera": {
"command": "/path/to/kubeopera-mcp-server",
"args": ["--toolsets", "kubeopera"],
"env": {
"K8S_MONITOR_BASE_URL": "http://localhost:8085",
"SECURITY_API_BASE_URL": "http://localhost:8086",
"CICD_GATEWAY_BASE_URL": "http://localhost:8087",
"KUBEOPERA_API_BASE_URL": "http://localhost:8080",
"ANOMALY_DETECTOR_BASE_URL": "http://localhost:8088",
"PREDICTIVE_SCALER_BASE_URL": "http://localhost:8089",
"INCIDENT_MANAGER_BASE_URL": "http://localhost:8090",
"OBSERVABILITY_AGENT_SRV_BASE_URL": "http://localhost:8092",
"ANALYSIS_AGENT_SRV_BASE_URL": "http://localhost:8093",
"ACTION_AGENT_SRV_BASE_URL": "http://localhost:8094",
"FEEDBACK_AGENT_SRV_BASE_URL": "http://localhost:8095",
"RECOMMENDATION_AGENT_SRV_BASE_URL": "http://localhost:8096",
"AGENT_RUNTIME_BASE_URL": "http://localhost:8111"
}
}
}
}

Kubernetes In-Cluster (production)​

When running KubeOpera inside Kubernetes, use in-cluster service DNS names:

{
"mcpServers": {
"kubeopera": {
"command": "/path/to/kubeopera-mcp-server",
"args": ["--toolsets", "kubeopera"],
"env": {
"K8S_MONITOR_BASE_URL": "http://k8s-monitor.kubeopera.svc.cluster.local:8085",
"SECURITY_API_BASE_URL": "http://security-api.kubeopera.svc.cluster.local:8086",
"CICD_GATEWAY_BASE_URL": "http://cicd-gateway.kubeopera.svc.cluster.local:8087",
"KUBEOPERA_API_BASE_URL": "http://kubeopera-api.kubeopera.svc.cluster.local:8080",
"ANOMALY_DETECTOR_BASE_URL": "http://anomaly-detector.kubeopera.svc.cluster.local:8088",
"PREDICTIVE_SCALER_BASE_URL": "http://predictive-scaler.kubeopera.svc.cluster.local:8089",
"INCIDENT_MANAGER_BASE_URL": "http://incident-manager.kubeopera.svc.cluster.local:8090",
"OBSERVABILITY_AGENT_SRV_BASE_URL": "http://observability-agent-srv.kubeopera.svc.cluster.local:8092",
"ANALYSIS_AGENT_SRV_BASE_URL": "http://analysis-agent-srv.kubeopera.svc.cluster.local:8093",
"ACTION_AGENT_SRV_BASE_URL": "http://action-agent-srv.kubeopera.svc.cluster.local:8094",
"FEEDBACK_AGENT_SRV_BASE_URL": "http://feedback-agent-srv.kubeopera.svc.cluster.local:8095",
"RECOMMENDATION_AGENT_SRV_BASE_URL": "http://recommendation-agent-srv.kubeopera.svc.cluster.local:8096",
"AGENT_RUNTIME_BASE_URL": "http://agent-runtime.kubeopera.svc.cluster.local:8111"
}
}
}
}

Claude Code Configuration​

Via CLI​

claude mcp add kubeopera \
--command /path/to/kubeopera-mcp-server \
--args "--toolsets kubeopera" \
--env K8S_MONITOR_BASE_URL=http://localhost:8085 \
--env SECURITY_API_BASE_URL=http://localhost:8086 \
--env AGENT_RUNTIME_BASE_URL=http://localhost:8111

Via .mcp.json​

Create .mcp.json in your project root:

{
"mcpServers": {
"kubeopera": {
"command": "/path/to/kubeopera-mcp-server",
"args": ["--toolsets", "kubeopera"],
"env": {
"K8S_MONITOR_BASE_URL": "http://localhost:8085",
"AGENT_RUNTIME_BASE_URL": "http://localhost:8111"
}
}
}
}

Toolset Selection​

The --toolsets flag controls which tool groups are loaded. You can combine multiple toolsets:

# KubeOpera tools only
./kubeopera-mcp-server --toolsets kubeopera

# KubeOpera + core Kubernetes tools
./kubeopera-mcp-server --toolsets kubeopera,core

# All available toolsets
./kubeopera-mcp-server --toolsets all

Available toolsets — kubeopera is this fork's own addition; the rest are inherited unmodified from the upstream containers/kubernetes-mcp-server project this server is built on:

ToolsetDescription
kubeoperaAll 49 KubeOpera platform tools (see the full reference)
coreStandard kubectl-equivalent tools
configKubeconfig and cluster-context management
helmHelm chart management
tektonTekton pipeline tools
kialiService mesh topology and health via Kiali
kubevirtKubeVirt VM management

Building from Source​

git clone https://github.com/ochestra-tech/kubeopera-mcp-server
cd kubeopera-mcp-server
go mod tidy
go build -o kubeopera-mcp-server ./cmd/server

Requirements: Go 1.22+


Verifying the Installation​

List all tools​

echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' \
| K8S_MONITOR_BASE_URL=http://localhost:8085 \
./kubeopera-mcp-server --toolsets kubeopera

The response should include all 49 KubeOpera tools in the result.tools array.

Test a tool call​

echo '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"get_cluster_health","arguments":{}}}' \
| K8S_MONITOR_BASE_URL=http://localhost:8085 \
./kubeopera-mcp-server --toolsets kubeopera

Test an agent launcher​

echo '{"jsonrpc":"2.0","id":3,"method":"tools/call","params":{"name":"run_sre_agent","arguments":{"cluster_id":"local","prompt":"Check cluster health and summarize findings"}}}' \
| AGENT_RUNTIME_BASE_URL=http://localhost:8111 \
./kubeopera-mcp-server --toolsets kubeopera

The response includes a run_id. Stream the agent's live reasoning:

curl -N http://localhost:8111/api/v1/runs/{run_id}/stream

HTTP Timeout​

Each tool call uses a 15-second HTTP timeout when querying backend services. If a backend service is unavailable, the tool returns an error message — it does not cause the MCP server to crash or block other tools.


Transport​

Everything on this page so far describes the common case: the MCP server run over stdio transport, launched as a subprocess by the AI client (Claude Desktop, Claude Code) and communicating over stdin/stdout, with no network port opened at all. This needs no firewall configuration, keeps every backend service URL reachable only from the machine running the client, and gives each new conversation a fresh, isolated server process.

Because this server is a fork of containers/kubernetes-mcp-server, it also inherits that project's --port flag, which starts a standalone streamable-HTTP/SSE server instead — useful when the MCP server needs to be reachable over the network rather than launched locally per client, for instance as a shared team deployment. That mode brings its own considerations (the server now needs to be reachable, so it needs the same care around network exposure and auth as any other backend service) that don't apply to the stdio case above; consult the upstream project's own documentation for the full set of HTTP-mode flags, since none of them are KubeOpera-specific.