Kubernetes MCP server
Last verified: 2026-09
kubectl-style cluster access.
Community Cloud & infra Needs a secret Claude Desktop, Cursor, Windsurf, Claude Code
What it does
kubectl-shaped tools against the current kubeconfig: get, describe, apply, delete, logs, rollout, helm. Same blast radius as handing someone kubectl.
It sits in Cloud & infra: Most of these are admin APIs.
Good for
- kubectl_get pods in one sandbox namespace.
- kubectl_logs on a crashing pod instead of context-switching.
- kubectl_describe when you already know the resource name.
- Leave apply/delete/helm off a cluster you cannot recreate.
Tools
- kubectl_get / kubectl_describe / kubectl_logs / kubectl_context / explain_resource / list_api_resources — Read.
- kubectl_create / kubectl_apply / kubectl_patch / kubectl_scale / scale_deployment / kubectl_rollout — Mutate.
- kubectl_delete / kubectl_generic / helm_template_apply / port_forward — Dangerous extras.
Config (Claude Desktop / Cursor / Windsurf)
Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets.
Windows paths look like C:\\Users\\you\\project, not /path/to.
Host-side steps →
Claude Desktop
| OS | Config file |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json
(usually C:\Users\<you>\AppData\Roaming\Claude\) |
| Linux | ~/.config/Claude/claude_desktop_config.json |
Cursor
| Scope | macOS / Linux | Windows |
|---|---|---|
| This project | .cursor/mcp.json in the repo root | |
| This user | ~/.cursor/mcp.json |
%USERPROFILE%\.cursor\mcp.json |
Windsurf
| OS | Config file |
|---|---|
| macOS / Linux | ~/.codeium/windsurf/mcp_config.json |
| Windows | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
{
"mcpServers": {
"kubernetes": {
"command": "npx",
"args": [
"-y",
"mcp-server-kubernetes"
],
"env": {
"KUBECONFIG": "/path/to/sandbox.kubeconfig"
}
}
}
}
Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.
One-liner: npx -y mcp-server-kubernetes
Secrets it wants: KUBECONFIG
How to get started
- Point KUBECONFIG at a sandbox cluster or a read-only user.
- Ask for kubectl_get pods in one namespace.
- Do not use a kubeconfig that can delete nodes.
Access risk
kubectl_delete and apply on prod. A stolen kubeconfig is cluster admin if you used the default user.
When to skip it
Skip it for Docker-only local work, or for cloud consoles you already have as AWS/GCP/Azure MCP.
Vs alternatives
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| Kubernetes | No | Yes | kubectl-style cluster access. |
| Docker | No | No | List containers and images on the local daemon. |
| AWS | No | Yes | Call AWS APIs with the default credential chain. |
| Grafana | No | Yes | Dashboards and datasources. |
More in Cloud & infra
FAQ
Which kubeconfig?
KUBECONFIG pointing at a sandbox or a read-only user. Cluster-admin plus Fetch in the same chat is prompt-injection → kubectl.
Is this kubectl?
kubectl-shaped tools (get, describe, apply, delete, logs, rollout, helm). Same blast radius as handing someone kubectl.
Kubernetes or Docker?
Cluster vs local daemon. EKS/GKE still wants this plus a locked-down cloud identity, not the other way around.
port_forward?
In the tool list. That opens a tunnel from your machine. Know what you are exposing.