k8s-pilot
The Central Pilot for Your Kubernetes Fleets βοΈβοΈ
k8s_pilot is a lightweight, centralized control plane server for managing multiple Kubernetes clusters at once.
With powerful tools and intuitive APIs, you can observe and control all your clusters from one cockpit.
π Overview
π Supports multi-cluster context switching
π§ Enables CRUD operations on most common Kubernetes resources
π Readonly mode for safe cluster inspection
βοΈ Powered by MCP for Claude AI and beyond
π Streamable HTTP transport support for remote access
π€ MCP Prompts for guided operations
π Context-aware logging for write operations
π§° Prerequisites
Python 3.13 or higher
uvpackage managerAccess to Kubernetes clusters (
~/.kube/configor in-cluster config)
# Install uv (if not installed)
# For MacOS
brew install uv
# For Linux
curl -LsSf https://astral.sh/uv/install.sh | shInstallation
# Clone the repository
git clone https://github.com/bourbonkk/k8s-pilot.git
cd k8s-pilot
# Launch with uv + MCP
uv run --with "mcp[cli]>=1.28.0,<2" python k8s_pilot.pyπ What's New in v2.0
Streamable HTTP Transport: Remote cluster management via HTTP (in addition to stdio)
MCP Prompts: Built-in prompt templates for common K8s operations
Context-aware Logging: Write operations now report progress via MCP context
Bug Fixes: Fixed missing API clients for Ingress and RBAC resources
Security: Added readonly checks for node modification operations
Dockerfile: Modernized with
uvpackage manager for faster builds
Usage
Normal Mode (Full Access)
# Start with full read/write access
uv run --with "mcp[cli]>=1.28.0,<2" python k8s_pilot.pyReadonly Mode (Safe Inspection)
# Start in readonly mode - only read operations allowed
uv run --with "mcp[cli]>=1.28.0,<2" python k8s_pilot.py --readonlyStreamable HTTP Mode (Remote Access)
# Start with Streamable HTTP transport for remote access
uv run --with "mcp[cli]>=1.28.0,<2" python k8s_pilot.py --transport streamable-httpCommand Line Options
# Show help
uv run --with "mcp[cli]>=1.28.0,<2" python k8s_pilot.py --helpRun via Docker
You can run k8s-pilot directly using the published Docker image without installing uv locally.
Make sure to mount your ~/.kube/config so the container can access your clusters.
docker run -i --rm \
-v ~/.kube/config:/root/.kube/config \
ghcr.io/bourbonkk/k8s-pilot:latestReadonly Mode
The --readonly flag enables a safety mode that prevents any write operations to your Kubernetes clusters. This is perfect for:
Cluster inspection without risk of accidental changes
Audit scenarios where you need to view but not modify
Learning environments where you want to explore safely
Production monitoring with zero risk of modifications
Protected Operations (Blocked in Readonly Mode)
pod_create,pod_update,pod_deletedeployment_create,deployment_update,deployment_deleteservice_create,service_update,service_deleteconfigmap_create,configmap_update,configmap_deletesecret_create,secret_update,secret_deletenamespace_create,namespace_deleteAll other create/update/delete operations
Allowed Operations (Always Available)
pod_list,pod_detail,pod_logsdeployment_list,deployment_getservice_list,service_getconfigmap_list,configmap_getsecret_list,secret_getnamespace_list,namespace_getAll other list/get operations
MCP Prompts
k8s-pilot includes built-in prompt templates for common operations:
Prompt | Description |
| Step-by-step pod troubleshooting guide |
| Guided application deployment workflow |
| Comprehensive cluster health assessment |
| Safe namespace cleanup procedure |
Usage with Claude Desktop
Use this config to run k8s_pilot MCP server from within Claude:
{
"mcpServers": {
"k8s_pilot": {
"command": "uv",
"args": [
"--directory",
"<path-to-cloned-repo>/k8s-pilot",
"run",
"--with",
"mcp[cli]>=1.28.0,<2",
"python",
"k8s_pilot.py"
]
}
}
}For readonly mode, use this configuration:
{
"mcpServers": {
"k8s_pilot_readonly": {
"command": "uv",
"args": [
"--directory",
"<path-to-cloned-repo>/k8s-pilot",
"run",
"--with",
"mcp[cli]>=1.28.0,<2",
"python",
"k8s_pilot.py",
"--readonly"
]
}
}
}For Docker, use this configuration (replace YOUR_USERNAME with your actual Mac user name):
{
"mcpServers": {
"k8s_pilot_docker": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-v",
"/Users/YOUR_USERNAME/.kube/config:/root/.kube/config",
"ghcr.io/bourbonkk/k8s-pilot:latest"
]
}
}
}Replace <path-to-cloned-repo> with the actual directory where you cloned the repo.
Scenario
Create a Deployment using the nginx:latest image in the pypy namespace, and also create a Service that connects to it.
Key Features
Multi-Cluster Management
Seamlessly interact with multiple Kubernetes clusters
Perform context-aware operations
Easily switch between clusters via MCP prompts
Resource Control
View, create, update, delete:
Deployments, Services, Pods
ConfigMaps, Secrets, Ingresses
StatefulSets, DaemonSets
Roles, ClusterRoles
PersistentVolumes & Claims
Namespace Operations
Create/delete namespaces
List all resources in a namespace
Manage labels and resource quotas
Node Management
View node details and conditions
Cordon/uncordon, label/taint nodes
List pods per node
License
This project is licensed under the MIT License. See the LICENSE file for details.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/bourbonkk/k8s-pilot'
If you have feedback or need assistance with the MCP directory API, please join our Discord server