cncf-tech-advisor-mcp
Provides read-only access to the public CNCF Landscape catalogue of 2,400+ cloud native projects and products, with tools to search by keyword or category, retrieve full project details (maturity, GitHub stars, contributors, latest release, license, homepage, repository), list all categories with project counts, and check whether the locally cached catalogue is still current.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@cncf-tech-advisor-mcpget details on the Prometheus project"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
CNCF Tech Advisor MCP Server
A Model Context Protocol server that gives a language model read-only access to the public CNCF Landscape: 2,400+ cloud native projects and products with category, maturity, GitHub stars, contributors, latest release, license, homepage and repository.
Java 25 · Quarkus 3.33 LTS · quarkus-mcp-server 2.0.1 (MCP specification 2026-07-28,
Streamable HTTP and stdio) · native executable via GraalVM/Mandrel.
Tools
Tool | What it does |
| Keyword and/or exact-category search; popular and graduated projects rank higher. |
| Full detail of one project by its exact name (case-insensitive). |
| Every category with its project count. |
| Ask the landscape whether the in-memory catalogue is current ( |
Every value the landscape publishes is third-party content — the landscape is a public
repository that accepts pull requests — so every tool renders it sanitized, inside a fence
carrying a per-response nonce, and tells the model not to follow instructions found inside.
The same sanitized record feeds the text and the structuredContent channel.
Related MCP server: scorecard_mcp
Run
Requires Java 25 (only the build and the JVM run; the native executable needs no Java).
git clone https://github.com/labjp-mcp/cncf-tech-advisor-mcp.git
cd cncf-tech-advisor-mcp
./mvnw package -DskipTests
java -jar target/quarkus-app/quarkus-run.jar # stdio (default): for Claude Desktop, Claude Code, ...Claude Code: claude mcp add cncf -- java -jar /path/to/target/quarkus-app/quarkus-run.jar.
Streamable HTTP (for the MCP Inspector or a gateway), endpoint http://127.0.0.1:8080/mcp:
java -Dquarkus.http.host-enabled=true -Dquarkus.mcp.server.stdio.enabled=false \
-jar target/quarkus-app/quarkus-run.jarNative executable (starts in ~30 ms, useful on stdio where the client launches the process per session):
./mvnw package -Pnative -DskipTests # needs GraalVM or Mandrel for Java 25
./target/cncf-tech-advisor-mcp-1.0.0-runner
scripts/mcp-native-parity.sh # proves JVM and native publish the same catalogueContainers: docker build -t cncf-tech-advisor-mcp . (JVM, builds inside the image) or
src/main/docker/Dockerfile.native / Dockerfile.native-micro (package a host-built
target/*-runner). Both images serve HTTP on 0.0.0.0:8080; run them as
docker run --rm -p 127.0.0.1:8080:8080 cncf-tech-advisor-mcp and put a network boundary
in front — the server has no authentication of its own.
Releases: a vX.Y.Z tag runs .github/workflows/release.yml, which attaches a
self-contained cncf-tech-advisor-mcp.jar (java -jar, stdio) and native executables for
Linux x64 and macOS arm64 to the GitHub Release, and pushes the JVM image to
ghcr.io/labjp-mcp/cncf-tech-advisor-mcp:X.Y.Z. Assets of releases older than this
workflow (v1.0.0) were built for the former npm wrapper. There is no npm package to install.
Configuration
All in src/main/resources/application.properties; override with -D or environment.
Key | Default | Meaning |
|
| Site root; |
|
| Deadline for the whole download, body included. |
|
| Largest body accepted, compressed or inflated. |
|
| How long a loaded catalogue is served without asking upstream. |
|
| No retry after a failed download for this long. |
|
|
|
|
| Per caller (remote address); |
|
| Loopback by default; the images set |
|
| Exact origins, never |
The download is conditional (If-None-Match; the landscape's CDN answers 304) and
gzip-encoded (≈0.85 MB instead of 3.8 MB). A sequence of tool calls costs one download per
cache-ttl; see SECURITY-PENTEST.md for the measurements.
Develop
./mvnw clean verify # 172 tests; a WireMock stands in for the landscape, nothing reaches cncf.io
./mvnw quarkus:dev # HTTP on, INFO logs
make helpLogging is INFO on stderr, one audit line per tool call
(tool=search_cncf source=127.0.0.1 outcome=ok ms=12 arg="kube"); stdout carries only the
protocol on stdio.
Documents: CLAUDE.md (architecture, conventions, rules), SECURITY-PENTEST.md (threat
model, attack catalogue with reproducible commands, residual risks), CHANGELOG.md.
Legacy files
npm/, bin/, test/*.js, test-mcp*.js, docker/, install-claude-desktop.*,
scripts/{build-npm,cross-build,deploy}.sh, claude-*-config.json and package.json
belong to an earlier npm-wrapper distribution that is not built, tested or published by
this repository today. They are kept for reference only.
License
Apache-2.0 — see LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Software component catalog: search your org's services, docs, APIs, dependencies, and ownership.
Read-only AI project discovery, verification, comparison, shortlisting, and stack planning.
Code intelligence for LLMs. Analyze, search, and retrieve code from any public git repository.
- acopioOAuthdev.acopio
Search and get recommendations from your own saved catalog of developer tools and services.
Related MCP Servers
- AlicenseAqualityDmaintenanceProvides GitHub data analysis for repositories, developers, and organizations, enabling insights into open source ecosystems through API calls and natural language queries.514MIT
- AlicenseNot gradedqualityDmaintenanceEnables asking natural language questions about OpenSSF Scorecard security assessments for open source projects.4Apache 2.0
- FlicenseAqualityDmaintenanceEnables natural-language queries about public GitHub repositories, including issues, pull requests, repo metadata, and READMEs, via the GitHub API.5-
- FlicenseNot gradedqualityDmaintenanceEnables natural language queries to search GitHub for trending repositories by topic, summarize project READMEs, and compare multiple repos to uncover ecosystem patterns.2-