Rubrik MCP
OfficialServer Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| RSC_URL | No | The Rubrik Security Cloud domain URL, e.g. https://<your-rsc-domain>. | |
| RSC_CLIENT_ID | No | The service account client ID (e.g. client|...). | |
| RSC_CLIENT_SECRET | No | The service account client secret. | |
| RUBRIK_MCP_CONFIG_DIR | No | Optional directory used to relocate the MCP config directory (default is ~/.config/rubrik-mcp). | |
| RSC_SERVICE_ACCOUNT_FILE | No | Path to the RSC service account JSON credential file (recommended method for providing credentials). |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| rsc_search_schemaA | Search the full RSC GraphQL schema to find relevant operations. Searches operation names/descriptions, field semantics, and type-level vocabulary in one call and returns the best candidate operations ranked by relevance. Use this whenever you need to find an operation and don't already know its name. The search runs three complementary indexes:
Results are deduplicated and merged; the same operation may be surfaced by multiple indexes and will appear once with the highest score. Args: search: Natural-language query or keywords describing what you want. Must be non-empty. Use descriptive terms, not operation names. operation_type: Filter results to "query", "mutation", or "all" (default). Use "query" for read-only intent, "mutation" for write intent. Returns: Dict with: - operations: list of dicts with name, type, description, return_type, score, source (ops/fields/types) - search: the search string used |
| rsc_describe_typeA | Get the definition of a GraphQL type used in RSC operations. Args: name: Type name (e.g. "CreateGlobalSlaInput", "SlaAssignTypeEnum"). Returns: Dict with name, kind, and either: - fields: {fieldName: {type, description}} for objects/inputs/interfaces - values: [str] for enums - types: [str] for unions |
| rsc_describe_operation_fullA | Get an operation's signature with all input types expanded inline. Returns an operation's argument signature with all input/enum types
expanded inline — recursively up to Args: name: camelCase operation name (e.g. "azureNativeVirtualMachines"). operation_type: "query" or "mutation". depth: How many levels of input types to expand (default 2). Returns: Dict with operation details plus: - "expanded_types": all referenced input/enum type definitions - "return_type_fields": object/interface types in the return type, expanded 2 levels deep (connection wrapper → node fields), so you know exactly which fields are selectable in the query body. Interface types include an "inline_fragments" key listing each concrete implementor and its fields — these fields are ONLY accessible via "... on TypeName { field }" inline fragments in your query; they cannot be queried directly on the interface. |
| rsc_get_workloadsA | List workloads with protection, compliance, usage, and backup status. Each result includes:
Args: object_type: Filter by workload type, e.g. "NutanixVirtualMachine", "VmwareVirtualMachine", "AzureNativeVm", "AwsNativeEc2Instance". Cannot be combined with excluded_object_types. protection_status: One of "Protected", "NoSla", "DoNotProtect". Omit to return all statuses. search_term: Filter by name substring. compliance_status: Filter by compliance state. One of: "IN_COMPLIANCE" — protected, active, no missed snapshots. "OUT_OF_COMPLIANCE" — protected, active, one or more missed snapshots. "UNPROTECTED" — no effective SLA assigned. "NOT_APPLICABLE" — protected but relic or archived; compliance not evaluated. "NOT_AVAILABLE" — protected and active but compliance could not be computed (SLA engine error or unmet precondition). "EMPTY" — report sync has not yet produced a value for this object; data is absent, not wrong. Indicates the cluster's report sync is lagging. Note: "NULL" also exists in the underlying store but is excluded from this filter — it indicates a workload with no compliance status object at all (distinct from EMPTY) and is not used in practice by the ETL pipeline. sla_time_range: Compliance window to evaluate. Defaults to the entire protection lifetime of each workload, which often overstates violations. Prefer a shorter window for actionable results. One of: "LAST_SNAPSHOT", "LAST_2_SNAPSHOTS", "LAST_3_SNAPSHOTS", "LAST_24_HOURS", "PAST_7_DAYS", "PAST_30_DAYS", "PAST_90_DAYS", "PAST_365_DAYS", "SINCE_PROTECTION". sla_id: Filter to workloads assigned to a specific SLA Domain ID. Use this to answer "list all VMs in SLA X" — pass the SLA's UUID. Matches on effective SLA (inherited or directly assigned). cluster_id: Filter to workloads managed by a specific Rubrik cluster UUID. object_fids: Filter to specific workload FIDs (list of UUIDs). Use to fetch details for a known set of workloads in a single call. object_state: Filter by lifecycle state. One of: "ACTIVE", "ARCHIVED", "RELIC", "NOT_SPECIFIED". Use "RELIC" to find decommissioned workloads that still have snapshots. org_id: Filter to workloads belonging to a specific organization UUID. is_local: True to return only local workloads; False for remote/replicated only. Omit to return both. excluded_object_types: List of workload types to exclude. Cannot be combined with object_type. sort_by: Field to sort by, e.g. "MissedSnapshots", "Name", "LastSnapshot", "ComplianceStatus", "SlaDomainName". sort_order: "ASC" or "DESC". limit: Maximum number of results to return. Omit for all results (bounded by the server-side record cap). Returns:
A dict with:
- count: the true total matching the filter (the connection's |
| rsc_search_helpA | Search Rubrik KB articles, product documentation, and known issues. Use when: an RSC event or workload has a failure/error message, the user asks a troubleshooting or "how do I" question, or an error code (e.g. RBK91030123) is present. Always call this before answering from memory — KB articles reflect the current product state. Results include title, description snippet, source type, and a direct link to the full article. Args: query: Free-text search string (e.g. "ransomware recovery", "SLA not applying"). source: Limit results to one source. One of: KB_ARTICLES, PRODUCT_DOCS, KNOWN_ISSUES. Omit to search all sources. limit: Maximum number of results to return. Default 10. Returns:
A dict with |
| rsc_get_eventsA | Get recent events and activity for workloads. Returns backup jobs, failures, anomalies, and other activity. Always scoped to a time window (default: last 24 hours) to keep queries fast. For failure details, each event includes the error message, reason, and recommended remedy where available. Args: last_hours: How far back to look, in hours. Default 24. Always provide this — omitting a time range makes the query very slow. workload_id: Filter to a specific workload FID (from rsc_get_workloads). Use this to answer "why did the backup fail for workload X". object_name: Filter by object name substring. status: Filter by event status. One of: SUCCESS, FAILURE, WARNING, RUNNING, CANCELED, CANCELING, QUEUED, PARTIAL_SUCCESS, TASK_FAILURE, TASK_SUCCESS, INFO. severity: Filter by severity. One of: SEVERITY_CRITICAL, SEVERITY_WARNING, SEVERITY_INFO. activity_type: Filter by activity type. Common values: BACKUP, RECOVERY, REPLICATION, ARCHIVE, ANOMALY, INDEX, LOG_BACKUP. cluster_id: Filter by Rubrik cluster UUID. limit: Maximum number of events to return. Default 100. Returns:
A dict with |
| rsc_get_clustersA | List Rubrik CDM clusters registered in RSC. Use for any question about cluster inventory, connection status (connected/disconnected/degraded), CDM version, storage capacity, runway, sync health, node health, or hardware warnings. Filters: name, connection status, cluster type. Each result includes:
Args: name_contains: Filter by cluster name. Passed to the server-side name filter. status: Connection status filter. One of: Connected, Disconnected, Initializing. cluster_type: Cluster type filter. One of: Cloud, ExoCompute, OnPrem, Polaris, Robo, Unknown. limit: Maximum number of clusters to return. Default 20, max 100. Returns:
A dict with:
- count: true total matching the filter (the connection's |
| rsc_get_sla_domainsA | List SLA Domains (protection policies) configured in RSC. Use for any question about protection policies — filter by name, protected workload type (including Kubernetes), cluster, or retention lock status. Also use for: counting SLA policies, finding which SLAs protect a specific workload type, identifying retention-locked SLAs, or finding SLAs with specific replication or archival configurations. Each result includes:
Args:
name_contains: Filter by SLA name (server-side name filter).
object_type: Filter by protected workload type. Must be a SlaObjectType enum
value, e.g. "VSPHERE_OBJECT_TYPE", "K8S_OBJECT_TYPE",
"AWS_EC2_EBS_OBJECT_TYPE", "NUTANIX_OBJECT_TYPE".
cluster_id: Filter by cluster UUID — returns SLAs associated with that cluster.
is_retention_locked: When True, return only retention-locked SLAs. When False,
return only non-retention-locked SLAs. Omit to return all. Applied
client-side after fetching; Returns: A dict with: - count: true total matching the server-side filter (before is_retention_locked). - returned: how many SLA domains are in this response. - truncated: True when returned < count. - sla_domains: list of SLA domain records. |
| rsc_wait_for_jobA | Poll an RSC job until it completes and return the final status. Handles all job types automatically based on objectType — no polling code needed from the caller. How to get job_id and cluster_id:
For background monitoring without blocking, run rsc-job-monitor via the Bash tool and watch it with the Monitor tool: Bash(run_in_background=true): /app/.venv/bin/rubrik-job-monitor --job-id --object-type [--cluster-id ] Monitor(command): /app/.venv/bin/rubrik-job-monitor --job-id --object-type [--cluster-id ] Args: job_id: Request ID (CDM) or taskchainUuid (cloud-native). object_type: Workload objectType — determines which status query to use. cluster_id: Rubrik cluster UUID. Required for CDM workloads. Get it from rsc_get_workloads cluster.id. timeout: Maximum seconds to wait before returning. Default 300. poll_interval: Seconds between status checks. Default 10. Returns: Dict with status, progress, done, raw, and optionally timed_out. CDM status values: SUCCEEDED, FAILED, CANCELED, QUEUED, IN_PROGRESS. Cloud-native state values: SUCCEEDED, FAILED, CANCELED, RUNNING, READY. jobInfo status values: SUCCESS, FAILURE, IN_PROGRESS, UNSPECIFIED. |
| rsc_execute_operationA | Execute a raw GraphQL query against the live RSC API. This tool supports queries only. Mutations are not available via raw GraphQL — use built-in tools (rsc_take_on_demand_snapshot, etc.) for supported write operations. If you submit a mutation, this tool returns a mutation_blocked error with the attempted operation so Claude can generate a Python code sample for you. IMPORTANT: Write Requires RSC credentials — set one of:
Args: operation: A complete GraphQL query string on a single line, e.g.: "query { accountId }" "query ListSLAs($after: String) { slaDomains(after: $after) { count nodes { id name } pageInfo { hasNextPage endCursor } } }" variables: Optional dict of variable values for parameterized operations. Returns: The raw JSON response from the RSC GraphQL API (data + errors if any). Returns {"error": "mutation_blocked", "blocked_operation": "...", "message": "..."} if a mutation is submitted — Claude will use this to generate a Python code sample. Note: returns the raw GraphQL response with no field filtering or redaction — do not use in contexts where data minimization of personal-data-bearing fields is required. |
| rsc_save_workflowA | Save a multi-step workflow as a named, callable MCP tool. Call this after completing a workflow in conversation to persist it for future use. The workflow is written to the workflows/ dir under the MCP config directory (~/.config/rubrik-mcp/workflows/ by default, or under $RUBRIK_MCP_CONFIG_DIR when set) and registered immediately. It loads automatically on next server start. The exact file path is returned in the response. Provide either Workflow spec format: { "schema_version": 1, "name": "rsc_my_workflow", "description": "What this does and when to use it.", "steps": [ { "id": "step1", "mcp": "rubrik", "tool": "rsc_execute_operation", "args": {"operation": "query { accountId }"} }, { "id": "step2", "mcp": "virustotal", "tool": "get_threat_actor_files", "args": {"threat_actor_id": "${step1.data.accountId}"} } ] } RSC steps ("mcp": "rubrik") execute server-side. Non-RSC steps are returned as next_steps for the LLM to execute. Use "${step_id.path.to.value}" in args to reference prior step results. Args: name: Tool name (valid Python identifier, e.g. "rsc_get_aws_failures"). description: What this workflow does and when to use it. steps: List of step dicts (id, mcp, tool, args). spec: Complete workflow spec dict — use instead of name/description/steps when passing the full definition at once. Returns: Dict with status, name, path, and a note about restart behavior. |
| rsc_list_workflowsA | List all user-defined workflows in the MCP config dir's workflows/ folder. Location is ~/.config/rubrik-mcp/workflows/ by default, or under $RUBRIK_MCP_CONFIG_DIR when set. Returns name, description preview, step count, and the resolved file path for each workflow. |
| rsc_delete_workflowA | Delete a user-defined workflow from the MCP config dir's workflows/ folder. Location is ~/.config/rubrik-mcp/workflows/ by default, or under $RUBRIK_MCP_CONFIG_DIR when set. Removes the workflow file from disk. The workflow remains callable in the current server session but will not load on next restart. Args: name: The workflow name (as returned by rsc_list_workflows). Returns: Dict with status, name, and path of the deleted file. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 13 tools
The three schema-introspection tools (rsc_search_schema, rsc_describe_type, rsc_describe_operation_full) are closely related but their descriptions clearly delineate search vs. type lookup vs. full operation expansion. The data-fetching tools each target a distinct resource (workloads, events, clusters, SLA domains), and workflow CRUD is unambiguous.
All tools share a uniform rsc_ prefix followed by a consistent snake_case verb_noun pattern (get_workloads, list_workflows, delete_workflow, search_schema, describe_type, wait_for_job). No mixed conventions or stray casing.
13 tools is well within the ideal 3-15 range, with each tool earning its place across introspection, read operations, job polling, and workflow management. No redundancy that would justify trimming.
Read coverage is solid (workloads, events, clusters, SLAs, help) and raw queries via rsc_execute_operation fill gaps, but mutations are explicitly blocked and there are no built-in write/recovery tools despite descriptions referencing rsc_take_on_demand_snapshot and similar 'built-in tools' that are absent from the surface. This leaves a notable gap for any write/protection workflow.