Skip to main content
Glama
sandeepbazar

io.github.sandeepbazar/ocm-mcp-server

by sandeepbazar

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
KUBECONFIGNoKubeconfig file path(s). Defaults to ~/.kube/config.
OCM_MCP_HOMENoState directory. Default ~/.ocm-mcp.~/.ocm-mcp
OCM_MCP_ISSUERNoToken issuer. Default ocm-mcp.ocm-mcp
OCM_MCP_AUDIENCENoToken audience. Default ocm-mcp-server.ocm-mcp-server
OCM_MCP_READ_ONLYNoSet to '1'/'true' for read-only mode. Default off.
OCM_MCP_AUDIT_ECHONoSet to '1' to echo audit lines to stderr. Default off.
OCM_MCP_CLIENT_TTLNoClient cache TTL in seconds. Default 600.600
OCM_MCP_SIGNER_KEYNoPath to the private Ed25519 signing key. Recommended to set off the server. Default OCM_MCP_HOME/approval_ed25519.~/.ocm-mcp/approval_ed25519
OCM_MCP_HUB_CONTEXTYesThe kubeconfig context that points at the OCM hub cluster. Required. Empty uses current context.
OCM_MCP_APPROVAL_TTLNoApproval token lifetime in seconds. Default 3600.3600
OCM_MCP_HEALTH_LIMITNoMax pods/deployments fetched by get_cluster_health. Default 500.500
OCM_MCP_METRICS_HOSTNoInterface for metrics endpoint. Default 127.0.0.1.127.0.0.1
OCM_MCP_METRICS_PORTNoPort to expose Prometheus metrics. Default off.
OCM_MCP_VERIFIER_KEYNoPath to the public verifier key. Default OCM_MCP_HOME/approval_ed25519.pub.~/.ocm-mcp/approval_ed25519.pub
OCM_MCP_SPOKE_TIMEOUTNoSpoke read timeout in seconds. Default 30.30
OCM_MCP_FANOUT_WORKERSNoConcurrent spoke scans during get_fleet_health. Default 8.8
OCM_MCP_REQUIRE_DIGESTNoSet to '1' to require digest-pinned images. Default off.
OCM_MCP_SPOKE_CONTEXTSNoComma-separated <managed-cluster-name>=<kubeconfig-context> pairs for accessing spoke clusters (events, logs, health). Optional for hub-level tools.
OCM_MCP_MAX_HPA_REPLICASNoMax HPA maxReplicas. Default 100.100
OCM_MCP_MAX_PROPOSAL_BYTESNoMax proposal size in bytes. Default 262144.262144
OTEL_EXPORTER_OTLP_ENDPOINTNoSet to emit OTel trace spans per tool call. Unset disables tracing.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
list_clustersA

List all managed clusters with availability, version, labels, and capacity.

get_clusterA

Full view of one ManagedCluster.

Args: cluster: managed cluster name as the hub knows it (see list_clusters).

Returns acceptance (hubAcceptsClient), taints, hub conditions, Kubernetes version, capacity/allocatable, and the cluster's ClusterClaims.

list_cluster_setsA

List ManagedClusterSets with their selector type and member clusters.

list_cluster_set_bindingsA

List ManagedClusterSetBindings (which ClusterSets a namespace's Placements may use).

Args: namespace: limit to one namespace; empty lists bindings across all namespaces.

list_cluster_claimsA

Every cluster's ClusterClaims (id, platform, region, version) rolled up from status.

get_cluster_infoA

Extended inventory for one cluster from the hub: OpenShift version, nodes, console URL.

Args: cluster: managed cluster name.

Reads ManagedClusterInfo on the hub, so it needs no spoke access and works for any spoke - external OpenShift, HCP, or cloud. Needs the ACM/MCE multicloud-operators-foundation add-on; reports clearly if it is not present.

get_cluster_healthA

Health summary for one cluster: hub conditions, unhealthy pods, degraded deployments.

Args: cluster: managed cluster name. Pod/deployment detail requires a read-only spoke context (OCM_MCP_SPOKE_CONTEXTS); hub conditions work without one.

get_fleet_healthA

Health of the WHOLE fleet in one call: hub conditions for every cluster plus concurrent pod/deployment scans of each spoke that has a read context.

Args: clusters: optional comma-separated managed-cluster names to scope the sweep; empty means every cluster on the hub.

Clusters with problems sort first. A broken spoke shows an 'error' entry instead of failing the sweep. Prefer this over calling get_cluster_health in a loop.

query_eventsA

Recent Kubernetes events from a managed cluster, newest first.

Args: cluster: managed cluster name. namespace: optional namespace filter; empty means all namespaces. limit: maximum number of events to return (default 40).

Use this to find the 'why' behind unhealthy pods.

get_pod_logsA

Tail logs from a pod on a managed cluster.

Args: cluster: managed cluster name. namespace: pod namespace. pod: pod name. container: container name; empty picks the default container. lines: number of trailing log lines (default 80).

Falls back to the previous container instance if the current one is crashing.

list_placementsA

List Placements and how many clusters each currently selects.

Args: namespace: limit to one namespace; empty lists across all namespaces.

get_placement_decisionA

Which clusters a Placement actually selected (reads its PlacementDecisions).

Args: placement: Placement name. namespace: the namespace the Placement lives in.

list_addon_placement_scoresA

List AddOnPlacementScores in a cluster's namespace (custom scores prioritizers consume).

Args: cluster: managed cluster name (its hub namespace holds the scores).

list_manifestworksA

List ManifestWorks targeting a cluster (what the hub is managing there).

Args: cluster: managed cluster name.

get_manifestworkA

Detailed ManifestWork status: top-level conditions and per-resource status feedback.

Args: cluster: managed cluster name. name: ManifestWork name.

Use this to answer 'why is this ManifestWork not Applied/Available' and to read status feedback (for example replica counts) reported back from the spoke.

list_manifestworkreplicasetsA

List ManifestWorkReplicaSets (a template fanned across a Placement) with rollout summary.

Args: namespace: limit to one namespace; empty lists across all namespaces.

propose_manifestworkA

Propose a change to one cluster as an OCM ManifestWork. Does NOT apply anything.

Args: cluster: target managed cluster name. name: a short kebab-case name for the ManifestWork. summary: one or two sentences a human approver will read. Be precise about what changes and why. manifests_json: JSON array of complete Kubernetes manifests (allowed kinds only; all namespaced; images pinned).

The proposal must pass static guardrails and a Kyverno dry-run on the hub. On success it is stored pending and the human operator must run ocm-mcp approve <id> to mint an approval token.

apply_manifestworkA

Apply a previously proposed ManifestWork. Requires a human-minted approval token.

Args: proposal_id: id returned by propose_manifestwork. approval_token: token the operator produced with ocm-mcp approve <id>.

propose_rollbackA

Propose rolling back an applied ManifestWork. Applies nothing; needs its own approval.

Args: proposal_id: id of an already-applied ManifestWork proposal.

Creates a distinct rollback proposal bound to the exact ManifestWork name and UID. The human approves it separately (ocm-mcp approve <rollback-id>), and the token can only authorize a rollback - an old apply token can never delete a workload.

rollback_manifestworkA

Delete a ManifestWork after a rollback proposal has been approved.

Args: rollback_proposal_id: id returned by propose_rollback. approval_token: a rollback token from ocm-mcp approve <rollback-id>.

list_cluster_management_addonsA

List fleet-level add-on definitions (ClusterManagementAddOn) and their install strategy.

get_addon_healthA

Per-cluster add-on health across the fleet (ManagedClusterAddOn Available / Degraded).

list_addons_for_clusterA

Every add-on installed on one cluster, with health (ManagedClusterAddOn in its namespace).

Args: cluster: managed cluster name.

list_pending_csrsA

List pending cluster-join / add-on registration CSRs awaiting hub approval.

propose_cluster_actionA

Propose an OCM cluster lifecycle action. Does NOT apply anything.

Args: cluster: target managed cluster name. action: one of 'cordon' (taint out of scheduling), 'uncordon' (undo cordon), 'set_label' (params: {"key","value"}; empty value removes the label), 'accept' (set hubAcceptsClient=true and approve pending join CSRs), 'enable_addon' (params: {"addon","install_namespace"?}; create a ManagedClusterAddOn), 'disable_addon' (params: {"addon"}; delete it). summary: one or two sentences the human approver will read. params_json: JSON object of action parameters (set_label and the addon actions need it; cordon/uncordon/accept do not).

The action is validated with a server-side dry-run, then stored pending. The human operator must run ocm-mcp approve <id> to mint the approval token.

apply_cluster_actionA

Apply a previously proposed cluster lifecycle action. Requires a human-minted token.

Args: proposal_id: id returned by propose_cluster_action. approval_token: token the operator produced with ocm-mcp approve <id>.

list_policiesA

List governance Policies and per-cluster compliance (only if the add-on is installed).

Args: namespace: limit to one namespace; empty lists across all namespaces.

list_policy_violationsA

Only the NonCompliant / Pending Policy-cluster pairs across the fleet - the open risks.

list_hosted_clustersA

List HyperShift HostedClusters, when the hub is the HCP hosting cluster.

Args: namespace: limit to one namespace; empty lists across all namespaces.

HostedCluster objects live on whichever cluster hosts the control plane. If your HCPs are hosted on a separate management cluster, they are not on this hub - this reports that clearly, and the spokes still appear via list_clusters.

get_hosted_clusterA

Detailed HostedCluster: version, conditions, and its NodePools.

Args: name: HostedCluster name. namespace: the namespace the HostedCluster lives in (its hosting namespace).

list_node_poolsA

List HyperShift NodePools (worker groups), optionally filtered to one HostedCluster.

Args: namespace: limit to one namespace; empty lists across all namespaces. cluster: optional HostedCluster name to filter node pools by.

list_resourcesA

Generic list over an allow-list of OCM API types (identity + conditions only).

Args: resource: an OCM resource type, e.g. managedclusters, placements, placementdecisions, manifestworks, managedclusteraddons, clustermanagementaddons, managedclustersets, policies, klusterlets. namespace: for namespaced types, limit to one namespace; empty lists all.

Only Open Cluster Management types are allowed. Secrets and other credential resources are not on the allow-list and cannot be read through this tool.

get_resourceA

Generic get of one allow-listed OCM resource, in full.

Args: resource: an OCM resource type (see list_resources for the allow-list). name: object name. namespace: required for namespaced types (usually the cluster namespace).

Never returns a Secret: Secrets are not on the allow-list, so this capability does not exist rather than being merely restricted.

list_pending_proposalsA

List proposals (ManifestWorks and cluster actions) waiting for human approval.

get_audit_trailA

Return the last N entries of this server's own tool-call audit log.

Args: last_n: number of trailing audit entries to return (default 30).

Use this at the end of an incident to write an accurate post-incident report of what was inspected, proposed, approved, and applied - from the record, not from memory.

Prompts

Interactive templates invoked by user choice

NameDescription
diagnose_fleetSweep the whole fleet and summarize what is unhealthy and why, without changing anything.
remediate_with_approvalInvestigate a symptom, propose the smallest safe fix, and wait for a human approval token.
incident_postmortemWrite a post-incident report strictly from the audit trail, not from memory.
why_not_scheduledExplain why a cluster was or was not selected by a Placement, from the live objects.
onboard_clusterSafely accept a pending cluster into the fleet, through the approval gate.
addon_troubleshootDiagnose a degraded add-on across the fleet, reads only.
hosted_cluster_healthAssess the health of a HyperShift hosted control plane and its node pools.
policy_compliance_reportSummarize governance policy compliance across the fleet, reads only.
capacity_reportFind clusters with spare capacity and clusters under pressure, reads only.
rollout_statusTrack a ManifestWorkReplicaSet rollout across the clusters a Placement selected.

Resources

Contextual data attached and managed by the client

NameDescription
resource_clustersAll ManagedClusters with availability, version, labels, and capacity.
resource_policiesGovernance Policies and per-cluster compliance (if the add-on is installed).
resource_proposalsProposals currently waiting for human approval.
resource_audit_tailThe last 50 entries of this server's own tamper-evident audit log.
resource_guardrailsThe effective static guardrail configuration this server enforces. Reading this before proposing avoids a rejection round-trip: it is the exact allow-list surface the guardrails check proposals against.

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/sandeepbazar/ocm-mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server