mcp-argocd
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| ARGOCD_URL | Yes | Base URL including any path prefix. Also reads ARGOCD_SERVER. | |
| ARGOCD_TOKEN | Yes | Bearer token. Also reads ARGOCD_AUTH_TOKEN, ARGOCD_API_TOKEN. | |
| ARGOCD_TIMEOUT | No | Request timeout in seconds | 30 |
| ARGOCD_READ_ONLY | No | true blocks the 9 write tools before any API call | false |
| ARGOCD_SSL_VERIFY | No | false skips SSL verification (ARGOCD_INSECURE=true is an alias) | true |
| ARGOCD_APP_NAMESPACE | No | Default appNamespace for apps-in-any-namespace installs |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| logging | {} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| argocd_list_applicationsA | List applications with slim rows (name, project, sync/health, source, destination, policy). Filters sync_status, health_status, destination, and name_prefix client-side; the Argo CD list endpoint has no paging, so results are sorted by name and sliced here. |
| argocd_get_applicationB | Get one application: spec, sync/health, conditions, operation, summary, resource counts. refresh=hard forces reconciliation and re-fetches target manifests from the repo server. |
| argocd_get_resource_treeA | Get the live resource tree as slim nodes (kind, name, health, images, parent). Drops networkingInfo, uid, and resourceVersion. Filters by kind and health client-side. |
| argocd_get_managed_resourcesA | Get managed resources with their live-vs-desired diffs (truncated by default). include_states adds the parsed target, normalized-live, and predicted-live manifests with managedFields stripped. |
| argocd_get_resourceA | Get a single managed resource's live manifest, with managedFields and the last-applied annotation removed. |
| argocd_get_manifestsB | Get the rendered desired manifests for a revision, parsed into objects and paged. |
| argocd_get_application_eventsA | Get Kubernetes events for an application, newest first, with messages capped at 500 chars. |
| argocd_get_pod_logsA | Get container logs (never follows). Returns lines with pod and timestamp, the pods seen, and a shown_lines count; stops at the stream's last marker. |
| argocd_get_application_historyB | Get deployment history (newest first) with revision, who deployed it, and the source. |
| argocd_get_revision_metadataB | Get commit metadata for a revision: author, date, message, tags, signature info. |
| argocd_get_operationA | Get the current or last sync operation: phase, who started it, and per-status result counts. Returns {"phase": null} when no operation has run. |
| argocd_wait_for_operationA | Poll an application until its operation reaches a terminal phase, disappears, or times out. Never errors on timeout; returns timed_out=true with the latest operation, sync, and health. |
| argocd_get_sync_windowsA | Get sync windows for an application: whether it can sync now, plus active and assigned windows. |
| argocd_list_resource_actionsA | List the custom resource actions available on a resource (e.g. restart, pause). |
| argocd_sync_applicationA | Sync an application. destructive because prune and force can delete or recreate resources. Returns the started operation; with wait=True, the final one. revision override needs the
|
| argocd_rollback_applicationA | Roll back to a prior deployment history entry. destructive. Argo CD refuses a rollback while auto-sync is on, so this pre-reads the app and returns an actionable error first. A rollback re-applies an old revision, so fix Git afterward. |
| argocd_terminate_operationA | Terminate the running sync operation. Use to unstick a sync hanging in Running. |
| argocd_create_applicationA | Create an application from flattened parameters. Use patch for anything this does not cover. Returns the created application, slim. Idempotent only with upsert=True. |
| argocd_patch_applicationA | Patch an application — the one tool for every update. Examples: change targetRevision with patch='{"spec":{"source":{"targetRevision":"v2"}}}'; disable auto-sync with patch='{"spec":{"syncPolicy":{"automated":null}}}'. |
| argocd_delete_applicationB | Delete an application. destructive. cascade=False removes only the Application object. |
| argocd_run_resource_actionB | Run a custom resource action (restart a Deployment, pause a Rollout). destructive. |
| argocd_delete_resourceB | Delete a single managed resource so the controller recreates it. destructive. |
| argocd_list_applicationsetsB | List ApplicationSets with slim rows (generators present, strategy, health, conditions). |
| argocd_get_applicationsetA | Get one ApplicationSet: generators, strategy, and the status of the apps it generates. |
| argocd_generate_applicationsetA | Dry-run the generators: preview the applications an ApplicationSet would produce. Creates nothing. The manifest must be JSON. |
| argocd_list_projectsA | List projects with slim rows (repo/destination counts, role names, sync-window count). |
| argocd_get_projectA | Get a project: allowed repos, destinations, resource whitelists/blacklists, and roles. Role token values (jwtTokens) are never returned; only a token count. |
| argocd_list_clustersA | List clusters with slim rows (connection state, server version, app and cache counts). The cluster credential config is never returned. |
| argocd_get_clusterA | Get one cluster by name or server URL. The credential config is always removed, even with full=True. |
| argocd_invalidate_cluster_cacheA | Invalidate a cluster's cached resources — the standard fix for phantom OutOfSync or Unknown health. Removes nothing real. |
| argocd_list_repositoriesA | List repositories with slim rows and connection state. Credentials are never returned; has_credentials reports whether any are configured. |
| argocd_get_repository_refsB | Get a repository's branches and tags, each paged separately with its own counts. |
| argocd_list_repository_appsB | List the application paths (and their config type) discoverable in a repository. |
| argocd_get_versionA | Get the Argo CD server version and its bundled tool versions. The connectivity probe. |
| argocd_get_userinfoA | Get the authenticated identity: username, groups, whether logged in, and the token issuer. |
| argocd_can_iA | Check whether the current account may perform resource/action on a subresource. Returns {allowed: bool, ...}; the API answers the string yes/no. |
| argocd_get_settingsA | Get server settings: URL, enabled features, tracking method, and plugin names. Drops OIDC/Dex config and UI banner fields in the slim view. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| triage_application | Diagnose why an application is Degraded or OutOfSync: conditions, tree, events, logs. Accepts namespace/name for app_namespace extraction. |
| diagnose_sync_failure | Find out why the last sync failed: failed resources, events, manifests, classification. |
| review_drift | Review OutOfSync apps and their diffs; recommend sync, a Git change, or an ignore rule. |
| safe_sync | Sync an application safely: check sync windows, dry-run, review, then sync and wait. |
| rollback_application | Roll back an app: pick history, confirm the commit, check auto-sync, then verify. |
| fleet_status | Report fleet health: clusters, connection state, and unhealthy or unsynced apps. |
| inspect_applicationset | Inspect an ApplicationSet: its generated apps, a dry-run generate, and a diff vs existing. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| Sync Safety Rules | Dry-run first, prune/force, sync options, sync windows, revision override |
| Rollback Rules | History limits, auto-sync blocking rollback, RBAC, fixing Git after a rollback |
| GitOps Change Flow | Git as source of truth, selfHeal, justified live fixes, never delete to fix drift |
| ApplicationSet Rules | Set owns generated apps; preservedFields, strategy, generate preview, finalizer |
| Status Triage Guide | Sync x health matrix, condition types, and how to investigate an unhealthy app |
| RBAC and Permission Errors | Resource/action model, fine-grained sub-resources, logs RBAC, reading 403s |
| API Token Setup | Local apiKey accounts, generate-token, project role tokens, read-only policy |
TDQS
Scored across 37 tools
Each tool targets a distinct Argo CD resource or action, such as applications, ApplicationSets, projects, clusters, repositories, and resource actions. Although there are many get_* tools, their scopes (tree, managed resources, single resource, manifests, events, logs) are clearly differentiated in the descriptions, so an agent can select correctly.
All tools use the argocd_ prefix and snake_case with consistent verb_noun or verb_noun_phrase patterns (e.g., argocd_list_applications, argocd_get_application, argocd_sync_application). Minor variations like argocd_can_i and argocd_get_userinfo are still predictable and readable.
37 tools far exceeds the typical 3-15 range and the rubric's threshold for 'too many' (25+). While Argo CD is a broad system, many tools could be consolidated (e.g., multiple resource-inspection tools) to reduce cognitive load.
The application lifecycle is well-covered (create, get, list, patch, delete, sync, rollback, terminate, wait, events, logs, history). However, other core Argo CD resources—ApplicationSets, Projects, Clusters, and Repositories—lack create/update/delete operations, leaving significant gaps that would cause agent failures when managing these resources.