Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
VMWARE_AVI_CONFIGNoPath to the config.yaml file (default: ~/.vmware-avi/config.yaml)

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
vs_listA

[READ] List Virtual Services on the AVI Controller.

Returns Name, Enabled, VIP and short UUID for every VS in one call; it cannot be paged or filtered, and carries no health score. Use this before drilling into one VS with vs_status.

vs_statusA

[READ] Detailed status for one Virtual Service: VIP, pool, health, connections, throughput.

Returns one detail block, not a list. Use vs_list first for the exact name — a name that does not match exactly fails. Then vs_analytics for metrics, vs_error_logs for 5xx.

vs_toggleA

[WRITE] Enable or disable a Virtual Service. Disabling stops all traffic to it.

Without confirm=True this only previews: it returns blast_radius (the VS name and uuid, whether it is enabled now, its VIPs and oper status, and the pools and member counts behind it) and changes nothing. Show that to the user and get their explicit decision. Do not set confirm=True on your own because the user asked earlier: they have not seen what it changes yet. A VS already in the requested state returns action "noop".

Refused with confirm=True: a VS whose uuid or pools cannot be read (the change would be blind). Use vs_status first to check current state.

pool_listA

[READ] Discover pools on the Controller.

Returns Name, member count, Enabled and short UUID per pool. Use this before pool_members: pools are often named differently from the VS that use them.

pool_membersA

[READ] List the members of a pool.

Returns Server IP, Port, Enabled and Ratio per member. Use before pool_member_enable or pool_member_disable; run pool_list first for the pool name. Reports configured state only, not live health-monitor results.

pool_member_enableA

[WRITE] Enable a pool member so it receives traffic again.

Returns a one-line confirmation. Use pool_members first to verify the server IP. The server must already belong to the pool — this adds nothing.

pool_member_disableA

[WRITE] Disable a pool member with graceful drain — existing connections complete, no new traffic.

Without confirm=True this only previews: it returns blast_radius (pool name and uuid, the member's IP/port/state, and how many members are enabled before and after) and changes nothing. Show that to the user and get their explicit decision. Do not set confirm=True on your own because the user asked earlier: they have not seen what it changes yet. An already disabled member returns action "noop".

Refused with confirm=True: the pool's only enabled member (the pool would serve nothing — enable another first, or use vs_toggle on purpose), an IP that matches more than one member, and a pool whose members cannot be read. Use for maintenance or rolling deployments; run pool_members first for the server IP, pool_member_enable to reverse it.

ssl_listA

[READ] List SSL/TLS certificates stored on the AVI Controller.

Returns Name, Subject, Expiry and Type per certificate, in one call that cannot be paged or filtered. Use for inventory or a certificate's exact name — use ssl_expiry_check instead for only the ones expiring soon.

ssl_expiry_checkA

[READ] Check which SSL certificates expire within N days (default 30).

Returns name, expiry date and days remaining, soonest first. Use this instead of ssl_list when you only want certificates near expiry. Expired certs are included, with negative days remaining.

vs_analyticsA

[READ] Performance metrics for one Virtual Service over the last hour.

Returns L4 (bandwidth, connections) and L7 (latency, % errors, responses) averages over a fixed window that cannot be changed (12 samples, 5 min apart). Empty output means no traffic, not an error. Use when vs_status shows degraded health; vs_error_logs gives per-request detail.

vs_error_logsA

[READ] Recent request error logs for one Virtual Service.

Returns up to 50 lines — timestamp, HTTP status, URI path, client IP — for status 400 and above. Use this instead of vs_analytics for per-request detail. An empty result may mean no errors, or capture disabled on the VS.

se_listA

[READ] List Service Engines (AVI data-plane VMs) on the Controller.

Returns Name, management IP, status (e.g. OPER_UP) and SE Group per SE, in one call that cannot be paged or filtered. Use to inventory capacity or find an SE's name and IP — use se_health instead for degraded VS health.

se_healthA

[READ] Health of every Service Engine — operational status and VS counts.

Returns name, operational state and the number of VSes placed on each SE. Use when VS health degrades to check if the issue is at the SE level; se_list gives the management IP and SE Group, vs_status the affected VS. An SE hosting no VS reports 0, not an error.

ako_statusA

[READ] Check AKO (AVI Kubernetes Operator) pod status in Kubernetes.

Returns pod name, phase, ready flag, restart count and namespace. First step for Ingress or LoadBalancer issues in Tanzu/K8s; follow with ako_logs when it is not Running. Looks in one context's AKO namespace only — run ako_clusters if not found.

ako_logsA

[READ] AKO pod logs — Ingress creation failures, sync errors, Controller connectivity.

Returns raw log text, not a table. Use when ako_status shows the pod unhealthy or ako_sync_diff reports a missing Ingress. Only the running container's logs are returned.

ako_restartA

[WRITE] Restart the AKO pod by deleting it — its StatefulSet recreates it.

Without confirm=True this only previews: it returns blast_radius (context, namespace, the pod's name, uid, phase and restarts, and the Ingresses whose programming pauses until the new pod is Running) and changes nothing. Show that to the user and get their explicit decision. Do not set confirm=True on your own because the user asked earlier: they have not seen what it changes yet. The pod deleted is the one measured (uid precondition).

Refused with confirm=True: a pod already terminating, and a pod or Ingress list that cannot be read. Use when AKO is stuck or after config changes; brief traffic disruption is possible. Run ako_status afterwards, and ako_logs if the pod is not Running.

ako_versionA

[READ] AKO version running in a cluster, read from the pod's image tag.

Returns the pod name and an Image/Version pair per container. Use it to check compatibility with the Controller, and before ako_config_diff or ako_config_upgrade so both target the installed chart. The tag is the only source, so 'latest' reports 'latest', not a number.

ako_config_showA

[READ] The AKO Helm release's values — controller IP, cloud name, network settings, feature flags.

Returns YAML as helm reports it. Use this first to read the live config; use ako_config_diff instead to see what an upgrade would change. Only values supplied at install time appear; chart defaults do not.

ako_config_diffA

[READ] Pending Helm value changes that have not been applied yet.

Returns helm's diff output; empty means nothing would change. Credential values in it read <redacted> — that is this skill blanking them, not the configured value. Use this before ako_config_upgrade — it runs the same command, so the preview is real. Note: with chart_version empty the registry's moving latest is resolved, so two runs can differ with no local change; read ako_version and pass it to both.

ako_config_upgradeA

[WRITE] Apply an AKO Helm upgrade to the avi-system release.

Finds the avi-system release automatically and upgrades the Broadcom OCI chart with --reuse-values. Without confirm=True this only previews: it returns blast_radius (release, the chart and app version it is on, revision and status, the chart it would move to) plus helm_dry_run, the output of helm upgrade --dry-run, and changes nothing. Show that to the user and get their explicit decision. Do not set confirm=True on your own because the user asked earlier: they have not seen what it changes yet.

Refused with confirm=True: a failing dry-run (the real upgrade would fail too), a release with another helm operation pending, and a release whose status cannot be read. Helm output has credential values blanked to <redacted> by this skill. Run ako_config_diff first to review the change.

ako_ingress_checkA

[READ] Validate every Ingress in one namespace: IngressClass and TLS secret references that would stop AKO creating a Virtual Service.

Returns name, IngressClass, issues and OK/ISSUES per Ingress. Run ako_ingress_map first for namespace names; use ako_ingress_diagnose instead for one named Ingress. Covers one namespace only, and TLS checks are skipped when its secrets cannot be listed.

ako_ingress_mapA

[READ] Inventory Kubernetes Ingresses across all namespaces.

Returns Namespace, Ingress name, Host(s) and IngressClass per Ingress. Start here for namespace and Ingress names, then pass them to ako_ingress_check or ako_ingress_diagnose. Lists the K8s side only — use ako_sync_diff for Ingresses with no Controller object.

ako_ingress_diagnoseA

[READ] Diagnose why one Ingress has no corresponding AVI Virtual Service.

Validates IngressClass ('avi'/'avi-lb'), TLS secrets and backend Services. Returns annotations, a numbered issue list and kubectl fixes. Use ako_ingress_map first to find Ingresses lacking a VS. Checks configuration only; when it is clean, try ako_logs and ako_sync_status.

ako_sync_statusA

[READ] Compare the number of K8s Ingresses with the number of AVI Virtual Services.

Returns both counts and a match/mismatch verdict. Use this first as a cheap check, then ako_sync_diff for which objects differ. A count comparison only — in AKO shard mode many Ingresses share one VS, so a mismatch does not by itself mean trouble.

ako_sync_diffA

[READ] List Ingresses with no matching Virtual Service or pool on the Controller.

Returns Type, namespace/name and Status per suspect Ingress. Use when ako_sync_status reports a mismatch; ako_sync_force reconciles. Shard-mode Ingresses are matched heuristically against AKO pool names, so confirm a 'Missing' result with pool_list before acting.

ako_sync_forceA

[WRITE] Force AKO to resync all K8s resources with the AVI Controller.

The resync restarts the AKO pod so it rebuilds every Virtual Service, pool and VS-VIP from the cluster's current resources. Without confirm=True this only previews: it returns blast_radius (context, namespace, the pod's name, uid and phase, and the Ingresses it re-programs) and changes nothing. Show that to the user and get their explicit decision. Do not set confirm=True on your own because the user asked earlier: they have not seen what it changes yet.

Refused with confirm=True: a pod already terminating, and a pod or Ingress list that cannot be read. Use when drift is detected; may cause brief traffic disruption. Run ako_sync_diff first to see what is out of sync, then ako_sync_status.

ako_clustersA

[READ] List every Kubernetes context in the active kubeconfig and whether AKO is deployed there.

Returns Context, AKO Status (pod phase or 'Not deployed') and Version per context. Requires kubectl on PATH; every context is probed, so unreachable clusters add latency. Start here for context names, then pass one to ako_status, ako_logs or ako_ingress_diagnose.

ako_amko_statusA

[READ] AMKO (AVI Multi-Cluster Kubernetes Operator) GSLB status.

Returns raw kubectl output: the AMKO pods in avi-system, then the GSLBConfig YAML if one exists. Use this only for multi-cluster GSLB questions — for single-cluster AKO health use ako_status instead. Always reads the current kubectl context; see ako_clusters.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A4.5/5.0

Scored across 28 tools

Disambiguation5/5

Each tool targets a distinct resource or action, with cross-references guiding selection (e.g., pool_list before pool_members, vs_list before vs_status). Even similar-sounding tools like ako_sync_status vs ako_sync_diff are clearly differentiated by purpose and output.

Naming Consistency5/5

All tools follow a consistent verb_noun snake_case pattern (e.g., pool_list, vs_toggle, ako_config_upgrade). Verbs are descriptive and nouns match the domain resources, making the surface predictable and easy to navigate.

Tool Count4/5

At 28 tools, the count is above the ideal range, but the server spans two related domains (AVI Controller and AKO/Kubernetes), justifying the breadth. Each tool serves a distinct operational or diagnostic purpose, though some consolidation could reduce overhead.

Completeness4/5

The tool set covers the full operational lifecycle for monitoring and managing AVI resources and AKO deployments, including reads, writes (toggles, restarts, upgrades), and diagnostics. Minor gaps exist, such as no tool for creating pools or VSes, but these fall outside the apparent operational focus.

Maintenance

ActivityActive
ResponsivenessResponsive