vmware-vks
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| VMWARE_VKS_CONFIG | Yes | Path to the configuration YAML file (e.g., ~/.vmware-vks/config.yaml). This file should contain the vCenter host and username. | |
| VMWARE_MY_VCENTER_PASSWORD | Yes | The vCenter password environment variable. According to the documentation, passwords must be provided via environment variables rather than the configuration file. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| check_vks_compatibilityA | [READ] Check whether this vCenter supports VKS (requires vSphere 8.x+). Returns compatible (bool), vcenter_version, wcp_enabled_clusters and wcp_clusters ({cluster, status}). Start here: those cluster MoRefs are the cluster_id for get_supervisor_status and create_namespace. Only reports vCenter-level support — a listed cluster may still be CONFIGURING. |
| get_supervisor_statusA | [READ] Get the health of one Supervisor Cluster (vSphere with Tanzu control plane). Returns cluster_id, config_status (RUNNING = healthy, else CONFIGURING / ERROR / REMOVING), kubernetes_status (READY / WARNING / ERROR), api_server_cluster_endpoint, kubernetes_version (null plus kubernetes_version_hint if unavailable), and network_provider. Run check_vks_compatibility first for cluster IDs; use this to confirm a Supervisor is healthy before create_namespace or create_tkc_cluster. |
| list_supervisor_storage_policiesA | [READ] List vCenter storage policies assignable to Supervisor Namespaces. Returns the list envelope: items of {policy (ID), name, description} plus returned/total/truncated — one call returns them all, so truncated is always false. Call this before create_namespace or update_namespace and pass the 'policy' ID as their storage_policy. For PVC-level usage use list_namespace_storage_usage instead. |
| list_namespacesA | [READ] List all vSphere Namespaces on the target vCenter with their status. Returns the list envelope: items of {namespace, config_status (RUNNING = healthy, CONFIGURING, REMOVING, ERROR), description} plus returned/total/truncated — one call returns them all, so truncated is always false. Start here, then call get_namespace for detail, list_tkc_clusters for what runs inside, or update_namespace / delete_namespace to change one. |
| get_namespaceA | [READ] Get detailed configuration for a single vSphere Namespace. Returns one raw vCenter namespace object, not the list envelope: config_status, description, storage_specs, quotas. Use list_namespaces first for the name; follow with list_namespace_storage_usage for PVC usage or list_tkc_clusters for the clusters inside. Point-in-time only — a CONFIGURING namespace may not have quotas applied. |
| create_namespaceA | [WRITE] Create a vSphere Namespace on a Supervisor Cluster. Without confirm=True this only previews: it returns blast_radius (the spec that would be applied, and whether the name is already taken) and creates nothing. Show it to the user and get their decision. Do not set confirm=True on your own because the user asked earlier — they have not seen the preview yet. confirm=True returns {action: "created", namespace, status, cluster, blast_radius}; it is refused when the name is taken (use update_namespace) or the existing names could not be read. Confirm with get_namespace afterwards. |
| update_namespaceA | [WRITE] Update resource quotas or storage policy of an existing vSphere Namespace. Only the fields you pass are patched; omitting all of them returns status "no_changes" without an API call, otherwise {namespace, status: "updated"}. Applies immediately — no dry run, no undo. Use this rather than create_namespace when the namespace exists; valid storage_policy values come from list_supervisor_storage_policies. |
| delete_namespaceA | [WRITE] Delete a vSphere Namespace and everything inside it (irreversible). Without confirm=True this only previews: it returns blast_radius (the namespace, and the TKC clusters, VMs and PVCs inside it, with counts and names) and deletes nothing. Show that to the user and get their explicit decision. Do not set confirm=True on your own because the user said "delete" earlier: they have not seen what it destroys yet. confirm=True returns {action: "deleted", namespace, status, blast_radius}. Refused while TKC clusters exist inside (run delete_tkc_cluster on each), and whenever the clusters, VMs or PVCs inside could not be read. Prefer update_namespace to only change quotas. |
| list_vm_classesA | [READ] List VM classes available for sizing TKC cluster nodes. Returns the list envelope: items of {id (e.g. 'best-effort-large'), cpu_count, memory_mb, gpu_count (vGPU + DirectPath I/O; 0 if none)} plus returned/total/truncated — one call returns them all, so truncated is always false. Call this before create_tkc_cluster and pass the chosen 'id' as its vm_class; 'guaranteed-' classes reserve resources, 'best-effort-' do not. |
| list_tkc_clustersA | [READ] List TanzuKubernetesCluster (TKC) clusters, optionally in one namespace. Returns the family list envelope: {items: [{name, namespace, phase, k8s_version}], returned, limit, total, truncated, hint}. The Supervisor list is walked to completion, so truncated is always False. Start here, then call get_tkc_cluster for full detail or get_tkc_kubeconfig for access. 'clusters' is a deprecated pre-1.8.0 alias of 'items', removed in 2.0 — read 'items'. |
| get_tkc_clusterA | [READ] Get detailed status for a single TKC cluster. Returns one object, not the list envelope: name, namespace, phase, k8s_version, control_plane_replicas, worker_replicas, conditions, infrastructure_ready, control_plane_ready. Run list_tkc_clusters first — a TKC name is only unique within one namespace. Poll this after create_tkc_cluster, scale_tkc_cluster or upgrade_tkc_cluster to watch an async change land. |
| get_tkc_available_versionsA | [READ] List Kubernetes versions (TanzuKubernetesReleases) available on the Supervisor. Returns {versions: [{name, version, e.g. 'v1.28.4+vmware.1'}]}, newest first. If the TanzuKubernetesRelease API is unavailable it returns an empty versions list with error and hint rather than raising. Call this before create_tkc_cluster or upgrade_tkc_cluster to pick a valid k8s_version. |
| create_tkc_clusterA | [WRITE] Create a TanzuKubernetesCluster in a vSphere Namespace. Without confirm=True this only previews: it returns blast_radius (node counts, VM class, the YAML manifest, and whether the name is taken) and creates nothing. Show it to the user and get their decision. Do not set confirm=True on your own because the user asked earlier — they have not seen the preview yet. confirm=True returns {action: "created", name, namespace, status: "creating", yaml, blast_radius} and provisions in the background — poll get_tkc_cluster until phase is running. Refused when the name is taken or the namespace's clusters could not be read. Call get_tkc_available_versions for k8s_version and list_vm_classes first. |
| scale_tkc_clusterA | [WRITE] Scale the worker node count of an existing TanzuKubernetesCluster (TKC). Asynchronous: returns {name, namespace, pool, worker_count, status: "scaling"} immediately — poll get_tkc_cluster to watch nodes appear or drain. Scales workers only; use upgrade_tkc_cluster instead for the K8s version. Not destructive, but lowering worker_count drains removed nodes. |
| upgrade_tkc_clusterA | [WRITE] Upgrade a TKC cluster to a new Kubernetes version. Returns {name, namespace, new_version, status: "upgrading"}. Asynchronous and irreversible — Kubernetes cannot be downgraded, so poll get_tkc_cluster until phase is running. There is no dry run. Use this only for the K8s version; prefer scale_tkc_cluster for node counts. |
| delete_tkc_clusterA | [WRITE] Delete a TKC cluster and all of its nodes (irreversible). Without confirm=True this only previews: it returns blast_radius (control plane and worker node counts per pool, and the running Deployments, StatefulSets and DaemonSets) and deletes nothing. Show that to the user and get their explicit decision. Do not set confirm=True on your own because the user said "delete" earlier: they have not seen what it destroys yet. confirm=True returns {action: "deleted", name, namespace, status: "deleting", blast_radius}. Refused while workloads run (drain them, or pass force=True, which skips the workload check entirely) and whenever the node counts or workloads could not be read. Use scale_tkc_cluster instead for fewer nodes. Empty a namespace of TKC clusters before delete_namespace accepts it. |
| get_supervisor_kubeconfigA | [WRITE] Credential access: get a kubeconfig for the Supervisor K8s API. Call only when the user explicitly asks for this kubeconfig; never as a side step. Returns {namespace, kubeconfig} as a YAML string, or {namespace, written_to} when output_path is given. The kubeconfig embeds a Supervisor bearer token (JWT from /wcp/login) that acts as the configured vCenter account until the JWT expires (typically hours; not tied to this process) — always pass output_path so the token never enters agent context, and report only the path. The file is created owner-only (0600). Use get_tkc_kubeconfig instead to reach workloads inside a TKC cluster. |
| get_tkc_kubeconfigA | [WRITE] Credential access: get a kubeconfig for one TKC cluster. Call only when the user explicitly asks for this kubeconfig; never as a side step. Returns {cluster, kubeconfig}, or {cluster, written_to} when output_path is given. The kubeconfig embeds a Supervisor bearer token (JWT from /wcp/login) that acts as the configured vCenter account until the JWT expires (typically hours; not tied to this process) — always pass output_path so the token never enters agent context, and report only the path. Nothing in the managed cluster changes, but output_path creates parent directories and truncates the named file (owner-only, 0600), so output_path='~/.kube/config' replaces the user's own kubeconfig. Run list_tkc_clusters first for name and namespace; use get_supervisor_kubeconfig instead for Supervisor-level access. |
| get_harbor_infoA | [READ] Get status of the embedded Harbor container registry on the Supervisor. Returns {registries: [{id, cluster (Supervisor MoRef), version, url, status, storage_used_mb}]}; status and storage come from a detail call and are null if it fails. If Harbor is not enabled it returns {error, hint} rather than raising. Use it to check registry health or find the push URL — it does not list repositories or images. Run check_vks_compatibility first if the Supervisor may be down. |
| list_namespace_storage_usageA | [READ] List PersistentVolumeClaims and storage usage inside one vSphere Namespace. Via the Supervisor K8s API. Returns the family list envelope: {namespace, items: [{name, namespace, status (Bound / Pending / Lost), capacity ('10Gi'), storage_class}], returned, limit, total, truncated, hint}. Every PVC comes back in one call, so truncated is always False. Run list_namespaces first for the namespace; use list_supervisor_storage_policies instead for policy-level rather than PVC-level information. 'pvcs' and 'pvc_count' are deprecated pre-1.8.0 aliases of 'items' and 'returned', removed in 2.0 — read 'items'. |
| list_vm_snapshotsA | [READ] List VirtualMachineSnapshot objects in a vSphere Namespace. VM Service snapshots (vmoperator.vmware.com CRD, new at v1alpha5) via the Supervisor K8s API — the served CRD version is discovered at runtime, not hardcoded. Returns the family list envelope: items of {name, namespace, vm_name, created, ready} plus returned/total/truncated (walked to completion, so truncated is always false) and served_version. If the Supervisor is older than v1alpha5 the error names the required version. Run list_namespaces first for the namespace; use list_vm_network_interfaces for a VM's NICs. |
| list_vm_groupsA | [READ] List VirtualMachineGroup objects and their bootOrder in a Namespace. VM Service groups (vmoperator.vmware.com CRD, v1alpha4+) via the Supervisor
K8s API — the served CRD version is discovered at runtime. Returns the
family list envelope: items of {name, namespace, boot_order, member_count}
plus returned/total/truncated (walked to completion) and served_version.
|
| list_vm_network_interfacesA | [READ] List the network interfaces (multi-NIC) of one VirtualMachine. Reads spec.network.interfaces[] off a single VM Service VirtualMachine (vmoperator.vmware.com) via the Supervisor K8s API; the served CRD version is discovered at runtime. Returns the family list envelope: items of {name, network_name, network_kind, network_api_version} plus returned/total/truncated and vm_name/served_version. A VM with no network block returns an empty list, not an error. Run list_namespaces for the namespace; the VM name comes from your own VM inventory in that namespace. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 23 tools
Each tool targets a distinct resource and action — Supervisor, namespace, TKC, storage, kubeconfigs, VM Service — so there is no duplicate functionality. The only spots where an agent might hesitate are the two kubeconfig tools and check_vks_compatibility vs get_supervisor_status, but the descriptions draw clear boundaries.
The dominant verb_noun pattern (list_*, get_*, create_*, delete_*) is consistent and readable. Deviations: get_supervisor_kubeconfig and get_tkc_kubeconfig are write-oriented credential actions labeled as get_, and get_tkc_available_versions returns a list rather than a single object.
23 tools is a large surface and sits in the 16–25 range that feels heavy; several VM Service inspection tools could arguably be bundled. That said, the core namespace/TKC lifecycle and supporting lookups mostly justify each tool's presence.
The namespace and TKC lifecycles are thoroughly covered: compatibility, status, CRUD, scale/upgrade/delete, versions, VM classes, storage policies, and kubeconfigs. Gaps are peripheral — no VirtualMachine list/create/delete, no Harbor repository listing, no namespace permission management — and don't block the primary workflows.