Skip to main content
Glama

get_tkc_kubeconfig

Idempotent

Retrieve a kubeconfig for a specific Tanzu Kubernetes Cluster (TKC) to authenticate and access it. Provide the cluster name and namespace; optionally save to a file.

Instructions

[WRITE] Credential access: get a kubeconfig for one TKC cluster.

Call only when the user explicitly asks for this kubeconfig; never as a side step. Returns {cluster, kubeconfig}, or {cluster, written_to} when output_path is given. The kubeconfig embeds a Supervisor bearer token (JWT from /wcp/login) that acts as the configured vCenter account until the JWT expires (typically hours; not tied to this process) — always pass output_path so the token never enters agent context, and report only the path. Nothing in the managed cluster changes, but output_path creates parent directories and truncates the named file (owner-only, 0600), so output_path='~/.kube/config' replaces the user's own kubeconfig. Run list_tkc_clusters first for name and namespace; use get_supervisor_kubeconfig instead for Supervisor-level access.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameYesTKC cluster name.
targetNovCenter in config.yaml; omit for the default.
namespaceYesNamespace holding it.
output_pathNoFile to write, e.g. '~/.kube/my.yaml'. Omit to return the kubeconfig inline.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed5 schema fields changedv1.8.14
    • addedInput schema / additionalProperties
      Added value: +false
    • addedInput schema / properties / name / description
      Added value: +"TKC cluster name."
    • addedInput schema / properties / namespace / description
      Added value: +"Namespace holding it."
    • addedInput schema / properties / output_path / description
      Added value: +"File to write, e.g. '~/.kube/my.yaml'. Omit to return the kubeconfig inline."
    • addedInput schema / properties / target / description
      Added value: +"vCenter in config.yaml; omit for the default."
  2. Addedv1.5.26
  3. Removedv1.5.23
  4. First observedv1.3.2

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only say readOnlyHint=false/destructiveHint=false/idempotentHint=true/openWorldHint=true; the description goes far beyond by disclosing the return shapes, the embedded JWT bearer-token lifecycle (hours, not tied to this process), and the concrete file side effects of output_path (creates parent dirs, truncates the target, 0600 owner-only, overwriting ~/.kube/config). It also gives the mitigating instruction to always pass output_path so the token never enters agent context. The file-truncation disclosure slightly exceeds the destructiveHint=false annotation, but it is added transparency rather than a contradiction.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the [WRITE] tag, purpose, and gating condition before the detail. The single dense paragraph is long and dash-heavy but nearly every clause (token lifetime, return shapes, overwrite warning, prerequisites) earns its place; minor tightening is possible in the token sentence.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description carries the return-value burden and does so fully, specifying both possible return shapes. It also covers the safety-critical side effects, the credential lifetime, and the prerequisite call, so an agent has everything needed to invoke correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the baseline is 3, but the description adds real meaning: output_path changes the return shape ({kubeconfig} vs {written_to}), carries the side-effect semantics (directory creation, truncation, permissions), and is framed as a strong recommendation rather than an optional toggle. It also implies name/namespace should be sourced from list_tkc_clusters.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('get a kubeconfig for one TKC cluster') and immediately frames it as credential access, which sets it apart from non-credential siblings like get_tkc_cluster. It also names the sibling it is not for (get_supervisor_kubeconfig) so the agent can disambiguate the two kubeconfig tools without opening schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit when-to-use ('only when the user explicitly asks') and when-not ('never as a side step'), plus a prerequisite ('Run list_tkc_clusters first for name and namespace') and a named alternative for the adjacent use case ('use get_supervisor_kubeconfig instead for Supervisor-level access'). Nothing about tool selection is left to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.