PluginBench
MCP Server
Active
Apache-2.0

MimiOps mcp server for Kubernetes MCP Server

io.github.sergelogvinov/mimiops-mcp

Safe, opinionated MCP server for Kubernetes troubleshooting and controlled operations.

What is the MimiOps mcp server for Kubernetes MCP server?

MimiOps is an opinionated MCP server for Kubernetes that provides AI agents with a limited, safe interface for observing and managing Kubernetes workloads. It restricts dangerous operations like direct resource editing, secret changes, and data deletion, while enabling investigation and controlled recovery actions. The server supports multi-cluster configurations and integrations with Helm, FluxCD, and Karpenter.

MimiOps gives AI agents safe, well-defined tools to investigate Kubernetes issues and perform controlled recovery operations without unrestricted cluster access. It's designed to prevent accidental damage from AI-driven changes while supporting common troubleshooting tasks. The server exposes read-only inspection tools by default, with optional destructive operations (pod deletion, scaling, rollbacks) available only when explicitly enabled.

How to install MimiOps mcp server for Kubernetes

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "mimiops-mcp": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/sergelogvinov/mimiops-mcp:v0.5.0"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • clusters_list — List multi-cluster configurations
  • clusters_describe — Describe cluster details
  • pods_list — List pods
  • pods_get — Get pod details
  • pods_describe — Describe pod configuration and status
  • pods_log — Retrieve pod logs
  • pods_delete — Delete a pod (requires --allow-destructive)
  • jobs_list — List jobs
  • jobs_get — Get job details
  • jobs_describe — Describe job configuration and status
  • jobs_log — Retrieve job logs
  • jobs_create — Create a new job
  • jobs_delete — Delete a job (requires --allow-destructive)
  • cronjobs_list — List cronjobs
  • cronjobs_get — Get cronjob details
  • cronjobs_describe — Describe cronjob configuration
  • cronjobs_suspend — Suspend scheduled cronjob runs (requires --allow-destructive)
  • cronjobs_resume — Resume cronjob runs (requires --allow-destructive)
  • nodes_list — List cluster nodes
  • nodes_get — Get node details

Use cases

  • Investigate pod failures and retrieve logs for troubleshooting
  • Inspect Kubernetes resource status, events, and configuration across clusters
  • Perform safe recovery actions like pod deletion and workload scaling
  • Manage Helm releases and FluxCD deployments with rollback capability
  • Monitor resource quotas, limits, and autoscaling policies

MimiOps mcp server for Kubernetes MCP server FAQ

What is MimiOps?

MimiOps is an opinionated MCP server that provides AI agents with safe, controlled access to Kubernetes. It enables investigation and limited recovery operations while preventing dangerous actions like direct resource editing or secret modification.

Is MimiOps free?

Yes, MimiOps is open-source under the Apache-2.0 license.

How do I install MimiOps in Claude Desktop?

Download the `.mcpb` release bundle and open/import it in Claude Desktop. The bundle automatically configures the server and prompts for your kubeconfig file.

How do I install MimiOps in Cursor or other JSON-config clients?

Add a server entry to your MCP configuration JSON with `"command": "mimiops-mcp"` and `"args": ["mcp"]`, then set the `KUBECONFIG` environment variable to your kubeconfig path.

What authentication does MimiOps require?

MimiOps uses your existing kubeconfig file and Kubernetes credentials. It supports standard Kubernetes authentication methods and can impersonate users via the `--as` flag.

Can MimiOps delete resources or make dangerous changes?

By default, MimiOps only exposes read-only inspection tools. Destructive operations (pod deletion, scaling, rollbacks) are available only when explicitly enabled with the `--allow-destructive` flag.

README (reference)

Source of truth, from the repository.

Mimiops MCP Server

Motivation

There are many ways to manage Kubernetes workloads, but there are also many ways to break them by accident. We have already seen cases where AI agents did something that we did not expect. Giving an AI agent full access to Kubernetes can be risky, especially when it can create, update, or delete resources directly.

In my opinion, we need to provide safe and well-defined tools for AI agents. These tools should limit what an agent can do, validate changes before applying them, and help prevent dangerous operations.

We also need tools that can help investigate and fix workload issues. Many workloads are already managed by well-known tools such as Argo CD, FluxCD, Helm, and other GitOps or deployment systems. An AI agent should understand who manages a resource and avoid making direct changes that can conflict with these tools.

The goal is not to give AI full control of Kubernetes. The goal is to give AI a safe interface that allows it to understand problems, suggest changes, and perform only controlled operations.

Overview

Mimi OPS is not designed to give AI agents unrestricted Kubernetes access. Instead, it provides a small set of well-known and controlled operations.

The agent can observe, investigate, and perform a limited number of safe recovery actions. More dangerous operations, such as editing arbitrary resources, applying YAML, changing secrets, or deleting persistent data are strongly restricted.

This makes Mimi OPS an opinionated interface between AI agents and Kubernetes: powerful enough for common troubleshooting, but limited enough to reduce the risk of unexpected changes.

Keep your AI on the leash.

Kubernetes core tools

Core tools are always registered. The names below are the MCP tool names exposed by the server:

  • Clusters: clusters_list (multi-cluster configurations only), clusters_describe.
  • Pods: pods_list, pods_get, pods_describe, pods_log.
  • Jobs: jobs_list, jobs_get, jobs_describe, jobs_log, jobs_create.
  • CronJobs: cronjobs_list, cronjobs_get, cronjobs_describe.
  • Nodes: nodes_list, nodes_get, nodes_describe.
  • Namespaces: namespaces_list, namespaces_describe.
  • Resource configuration: resourcequotas_list, resourcequotas_describe, limitranges_list, limitranges_describe, storageclasses_list, persistentvolumeclaims_list, persistentvolumeclaims_describe, priorityclasses_list.
  • Events: events_get.
  • Workloads (Deployments, StatefulSets, and DaemonSets): workloads_list, workloads_get, workloads_describe.
  • Autoscaling: hpa_list, hpa_describe.
  • Services: services_list, services_describe.

The following additional recovery tools are registered only when --allow-destructive is enabled:

  • pods_delete — delete a pod so its controller can recreate it.
  • jobs_delete — delete a Job.
  • cronjobs_suspend, cronjobs_resume — suspend or resume scheduled runs.
  • workloads_scale — scale a Deployment, StatefulSet, or DaemonSet.

Helm extension

Helm tools are enabled by default with --extensions helm:

  • helm_list — list Helm releases.
  • helm_status — inspect release status, revision, and related information.
  • helm_rollback — roll back a release to its previous revision; available only with --allow-destructive.

FluxCD extension

Enable FluxCD tools with --extensions fluxcd (or --extensions all). Read-only inspection tools include:

  • GitRepository: flux_gitrepositories_list, flux_gitrepositories_describe.
  • OCIRepository: flux_ocirepositories_list, flux_ocirepositories_describe.
  • HelmRelease: flux_helmreleases_list, flux_helmreleases_describe.
  • Kustomization: flux_kustomizations_list, flux_kustomizations_describe.

With --allow-destructive, Flux also exposes:

  • flux_reconcile — trigger an immediate reconciliation of a GitRepository, HelmRelease, or Kustomization.
  • flux_reconciliation — suspend or resume a Flux HelmRelease or Kustomization.

Karpenter extension

Enable Karpenter tools with --extensions karpenter (or --extensions all). Read-only inspection tools include:

  • NodePool: karpenter_nodepools_list — list NodePools with node class, node count, readiness, weight, and CPU/memory provisioned vs limits.

Installation

brew install sergelogvinov/tap/mimiops-mcp

MCPB-compatible clients

MimiOPS includes an MCPB manifest for clients that support MCP bundles, such as Claude Desktop. Download the .mcpb release bundle and open/import it in the client. The bundle:

  • starts server/mimiops-mcp mcp;
  • prompts for a kubeconfig file; and
  • passes that file as KUBECONFIG to the server.

Manual editor configuration

For clients that use a JSON MCP configuration, add a server entry similar to the following:

{
  "mcpServers": {
    "mimiops": {
      "command": "mimiops-mcp",
      "args": ["mcp"]
    }
  }
}

Zed uses a command object under context_servers:

{
  "context_servers": {
    "mimiops": {
      "command": {
        "path": "mimiops-mcp",
        "args": ["mcp"],
        "env": {
          "KUBECONFIG": "/absolute/path/to/kubeconfig"
        }
      }
    }
  }
}

Restart or reload the client after saving its configuration. The server will then appear as mimiops and expose the tools listed below.

Running

Common flags

Kubernetes and application flags are global (persistent) and inherited by mcp, server, and tools:

FlagDefaultEnvironment variableDescription
--kubeconfig <path>autoKUBECONFIGPath to kubeconfig; uses the default Kubernetes loading rules when unset
--context <name>current contextCONTEXTKubernetes context to use
--namespace <name>all namespacesNAMESPACEDefault namespace scope for operations
--as <user>unsetASKubernetes impersonation user
--extensions <list>helmEXTENSIONSComma-separated extensions to enable, or all
--allow-destructivefalseALLOW_DESTRUCTIVEEnable destructive or mutating tools
--log-level <level>infoLOG_LEVELdebug, info, warn, or error
--log-format <format>textLOG_FORMATtext or json

The Kubernetes client also exposes the standard genericclioptions connection and authentication flags. The tools command adds this command-specific flag:

CommandFlagDefaultDescription
tools--output, -otextRender tool results as text, json, or yaml
server--port8080HTTP/SSE listen port; environment variable: PORT

Available commands are mcp (stdio), server (HTTP/SSE), tools (direct CLI invocation), and version.

Examples

# stdio with kubeconfig and impersonation
./bin/mimiops-mcp mcp --kubeconfig ~/.kube/dev.yaml --as developer

# SSE server scoped to a namespace, with destructive tools enabled
./bin/mimiops-mcp server --namespace default --allow-destructive --port 8080

# List enabled tools, or invoke one directly from the CLI
./bin/mimiops-mcp tools --extensions all
./bin/mimiops-mcp tools pods_list namespace=default -o json

License

Apache-2.0

Related MCP servers

Proxmox MCP is an opinionated MCP server

2
Go
Apache-2.0
View repository →

A transparent MCP server for agent reflection, conversation, and operator-enabled task decline.

0
TypeScript
MIT
View repository →
HOHostwatch logo

Hostwatch

Active

Observe and safely control sites, TLS, containers, traffic, databases and jobs with Hostwatch.

0
Go
View repository →
RARadioChron logo

Local-first Wi-Fi incident diagnostics with native BLE scan, history, and risk evidence.

1
Rust
MIT
View repository →
WEWeavatrix logo

Weavatrix

Active

Native Weavatrix MCP: 43 read-only repository tools across 24 code and configuration surfaces.

4
JavaScript
MIT
View repository →

Fast, bounded, read-only Git evidence for local AI coding agents.

0
Rust
MIT
View repository →