apiVersion: toolhive.stacklok.dev/v1beta1 kind: MCPServer metadata: name: kubernetes-mcp namespace: toolhive-system annotations: toolhive.stacklok.dev/registry-export: "true" toolhive.stacklok.dev/registry-title: Kubernetes MCP toolhive.stacklok.dev/registry-description: Write-capable Kubernetes MCP server for cluster inspection, troubleshooting, and GitOps maintenance actions. toolhive.stacklok.dev/registry-url: http://mcp-kubernetes-mcp-proxy.toolhive-system.svc.cluster.local:8080/mcp spec: # containers/kubernetes-mcp-server. Authenticates to the API in-cluster via the # kubernetes-mcp ServiceAccount (write-capable ClusterRole, see rbac file). Speaks # stdio; ToolHive proxies to streamable-http at # http://mcp-kubernetes-mcp-proxy.mcp-services:8080/mcp. image: ghcr.io/containers/kubernetes-mcp-server:latest transport: stdio # The current image's default CMD starts HTTP mode with `--port 8080`. # Override args so ToolHive's stdio proxy talks to a stdio MCP server. args: - --log-file - stderr proxyMode: streamable-http proxyPort: 8080 groupRef: name: homelab-core # Pin the MCP server pod to the ServiceAccount that carries its Kubernetes API # write permissions. serviceAccount: kubernetes-mcp permissionProfile: type: builtin name: network resources: requests: cpu: 100m memory: 128Mi limits: cpu: 500m memory: 512Mi