Skip to content

docs(specs): add Kubernetes MCP design - #187

Open
nickvigilante wants to merge 1 commit into
mainfrom
docs/kubernetes-mcp-spec
Open

docs(specs): add Kubernetes MCP design#187
nickvigilante wants to merge 1 commit into
mainfrom
docs/kubernetes-mcp-spec

Conversation

@nickvigilante

Copy link
Copy Markdown
Owner

Summary

  • Add the design spec for the Kubernetes MCP sub-project:
    read-only-by-default, gated-write access for Claude to the gandalf k3s cluster
    via self-hosted containers/kubernetes-mcp-server over Tailscale, with a
    least-privilege claude-mcp identity and Flux-managed RBAC.
  • Docs only — no cluster or host changes. Review and implementation are deferred
    to Claude MCP access — Kubernetes: review spec, then implement #186 (drafted off the usual homelab machine).

Before merge

  • No secrets in the diff — tokens referenced by Bitwarden item/field only.
  • New persistent dirs — none (docs only).
  • Host-level changes — none (docs only).
  • SPOF impact — none (read-only external client; no new in-cluster service).
  • DNS — no new hostname (uses gandalf's existing tailnet API endpoint).
  • README walkthrough — n/a; design spec. Setup steps land with implementation (Claude MCP access — Kubernetes: review spec, then implement #186).

Test plan


🤖 Built with AI assistance.

Read-only-by-default, gated-write access for Claude to the gandalf k3s cluster
via self-hosted containers/kubernetes-mcp-server over Tailscale, authenticating
as a least-privilege claude-mcp identity with Flux-managed RBAC. Drafted off the
usual homelab machine, so review/implementation is deferred to #186.

Assisted-by: AI
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant