Monitoring · Security

Kube Audit MCP logo

Kube Audit MCP

mozillazg/kube-audit-mcp

kube-audit-mcp is a Model Context Protocol (MCP) server that gives AI agents, assistants, and chatbots the ability to query Kubernetes Audit Logs.

Install

docker run -i --rm -v /etc/kube-audit-mcp/config.yaml:/etc/kube-audit-mcp/config.yaml:ro quay.io/mozillazg/kube-audit-mcp:latest mcp --config /etc/kube-audit-mcp/config.yaml

Client configuration

{
  "mcpServers": {
    "kube-audit": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "-v",
        "/etc/kube-audit-mcp/config.yaml:/etc/kube-audit-mcp/config.yaml:ro",
        "quay.io/mozillazg/kube-audit-mcp:latest",
        "mcp",
        "--config",
        "/etc/kube-audit-mcp/config.yaml"
      ],
      "env": {
        "ALIBABA_CLOUD_ACCESS_KEY_ID": "<ALIBABA_CLOUD_ACCESS_KEY_ID>",
        "ALIBABA_CLOUD_ACCESS_KEY_SECRET": "<ALIBABA_CLOUD_ACCESS_KEY_SECRET>",
        "AWS_ACCESS_KEY_ID": "<AWS_ACCESS_KEY_ID>",
        "AWS_SECRET_ACCESS_KEY": "<AWS_SECRET_ACCESS_KEY>",
        "GOOGLE_APPLICATION_CREDENTIALS": "<GOOGLE_APPLICATION_CREDENTIALS>"
      }
    }
  }
}

Environment variables

ALIBABA_CLOUD_ACCESS_KEY_IDALIBABA_CLOUD_ACCESS_KEY_SECRETAWS_ACCESS_KEY_IDAWS_SECRET_ACCESS_KEYGOOGLE_APPLICATION_CREDENTIALS
Category
Monitoring, Security
Updated
Oct 6, 2026

Tools (3)

  • query_audit_log

    Queries the Kubernetes audit logs from the configured provider.

  • list_clusters

    Lists all clusters that are configured in the config.yaml file.

  • list_common_resource_types

    Returns a list of common Kubernetes resource types, grouped by category (e.g., "Core Resources", "Apps Resources").

Details on this page are taken from the project's README. Open README

Supported clients

Clients mentioned in this server's README:

View all
Claude Desktop logo

Claude Desktop

Desktop · Freemium · Proprietary

Anthropic's official Claude AI desktop application. Supports MCP servers to extend functionality.

WindowsMacOS
VS Code GitHub Copilot logo

VS Code GitHub Copilot

Desktop · Freemium · MIT

VS Code integrates MCP with GitHub Copilot through agent mode, allowing direct interaction with MCP-provided tools in your agentic coding workflow. Configure servers in Claude Desktop, workspace, or user settings, with guided MCP installation and secure handling of secrets in input variables to avoid leaking hardcoded keys.

WindowsMacOSLinuxWeb

Related MCP servers

More servers
2344 logo

2344

comet-ml/opik

7k

Opik is the open-source LLM observability and evaluation platform for AI agent tracing, LLM evaluation, prompt management, and production monitoring. Built by Comet. Apache-2.0 licensed, free to self-host the full platform, with 20,000+ GitHub stars.

Monitoring
MCP Grafana logo

MCP Grafana

grafana/mcp-grafana

612

A Model Context Protocol (MCP) server for Grafana.

Monitoring
Vite Plugin Vue MCP logo

Vite Plugin Vue MCP

webfansplz/vite-plugin-vue-mcp

407

Vite plugin that enables a MCP server for your Vue app to provide information about the component tree, state, routes, and pinia tree and state.

Monitoring
api200 logo

api200

API-200/api200

169

API 200 is all-in-one gateway for managing third-party APIs efficiently. Integrate third-party APIs or setup MCP server in minutes with auto-generated code, docs, auth, caching and error handling – so you can focus on what really matters.

Monitoring
WireMCP (Wireshark) logo

WireMCP (Wireshark)

0xkoda/wiremcp

98

WireMCP is a Model Context Protocol (MCP) server designed to empower Large Language Models (LLMs) with real-time network traffic analysis capabilities.

Monitoring
gospy logo

gospy

monsterxx03/gospy

90

A tool for inspecting and analyzing running Go processes, including goroutine states, memory statistics, and binary information.

Monitoring