Sign inSign up

netscaler/netscaler-console-mcp-server

By netscaler

•Updated 6 months ago

A Model Context Protocol (MCP) server for Citrix NetScaler Console (ADM).

Image
1

538

netscaler/netscaler-console-mcp-server repository overview

⁠NetScaler Console MCP Server

A Model Context Protocol (MCP) server for Citrix NetScaler Console (ADM). It exposes monitoring, analytics, and management tools to MCP-capable AI clients.

⁠Table of Contents

⁠Capabilities

  • Instance discovery, health, and capacity scoring
  • Performance and usage metrics (CPU, memory, throughput)
  • CVE advisory and vulnerability details

⁠Available Tools

  • get_netscaler_instances - List instances with filtering
  • get_netscaler_features - Get enabled features for an instance
  • get_netscaler_instances_score - Health scores and capacity metrics
  • get_netscaler_instances_usage_stats - CPU, memory, and throughput usage
  • get_netscaler_network_interface - Network interface status
  • get_netscaler_cve_details - Instances with detected CVEs
  • get_netscaler_cve_advisory_details - CVE advisory information
  • get_cve_info - Details for a specific CVE ID
  • get_netscaler_ssl_certificates - Details of installed certificates
  • get_netscaler_ssl_vserver - Details for SSL vServers

⁠Prerequisites

  • Container Engine: Docker or Kubernetes cluster (v1.19+).
  • NetScaler Console: Account with API access.
  • Connectivity: Network access to the NetScaler Console FQDN.
  • Certificates (Optional): TLS .crt and .key files if using HTTPS.
  • Identity Provider (If using OAuth 2.1): An OIDC-compliant provider is required. The MCP server acts as an OAuth 2.1 Resource Server. Below is a reference configuration for IDP (example Keycloak) :
    • Realm: Create a Realm. (example: NetScaler_Realm, Access Token Lifetime: configurable; Session Max: <24h>).
    • Client: Create a Public client for MCP clients (VS Code, Claude Desktop, etc.). (example: client named mcp-client).
    • Flows: Enable "Standard Flow" (Authorization Code with PKCE).
    • PKCE: Required - Code Challenge Method: S256.
    • Update valid Redirect URIs:
    • Web Origins: Set to * to allow CORS.
    • User: Ensure users are created, enabled, and have verified email with scopes: openid, profile, email.
    • Note: The MCP server requires two mandatory environment variables for OAuth:
      • MCP_NS_OAUTH_ISSUER: Full issuer URL
      • MCP_NS_JWKS_URI: JWKS endpoint for public keys
      • MCP_NS_OAUTH_AUTH_ENDPOINT: Issuer authentication endpoint (optional)
      • MCP_NS_OAUTH_TOKEN_ENDPOINT: Issuer token endpoint (optional)

⁠Authentication

⁠NetScaler Console Authentication

The server supports three ways to authenticate requests.

  1. Passing CLIENT_ID, CLIENT_SECRET and CC_ID Environment Variables to container while deployment
  2. Passing CLIENT_ID, CLIENT_SECRET and CC_ID as part of headers for client request.
  3. Passing Bearer Token as part of headers for client request.
⁠Identity Provider Authentication
  • OAuth 2.1 for JWT validation

⁠Quick Start (Docker)

HTTPS + OAuth 2.1 example:

docker run -d \
  --name netscaler-mcp-server \
  -p 10000:10000 \
  -v <PATH_TO_KEY>:/app/certs/server.key \
  -v <PATH_TO_CRT>:/app/certs/server.crt \
  -e MCP_SERVER_PROTOCOL=https \
  -e GLOBAL_FQDN="<NS_CONSOLE_FQDN>" \
  -e CC_TRUST_AUTH_URL="<CC_TRUST_URL>" \
  -e MCP_NS_OAUTH_ISSUER="<IDP_ISSUER_URL>" \
  -e MCP_NS_JWKS_URI="<IDP_JWKS_URL>" \
  -e MCP_SERVER_EXTERNAL_HOST="<HOST_IP>" \
  -e MCP_SERVER_EXTERNAL_PORT="<HOST_PORT>" \
  <IMAGE_NAME>:<TAG>

⁠Kubernetes Deployment

⁠Prerequisite Secrets

Run these commands to create the necessary secrets before applying the deployment manifests.

# For Static/Env Auth
kubectl create secret generic netscaler-secret \
  --from-literal=CLIENT_ID='<YOUR_ID>' \
  --from-literal=CLIENT_SECRET='<YOUR_SECRET>'

# For HTTPS
kubectl create secret tls mcp-tls-certs \
  --cert=<PATH_TO_CRT> \
  --key=<PATH_TO_KEY>
⁠HTTPS + OAuth 2.1

Secure HTTPS deployment integrated with an Identity Provider (OAuth 2.1 Resource Server).

apiVersion: apps/v1
kind: Deployment
metadata:
  name: auth-netscaler-mcp-server
spec:
  replicas: 1
  selector:
    matchLabels:
      app: auth-netscaler-mcp-server
  template:
    metadata:
      labels:
        app: auth-netscaler-mcp-server
    spec:
      containers:
        - name: auth-netscaler-mcp-server
          image: <IMAGE_NAME>:<TAG>
          ports:
            - containerPort: 10000
          volumeMounts:
            - name: tls-certs
              mountPath: /app/certs
              readOnly: true
          env:
            - name: MCP_SERVER_PROTOCOL
              value: "https"
            - name: GLOBAL_FQDN
              value: "<NS_CONSOLE_FQDN>"
            - name: CC_TRUST_AUTH_URL
              value: "<CC_TRUST_URL>"
            - name: MCP_NS_OAUTH_ISSUER
              value: "<IDP_ISSUER_URL>"
            - name: MCP_NS_JWKS_URI
              value: "<IDP_JWKS_URL>"
            - name: MCP_SERVER_EXTERNAL_HOST
              value: "<NODE_IP>"
            - name: MCP_SERVER_EXTERNAL_PORT
              value: "<NODE_PORT>"
      volumes:
        - name: tls-certs
          secret:
            secretName: mcp-tls-certs
            defaultMode: 0444
---
apiVersion: v1
kind: Service
metadata:
  name: auth-netscaler-mcp-server
spec:
  type: NodePort
  selector:
    app: auth-netscaler-mcp-server
  ports:
    - protocol: TCP
      port: 10000
      targetPort: 10000
      nodePort: <NODE_PORT>

⁠Configuration

Environment variables:

VariableDescriptionDefault
GLOBAL_FQDNNetScaler Console FQDNadm.cloud.com
CC_TRUST_AUTH_URLCitrix Cloud Trust Authentication URLhttps://api.cloud.com/cctrustoauth2/
CC_IDCitrix Cloud ID-
CLIENT_IDNetScaler Console Client ID (Static Auth)-
CLIENT_SECRETNetScaler Console Client Secret (Static Auth)-
MCP_NS_OAUTH_ISSUEROAuth Issuer URL (enables OAuth when set with MCP_NS_JWKS_URI)-
MCP_NS_JWKS_URIJWKS endpoint URL for JWT token verification-
MCP_NS_OAUTH_AUTH_ENDPOINTIssuer authentication endpoint-
MCP_NS_OAUTH_TOKEN_ENDPOINTIssuer token endpoint-
MCP_SERVER_EXTERNAL_HOSTHost IP/Name for external access-
MCP_SERVER_EXTERNAL_PORTHost Port for external access-
MCP_SERVER_HOSTHost IP/Name for Redirect URIslocalhost
MCP_SERVER_PORTHost Port for Redirect URIs10000

⁠Notes

  • Default server port: 10000

  • Transport: SSE

  • Example headers for dynamic/header auth:

-H "CLIENT_ID: <client id>"
-H "CLIENT_SECRET: <client secret>"
-H "Citrix-CustomerId: <CC_ID>"

⁠License

Copyright (c) 2026. Cloud Software Group, Inc. All Rights Reserved. Confidential & Proprietary.

Tag summary

Content type

Image

Digest

sha256:7ac702efe…

Size

48 MB

Last updated

6 months ago

docker pull netscaler/netscaler-console-mcp-server:1.0.3