A Model Context Protocol (MCP) server for Citrix NetScaler Console (ADM).
538
A Model Context Protocol (MCP) server for Citrix NetScaler Console (ADM). It exposes monitoring, analytics, and management tools to MCP-capable AI clients.
get_netscaler_instances - List instances with filteringget_netscaler_features - Get enabled features for an instanceget_netscaler_instances_score - Health scores and capacity metricsget_netscaler_instances_usage_stats - CPU, memory, and throughput usageget_netscaler_network_interface - Network interface statusget_netscaler_cve_details - Instances with detected CVEsget_netscaler_cve_advisory_details - CVE advisory informationget_cve_info - Details for a specific CVE IDget_netscaler_ssl_certificates - Details of installed certificatesget_netscaler_ssl_vserver - Details for SSL vServers.crt and .key files if using HTTPS.NetScaler_Realm, Access Token Lifetime: configurable; Session Max: <24h>).mcp-client).* to allow CORS.MCP_NS_OAUTH_ISSUER: Full issuer URLMCP_NS_JWKS_URI: JWKS endpoint for public keysMCP_NS_OAUTH_AUTH_ENDPOINT: Issuer authentication endpoint (optional)MCP_NS_OAUTH_TOKEN_ENDPOINT: Issuer token endpoint (optional)The server supports three ways to authenticate requests.
CLIENT_ID, CLIENT_SECRET and CC_ID Environment Variables to container while deploymentCLIENT_ID, CLIENT_SECRET and CC_ID as part of headers for client request.HTTPS + OAuth 2.1 example:
docker run -d \
--name netscaler-mcp-server \
-p 10000:10000 \
-v <PATH_TO_KEY>:/app/certs/server.key \
-v <PATH_TO_CRT>:/app/certs/server.crt \
-e MCP_SERVER_PROTOCOL=https \
-e GLOBAL_FQDN="<NS_CONSOLE_FQDN>" \
-e CC_TRUST_AUTH_URL="<CC_TRUST_URL>" \
-e MCP_NS_OAUTH_ISSUER="<IDP_ISSUER_URL>" \
-e MCP_NS_JWKS_URI="<IDP_JWKS_URL>" \
-e MCP_SERVER_EXTERNAL_HOST="<HOST_IP>" \
-e MCP_SERVER_EXTERNAL_PORT="<HOST_PORT>" \
<IMAGE_NAME>:<TAG>
Run these commands to create the necessary secrets before applying the deployment manifests.
# For Static/Env Auth
kubectl create secret generic netscaler-secret \
--from-literal=CLIENT_ID='<YOUR_ID>' \
--from-literal=CLIENT_SECRET='<YOUR_SECRET>'
# For HTTPS
kubectl create secret tls mcp-tls-certs \
--cert=<PATH_TO_CRT> \
--key=<PATH_TO_KEY>
Secure HTTPS deployment integrated with an Identity Provider (OAuth 2.1 Resource Server).
apiVersion: apps/v1
kind: Deployment
metadata:
name: auth-netscaler-mcp-server
spec:
replicas: 1
selector:
matchLabels:
app: auth-netscaler-mcp-server
template:
metadata:
labels:
app: auth-netscaler-mcp-server
spec:
containers:
- name: auth-netscaler-mcp-server
image: <IMAGE_NAME>:<TAG>
ports:
- containerPort: 10000
volumeMounts:
- name: tls-certs
mountPath: /app/certs
readOnly: true
env:
- name: MCP_SERVER_PROTOCOL
value: "https"
- name: GLOBAL_FQDN
value: "<NS_CONSOLE_FQDN>"
- name: CC_TRUST_AUTH_URL
value: "<CC_TRUST_URL>"
- name: MCP_NS_OAUTH_ISSUER
value: "<IDP_ISSUER_URL>"
- name: MCP_NS_JWKS_URI
value: "<IDP_JWKS_URL>"
- name: MCP_SERVER_EXTERNAL_HOST
value: "<NODE_IP>"
- name: MCP_SERVER_EXTERNAL_PORT
value: "<NODE_PORT>"
volumes:
- name: tls-certs
secret:
secretName: mcp-tls-certs
defaultMode: 0444
---
apiVersion: v1
kind: Service
metadata:
name: auth-netscaler-mcp-server
spec:
type: NodePort
selector:
app: auth-netscaler-mcp-server
ports:
- protocol: TCP
port: 10000
targetPort: 10000
nodePort: <NODE_PORT>
Environment variables:
| Variable | Description | Default |
|---|---|---|
GLOBAL_FQDN | NetScaler Console FQDN | adm.cloud.com |
CC_TRUST_AUTH_URL | Citrix Cloud Trust Authentication URL | https://api.cloud.com/cctrustoauth2/ |
CC_ID | Citrix Cloud ID | - |
CLIENT_ID | NetScaler Console Client ID (Static Auth) | - |
CLIENT_SECRET | NetScaler Console Client Secret (Static Auth) | - |
MCP_NS_OAUTH_ISSUER | OAuth Issuer URL (enables OAuth when set with MCP_NS_JWKS_URI) | - |
MCP_NS_JWKS_URI | JWKS endpoint URL for JWT token verification | - |
MCP_NS_OAUTH_AUTH_ENDPOINT | Issuer authentication endpoint | - |
MCP_NS_OAUTH_TOKEN_ENDPOINT | Issuer token endpoint | - |
MCP_SERVER_EXTERNAL_HOST | Host IP/Name for external access | - |
MCP_SERVER_EXTERNAL_PORT | Host Port for external access | - |
MCP_SERVER_HOST | Host IP/Name for Redirect URIs | localhost |
MCP_SERVER_PORT | Host Port for Redirect URIs | 10000 |
Default server port: 10000
Transport: SSE
Example headers for dynamic/header auth:
-H "CLIENT_ID: <client id>"
-H "CLIENT_SECRET: <client secret>"
-H "Citrix-CustomerId: <CC_ID>"
Copyright (c) 2026. Cloud Software Group, Inc. All Rights Reserved. Confidential & Proprietary.
Content type
Image
Digest
sha256:7ac702efe…
Size
48 MB
Last updated
6 months ago
docker pull netscaler/netscaler-console-mcp-server:1.0.3