Sign inSign up

talkopsai/argo-rollout-mcp-server

By talkopsai

•Updated 7 months ago

MCP Server for Argo Rollouts progressive delivery and rolling update strategies

Image
0

393

talkopsai/argo-rollout-mcp-server repository overview

⁠Argo Rollout MCP Server

A comprehensive Model Context Protocol (MCP) server for managing Kubernetes progressive delivery via Argo Rollouts. This image allows AI assistants (like Claude, Cline, or your own agent) to perform secure, production-grade Argo Rollout operations — from converting Deployments to Rollouts, orchestrating canary and blue-green deployments, to promoting, pausing, aborting, and monitoring rollout health.

⁠✨ Features

  • Zero YAML Onboarding: Auto-fetch live K8s Deployments, preserve resource limits and probes, and generate Rollout CRDs and Services directly into the cluster — no copy-pasting required.
  • Lifecycle Orchestration: Create Canary, Blue-Green, and Rolling Rollouts; update images to trigger rollouts; promote canaries step-by-step or to 100%; pause, resume, and abort safely.
  • Deployment Migration: Convert Deployments → Rollouts (direct or workloadRef for Argo CD–managed apps) and back to standard Deployments.
  • Observation & Context: Read real-time Rollout statuses, cluster-wide traffic strategies, and historical ReplicaSet hashes.
  • Validation & Safety: Instant emergency aborts, Prometheus-backed AnalysisTemplates, and intelligent promotion flows.
  • Multi-Cluster Support: Connect across namespaces and contexts using your mounted kubeconfig.
  • Built-in Guidance: Pre-loaded AI prompts for Canary, Blue-Green, Cost-Aware, and Multi-Cluster progressive delivery workflows.

⁠🚀 How to use this image

This Docker image is designed to be used as an MCP server. It requires access to your Kubernetes cluster via a kubeconfig file and the Argo Rollouts Controller installed on the target cluster.

⁠Running Standalone (HTTP Transport)

Run the container mapping port 8768 so clients can connect locally:

docker run --rm -it \
  -p 8768:8768 \
  -v ~/.kube:/app/.kube:ro \
  -e K8S_KUBECONFIG=/app/.kube/config \
  talkopsai/argo-rollout-mcp-server:latest

Tip: Mount the full ~/.kube directory (not just config) so certificate paths referenced in your kubeconfig (e.g. minikube, kind) are available inside the container.

Then configure your MCP client to connect over HTTP/SSE:

{
  "mcpServers": {
    "argo-rollout": {
      "url": "http://localhost:8768/mcp",
      "description": "MCP Server for managing Argo Rollouts and K8s Progressive Delivery"
    }
  }
}
⁠Important: Kubeconfig Access

Cluster access is entirely handled via the mounted kubeconfig. Ensure your kubeconfig has appropriate RBAC permissions for Argo Rollouts CRDs (Rollouts, AnalysisTemplates, Experiments, etc.). If the Argo Rollouts Controller is not installed, you can install it via the Helm MCP Server⁠.


⁠🛠️ Configuration (Claude Desktop - Stdio)

To use this image securely over stdio transport directly inside Claude Desktop, format the invocation like this:

macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json

{
  "mcpServers": {
    "argo-rollout-mcp-server": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "-v", "/Users/YOUR_USERNAME/.kube:/app/.kube:ro",
        "-e", "K8S_KUBECONFIG=/app/.kube/config",
        "-e", "K8S_CONTEXT=production-cluster",
        "-e", "MCP_TRANSPORT=stdio",
        "-e", "MCP_LOG_LEVEL=INFO",
        "talkopsai/argo-rollout-mcp-server:latest"
      ]
    }
  }
}

Replace /Users/YOUR_USERNAME/.kube with your actual kubeconfig path (e.g. C:\Users\YourUser\.kube on Windows).


⁠⚙️ Environment Variables

The image supports several environment variables for cluster access and advanced configuration:

VariableDefaultDescription
K8S_KUBECONFIG/app/.kube/configPath to kubeconfig file inside the container
K8S_CONTEXT(empty)Specific Kubernetes context to use (e.g. production-cluster)
K8S_IN_CLUSTERfalseSet to true if running inside a Kubernetes pod (in-cluster config)
PROMETHEUS_URLhttp://prometheus:9090Prometheus server URL for metrics resources (request rate, error rate, latency)
MCP_TRANSPORThttpTransport protocol (stdio or http)
MCP_HOST0.0.0.0Host interface to bind to (if HTTP transport)
MCP_PORT8768Port to bind to (if HTTP transport)
MCP_PATH/mcpMCP endpoint path
MCP_LOG_LEVELINFOLogging level (DEBUG, INFO, WARNING, ERROR)
MCP_LOG_FORMATjsonLog format (json or text)

⁠🔐 Security Best Practices

  1. RBAC Least Privilege: Ensure the kubeconfig identity has only the permissions needed for Argo Rollouts operations (Rollouts, AnalysisTemplates, Experiments, Services, etc.). Avoid cluster-admin if not necessary.
  2. Read-Only Mount: Always mount kubeconfig with :ro so the container cannot modify your credentials.
  3. Namespace Isolation: Use K8S_CONTEXT and namespace-scoped RBAC to limit the AI to specific clusters or namespaces.
  4. Review Before Apply: Use apply=False when generating Rollouts to preview manifests before applying to the cluster.

If you find this MCP server useful, consider leaving a ⭐ on the GitHub repository⁠!

Tag summary

Content type

Image

Digest

sha256:946a5d656…

Size

141.3 MB

Last updated

7 months ago

docker pull talkopsai/argo-rollout-mcp-server