{"name":"io.github.ocm-mcp-server/ocm-mcp-server","slug":"ocm-mcp-server","title":null,"description":"Guardrailed fleet ops for AI agents: multi-cluster Kubernetes via OCM with policy, approval, audit.","url":"https://mcp.market/server/ocm-mcp-server","rating":null,"grade":"B","score":83,"certified":false,"status":"active","category":"devtools","tags":["devtools"],"presence":{"score":41,"stars":36,"forks":11,"downloads_week":32,"last_push_at":"2026-09-19T16:44:39.000Z","license":"Apache-2.0"},"uptime":null,"claimed":false,"transport":"mixed","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/ocm-mcp-server/ocm-mcp-server","website":"https://github.com/ocm-mcp-server/ocm-mcp-server/wiki","version":"0.6.0","remotes":[],"packages":[{"registryType":"pypi","identifier":"ocm-mcp-server","version":"0.6.0","runtimeHint":"uvx","transport":{"type":"stdio"},"environmentVariables":[{"description":"Path to the kubeconfig with the OCM hub context (and optional spoke contexts).","isRequired":true,"format":"string","name":"KUBECONFIG"},{"description":"Kubeconfig context name of the OCM hub cluster (defaults to the current context).","format":"string","name":"OCM_MCP_HUB_CONTEXT"},{"description":"Set to 'true' to disable the gated write path entirely (read-only fleet access).","format":"string","name":"OCM_MCP_READ_ONLY"}]},{"registryType":"oci","identifier":"ghcr.io/ocm-mcp-server/ocm-mcp-server:0.6.0","runtimeHint":"docker","transport":{"type":"stdio"},"environmentVariables":[{"description":"Path (inside the container) to the mounted kubeconfig with the OCM hub context.","isRequired":true,"format":"string","name":"KUBECONFIG"},{"description":"Kubeconfig context name of the OCM hub cluster (defaults to the current context).","format":"string","name":"OCM_MCP_HUB_CONTEXT"},{"description":"Set to 'true' to disable the gated write path entirely (read-only fleet access).","format":"string","name":"OCM_MCP_READ_ONLY"}]}],"tools":[{"name":"apply_cluster_action","description":"Apply a previously proposed cluster lifecycle action. Requires a human-minted token.","write_action":false,"price_micros":0,"input_schema":null},{"name":"apply_manifestwork","description":"Apply a previously proposed ManifestWork. Requires a human-minted approval token.","write_action":false,"price_micros":0,"input_schema":null},{"name":"compute","description":"","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_addon_health","description":"Per-cluster add-on health across the fleet (ManagedClusterAddOn Available / Degraded).","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_audit_trail","description":"Return the last N entries of this server's own tool-call audit log.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_cluster","description":"Full view of one ManagedCluster.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_cluster_health","description":"Health summary for one cluster: hub conditions, unhealthy pods, degraded deployments.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_cluster_info","description":"Extended inventory for one cluster from the hub: OpenShift version, nodes, console URL.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_fleet_health","description":"Health of the WHOLE fleet in one call: hub conditions for every cluster plus concurrent pod/deployment scans of each spoke that has a read context.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_hosted_cluster","description":"Detailed HostedCluster: version, conditions, and its NodePools.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_manifestwork","description":"Detailed ManifestWork status: top-level conditions and per-resource status feedback.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_placement_decision","description":"Which clusters a Placement actually selected (reads its PlacementDecisions).","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_pod_logs","description":"Tail logs from a pod on a managed cluster.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_resource","description":"Generic get of one allow-listed OCM resource, in full.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_addon_placement_scores","description":"List AddOnPlacementScores in a cluster's namespace (custom scores prioritizers consume).","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_addons_for_cluster","description":"Every add-on installed on one cluster, with health (ManagedClusterAddOn in its namespace).","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_cluster_claims","description":"Every cluster's ClusterClaims (id, platform, region, version) rolled up from status.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_cluster_management_addons","description":"List fleet-level add-on definitions (ClusterManagementAddOn) and their install strategy.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_cluster_set_bindings","description":"List ManagedClusterSetBindings (which ClusterSets a namespace's Placements may use).","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_cluster_sets","description":"List ManagedClusterSets with their selector type and member clusters.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_clusters","description":"List all managed clusters with availability, version, labels, and capacity.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_hosted_clusters","description":"List HyperShift HostedClusters, when the hub is the HCP hosting cluster.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_manifestworkreplicasets","description":"List ManifestWorkReplicaSets (a template fanned across a Placement) with rollout summary.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_manifestworks","description":"List ManifestWorks targeting a cluster (what the hub is managing there).","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_node_pools","description":"List HyperShift NodePools (worker groups), optionally filtered to one HostedCluster.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_pending_csrs","description":"List pending cluster-join / add-on registration CSRs awaiting hub approval.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_pending_proposals","description":"List proposals (ManifestWorks and cluster actions) waiting for human approval.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_placements","description":"List Placements and how many clusters each currently selects.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_policies","description":"List governance Policies and per-cluster compliance (only if the add-on is installed).","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_policy_violations","description":"Only the NonCompliant / Pending Policy-cluster pairs across the fleet - the open risks.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_resources","description":"Generic list over an allow-list of OCM API types (identity + conditions only).","write_action":false,"price_micros":0,"input_schema":null},{"name":"propose_cluster_action","description":"Propose an OCM cluster lifecycle action. Does NOT apply anything.","write_action":false,"price_micros":0,"input_schema":null},{"name":"propose_manifestwork","description":"Propose a change to one cluster as an OCM ManifestWork. Does NOT apply anything.","write_action":false,"price_micros":0,"input_schema":null},{"name":"propose_rollback","description":"Propose rolling back an applied ManifestWork. Applies nothing; needs its own approval.","write_action":false,"price_micros":0,"input_schema":null},{"name":"query_events","description":"Recent Kubernetes events from a managed cluster, newest first.","write_action":false,"price_micros":0,"input_schema":null},{"name":"rollback_manifestwork","description":"Delete a ManifestWork after a rollback proposal has been approved.","write_action":true,"price_micros":0,"input_schema":null}],"scan":{"score":83,"grade":"B","scanned_at":"2026-09-20T20:59:30.701Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-20T20:59:30.696Z","components":{"code":{"score":20,"max":25,"notes":["57 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":15,"max":15,"notes":["last push 1 days ago"]},"identity":{"score":7,"max":10,"notes":["registry namespace matches repository owner"]}},"findings":[{"id":"exec.shell-true","severity":"medium","component":"code","title":"subprocess with shell=True","evidence":"ocm_mcp_server-0.6.0/eval/run_eval.py: … return subprocess.run( cmd, shell=True, capture_output=True, text=True, timeou…"}],"inputs":{"packages":[{"registryType":"pypi","identifier":"ocm-mcp-server","version":"0.6.0","found":true,"weeklyDownloads":32,"license":"Apache-2.0","dependencyCount":15,"publishedAt":"2026-08-29T17:39:53.837239Z","repositoryUrl":"https://github.com/ocm-mcp-server/ocm-mcp-server"}],"repo":{"found":true,"owner":"ocm-mcp-server","repo":"ocm-mcp-server","archived":false,"pushedAt":"2026-09-19T16:44:39Z","stars":36,"forks":11,"openIssues":7,"ownerType":"Organization","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/322349691?v=4","ownerCreatedAt":"2026-08-29T04:06:21Z","license":"Apache-2.0"},"icon":{"url":null,"source":"none"},"presence":{"stars":36,"forks":11,"downloadsWeek":32,"license":"Apache-2.0","lastPushAt":"2026-09-19T16:44:39.000Z","score":41}}}},"grade_history":[],"reviews":[]}