Ocm MCP server
Guardrailed fleet ops for AI agents: multi-cluster Kubernetes via OCM with policy, approval, audit.
36 stars32 downloads/wk
Reviews
Write oneNobody has reviewed Ocm yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Ocm tools (36, 1 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
apply_cluster_actionApply a previously proposed cluster lifecycle action. Requires a human-minted token.
apply_manifestworkApply a previously proposed ManifestWork. Requires a human-minted approval token.
computeget_addon_healthPer-cluster add-on health across the fleet (ManagedClusterAddOn Available / Degraded).
get_audit_trailReturn the last N entries of this server's own tool-call audit log.
get_clusterFull view of one ManagedCluster.
get_cluster_healthHealth summary for one cluster: hub conditions, unhealthy pods, degraded deployments.
get_cluster_infoExtended inventory for one cluster from the hub: OpenShift version, nodes, console URL.
get_fleet_healthHealth of the WHOLE fleet in one call: hub conditions for every cluster plus concurrent pod/deployment scans of each spoke that has a read context.
get_hosted_clusterDetailed HostedCluster: version, conditions, and its NodePools.
get_manifestworkDetailed ManifestWork status: top-level conditions and per-resource status feedback.
get_placement_decisionWhich clusters a Placement actually selected (reads its PlacementDecisions).
get_pod_logsTail logs from a pod on a managed cluster.
get_resourceGeneric get of one allow-listed OCM resource, in full.
list_addon_placement_scoresList AddOnPlacementScores in a cluster's namespace (custom scores prioritizers consume).
list_addons_for_clusterEvery add-on installed on one cluster, with health (ManagedClusterAddOn in its namespace).
list_cluster_claimsEvery cluster's ClusterClaims (id, platform, region, version) rolled up from status.
list_cluster_management_addonsList fleet-level add-on definitions (ClusterManagementAddOn) and their install strategy.
list_cluster_set_bindingsList ManagedClusterSetBindings (which ClusterSets a namespace's Placements may use).
list_cluster_setsList ManagedClusterSets with their selector type and member clusters.
list_clustersList all managed clusters with availability, version, labels, and capacity.
list_hosted_clustersList HyperShift HostedClusters, when the hub is the HCP hosting cluster.
list_manifestworkreplicasetsList ManifestWorkReplicaSets (a template fanned across a Placement) with rollout summary.
list_manifestworksList ManifestWorks targeting a cluster (what the hub is managing there).
list_node_poolsList HyperShift NodePools (worker groups), optionally filtered to one HostedCluster.
list_pending_csrsList pending cluster-join / add-on registration CSRs awaiting hub approval.
list_pending_proposalsList proposals (ManifestWorks and cluster actions) waiting for human approval.
list_placementsList Placements and how many clusters each currently selects.
list_policiesList governance Policies and per-cluster compliance (only if the add-on is installed).
list_policy_violationsOnly the NonCompliant / Pending Policy-cluster pairs across the fleet - the open risks.
list_resourcesGeneric list over an allow-list of OCM API types (identity + conditions only).
propose_cluster_actionPropose an OCM cluster lifecycle action. Does NOT apply anything.
propose_manifestworkPropose a change to one cluster as an OCM ManifestWork. Does NOT apply anything.
propose_rollbackPropose rolling back an applied ManifestWork. Applies nothing; needs its own approval.
query_eventsRecent Kubernetes events from a managed cluster, newest first.
rollback_manifestworkwrite actionDelete a ManifestWork after a rollback proposal has been approved.
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
- Code scan57 source files scanned20/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 1 days ago15/15
- Maintainer identityregistry namespace matches repository owner7/10
Findings (1)
- mediumsubprocess with shell=True
exec.shell-trueocm_mcp_server-0.6.0/eval/run_eval.py: … return subprocess.run( cmd, shell=True, capture_output=True, text=True, timeou…
What the publisher says
From the Ocm repository's README, as published. We do not edit it. Read it on GitHub
<!-- mcp-name: io.github.ocm-mcp-server/ocm-mcp-server -->
🛡️ ocm-mcp-server
📖 Read the docs site → ocm-mcp-server.github.io
Star us ❤️ →
AgentOps for Kubernetes fleets, done safely.
An MCP server that lets AI agents operate a multi-cluster Kubernetes fleet through an Open Cluster Management hub, with policy, approval, and audit between the model and your clusters.
The agent never holds a kubeconfig. Every write is policy-checked, human-approved, and traced.
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Install directly
claude mcp add ocm-mcp-server -- uvx ocm-mcp-server
Ocm: common questions
- Is Ocm MCP server safe?
- Mostly: it is graded B (83/100). Read the Ocm safety report
- How do I install Ocm?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Ocm need an API key?
- No secret keys are declared. It reads 6 settings from the environment.
- Is Ocm maintained?
- The last commit was in the last day (2026-09-19). The latest release is v0.6.0.
- What can I use instead of Ocm?
- Servers from other publishers that do the same job: k8s AIops MCP server, KSail MCP server and Kubeview MCP server. Compare all Ocm alternatives.
Alternatives to Ocm
Same job from other publishers: the closest match first, then the best rated.
- k8s AIopsGoverned Kubernetes ops — 55 MCP tools with audit, budget, undo, risk-tier audit labels.not reviewedGrowingA
- KSailSDK for creating, managing, and operating Kubernetes clusters and workloads with ease.not reviewedGrowingA
- KubeviewRead-only Model Context Protocol MCP server enabling code-driven AI analysis of Kubernetes clusters.not reviewedGrowingB
- VMware AVIVMware AVI (NSX ALB) load balancer plus AKO Kubernetes ops — 28 MCP tools.not reviewedGrowingA
- KubernetesKubernetes monitoring & ops for AI agents — safe-by-default access modes and guards.not reviewedGrowingA