1. Conduid
  2. Developer Tools
  3. Istio MCP Server
MCP server · Developer Tools

Istio MCP Server

Model Context Protocol (MCP) server for Istio service mesh - provides AI assistants with read-only access to Istio resources, Virtual Services, Destination Rules, Gateways, and Envoy proxy configurations in Kubernetes clusters

59Fair

Scored 3 months ago · breakdown

About Istio MCP Server

Istio MCP Server is an MCP server published by krutsko in the Developer Tools category: model Context Protocol (MCP) server for Istio service mesh - provides AI assistants with read-only access to Istio resources, Virtual Services, Destination Rules, Gateways, and Envoy proxy configurations in Kubernetes clusters. It has been installed 0 times through Conduid.

The repository has 1 stars and 0 forks, with the last commit 12 months ago. Six months or more without a commit doesn't mean the server is broken, but check the open issues (0) before depending on it in production.

Install

Install
npx istio-mcp-server

This server has no ConduID identity, so agent calls to it are not receipted. Pin the version you install and review the source before granting it credentials.

Ask AI

Ask AI about Istio MCP Server

Powered by Claude · Grounded in docs

I know everything about Istio MCP Server. Ask me about installation, configuration, usage, or troubleshooting.

Security checks

  • ·README presentNot checked yet.
  • ·License declaredNot checked yet.
  • ·Tests presentNot checked yet.
  • ·Dependencies pinnedNot checked yet.
  • ·No dynamic code executionNot checked yet.
  • !Scoped permissionsDoesn't declare a permission scope. Assume it can do anything its process can.

README

Istio MCP Server

A Model Context Protocol (MCP) server that provides AI assistants and developers with read-only access to Istio service mesh resources in Kubernetes clusters. This server enables intelligent querying of Istio configurations, Virtual Services, Destination Rules, service mesh hosts, and Envoy proxy configurations through a safe, non-destructive interface.

🚀 Overview

The Istio MCP Server bridges the gap between AI assistants and Istio service mesh operations by implementing the Model Context Protocol. It provides comprehensive tools for querying Istio resources including Virtual Services, Destination Rules, service mesh hosts, and proxy configurations without any risk of modifying or deleting resources.

Key Benefits:

  • 🔒 100% Read-Only Operations - No destructive commands allowed
  • 🤖 AI Assistant Friendly - Designed for MCP protocol integration
  • 🔍 Comprehensive Istio Access - Covers all major Istio resource types
  • 🛡️ Safe by Design - Zero risk of accidental resource modifications
  • 🌐 Multi-Protocol Support - STDIO, SSE, and HTTP protocols
  • 📊 Rich Observability - Access to Envoy proxy configurations and telemetry

✨ Features

🔧 Core Istio Resources (Read-Only)

  • Virtual Services: Query specific Istio Virtual Services and routing rules by name
  • Destination Rules: Query specific Istio Destination Rules and traffic policies by name
  • Service Mesh Hosts: Comprehensive overview of all hosts in the service mesh

📊 Observability & Telemetry (Read-Only)

  • Proxy Status: Get Envoy proxy health and status information
  • Configuration Summaries: Comprehensive Istio configuration overviews
  • External Dependency Checks: Verify external service accessibility

🌐 Envoy Proxy Access (Read-Only)

  • Cluster Configuration: Access Envoy cluster configurations
  • Listener Configuration: Access Envoy listener configurations
  • Route Configuration: Access Envoy route configurations
  • Endpoint Configuration: Access Envoy endpoint configurations
  • Bootstrap Configuration: Access Envoy bootstrap configurations
  • Full Configuration Dumps: Complete Envoy configuration snapshots

🚀 Getting Started

Prerequisites

  • Go 1.24+ for building from source
  • Kubernetes cluster with Istio installed
  • kubectl configured with appropriate permissions
  • istioctl installed (for advanced proxy configuration features)

Installation

# Install via npm (recommended)
npm install -g istio-mcp-server

# Or build from source
git clone https://github.com/krutsko/istio-mcp-server.git
cd istio-mcp-server
make build

Claude Desktop

Using npx

If you have npm installed, this is the fastest way to get started with istio-mcp-server on Claude Desktop.

Open your claude_desktop_config.json and add the mcp server to the list of mcpServers:

{
  "mcpServers": {
    "istio": {
      "command": "npx",
      "args": [
        "-y",
        "istio-mcp-server@latest"
      ]
    }
  }
}

VS Code / VS Code Insiders

Install the Istio MCP server extension in VS Code Insiders manually by running the following command:

# For VS Code
code --add-mcp '{"name":"istio","command":"npx","args":["istio-mcp-server@latest"]}'
# For VS Code Insiders
code-insiders --add-mcp '{"name":"istio","command":"npx","args":["istio-mcp-server@latest"]}'

Cursor

Install the Istio MCP server extension in Cursor by pressing the following link:

Install MCP Server

Alternatively, you can install the extension manually by editing the mcp.json file:

{
  "mcpServers": {
    "istio-mcp-server": {
      "command": "npx",
      "args": ["-y", "istio-mcp-server@latest"]
    }
  }
}

Goose CLI

Goose CLI is the easiest (and cheapest) way to get rolling with artificial intelligence (AI) agents.

Using npm

If you have npm installed, this is the fastest way to get started with istio-mcp-server.

Open your goose config.yaml and add the mcp server to the list of mcpServers:

extensions:
  istio:
    command: npx
    args:
      - -y
      - istio-mcp-server@latest

Basic Usage

# Run in STDIO mode (for MCP clients)
./bin/istio-mcp-server --kubeconfig ~/.kube/config

# Run SSE server on port 8080
./bin/istio-mcp-server --sse-port 8080

# Run HTTP server on port 8080
./bin/istio-mcp-server --http-port 8080

# Show all available options
./bin/istio-mcp-server --help

🛠️ Available Tools

🌐 Networking Resources

  • get-virtual-service - Get a specific Virtual Service configuration by name
  • get-destination-rule - Get a specific Destination Rule configuration by name
  • get-service-mesh-hosts - List all services and hosts in the service mesh for a namespace

🔍 Service Discovery & Analysis

  • discover-istio-namespaces - Discover namespaces with Istio sidecars ranked by injection density
  • check-external-dependency-availability - Check if an external dependency is properly configured
  • get-pods-by-service - Find all pods backing a specific Kubernetes service

🔍 Proxy Configuration

  • get-proxy-clusters - Get Envoy cluster configuration from a pod
  • get-proxy-listeners - Get Envoy listener configuration from a pod
  • get-proxy-routes - Get Envoy route configuration from a pod
  • get-proxy-endpoints - Get Envoy endpoint configuration from a pod
  • get-proxy-bootstrap - Get Envoy bootstrap configuration from a pod
  • get-proxy-config-dump - Get full Envoy configuration dump from a pod
  • get-proxy-status - Get proxy status information

⚙️ Configuration

The server supports various configuration options:

Option Description Default
--kubeconfig Path to kubeconfig file ~/.kube/config
--sse-port Start SSE server on specified port Disabled
--http-port Start HTTP server on specified port Disabled
--log-level Set logging level (0-9) 0
--profile MCP profile to use "full"

🔒 Security Note: This server operates in read-only mode by design. All operations are safe and non-destructive.

🏗️ Architecture

The Istio MCP Server follows clean architecture principles with clear separation of concerns:

istio-mcp-server/
├── cmd/                    # Application entrypoints and CLI commands
├── pkg/
│   ├── istio-mcp-server/  # Core application logic and CLI handling
│   ├── istio/             # Istio client and resource management
│   ├── mcp/               # MCP server implementation and tool definitions
│   ├── version/           # Version information and build metadata
│   └── output/            # Output formatting and display utilities
└── npm/                   # NPM package distribution

🧪 Development

# Install development dependencies
make deps

# Format code
make fmt

# Run linter
make lint

# Run tests
make test

# Clean build artifacts
make clean

# Build for all platforms
make build-all-platforms

# Test release process
make test-release

🔗 Related Projects

📄 License

This project is licensed under the MIT License - see the LICENSE file for details.

🤝 Contributing

Contributions are welcome! Please feel free to submit a Pull Request. For major changes, please open an issue first to discuss what you would like to change.

README mirrored from the source repository 3 months ago. The original is authoritative.

Questions

About Istio MCP Server

How do I install Istio MCP Server?

Run npx istio-mcp-server, then add the server to your MCP client's configuration. Conduid has recorded 0 installs, so the command is known to work with current clients.

Is Istio MCP Server safe to use with an AI agent?

Its trust score is 59 out of 100 (fair). It passes 0 of 1 static security checks; the failures are listed above. It has no ConduID identity yet, so agent calls to it are not receipted.

Is Istio MCP Server still maintained?

The last commit was 12 months ago, with 0 open issues. That's long enough that you should check whether the maintainer is responding to issues before depending on it.