Install
$ agentstack add mcp-reasy-k8s-ariadne-rs ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Ariadne
Ariadne is a Kubernetes graph MCP for coding agents. It ingests the cluster state into a property graph and exposes three deterministic tools:
graph_queryfor read-only Cyphergraph_schemafor schema discoverygraph_healthfor freshness and readiness
The Rust MCP server is the primary product surface. The Rust CLI and Python agent in this repo are local harnesses for debugging, evaluation, and experimentation.
> Short version: kubectl lists objects. Ariadne answers relationship questions.
TL;DR
- MCP-first: Ariadne is designed to plug into coding agents, not replace them.
- Topology over inventory: Ariadne is strongest on multi-hop Kubernetes questions such as
Host -> Ingress -> IngressServiceBackend -> Service -> EndpointSlice -> Endpoint -> EndpointAddress -> Pod. - Deterministic execution: the model generates Cypher; the graph executes modeled relationships.
- Compact defaults:
graph_schema()andgraph_health()default to compact, model-friendly responses to reduce token overhead. - Shared validation:
ariadne-coreowns Cypher validation and shared query-issue classification used by both the MCP server and local tooling.
Demo
https://github.com/user-attachments/assets/c73a521e-612d-4cad-9dc2-a22acd431baf
[mcp.mp4](docs/demo/mcp.mp4)
Why Ariadne
Most "LLM + Kubernetes" workflows make the model reason over raw JSON or YAML:
Kubernetes API -> giant object dump -> LLM context -> ad hoc joins in code
That works for direct inventory, but it breaks down on relationship-heavy questions:
- which pods back a host?
- which services have no endpoint slices?
- which pods claim PVCs whose PV has no storage class?
- which deployment owns these pods through replica sets?
Those are graph questions. Ariadne gives the agent explicit edges instead of forcing it to reconstruct joins with Python, shell, or jq.
When Ariadne Wins
Ariadne is strongest when the answer depends on multi-hop traversals across resource kinds:
Host -> Ingress -> IngressServiceBackend -> Service -> EndpointSlice -> Endpoint -> EndpointAddress -> PodService -> EndpointSlice -> Endpoint -> EndpointAddress -> PodDeployment -> ReplicaSet -> PodPod -> PersistentVolumeClaim -> PersistentVolume -> StorageClass- negative graph queries such as "resources with no backing edges"
These are literal graph paths. Ariadne derives helper nodes such as Host, IngressServiceBackend, Endpoint, EndpointAddress, and Container from raw Kubernetes objects during graph construction.
For these questions, Ariadne helps with:
- correctness: joins are encoded as graph edges, not improvised by the agent
- lower agent-side complexity: one declarative query replaces bespoke glue code
- scaling with hop depth: adding another relationship hop extends the traversal instead of rewriting the whole approach
When kubectl Is Fine
Ariadne is not meant to replace kubectl for every cluster question. Plain read-only kubectl is often enough for:
- listing pods, services, ingresses, or PVCs
- top namespaces by pod count
- straightforward spec/status checks
- direct inventory dumps with little or no joining
The goal is not to out-kubectl kubectl. The goal is to give agents a safer query substrate for relationship-heavy Kubernetes questions.
Core flow
User question
↓
Coding agent
↓
Query issue loop
(static validation + repairable execution feedback)
↓
GraphDB (Memgraph)
↓
Deterministic execution over the current graph state
Key idea:
- the model does not need raw cluster state in context
- it generates a query against a modeled graph
- Ariadne validates the query and returns structured results or structured repair feedback
Quick start
1) Start Memgraph
docker compose up -d
Memgraph listens on localhost:7687 and Memgraph Lab on localhost:3000.
2) Run the MCP server
CLUSTER= \
KUBE_CONTEXT= \
cargo run --release -p ariadne-mcp
By default this starts an HTTP MCP server on:
http://127.0.0.1:8080/mcp
The main tools are:
graph_query: execute read-only Cyphergraph_schema: compact schema by default; requestformat = "structured"for full machine-readable detailsgraph_health: compact freshness/status by default; requestdetail = "full"ordetail = "debug"for full diagnostics
3) Connect a coding agent
Point your coding agent at the MCP endpoint above. If you want reusable agent guidance, use [AGENTS.template.md](AGENTS.template.md) as a template in the consuming workspace, not as an active instruction file in this repo.
4) Optional local tooling
The repo also includes local harnesses:
ariadne-cli: local GUI/debug clientpython/agent: evaluation and experimentation layer for NL -> Cypher workflows
Example Python agent setup:
cd python/agent
uv venv
uv sync
MCP_URL=http://localhost:8080/mcp \
LLM_MODEL=openai/gpt-5.2 \
k8s-graph-agent --use-adk "What are the pods backing DNS name litmus.qa.agoda.is?"
Docs
- Architecture: [docs/architecture.md](docs/architecture.md)
- MCP tool contract: [docs/specs/mcptoolsv1.md](docs/specs/mcptoolsv1.md)
- Development & build: [docs/development.md](docs/development.md)
- Snapshots: [docs/snapshots.md](docs/snapshots.md)
- Python agent + eval harness: [python/agent/README.md](python/agent/README.md)
- CLI: [ariadne-cli/README.md](ariadne-cli/README.md)
Repo structure
ariadne-core/- kube clients, snapshot resolver, shared graph model/backends, validation, and query-issue classificationariadne-mcp/- MCP + HTTP server that wiresariadne-coreinto the primary product surfaceariadne-cli/- local GUI/debug harness with optional Memgraph or in-memory executionariadne-tools/- schema generation tooling used bygraph_schemaariadne-cypher/- Cypher parser, AST, and semantic validationpython/agent/- MCP client, agent experiments, eval harness, and structured-schema consumers
License
See [LICENSE](LICENSE).
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: REASY
- Source: REASY/k8s-ariadne-rs
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.