[ 
https://issues.apache.org/jira/browse/FLINK-40287?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

vaquar khan updated FLINK-40287:
--------------------------------
    Description: 
As a platform operator, I want a first-party MCP server that exposes Flink's 
control and observability plane (jobs, SQL Gateway, savepoints, metrics, 
exceptions, JARs) to agents through a secure-by-default governance layer, so 
that agents can operate and observe Flink safely without me trusting an 
ungoverned third-party process against production JobManagers.

{*}Description{*}: The server runs as a standalone process outside the 
JobManager and TaskManagers, consistent with the FLIP-577 engine non-goal. It 
wraps the existing JobManager REST API and SQL Gateway, and applies a 
fail-closed governance pipeline  to every tool call. It complements FLIP-531 
and FLIP-548, which make Flink an MCP client; this makes Flink an MCP server. 
Full design in FLIP-XXXX (My Confluence access not enabled once get access will 
add details here) .

*Acceptance criteria (Given / When / Then):*

Given the server is running, when a client sends initialize, tools/list, and 
resources/list over stdio or authenticated HTTP, then it completes the MCP 
handshake and advertises the read-only tools and resources; HTTP without valid 
credentials is rejected.

Given default configuration, when a client lists tools, then no tool classified 
mutate or destructive is present (secure-by-default).

Given any tool call, when it is processed, then it passes an ordered 
fail-closed pipeline (exposure, scope, policy, approval, rate limit, breaker) 
where the first denial wins and every denial is audited.

Given read-only tools (list_jobs, get_job, get_job_exceptions, get_job_metrics, 
list_checkpoints, list_jars), when called, then they return data mapped from 
the corresponding REST endpoints, and responses are size-bounded with secrets 
and PII redacted.

Given the audit resource flink://audit/recent, when read, then it returns a 
tamper-evident record of calls and denials.

Given existing Flink users, then nothing changes: the server is additive and 
optional, with no modification to the engine, runtime, REST API, or SQL Gateway.

*Definition of Done:* unit and integration tests passing; additive only; 
secure-by-default preserved; audit produced for every call and denial; 
documentation updated including which capabilities remain intentionally absent.

  was:
As a platform operator, I want a first-party MCP server that exposes Flink's 
control and observability plane (jobs, SQL Gateway, savepoints, metrics, 
exceptions, JARs) to agents through a secure-by-default governance layer, so 
that agents can operate and observe Flink safely without me trusting an 
ungoverned third-party process against production JobManagers.

{*}Description{*}: The server runs as a standalone process outside the 
JobManager and TaskManagers, consistent with the FLIP-577 engine non-goal. It 
wraps the existing JobManager REST API and SQL Gateway, and applies a 
fail-closed governance pipeline (adapted from the KIP-1318 control model) to 
every tool call. It complements FLIP-531 and FLIP-548, which make Flink an MCP 
client; this makes Flink an MCP server. Full design in FLIP-XXXX (My Confluance 
access not enabled once get access will add details here) .

*Acceptance criteria (Given / When / Then):*

Given the server is running, when a client sends initialize, tools/list, and 
resources/list over stdio or authenticated HTTP, then it completes the MCP 
handshake and advertises the read-only tools and resources; HTTP without valid 
credentials is rejected.


Given default configuration, when a client lists tools, then no tool classified 
mutate or destructive is present (secure-by-default).


Given any tool call, when it is processed, then it passes an ordered 
fail-closed pipeline (exposure, scope, policy, approval, rate limit, breaker) 
where the first denial wins and every denial is audited.


Given read-only tools (list_jobs, get_job, get_job_exceptions, get_job_metrics, 
list_checkpoints, list_jars), when called, then they return data mapped from 
the corresponding REST endpoints, and responses are size-bounded with secrets 
and PII redacted.


Given the audit resource flink://audit/recent, when read, then it returns a 
tamper-evident record of calls and denials.


Given existing Flink users, then nothing changes: the server is additive and 
optional, with no modification to the engine, runtime, REST API, or SQL Gateway.


*Definition of Done:* unit and integration tests passing; additive only; 
secure-by-default preserved; audit produced for every call and denial; 
documentation updated including which capabilities remain intentionally absent.


> Provide a first-party, governed MCP server for Apache Flink
> -----------------------------------------------------------
>
>                 Key: FLINK-40287
>                 URL: https://issues.apache.org/jira/browse/FLINK-40287
>             Project: Flink
>          Issue Type: New Feature
>            Reporter: vaquar khan
>            Priority: Major
>
> As a platform operator, I want a first-party MCP server that exposes Flink's 
> control and observability plane (jobs, SQL Gateway, savepoints, metrics, 
> exceptions, JARs) to agents through a secure-by-default governance layer, so 
> that agents can operate and observe Flink safely without me trusting an 
> ungoverned third-party process against production JobManagers.
> {*}Description{*}: The server runs as a standalone process outside the 
> JobManager and TaskManagers, consistent with the FLIP-577 engine non-goal. It 
> wraps the existing JobManager REST API and SQL Gateway, and applies a 
> fail-closed governance pipeline  to every tool call. It complements FLIP-531 
> and FLIP-548, which make Flink an MCP client; this makes Flink an MCP server. 
> Full design in FLIP-XXXX (My Confluence access not enabled once get access 
> will add details here) .
> *Acceptance criteria (Given / When / Then):*
> Given the server is running, when a client sends initialize, tools/list, and 
> resources/list over stdio or authenticated HTTP, then it completes the MCP 
> handshake and advertises the read-only tools and resources; HTTP without 
> valid credentials is rejected.
> Given default configuration, when a client lists tools, then no tool 
> classified mutate or destructive is present (secure-by-default).
> Given any tool call, when it is processed, then it passes an ordered 
> fail-closed pipeline (exposure, scope, policy, approval, rate limit, breaker) 
> where the first denial wins and every denial is audited.
> Given read-only tools (list_jobs, get_job, get_job_exceptions, 
> get_job_metrics, list_checkpoints, list_jars), when called, then they return 
> data mapped from the corresponding REST endpoints, and responses are 
> size-bounded with secrets and PII redacted.
> Given the audit resource flink://audit/recent, when read, then it returns a 
> tamper-evident record of calls and denials.
> Given existing Flink users, then nothing changes: the server is additive and 
> optional, with no modification to the engine, runtime, REST API, or SQL 
> Gateway.
> *Definition of Done:* unit and integration tests passing; additive only; 
> secure-by-default preserved; audit produced for every call and denial; 
> documentation updated including which capabilities remain intentionally 
> absent.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to