[
https://issues.apache.org/jira/browse/KUDU-3806?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Marton Greber updated KUDU-3806:
--------------------------------
Description:
Introduce kudu mcp serve, an MCP server that exposes existing kudu CLI actions
as MCP tools so operators can drive cluster diagnostics and administration from
an MCP-capable client (e.g. an LLM agent) without hand-crafting command lines.
Design highlights:
- Safety classification. Every action in the CLI action tree resolves to
exactly one Disposition:
-- SURFACE — read-only, always exposed (node-local reads are surfaced but
tagged as only meaningful on that node);
-- GATED — cluster-mutating, hidden unless --allow-writes is set;
-- REJECT — long-running/never-promptly-returning ops that would wedge the
single-threaded serve loop;
-- EXCLUDE — interactive or node-local mutating actions, never surfaced.
- Read-only by default. Mutating tools are only advertised with --allow-writes.
- Process isolation. Each tools/call runs its action in a fresh child kudu
process bounded by --mcp_tool_timeout_sec (default 60s), so a hung action
cannot freeze the server.
- Credential hygiene. --master_addresses is registered once at serve time and
injected into each call, so it never has to appear in the conversation.
was:
Introduce kudu mcp serve, an MCP server that exposes existing kudu CLI actions
as MCP tools so operators can drive cluster diagnostics and administration from
an MCP-capable client (e.g. an LLM agent) without hand-crafting command lines.
Design highlights:
- Safety classification. Every action in the CLI action tree resolves to
exactly one Disposition:
▎ - SURFACE — read-only, always exposed (node-local reads are surfaced but
tagged as only meaningful on that node);
▎ - GATED — cluster-mutating, hidden unless --allow-writes is set;
▎ - REJECT — long-running/never-promptly-returning ops that would wedge the
single-threaded serve loop;
▎ - EXCLUDE — interactive or node-local mutating actions, never surfaced.
▎ - Read-only by default. Mutating tools are only advertised with
--allow-writes.
▎ - Process isolation. Each tools/call runs its action in a fresh child kudu
process bounded by --mcp_tool_timeout_sec (default 60s), so a hung action
cannot freeze the server.
▎ - Credential hygiene. --master_addresses is registered once at serve time and
injected into each call, so it never has to appear in the conversation.
> Kudu MCP
> --------
>
> Key: KUDU-3806
> URL: https://issues.apache.org/jira/browse/KUDU-3806
> Project: Kudu
> Issue Type: New Feature
> Reporter: Marton Greber
> Assignee: Marton Greber
> Priority: Major
>
> Introduce kudu mcp serve, an MCP server that exposes existing kudu CLI
> actions as MCP tools so operators can drive cluster diagnostics and
> administration from an MCP-capable client (e.g. an LLM agent) without
> hand-crafting command lines.
> Design highlights:
> - Safety classification. Every action in the CLI action tree resolves to
> exactly one Disposition:
> -- SURFACE — read-only, always exposed (node-local reads are surfaced but
> tagged as only meaningful on that node);
> -- GATED — cluster-mutating, hidden unless --allow-writes is set;
> -- REJECT — long-running/never-promptly-returning ops that would wedge the
> single-threaded serve loop;
> -- EXCLUDE — interactive or node-local mutating actions, never surfaced.
> - Read-only by default. Mutating tools are only advertised with
> --allow-writes.
> - Process isolation. Each tools/call runs its action in a fresh child kudu
> process bounded by --mcp_tool_timeout_sec (default 60s), so a hung action
> cannot freeze the server.
> - Credential hygiene. --master_addresses is registered once at serve time
> and injected into each call, so it never has to appear in the conversation.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)