[ 
https://issues.apache.org/jira/browse/KUDU-3806?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Marton Greber updated KUDU-3806:
--------------------------------
    Description: 
 Introduce kudu mcp serve, an MCP server that exposes existing kudu CLI actions 
as MCP tools so operators can drive cluster diagnostics and administration from 
an MCP-capable client (e.g. an LLM agent) without hand-crafting command lines.

Design highlights:
 - Safety classification. Every action in the CLI action tree resolves to 
exactly one Disposition:
 -- SURFACE — read-only, always exposed (node-local reads are surfaced but 
tagged as only meaningful on that node);
 -- GATED — cluster-mutating, hidden unless --allow-writes is set;
 -- REJECT — long-running/never-promptly-returning ops that would wedge the 
single-threaded serve loop;
 -- EXCLUDE — interactive or node-local mutating actions, never surfaced.
 - Read-only by default. Mutating tools are only advertised with --allow-writes.
 - Process isolation. Each tools/call runs its action in a fresh child kudu 
process bounded by --mcp_tool_timeout_sec (default 60s), so a hung action 
cannot freeze the server.
 - Credential hygiene. --master_addresses is registered once at serve time and 
injected into each call, so it never has to appear in the conversation.

  was:
 Introduce kudu mcp serve, an MCP server that exposes existing kudu CLI actions 
as MCP tools so operators can drive cluster diagnostics and administration from 
an MCP-capable client (e.g. an LLM agent) without hand-crafting command lines.

Design highlights:
- Safety classification. Every action in the CLI action tree resolves to 
exactly one Disposition:
▎   - SURFACE — read-only, always exposed (node-local reads are surfaced but 
tagged as only meaningful on that node);
▎   - GATED — cluster-mutating, hidden unless --allow-writes is set;
▎   - REJECT — long-running/never-promptly-returning ops that would wedge the 
single-threaded serve loop;
▎   - EXCLUDE — interactive or node-local mutating actions, never surfaced.
▎ - Read-only by default. Mutating tools are only advertised with 
--allow-writes.
▎ - Process isolation. Each tools/call runs its action in a fresh child kudu 
process bounded by --mcp_tool_timeout_sec (default 60s), so a hung action 
cannot freeze the server.
▎ - Credential hygiene. --master_addresses is registered once at serve time and 
injected into each call, so it never has to appear in the conversation.


> Kudu MCP
> --------
>
>                 Key: KUDU-3806
>                 URL: https://issues.apache.org/jira/browse/KUDU-3806
>             Project: Kudu
>          Issue Type: New Feature
>            Reporter: Marton Greber
>            Assignee: Marton Greber
>            Priority: Major
>
>  Introduce kudu mcp serve, an MCP server that exposes existing kudu CLI 
> actions as MCP tools so operators can drive cluster diagnostics and 
> administration from an MCP-capable client (e.g. an LLM agent) without 
> hand-crafting command lines.
> Design highlights:
>  - Safety classification. Every action in the CLI action tree resolves to 
> exactly one Disposition:
>  -- SURFACE — read-only, always exposed (node-local reads are surfaced but 
> tagged as only meaningful on that node);
>  -- GATED — cluster-mutating, hidden unless --allow-writes is set;
>  -- REJECT — long-running/never-promptly-returning ops that would wedge the 
> single-threaded serve loop;
>  -- EXCLUDE — interactive or node-local mutating actions, never surfaced.
>  - Read-only by default. Mutating tools are only advertised with 
> --allow-writes.
>  - Process isolation. Each tools/call runs its action in a fresh child kudu 
> process bounded by --mcp_tool_timeout_sec (default 60s), so a hung action 
> cannot freeze the server.
>  - Credential hygiene. --master_addresses is registered once at serve time 
> and injected into each call, so it never has to appear in the conversation.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to