[
https://issues.apache.org/jira/browse/KUDU-3806?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Marton Greber updated KUDU-3806:
--------------------------------
Description:
Introduce kudu mcp serve, an MCP server that exposes existing kudu CLI actions
as MCP tools so operators can drive cluster diagnostics and administration from
an MCP-capable client (e.g. an LLM agent) without hand-crafting command lines.
Design highlights:
- Safety classification. Every action in the CLI action tree resolves to
exactly one Disposition:
▎ - SURFACE — read-only, always exposed (node-local reads are surfaced but
tagged as only meaningful on that node);
▎ - GATED — cluster-mutating, hidden unless --allow-writes is set;
▎ - REJECT — long-running/never-promptly-returning ops that would wedge the
single-threaded serve loop;
▎ - EXCLUDE — interactive or node-local mutating actions, never surfaced.
▎ - Read-only by default. Mutating tools are only advertised with
--allow-writes.
▎ - Process isolation. Each tools/call runs its action in a fresh child kudu
process bounded by --mcp_tool_timeout_sec (default 60s), so a hung action
cannot freeze the server.
▎ - Credential hygiene. --master_addresses is registered once at serve time and
injected into each call, so it never has to appear in the conversation.
> Kudu MCP
> --------
>
> Key: KUDU-3806
> URL: https://issues.apache.org/jira/browse/KUDU-3806
> Project: Kudu
> Issue Type: New Feature
> Reporter: Marton Greber
> Assignee: Marton Greber
> Priority: Major
>
> Introduce kudu mcp serve, an MCP server that exposes existing kudu CLI
> actions as MCP tools so operators can drive cluster diagnostics and
> administration from an MCP-capable client (e.g. an LLM agent) without
> hand-crafting command lines.
> Design highlights:
> - Safety classification. Every action in the CLI action tree resolves to
> exactly one Disposition:
> ▎ - SURFACE — read-only, always exposed (node-local reads are surfaced but
> tagged as only meaningful on that node);
> ▎ - GATED — cluster-mutating, hidden unless --allow-writes is set;
> ▎ - REJECT — long-running/never-promptly-returning ops that would wedge the
> single-threaded serve loop;
> ▎ - EXCLUDE — interactive or node-local mutating actions, never surfaced.
> ▎ - Read-only by default. Mutating tools are only advertised with
> --allow-writes.
> ▎ - Process isolation. Each tools/call runs its action in a fresh child kudu
> process bounded by --mcp_tool_timeout_sec (default 60s), so a hung action
> cannot freeze the server.
> ▎ - Credential hygiene. --master_addresses is registered once at serve time
> and injected into each call, so it never has to appear in the conversation.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)