Skip to content
mcp/skillhub

Kubernetes Ephemeral Job MCP Server

by inhumanio.github.inhuman/mcp-k8s-ephemeral-jobv0.7.1

Runs a command in a throwaway Kubernetes pod and returns exit code, output and artifacts.

0Dockerstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Maintained3mo ago

Install Kubernetes Ephemeral Job MCP server

Install in Claude Code

claude mcp add k8s-ephemeral-job -e MCP_K8S_ALLOWED_IMAGES='<mcp-k8s-allowed-images>' -e MCP_K8S_CLONE_SECRET='<mcp-k8s-clone-secret>' -e MCP_K8S_AUTH_TOKEN='<mcp-k8s-auth-token>' -- docker run -i --rm -e MCP_K8S_ALLOWED_IMAGES -e MCP_K8S_CLONE_SECRET -e MCP_K8S_AUTH_TOKEN docker.io/idconstruct/mcp-k8s-ephemeral-job:v0.7.1

Configuration

VariableRequiredSecretDescription
MCP_K8S_ALLOWED_IMAGESyes—Strict image allowlist (CSV). Empty means every call is rejected, so this must be set.
MCP_K8S_KUBECONFIG——Path to the kubeconfig inside the container. Empty = use in-cluster credentials.
MCP_K8S_NAMESPACE——Namespace the ephemeral pods are created in. Needs a Role/RoleBinding for jobs and pods.
MCP_K8S_TRANSPORT——MCP transport: stdio | http | sse. Must be 'stdio' for direct docker/stdio use.
MCP_K8S_DEFAULT_TIMEOUT_S——Default wall-clock timeout per job, seconds.
MCP_K8S_MAX_TIMEOUT_S——Maximum wall-clock timeout a caller may request, seconds.
MCP_K8S_MAX_OUTPUT_BYTES——Cap on combined stdout/stderr before truncation.
MCP_K8S_MAX_ARTIFACT_BYTES——Cap on the total size of returned artifacts.
MCP_K8S_MAX_CONCURRENT——Maximum ephemeral pods running at the same time.
MCP_K8S_DEFAULT_CPU——Pod CPU request; limits come from the caller or the namespace LimitRange.
MCP_K8S_DEFAULT_MEMORY——Pod memory request; limits come from the caller or the namespace LimitRange.
MCP_K8S_SIDECAR_IMAGE——Helper image used to inject input files and collect artifacts.
MCP_K8S_CLONE_IMAGE——Image carrying git for the clone init container. Empty disables the clone field.
MCP_K8S_CLONE_SECRET—yesSecret with git tokens, mounted only on the cloner. Empty disables the clone field.
MCP_K8S_CACHE_PVC——Existing PVC mounted into every job pod as a shared cache. Empty = no cache.
MCP_K8S_CACHE_MOUNT_PATH——Where the cache PVC is mounted, e.g. /go/pkg/mod. Empty = no cache.
MCP_K8S_JOB_EXTRA_ENV——JSON object of env vars added to every job pod; caller keys win on collision.
MCP_K8S_AUTH_TOKEN—yesOptional X-MCP-AUTH token required on every request (http/sse transports only).

Freshness

Maintained — last maintenance signal 3mo ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-07-20 · 3mo ago · GitHub

  2. Latest release

    no data · GitHub

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-07-20 · 3mo ago · official registry · v0.7.1

FAQ

›How do I install the Kubernetes Ephemeral Job MCP server in Claude Code?

Run: claude mcp add k8s-ephemeral-job -e MCP_K8S_ALLOWED_IMAGES='<mcp-k8s-allowed-images>' -e MCP_K8S_CLONE_SECRET='<mcp-k8s-clone-secret>' -e MCP_K8S_AUTH_TOKEN='<mcp-k8s-auth-token>' -- docker run -i --rm -e MCP_K8S_ALLOWED_IMAGES -e MCP_K8S_CLONE_SECRET -e MCP_K8S_AUTH_TOKEN docker.io/idconstruct/mcp-k8s-ephemeral-job:v0.7.1. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does Kubernetes Ephemeral Job require an API key?

Yes. It expects MCP_K8S_ALLOWED_IMAGES, MCP_K8S_CLONE_SECRET, MCP_K8S_AUTH_TOKEN, of which 2 are secrets.

›Can I use Kubernetes Ephemeral Job as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is Kubernetes Ephemeral Job in the official MCP registry?

Yes, as io.github.inhuman/mcp-k8s-ephemeral-job.

Alternatives to Kubernetes Ephemeral Job

Other devops & ci/cd MCP servers.

View all