Radar
An open-source Kubernetes UI with a built-in MCP server: the agent inspects the cluster, diagnoses breakages and operates it with RBAC in mind
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Gives the agent access to the Kubernetes cluster
- Write operations affect the real cluster
- Optional route probing creates temporary pods
Install
Manual install
curl -fsSL https://get.radarhq.io | sh && kubectl radarInstalls a single binary and starts Radar. The MCP server is enabled by default at http://localhost:9280/mcp.
This is third-party code. Review the repository files before installing.
What it does
Radar is an open-source Kubernetes UI in a single Go binary: topology, resources, event timeline, Helm, GitOps, live service traffic, cost and cluster audits. Its built-in MCP server lets the agent work with the cluster not through raw kubectl but through token-optimized tools: resources are stripped of noise, data is enriched with a topology graph, health assessment and filtered logs. Diagnosis is read-only by default, while write tools such as restart, scale, apply and rollback are flagged for confirmation and enforced through the cluster's RBAC. Secrets are not exposed, and environment values and logs are scrubbed of keys. It runs from a laptop or in-cluster via Helm.
Who it is for. For DevOps and SRE engineers and developers who want Kubernetes inspection and troubleshooting through an agent.
Good fit when
- You want the agent to inspect the cluster and explain what broke and why
- You want cluster operations over MCP with confirmation and RBAC
- You want the agent to reach topology, events, Helm and GitOps without raw kubectl
Not a fit when
- You cannot give the agent cluster access even with RBAC
- You only need the visual UI without an agent connection
Example request
Inspect the cluster, find pods in crashloop and explain what changed before the failureLimitations
The MCP server works with your kubeconfig permissions and is bounded by the cluster's RBAC. Write operations affect the real cluster; they are flagged for confirmation, but the confirmation is your responsibility. Optional in-cluster route probing spins up short-lived, self-deleting pods. The MCP server is enabled by default and turned off with a flag.
How to disable. Run Radar with the --no-mcp flag to disable the MCP server and remove its address from the agent config.
MCP
- Transport
- http
- Authentication
- not required
Security check
- Gives the agent access to the Kubernetes cluster
- Write operations affect the real cluster
- Optional route probing creates temporary pods
README in short
The README describes Radar as an open-source Kubernetes UI in a single Go binary that runs from a laptop or in-cluster with no agents or CRDs. Views: topology, resources, timeline, Helm, compare, TLS, GitOps, traffic, cost, audit, upgrade impact, RBAC and MCP. The built-in MCP server gives agents token-optimized, safe tools with enriched data and RBAC awareness, served over HTTP on the port from the --port flag. Cluster data stays on the machine, with no account or cloud sync. Apache-2.0 licensed.
FAQ
Why MCP over raw kubectl?
Responses are stripped of noise and enriched with topology, health and filtered logs; diagnosis is read-only by default, and changes go through confirmation and RBAC.
Are secrets exposed?
No. Secret data is not returned, and environment values and logs are scrubbed of keys and tokens.
Related
An MCP server built into the Netdata agent: metrics, logs, alerts and live process, service and container data for an AI assistant
GitHub's official MCP server: code, issues, pull requests, Actions and security alerts straight from the agent
Agent Skills for Google products
Agent Skills for Google products and technologies
Official Google skill collection for working with Google Cloud, BigQuery, GKE, ads and analytics from an agent
AWS's official MCP server suite: docs, IaC, containers, serverless, databases, cost and monitoring