---
bezeichner: "io.github.inhuman/mcp-k8s-ephemeral-job"
art: "mcp_server"
slug: "io-github-inhuman-mcp-k8s-ephemeral-job"
paketkoordinate: "oci:docker.io/idconstruct/mcp-k8s-ephemeral-job:v0.7.1"
status: "aktiv"
homepage: "https://github.com/inhuman/mcp-k8s-ephemeral-job"
erhebungsstand: "2026-10-11T01:17:01.851Z"
namensraum: "io.github.inhuman"
registerseite: "https://tracevero.com/mcp/io-github-inhuman-mcp-k8s-ephemeral-job"
abgerufen_am: "2026-10-11"
zugangsdaten_erforderlich: false
ausfuehrungsort: "lokal"
dateisystem_pfadargument: false
quelloffen_einsehbar: true
einsatzgebiet: "infrastruktur"
roh_beschreibung: "Runs a command in a throwaway Kubernetes pod and returns exit code, output and artifacts."
version: "0.7.1"
roh_umgebungsvariablen: "MCP_K8S_ALLOWED_IMAGES, MCP_K8S_KUBECONFIG, MCP_K8S_NAMESPACE, MCP_K8S_TRANSPORT, MCP_K8S_DEFAULT_TIMEOUT_S, MCP_K8S_MAX_TIMEOUT_S, MCP_K8S_MAX_OUTPUT_BYTES, MCP_K8S_MAX_ARTIFACT_BYTES, MCP_K8S_MAX_CONCURRENT, MCP_K8S_DEFAULT_CPU, MCP_K8S_DEFAULT_MEMORY, MCP_K8S_SIDECAR_IMAGE, MCP_K8S_CLONE_IMAGE, MCP_K8S_CLONE_SECRET, MCP_K8S_CACHE_PVC, MCP_K8S_CACHE_MOUNT_PATH, MCP_K8S_JOB_EXTRA_ENV, MCP_K8S_AUTH_TOKEN"
roh_geheime_pflichtvariablen: ""
roh_transportarten: "stdio"
roh_pfadargumente: ""
roh_repository_url: "https://github.com/inhuman/mcp-k8s-ephemeral-job"
roh_paketquellen: "oci"
roh_geheime_pflichtkopfzeilen: ""
roh_pfad_umgebungsvariablen: ""
roh_remote_adressen: ""
roh_remote_hosts: ""
roh_statusmeldung: ""
roh_veroeffentlicht_am: "2026-07-20"
roh_aktualisiert_am: "2026-07-20"
roh_schemafassung: "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json"
roh_bereitstellungsform: "paket"
roh_repository_quelle: "github"
roh_repository_unterordner: ""
roh_paketbezeichner: "docker.io/idconstruct/mcp-k8s-ephemeral-job:v0.7.1"
roh_paketversionen: ""
roh_laufzeithinweise: "docker"
roh_umgebungsformate: ""
roh_umgebungsbeschreibungen: "MCP_K8S_ALLOWED_IMAGES=Strict image allowlist (CSV). Empty means every call is rejected, so this must be set. · MCP_K8S_AUTH_TOKEN=Optional X-MCP-AUTH token required on every request (http/sse transports only). · MCP_K8S_CACHE_MOUNT_PATH=Where the cache PVC is mounted, e.g. /go/pkg/mod. Empty = no cache. · MCP_K8S_CACHE_PVC=Existing PVC mounted into every job pod as a shared cache. Empty = no cache. · MCP_K8S_CLONE_IMAGE=Image carrying git for the clone init container. Empty disables the clone field. · MCP_K8S_CLONE_SECRET=Secret with git tokens, mounted only on the cloner. Empty disables the clone field. · MCP_K8S_DEFAULT_CPU=Pod CPU request; limits come from the caller or the namespace LimitRange. · MCP_K8S_DEFAULT_MEMORY=Pod memory request; limits come from the caller or the namespace LimitRange. · MCP_K8S_DEFAULT_TIMEOUT_S=Default wall-clock timeout per job, seconds. · MCP_K8S_JOB_EXTRA_ENV=JSON object of env vars added to every job pod; caller keys win on collision. · MCP_K8S_KUBECONFIG=Path to the kubeconfig inside the container. Empty = use in-cluster credentials. · MCP_K8S_MAX_ARTIFACT_BYTES=Cap on the total size of returned artifacts. · MCP_K8S_MAX_CONCURRENT=Maximum ephemeral pods running at the same time. · MCP_K8S_MAX_OUTPUT_BYTES=Cap on combined stdout/stderr before truncation. · MCP_K8S_MAX_TIMEOUT_S=Maximum wall-clock timeout a caller may request, seconds. · MCP_K8S_NAMESPACE=Namespace the ephemeral pods are created in. Needs a Role/RoleBinding for jobs and pods. · MCP_K8S_SIDECAR_IMAGE=Helper image used to inject input files and collect artifacts. · MCP_K8S_TRANSPORT=MCP transport: stdio | http | sse. Must be 'stdio' for direct docker/stdio use."
roh_symbolformate: ""
roh_verbindungswege: "{\"packages\":[{\"registryType\":\"oci\",\"identifier\":\"docker.io/idconstruct/mcp-k8s-ephemeral-job:v0.7.1\",\"runtimeHint\":\"docker\",\"transport\":\"stdio\",\"environment\":[{\"name\":\"MCP_K8S_ALLOWED_IMAGES\",\"description\":\"Strict image allowlist (CSV). Empty means every call is rejected, so this must be set.\",\"required\":true,\"secret\":false},{\"name\":\"MCP_K8S_KUBECONFIG\",\"description\":\"Path to the kubeconfig inside the container. Empty = use in-cluster credentials.\",\"required\":false,\"secret\":false},{\"name\":\"MCP_K8S_NAMESPACE\",\"description\":\"Namespace the ephemeral pods are created in. Needs a Role/RoleBinding for jobs and pods.\",\"required\":false,\"secret\":false},{\"name\":\"MCP_K8S_TRANSPORT\",\"description\":\"MCP transport: stdio | http | sse. Must be 'stdio' for direct docker/stdio use.\",\"required\":false,\"secret\":false},{\"name\":\"MCP_K8S_DEFAULT_TIMEOUT_S\",\"description\":\"Default wall-clock timeout per job, seconds.\",\"required\":false,\"secret\":false},{\"name\":\"MCP_K8S_MAX_TIMEOUT_S\",\"description\":\"Maximum wall-clock timeout a caller may request, seconds.\",\"required\":false,\"secret\":false},{\"name\":\"MCP_K8S_MAX_OUTPUT_BYTES\",\"description\":\"Cap on combined stdout/stderr before truncation.\",\"required\":false,\"secret\":false},{\"name\":\"MCP_K8S_MAX_ARTIFACT_BYTES\",\"description\":\"Cap on the total size of returned artifacts.\",\"required\":false,\"secret\":false},{\"name\":\"MCP_K8S_MAX_CONCURRENT\",\"description\":\"Maximum ephemeral pods running at the same time.\",\"required\":false,\"secret\":false},{\"name\":\"MCP_K8S_DEFAULT_CPU\",\"description\":\"Pod CPU request; limits come from the caller or the namespace LimitRange.\",\"required\":false,\"secret\":false},{\"name\":\"MCP_K8S_DEFAULT_MEMORY\",\"description\":\"Pod memory request; limits come from the caller or the namespace LimitRange.\",\"required\":false,\"secret\":false},{\"name\":\"MCP_K8S_SIDECAR_IMAGE\",\"description\":\"Helper image used to inject input files and collect artifacts.\",\"required\":false,\"secret\":false},{\"name\":\"MCP_K8S_CLONE_IMAGE\",\"description\":\"Image carrying git for the clone init container. Empty disables the clone field.\",\"required\":false,\"secret\":false},{\"name\":\"MCP_K8S_CLONE_SECRET\",\"description\":\"Secret with git tokens, mounted only on the cloner. Empty disables the clone field.\",\"required\":false,\"secret\":true},{\"name\":\"MCP_K8S_CACHE_PVC\",\"description\":\"Existing PVC mounted into every job pod as a shared cache. Empty = no cache.\",\"required\":false,\"secret\":false},{\"name\":\"MCP_K8S_CACHE_MOUNT_PATH\",\"description\":\"Where the cache PVC is mounted, e.g. /go/pkg/mod. Empty = no cache.\",\"required\":false,\"secret\":false},{\"name\":\"MCP_K8S_JOB_EXTRA_ENV\",\"description\":\"JSON object of env vars added to every job pod; caller keys win on collision.\",\"required\":false,\"secret\":false},{\"name\":\"MCP_K8S_AUTH_TOKEN\",\"description\":\"Optional X-MCP-AUTH token required on every request (http/sse transports only).\",\"required\":false,\"secret\":true}],\"additional_arguments_declared\":true}],\"remotes\":[]}"
---

# Kubernetes Ephemeral Job

## Measured values

| Property | Value | Source | Collected on | Level of trust | Raw declaration |
| --- | --- | --- | --- | --- | --- |
| Required secrets declared | false | MCP-Register | 2026-08-06T13:57:41.838Z | abgeleitet | roh_geheime_pflichtvariablen: ; roh_geheime_pflichtkopfzeilen: |
| Execution location | lokal | MCP-Register | 2026-08-06T13:57:41.838Z | abgeleitet | roh_transportarten: stdio |
| Path argument present | false | MCP-Register | 2026-08-06T13:57:41.838Z | abgeleitet | roh_pfadargumente: ; roh_pfad_umgebungsvariablen: |
| Repository URL listed | true | MCP-Register | 2026-08-06T13:57:41.838Z | abgeleitet | roh_repository_url: https://github.com/inhuman/mcp-k8s-ephemeral-job |
| Field of use, derived from the vendor description | infrastruktur | MCP-Register | 2026-08-26T16:45:01.514Z | abgeleitet | roh_beschreibung: Runs a command in a throwaway Kubernetes pod and returns exit code, output and artifacts. |
| Description (raw) | Runs a command in a throwaway Kubernetes pod and returns exit code, output and artifacts. | MCP-Register | 2026-08-26T16:45:01.514Z | selbstauskunft |  |
| Declared version | 0.7.1 | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Environment variables (raw) | MCP_K8S_ALLOWED_IMAGES, MCP_K8S_KUBECONFIG, MCP_K8S_NAMESPACE, MCP_K8S_TRANSPORT, MCP_K8S_DEFAULT_TIMEOUT_S, MCP_K8S_MAX_TIMEOUT_S, MCP_K8S_MAX_OUTPUT_BYTES, MCP_K8S_MAX_ARTIFACT_BYTES, MCP_K8S_MAX_CONCURRENT, MCP_K8S_DEFAULT_CPU, MCP_K8S_DEFAULT_MEMORY, MCP_K8S_SIDECAR_IMAGE, MCP_K8S_CLONE_IMAGE, MCP_K8S_CLONE_SECRET, MCP_K8S_CACHE_PVC, MCP_K8S_CACHE_MOUNT_PATH, MCP_K8S_JOB_EXTRA_ENV, MCP_K8S_AUTH_TOKEN | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Required secret variables (raw) |  | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Transports (raw) | stdio | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Path arguments (raw) |  | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Repository (raw) | https://github.com/inhuman/mcp-k8s-ephemeral-job | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Package registries (raw) | oci | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Required secret headers (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Path environment variables (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Remote URLs (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Remote hosts (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Registry status message (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| First listed in the registry (raw) | 2026-07-20 | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Last changed in the registry (raw) | 2026-07-20 | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Schema version of the raw record (raw) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Delivery form (raw) | paket | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Repository platform (raw) | github | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Repository subfolder (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Package identifiers (raw) | docker.io/idconstruct/mcp-k8s-ephemeral-job:v0.7.1 | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Package versions (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Runtime hints (raw) | docker | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Environment variable formats (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Environment variable descriptions (raw) | MCP_K8S_ALLOWED_IMAGES=Strict image allowlist (CSV). Empty means every call is rejected, so this must be set. · MCP_K8S_AUTH_TOKEN=Optional X-MCP-AUTH token required on every request (http/sse transports only). · MCP_K8S_CACHE_MOUNT_PATH=Where the cache PVC is mounted, e.g. /go/pkg/mod. Empty = no cache. · MCP_K8S_CACHE_PVC=Existing PVC mounted into every job pod as a shared cache. Empty = no cache. · MCP_K8S_CLONE_IMAGE=Image carrying git for the clone init container. Empty disables the clone field. · MCP_K8S_CLONE_SECRET=Secret with git tokens, mounted only on the cloner. Empty disables the clone field. · MCP_K8S_DEFAULT_CPU=Pod CPU request; limits come from the caller or the namespace LimitRange. · MCP_K8S_DEFAULT_MEMORY=Pod memory request; limits come from the caller or the namespace LimitRange. · MCP_K8S_DEFAULT_TIMEOUT_S=Default wall-clock timeout per job, seconds. · MCP_K8S_JOB_EXTRA_ENV=JSON object of env vars added to every job pod; caller keys win on collision. · MCP_K8S_KUBECONFIG=Path to the kubeconfig inside the container. Empty = use in-cluster credentials. · MCP_K8S_MAX_ARTIFACT_BYTES=Cap on the total size of returned artifacts. · MCP_K8S_MAX_CONCURRENT=Maximum ephemeral pods running at the same time. · MCP_K8S_MAX_OUTPUT_BYTES=Cap on combined stdout/stderr before truncation. · MCP_K8S_MAX_TIMEOUT_S=Maximum wall-clock timeout a caller may request, seconds. · MCP_K8S_NAMESPACE=Namespace the ephemeral pods are created in. Needs a Role/RoleBinding for jobs and pods. · MCP_K8S_SIDECAR_IMAGE=Helper image used to inject input files and collect artifacts. · MCP_K8S_TRANSPORT=MCP transport: stdio \| http \| sse. Must be 'stdio' for direct docker/stdio use. | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Icon formats (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Connection paths (source structure) | {"packages":[{"registryType":"oci","identifier":"docker.io/idconstruct/mcp-k8s-ephemeral-job:v0.7.1","runtimeHint":"docker","transport":"stdio","environment":[{"name":"MCP_K8S_ALLOWED_IMAGES","description":"Strict image allowlist (CSV). Empty means every call is rejected, so this must be set.","required":true,"secret":false},{"name":"MCP_K8S_KUBECONFIG","description":"Path to the kubeconfig inside the container. Empty = use in-cluster credentials.","required":false,"secret":false},{"name":"MCP_K8S_NAMESPACE","description":"Namespace the ephemeral pods are created in. Needs a Role/RoleBinding for jobs and pods.","required":false,"secret":false},{"name":"MCP_K8S_TRANSPORT","description":"MCP transport: stdio \| http \| sse. Must be 'stdio' for direct docker/stdio use.","required":false,"secret":false},{"name":"MCP_K8S_DEFAULT_TIMEOUT_S","description":"Default wall-clock timeout per job, seconds.","required":false,"secret":false},{"name":"MCP_K8S_MAX_TIMEOUT_S","description":"Maximum wall-clock timeout a caller may request, seconds.","required":false,"secret":false},{"name":"MCP_K8S_MAX_OUTPUT_BYTES","description":"Cap on combined stdout/stderr before truncation.","required":false,"secret":false},{"name":"MCP_K8S_MAX_ARTIFACT_BYTES","description":"Cap on the total size of returned artifacts.","required":false,"secret":false},{"name":"MCP_K8S_MAX_CONCURRENT","description":"Maximum ephemeral pods running at the same time.","required":false,"secret":false},{"name":"MCP_K8S_DEFAULT_CPU","description":"Pod CPU request; limits come from the caller or the namespace LimitRange.","required":false,"secret":false},{"name":"MCP_K8S_DEFAULT_MEMORY","description":"Pod memory request; limits come from the caller or the namespace LimitRange.","required":false,"secret":false},{"name":"MCP_K8S_SIDECAR_IMAGE","description":"Helper image used to inject input files and collect artifacts.","required":false,"secret":false},{"name":"MCP_K8S_CLONE_IMAGE","description":"Image carrying git for the clone init container. Empty disables the clone field.","required":false,"secret":false},{"name":"MCP_K8S_CLONE_SECRET","description":"Secret with git tokens, mounted only on the cloner. Empty disables the clone field.","required":false,"secret":true},{"name":"MCP_K8S_CACHE_PVC","description":"Existing PVC mounted into every job pod as a shared cache. Empty = no cache.","required":false,"secret":false},{"name":"MCP_K8S_CACHE_MOUNT_PATH","description":"Where the cache PVC is mounted, e.g. /go/pkg/mod. Empty = no cache.","required":false,"secret":false},{"name":"MCP_K8S_JOB_EXTRA_ENV","description":"JSON object of env vars added to every job pod; caller keys win on collision.","required":false,"secret":false},{"name":"MCP_K8S_AUTH_TOKEN","description":"Optional X-MCP-AUTH token required on every request (http/sse transports only).","required":false,"secret":true}],"additional_arguments_declared":true}],"remotes":[]} | MCP-Register | 2026-09-08T01:17:01.649Z | selbstauskunft |  |

## Links

- Namespace: [[namensraum/io-github-inhuman|io.github.inhuman]]

---

- Registry page: <https://tracevero.com/mcp/io-github-inhuman-mcp-k8s-ephemeral-job>
- Retrieved on: 2026-10-11
