
Talos MCP server for Talos Linux
io.github.sergelogvinovv0.2.0更新于 Oct 5, 2026
Talos MCP is an opinionated MCP server for Talos Linux
概览
让 AI 助手通过 Talos API 检查 Talos Linux 集群与节点,读取版本、日志、事件和发现服务成员信息。
- 功能
- 将 MCP 客户端连接到 Talos API(apid),并可选连接发现服务,支持多个集群并返回结构化数据。工具可列出已配置集群、描述集群节点的角色与版本、查看最近的运行时事件、列出发现服务成员,以及读取节点详情、服务日志和内核日志。显式启用后可提供一个重启节点的破坏性工具。
- 适用场景
- 适合让助手收集和分析 Talos 集群信息,而不必手动执行大量 talosctl 命令,例如在变更基础设施之前。它不替代 Terraform、Ansible 或 GitOps,这些工具仍是基础设施变更的主要来源。
- 运行要求
- 以 stdio 本地进程运行(可通过 Homebrew 或容器镜像安装)。需要 talosconfig 文件,通过 --talosconfig 或 TALOSCONFIG 指定,并为每个集群配置凭据;加密字段需要解锁来源,如 TALOSCONFIG_IDENTITY、TALOSCONFIG_PASSPHRASE_FILE 或 TALOSCONFIG_ASKPASS。需要访问 Talos API 端点的网络。也提供 HTTP 服务器模式。
安装
在 SourceWeft 中
- 打开 控制台中的 Talos MCP server for Talos Linux,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
Talos opinionated MCP Server
NOTE: This project is under active development.
Motivation
Modern infrastructure often uses tools such as Terraform/OpenTofu, Ansible, and GitOps. These tools deploy and configure Talos Linux nodes and Kubernetes clusters.
The Talos MCP Server does not replace these tools. It gives AI assistants and automation agents access to information about your Talos clusters.
The default tools are read-only. An optional action tool can be enabled with
--allow-destructive to reboot a node.
Instead of running many talosctl commands across nodes, you can ask an AI
assistant to collect and analyze the required information. Your existing
automation tools remain the main source for infrastructure changes.
Overview
The server connects an MCP client, such as an AI assistant, to the Talos API (apid) and, optionally, to the Talos discovery service. It supports multiple Talos clusters and returns structured data.
You can use it to:
- inspect clusters, nodes, and their Talos and Kubernetes versions
- read Talos service logs and kernel logs (dmesg) of a node
- review recent Talos runtime events
- list cluster members from the discovery service, even when the Talos API is down
- collect information before you make infrastructure changes
Keep your AI on the leash.
Talos tools
The MCP server provides the following tools:
cluster is a talosconfig context name. When it is omitted, the current
context is used. Use talos_clusters_list first to find the cluster names.
MCP clients can discover the full input and output schemas. You can also list
the tools from the command line:
When --allow-destructive is enabled and the cluster's credential has the
os:operator role, talos_node_reboot accepts cluster, node, and an
optional mode (default or powercycle). It returns once Talos accepts the
request; it does not wait for the node to come back.
The tools available on each cluster depend on the role of its client
certificate: os:reader gets the read-only tools, os:operator also gets
the reboot tool.
Installation
For a local installation with Homebrew, run:
You do not need a local installation when you use an MCP server hosted on another machine.
Configure Talos clusters
The server reads a standard talosconfig, the same file talosctl uses.
Each context is one cluster. Create a dedicated credential with the smallest
role you need:
A context may also have an optional discovery block with the cluster ID and
secret, which enables talos_clusters_members:
The private key and cluster_secret can be stored encrypted with a
passphrase, an age key, or your SSH key:
Set the talosconfig path with --talosconfig or TALOSCONFIG. The default is
~/.talos/config.
See docs/config.md for every talosconfig field, the
discovery block, credential roles, the unlock options for encrypted secrets,
the config import, encrypt, decrypt, and check commands, deployment recipes, and
troubleshooting.
Configure an MCP client
Local stdio server
For clients that use a JSON MCP configuration, add an entry like this:
If the talosconfig has encrypted fields, also set an unlock source, for
example "TALOSCONFIG_IDENTITY": "/absolute/path/to/.ssh/id_ed25519". The
mcp command never prompts for a passphrase.
Remote HTTP server
Start the streamable HTTP server with:
The MCP endpoint is http://host:8080/mcp, and a health check is served on
/healthz.
For a remote client, use an HTTPS URL that ends with /mcp:
The server does not provide user authentication for the HTTP endpoint. Every caller uses the credentials from the server's talosconfig, so protect the endpoint with a network policy or an authenticating proxy.
A Helm chart for Kubernetes is available in charts/talos-mcp.
Restart or reload the MCP client after you save its configuration.
Running
Common flags
The mcp, server, and tools commands use the following flags. Each flag
can also be set with an environment variable. A command-line flag has higher
priority than an environment variable.
The server command also accepts --listen-address (LISTEN_ADDRESS,
default 127.0.0.1:8080) and --require-all-contexts
(REQUIRE_ALL_CONTEXTS). The container image sets LISTEN_ADDRESS=:8080. The tools command accepts --output (-o) with
text, json, or yaml. Its default is text.
For example, run the stdio server with JSON logs:
Test the configuration
Check the talosconfig and its encrypted fields:
List all available tools:
Call a tool directly:
License
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
Talos Linux is a trademark of Sidero Labs, Inc.
来源:README.md,提交 ed32ca8
工具
0版本历史
1- v0.2.0最新Oct 5, 2026


