Mcp Argocd

io.github.vish288v0.1.0更新於 Oct 6, 2026

Argo CD MCP server for MCP 2026-07-28: app status, sync, rollback, drift, logs, ApplicationSets

概覽

AI 產生的概覽

讓助理檢查並操作 Argo CD 應用程式,包括狀態排查、同步、回復、漂移審查、日誌與 ApplicationSet。

功能
這是一個面向 Argo CD REST API 的本機 MCP 伺服器,提供 37 個工具、7 個資源與 7 個提示。讀取類工具涵蓋應用程式狀態、資源樹、實際與期望差異、資訊清單、事件、Pod 日誌、歷史、同步視窗、專案、叢集與儲存庫。寫入類工具可同步、回復、終止操作、建立、修補或刪除應用程式,以及執行或刪除單一資源。內建的 GitOps 規則資源與流程提示支援排查、漂移審查、安全同步、回復與叢集狀態回報。
適用情境
適合讓助理協助維運或診斷 Argo CD GitOps 部署:排查 Degraded 或 OutOfSync 應用程式、審查漂移、同步前檢查同步視窗、執行回復或彙整叢集健康狀態。它只存取 Argo CD API,不需要 kubectl 或叢集憑證。
執行需求
透過 uvx 或 pip 在本機執行(Python 3.10-3.14)。需要 ARGOCD_URL 與 ARGOCD_TOKEN 中的 bearer 權杖(也會讀取 ARGOCD_AUTH_TOKEN 或 ARGOCD_API_TOKEN),權杖來自具備 apiKey 能力的 Argo CD 本機帳號或專案角色。選用變數包括 ARGOCD_READ_ONLY、ARGOCD_TIMEOUT、ARGOCD_SSL_VERIFY 與 ARGOCD_APP_NAMESPACE。需要能連線至 Argo CD 伺服器的網路。
安裝前請注意
權杖擁有 Argo CD RBAC 授予的全部權限,應使用最小權限角色。寫入類工具可帶 prune 或 force 同步、回復、終止操作、建立、修補或刪除應用程式,以及執行或刪除資源;設定 ARGOCD_READ_ONLY=true 會在任何 API 呼叫前阻擋這九個寫入工具。ARGOCD_SSL_VERIFY=false 會關閉憑證檢查,僅應在可信任網路中使用。權杖從環境變數讀取,不會被持久化保存。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Mcp Argocd,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

mcp-argocd

[PyPI version] [PyPI downloads] [Python] [License: MIT] [CI] [MCP Registry]

mcp-argocd is a Model Context Protocol (MCP) server for the Argo CD REST API. It gives AI assistants 37 tools, 7 resources, and 7 prompts to triage application status, sync, roll back, inspect drift, read logs, and manage ApplicationSets, clusters, projects, and repositories. Works with Claude Desktop, Claude Code, Cursor, Windsurf, VS Code Copilot, and any MCP-compatible client.

Works with Argo CD 3.3+ (any install: OSS, Akuity, OpenShift GitOps). Needs an API token, no cluster access.

Supports the MCP 2026-07-28 specification, often called MCP 2.0, and stays compatible with 2025-11-25 clients.

Built with FastMCP 4.x, httpx, and Pydantic.

Install: uvx mcp-argocd | PyPI | MCP Registry | Changelog

1-Click Installation

[Install in Cursor]

[Install in VS Code]

Tip: For other AI assistants (Claude Code, Windsurf, IntelliJ, Gemini CLI), visit the Argo CD MCP Installation Gateway.

Manual Setup Guides (Click to expand)

Prerequisite: Install uv first. Install uv.

Claude Code

bash
claude mcp add argocd -- uvx mcp-argocd

Windsurf & IntelliJ

Windsurf: Add to ~/.codeium/windsurf/mcp_config.json IntelliJ: Add to Settings | Tools | MCP Servers

json
{  "mcpServers": {    "argocd": {      "command": "uvx",      "args": ["mcp-argocd"],      "env": {        "ARGOCD_URL": "https://argocd.example.com",        "ARGOCD_TOKEN": "<token>"      }    }  }}

Gemini CLI

The repo ships gemini-extension.json; install it with the Gemini CLI extension flow.

pip / uv

bash
uvx mcp-argocd            # run without installingpip install mcp-argocd    # or install into an environment

Configuration

VariableRequiredDefaultDescription
ARGOCD_URLYes-Base URL including any path prefix. Also reads ARGOCD_SERVER.
ARGOCD_TOKENYes-Bearer token. Also reads ARGOCD_AUTH_TOKEN, ARGOCD_API_TOKEN.
ARGOCD_READ_ONLYNofalsetrue blocks the 9 write tools before any API call
ARGOCD_TIMEOUTNo30Request timeout in seconds
ARGOCD_SSL_VERIFYNotruefalse skips SSL verification (ARGOCD_INSECURE=true is an alias)
ARGOCD_APP_NAMESPACENo-Default appNamespace for apps-in-any-namespace installs

Getting an API token

Argo CD tokens come from a local account with the apiKey capability, or from a project role.

  1. Add a local account in argocd-cm: set accounts.ci-bot: apiKey.
  2. Generate a token: argocd account generate-token --account ci-bot --expires-in 24h.
  3. Set ARGOCD_URL and ARGOCD_TOKEN.

Minimum read-only RBAC:

p, role:mcp-ro, applications, get, */*, allowp, role:mcp-ro, logs, get, */*, allowp, role:mcp-ro, applicationsets, get, */*, allowp, role:mcp-ro, projects, get, *, allowp, role:mcp-ro, clusters, get, *, allowp, role:mcp-ro, repositories, get, *, allow

Compatibility

ComponentSupported
Argo CD3.3+ (OSS, Akuity, OpenShift GitOps); most tools also work on 2.x
Python3.10, 3.11, 3.12, 3.13, 3.14
Transportsstdio, streamable-http, sse (deprecated)
MCP spec2026-07-28 (MCP 2.0); compatible with 2025-11-25

Protocol support

Supports the MCP 2026-07-28 specification (MCP 2.0) and stays compatible with 2025-11-25 clients. Built on FastMCP 4.x. A regression test lists all 37 tools with an in-memory MCP client pinned to 2026-07-28. The sse transport is deprecated by the 2026-07-28 specification; it still works and prints a warning. The server uses no roots, sampling, logging, elicitation, or resource subscriptions.

Tools (37)

CategoryCount
Applications — read14
Applications — write8
ApplicationSets3
Projects2
Clusters3
Repositories3
Server and account4
Full tool reference (Click to expand)

Applications — read

  • argocd_list_applications — List applications with slim rows; filter by sync, health, destination.
  • argocd_get_application — Get one application: spec, sync/health, conditions, operation, counts.
  • argocd_get_resource_tree — Get the live resource tree as slim nodes.
  • argocd_get_managed_resources — Get live-vs-desired diffs for managed resources.
  • argocd_get_resource — Get a single managed resource's live manifest.
  • argocd_get_manifests — Get the rendered desired manifests for a revision.
  • argocd_get_application_events — Get Kubernetes events for an application.
  • argocd_get_pod_logs — Get container logs; never follows.
  • argocd_get_application_history — Get deployment history, newest first.
  • argocd_get_revision_metadata — Get commit metadata for a revision.
  • argocd_get_operation — Get the current or last sync operation.
  • argocd_wait_for_operation — Poll until an operation is terminal, gone, or times out.
  • argocd_get_sync_windows — Get sync windows and whether the app can sync now.
  • argocd_list_resource_actions — List the custom actions available on a resource.

Applications — write

  • argocd_sync_application — Sync an application; prune and force can delete or recreate resources.
  • argocd_rollback_application — Roll back to a prior deployment history entry.
  • argocd_terminate_operation — Terminate the running sync operation.
  • argocd_create_application — Create an application from flattened parameters.
  • argocd_patch_application — Patch an application; the one tool for every update.
  • argocd_delete_application — Delete an application.
  • argocd_run_resource_action — Run a custom resource action, such as restart.
  • argocd_delete_resource — Delete a single managed resource so the controller recreates it.

ApplicationSets

  • argocd_list_applicationsets — List ApplicationSets with slim rows.
  • argocd_get_applicationset — Get one ApplicationSet and the status of its generated apps.
  • argocd_generate_applicationset — Dry-run the generators to preview generated apps; creates nothing.

Projects

  • argocd_list_projects — List projects with slim rows.
  • argocd_get_project — Get a project's repos, destinations, and roles.

Clusters

  • argocd_list_clusters — List clusters with connection state, versions, and counts.
  • argocd_get_cluster — Get one cluster by name or server URL.
  • argocd_invalidate_cluster_cache — Invalidate a cluster's cached resources.

Repositories

  • argocd_list_repositories — List repositories; credentials are never returned.
  • argocd_get_repository_refs — Get a repository's branches and tags.
  • argocd_list_repository_apps — List the application paths discoverable in a repository.

Server and account

  • argocd_get_version — Get the Argo CD server version and bundled tool versions.
  • argocd_get_userinfo — Get the authenticated identity.
  • argocd_can_i — Check whether the account may perform a resource/action.
  • argocd_get_settings — Get server settings and enabled features.

Resources (7)

The server exposes curated GitOps rules and guides as MCP resources.

  • resource://rules/sync-safety — Sync Safety Rules.
  • resource://rules/rollback — Rollback Rules.
  • resource://rules/gitops-change-flow — GitOps Change Flow.
  • resource://rules/applicationsets — ApplicationSet Rules.
  • resource://guides/status-triage — Status Triage Guide.
  • resource://guides/rbac — RBAC and Permission Errors.
  • resource://guides/api-token-setup — API Token Setup.

Prompts (7)

The server provides MCP prompts — multi-tool workflow templates clients surface as slash commands.

  • triage_application — Diagnose a Degraded or OutOfSync application.
  • diagnose_sync_failure — Classify why the last sync failed.
  • review_drift — Review OutOfSync apps and recommend a fix.
  • safe_sync — Check sync windows, dry-run, then sync and wait.
  • rollback_application — Roll back with the auto-sync check.
  • fleet_status — Report clusters and apps that are not Synced/Healthy.
  • inspect_applicationset — Compare generated vs existing apps.

Usage Examples

  • Triage: "Why is payments Degraded?" runs triage_application — app conditions, unhealthy nodes, warning events, then pod logs.
  • Drift: "What has drifted in prod?" runs review_drift — lists OutOfSync apps and shows each diff.
  • Safe sync: "Sync web safely" runs safe_sync — checks sync windows, dry-runs, then syncs and waits.
  • Rollback: "Roll api back to the last good deploy" runs rollback_application — checks auto-sync first.
  • Fleet: "Show cluster health" runs fleet_status — clusters and the apps that are not healthy.

Security Considerations

  • Token scope: use the minimum RBAC the workflow needs. A read-only role needs applications, get and logs, get.
  • Read-only mode: ARGOCD_READ_ONLY=true blocks all 9 write tools before any API call.
  • SSL verification: on by default. Disable only for self-signed certificates in trusted networks.
  • Secret scrubbing: repository, cluster, and project payloads are scrubbed of credentials, cluster config, and role jwtTokens, even with full=True.
  • MCP tool annotations: every tool declares readOnlyHint, destructiveHint, and idempotentHint.
  • No credential storage: the server reads the token from the environment at startup and never persists it.
  • Destructive tools: argocd_sync_application, argocd_rollback_application, argocd_terminate_operation, argocd_delete_application, argocd_run_resource_action, argocd_delete_resource.

Permissions

OperationArgo CD RBAC resource, action
Read apps and resourcesapplications, get
Read pod logslogs, get
Syncapplications, sync
Override a revisionapplications, override
Roll backapplications, sync (or applications, rollback when enforced)
Delete an appapplications, delete
Run a resource actionapplications, action/<group>/<kind>/<action>
Read clusters, projects, reposclusters, get / projects, get / repositories, get

CLI & Transport Options

bash
uvx mcp-argocd                                   # stdio (default)uvx mcp-argocd --transport streamable-http --port 9000uvx mcp-argocd --transport sse                   # deprecated; prints a warninguvx mcp-argocd --read-only --insecure

FAQ

Does mcp-argocd support MCP 2026-07-28 (MCP 2.0)? Yes. It supports the MCP 2026-07-28 specification, often called MCP 2.0, and stays compatible with 2025-11-25 clients.

How is it different from argoproj-labs/mcp-for-argocd? argoproj-labs/mcp-for-argocd is the official TypeScript server with 15 tools. mcp-argocd adds 37 tools with slim payloads by default, plus diff, rollback, terminate, wait-for-operation, ApplicationSet dry-run, and RBAC error hints.

Which Argo CD versions work? Argo CD 3.3 and newer. Most tools also work on 2.x; only run_resource_action uses a 3.x endpoint.

Does it need kubectl or cluster credentials? No. It talks to the Argo CD API over HTTPS with a bearer token. It never touches the cluster directly.

Is it safe for read-only use? Yes. Set ARGOCD_READ_ONLY=true. The server blocks all nine write tools before any API call.

Which token does it need? It needs a bearer token in ARGOCD_TOKEN. Generate one from a local account with the apiKey capability, or use a project-role token. It also reads ARGOCD_AUTH_TOKEN and ARGOCD_API_TOKEN.

Why do I get a 403 for an app that exists? Without project, Argo CD returns 403 for an app that does not exist. Pass project to get a real 404.

Can it sync only one resource? Yes. Pass resources to argocd_sync_application with [group:]kind:name[/namespace] selectors.

Can it roll back? Yes. Use argocd_rollback_application with a history id. It refuses while auto-sync is on and tells you how to disable it.

How does it keep responses small? Every tool returns a slim payload by default and pages lists client-side. Pass full=True for the raw payload.

Which transports? stdio, streamable-http, and sse. sse is deprecated by the 2026-07-28 spec but still works.

How do I install? Run uvx mcp-argocd, or add it to your MCP client config.

Related MCP Servers

  • mcp-gitlab — GitLab integration (83 tools, 7 resources, 6 prompts)
  • mcp-atlassian-extended — Jira + Confluence integration (22 tools, 15 resources, 5 prompts)
  • mcp-coda — Coda integration (53 tools, 12 resources, 5 prompts)

Development

bash
git clone https://github.com/vish288/mcp-argocd.gitcd mcp-argocduv sync --all-extras
uv run pytest --covuv run ruff check .uv run ruff format --check .

License

MIT — see LICENSE.

來源:README.md,提交 e543ffb

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.0最新Oct 6, 2026