kubeshark
eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via MCP and humans via dashboard.
The Kubeshark MCP server enables AI agents to query and analyze Kubernetes cluster network traffic through natural language. Built on eBPF kernel-level packet capture, it indexes L4 and L7 traffic with full Kubernetes context and automatically decrypts TLS without requiring keys or sidecars. Agents can investigate API calls, trace requests across services, analyze error rates, and perform root cause analysis by querying network data using Kubeshark's protocol-aware indexing and KFL query language. Works with Claude, Cursor, and any MCP-compatible client.
Key Features
Use Cases
- 01Investigating production incidents by asking AI to trace failed requests through microservices
- 02Analyzing service error rates and latency patterns through natural language queries
- 03Performing root cause analysis on network-related issues without manual PCAP inspection
- 04Identifying TCP retransmissions and network bottlenecks across node-to-node communication
- 05Debugging API integration issues by querying decrypted traffic between specific workloads
- 06Generating retrospective PCAPs for compliance and security audits with full TLS visibility
Related MCP Servers
View moremarkitdown
Python tool for converting files and office documents to Markdown.
firecrawl
The context API to search, scrape, and interact with the web at scale. 🔥
prompts.chat
f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete privacy.
langflow
Langflow is a powerful tool for building and deploying AI-powered agents and workflows.
kubeshark — FAQ
What is the Kubeshark MCP server?+
The Kubeshark MCP server is a Model Context Protocol interface that exposes Kubernetes cluster network traffic data to AI agents. It allows agents to query captured packets, API calls, and network patterns using natural language, enabling automated investigation and root cause analysis.
How do I install and connect Kubeshark to Claude?+
First install Kubeshark and deploy it to your cluster via Helm. Then install the Kubeshark CLI locally and add it as an MCP server to Claude using 'claude mcp add kubeshark -- kubeshark mcp'. The MCP server connects Claude to your cluster's live network data.
Which AI clients work with Kubeshark MCP server?+
Kubeshark works with Claude Code, Claude Desktop, Cursor, and any other MCP-compatible AI client. The README specifically mentions compatibility with Claude and Copilot for AI-driven workflows.
Do I need API keys or special prerequisites?+
You need a running Kubernetes cluster with kubectl access and Helm installed. Kubeshark uses eBPF which requires kernel support (Linux 4.14+). No external API keys are required since it runs entirely on-premises within your cluster.
Is Kubeshark free and open source?+
Yes, Kubeshark is open source under the Apache-2.0 license. It supports 100% on-premises deployment with air-gapped environments and has no external dependencies or licensing costs.
How does Kubeshark decrypt TLS traffic without certificates?+
Kubeshark uses eBPF to hook into the kernel and capture traffic at the encryption boundary, before it's encrypted or after it's decrypted in memory. This eliminates the need for certificate management, sidecars, or man-in-the-middle proxies.
How do I install kubeshark?+
Open the source repository on GitHub and follow its README. kubeshark is a mcp server — MCP Agents Market links you directly to the official repo.
Is kubeshark free?+
kubeshark is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.