# apply_k8s_manifest

Applies a Kubernetes manifest to a cluster using server-side apply. This is similar to running kubectl apply --server-side.

Agent View of the PolicyLayer registry record for `apply_k8s_manifest`. HTML page: https://policylayer.com/tools/com-googleapis-container-mcp/apply-k8s-manifest

## Facts

- Tool: `apply_k8s_manifest`
- Server: Mcp (`https://container.googleapis.com/mcp`) — https://policylayer.com/tools/com-googleapis-container-mcp.md
- Homepage: https://github.com/https://container.googleapis.com/mcp
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 4 (2 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `dryRun` | boolean | no | Optional. If true, run in dry-run mode. |
| `parent` | string | yes | Required. The cluster to apply the manifest to. Format: projects/{project}/locations/{location}/clusters/{cluster} |
| `yamlManifest` | string | yes | Required. The YAML manifest to apply. |
| `forceConflicts` | boolean | no | Optional. If true, force conflicts resolution when applying. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "apply_k8s_manifest",
    "arguments": {
      "parent": "<parent>",
      "yamlManifest": "<yamlManifest>"
    }
  }
}
```

## Why apply_k8s_manifest is rated Medium

Applying a Kubernetes manifest creates or modifies resources in a cluster (deployments, services, configs, RBAC rules, etc.). This is a Write operation since `kubectl apply` is additive/updating and generally reversible, but it carries high severity because misuse could reconfigure critical cluster workloads, expose services, escalate privileges, or alter security policies across the cluster.

From the tool's own definition: "Applies a Kubernetes manifest to a cluster using server-side apply. This is similar to running `kubectl apply --server-side`."

## Use case

AI agents use apply_k8s_manifest to create or update resources in Mcp, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Mcp environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Mcp:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "apply_k8s_manifest": {
      "limits": [
        {
          "counter": "apply_k8s_manifest_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Mcp (22)

- `delete_k8s_resource` — Destructive — https://policylayer.com/tools/com-googleapis-container-mcp/delete-k8s-resource.md
- `cancel_operation` — Execute — https://policylayer.com/tools/com-googleapis-container-mcp/cancel-operation.md
- `check_k8s_auth` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/check-k8s-auth.md
- `describe_k8s_resource` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/describe-k8s-resource.md
- `get_cluster` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-cluster.md
- `get_k8s_cluster_info` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-cluster-info.md
- `get_k8s_logs` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-logs.md
- `get_k8s_resource` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-resource.md
- `get_k8s_rollout_status` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-rollout-status.md
- `get_k8s_version` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-version.md
- `get_node_pool` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-node-pool.md
- `get_operation` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-operation.md
- `list_clusters` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-clusters.md
- `list_k8s_api_resources` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-k8s-api-resources.md
- `list_k8s_events` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-k8s-events.md
- `list_node_pools` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-node-pools.md
- `list_operations` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-operations.md
- `create_cluster` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/create-cluster.md
- `create_node_pool` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/create-node-pool.md
- `patch_k8s_resource` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/patch-k8s-resource.md
- `update_cluster` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/update-cluster.md
- `update_node_pool` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/update-node-pool.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=com-googleapis-container-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/com-googleapis-container-mcp
