New Your team’s decisions, in one playbook every coding agent works from. Never answer your agent twice

check_k8s_auth

Checks whether an action is allowed on a Kubernetes resource. This is similar to running kubectl auth can-i.

SERVERMcp SOURCEhttps://container.googleapis.com/mcp
Low RISK CLASS
Category Read
Parameters 53 required
Recommended Allowedsee the rule below
Registry record Grade F, identity unverified Pull the record →

This record as markdown: /tools/com-googleapis-container-mcp/check-k8s-auth.md

What check_k8s_auth does on Mcp

AI agents call check_k8s_auth to retrieve information from Mcp without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

ParameterTypeRequiredDescription
verb string Yes Required. The verb to check. e.g. "get", "list", "watch", "create", "update", "patch", "delete".
parent string Yes Required. The cluster to check authorization against. Format: projects/{project}/locations/{location}/clusters/{cluster}
resource string Optional. The name of the resource to check.
namespace string Optional. The namespace of the resource. If not specified, "default" is used for namespace-scoped resources.
resourceType string Yes Required. The type of resource to check. e.g. "pods", "deployments", "services".

Parameters from the server's own tool schema.

Why check_k8s_auth is rated Low

This tool queries authorization status without executing, creating, modifying, or deleting resources. It is purely informational and has no side effects. The kubectl auth can-i command is explicitly a read-only audit mechanism. While the sibling tools on this server include destructive operations (delete_k8s_resource, create_cluster), this specific tool only reads and reports permission information.

From the tool's definition Tool description states it 'Checks whether an action is allowed' and is 'similar to running `kubectl auth can-i`'. The `can-i` command is a read-only authorization check that returns yes/no without performing any action or modifying state.

Questions about check_k8s_auth

What does the check_k8s_auth tool do? +

Checks whether an action is allowed on a Kubernetes resource. This is similar to running kubectl auth can-i. It is categorised as a Read tool in the Mcp MCP Server, which means it retrieves data without modifying state.

What parameters does check_k8s_auth accept? +

check_k8s_auth accepts 5 parameters: verb, parent, resource, namespace, resourceType. Required: verb, parent, resourceType. The full parameter table on this page comes from the server's own tool schema.

How do I enforce a policy on check_k8s_auth? +

Register the MCP server in PolicyLayer and add a rule for check_k8s_auth: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Mcp. Nothing to install.

What risk level is check_k8s_auth? +

check_k8s_auth is a Read tool with low risk. Read-only tools are generally safe to allow by default.

Can I rate-limit check_k8s_auth? +

Yes. Add a rate_limit block to the check_k8s_auth rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.

How do I block check_k8s_auth completely? +

Set action: deny in the PolicyLayer policy for check_k8s_auth. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.

What MCP server provides check_k8s_auth? +

check_k8s_auth is provided by the MCP server (https://container.googleapis.com/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.

More on , and thousands of servers like it.

This server

Across the catalogue

// THE MCP REGISTRY

PolicyLayer tracks 44,603 MCP servers and 515,000+ tools.

Every server has a live record: who publishes it, whether it answers without auth, its risk grade, every tool classified, the recommended policy. This page is one line of 's. Pull the full record:

Teams ship this data inside their own products. See what a licence covers →

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.