# delete_k8s_resource

Deletes a Kubernetes resource from a cluster. This is similar to running kubectl delete.

Agent View of the PolicyLayer registry record for `delete_k8s_resource`. HTML page: https://policylayer.com/tools/com-googleapis-container-mcp/delete-k8s-resource

## Facts

- Tool: `delete_k8s_resource`
- Server: Mcp (`https://container.googleapis.com/mcp`) — https://policylayer.com/tools/com-googleapis-container-mcp.md
- Homepage: https://github.com/https://container.googleapis.com/mcp
- Risk category: Destructive (Critical risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 6 (3 required)
- Recommended policy verdict: Hidden

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `name` | string | yes | Required. The name of the resource to delete. |
| `dryRun` | boolean | no | Optional. If true, run in dry-run mode. |
| `parent` | string | yes | Required. The cluster, which owns this collection of resources. Format: projects/{project}/locations/{location}/clusters/{cluster} |
| `cascade` | string | no | Optional. The cascading deletion policy to use. If not specified, 'background' is used. Valid values are 'background', 'foreground', and 'orphan'. |
| `namespace` | string | no | Optional. The namespace of the resource. If not specified, "default" is used. |
| `resourceType` | string | yes | Required. The type of resource to delete. Kubernetes resource/kind name in singular form, lower case. e.g. "pod", "deployment", "service". |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "delete_k8s_resource",
    "arguments": {
      "name": "<name>",
      "parent": "<parent>",
      "resourceType": "<resourceType>"
    }
  }
}
```

## Why delete_k8s_resource is rated Critical

This tool permanently removes Kubernetes resources (pods, deployments, services, etc.) from a cluster with no built-in undo mechanism. Deletion of cluster resources cannot be reversed and can cause immediate service outages, data loss, and infrastructure failure. An AI agent with access could maliciously or accidentally destroy critical production workloads. This is the most severe category applicable.

From the tool's own definition: "Tool name is 'delete_k8s_resource' and description explicitly states 'Deletes a Kubernetes resource from a cluster."

## Use case

AI agents call delete_k8s_resource to permanently remove resources in Mcp, typically in cleanup and lifecycle workflows. It does its job in a single call, and there is no undo.

## Recommended policy (PolicyLayer)

Verdict: **Hidden**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Mcp:

```json
{
  "version": "1",
  "default": "deny",
  "hide": [
    "delete_k8s_resource"
  ]
}
```

## Other tools on Mcp (22)

- `cancel_operation` — Execute — https://policylayer.com/tools/com-googleapis-container-mcp/cancel-operation.md
- `check_k8s_auth` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/check-k8s-auth.md
- `describe_k8s_resource` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/describe-k8s-resource.md
- `get_cluster` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-cluster.md
- `get_k8s_cluster_info` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-cluster-info.md
- `get_k8s_logs` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-logs.md
- `get_k8s_resource` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-resource.md
- `get_k8s_rollout_status` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-rollout-status.md
- `get_k8s_version` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-version.md
- `get_node_pool` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-node-pool.md
- `get_operation` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-operation.md
- `list_clusters` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-clusters.md
- `list_k8s_api_resources` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-k8s-api-resources.md
- `list_k8s_events` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-k8s-events.md
- `list_node_pools` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-node-pools.md
- `list_operations` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-operations.md
- `apply_k8s_manifest` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/apply-k8s-manifest.md
- `create_cluster` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/create-cluster.md
- `create_node_pool` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/create-node-pool.md
- `patch_k8s_resource` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/patch-k8s-resource.md
- `update_cluster` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/update-cluster.md
- `update_node_pool` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/update-node-pool.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=com-googleapis-container-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/com-googleapis-container-mcp
