# get_cluster

Gets the details of a specific GKE cluster.

Agent View of the PolicyLayer registry record for `get_cluster`. HTML page: https://policylayer.com/tools/com-googleapis-container-mcp/get-cluster

## Facts

- Tool: `get_cluster`
- Server: Mcp (`https://container.googleapis.com/mcp`) — https://policylayer.com/tools/com-googleapis-container-mcp.md
- Homepage: https://github.com/https://container.googleapis.com/mcp
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 2 (1 required)
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `name` | string | yes | Required. The name (project, location, cluster) of the cluster to retrieve. Specified in the format `projects/*/locations/*/clusters/*`. |
| `readMask` | string | no | Optional. The field mask to specify the fields to be returned in the response. Use a single "*" to get all fields. Default: autopilot,createTime,currentMasterVe |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_cluster",
    "arguments": {
      "name": "<name>"
    }
  }
}
```

## Why get_cluster is rated Low

This tool retrieves and returns cluster information (name, configuration, status, etc.) without creating, modifying, deleting, or executing operations. It is a pure query operation with no side effects. Even if an AI agent misuses it by requesting sensitive cluster details, the blast radius is limited to information disclosure—no resources are altered or destroyed.

From the tool's own definition: "Tool name 'get_cluster' and description 'Gets the details of a specific GKE cluster' indicate retrieval of cluster metadata without modification."

## Use case

AI agents call get_cluster to retrieve information from Mcp without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Mcp:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "get_cluster": {}
  }
}
```

## Other tools on Mcp (22)

- `delete_k8s_resource` — Destructive — https://policylayer.com/tools/com-googleapis-container-mcp/delete-k8s-resource.md
- `cancel_operation` — Execute — https://policylayer.com/tools/com-googleapis-container-mcp/cancel-operation.md
- `check_k8s_auth` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/check-k8s-auth.md
- `describe_k8s_resource` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/describe-k8s-resource.md
- `get_k8s_cluster_info` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-cluster-info.md
- `get_k8s_logs` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-logs.md
- `get_k8s_resource` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-resource.md
- `get_k8s_rollout_status` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-rollout-status.md
- `get_k8s_version` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-version.md
- `get_node_pool` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-node-pool.md
- `get_operation` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-operation.md
- `list_clusters` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-clusters.md
- `list_k8s_api_resources` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-k8s-api-resources.md
- `list_k8s_events` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-k8s-events.md
- `list_node_pools` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-node-pools.md
- `list_operations` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-operations.md
- `apply_k8s_manifest` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/apply-k8s-manifest.md
- `create_cluster` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/create-cluster.md
- `create_node_pool` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/create-node-pool.md
- `patch_k8s_resource` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/patch-k8s-resource.md
- `update_cluster` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/update-cluster.md
- `update_node_pool` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/update-node-pool.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=com-googleapis-container-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/com-googleapis-container-mcp
