# list_k8s_api_resources

Retrieves the available API groups and resources from a Kubernetes cluster. This is similar to running kubectl api-resources.

Agent View of the PolicyLayer registry record for `list_k8s_api_resources`. HTML page: https://policylayer.com/tools/com-googleapis-container-mcp/list-k8s-api-resources

## Facts

- Tool: `list_k8s_api_resources`
- Server: Mcp (`https://container.googleapis.com/mcp`) — https://policylayer.com/tools/com-googleapis-container-mcp.md
- Homepage: https://github.com/https://container.googleapis.com/mcp
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 1 (1 required)
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `parent` | string | yes | Required. The cluster, which owns this collection of resource types. Format: projects/{project}/locations/{location}/clusters/{cluster} |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "list_k8s_api_resources",
    "arguments": {
      "parent": "<parent>"
    }
  }
}
```

## Why list_k8s_api_resources is rated Low

This tool queries metadata about available Kubernetes API resources without modifying state, executing workloads, or accessing sensitive data beyond cluster schema information. The blast radius of misuse is minimal—an attacker gains only knowledge of what resource types exist in the cluster, not access to actual resources or their data. This is informational read-access only.

From the tool's own definition: "Tool name contains 'list' and description states 'Retrieves the available API groups and resources' with no mention of modification, deletion, or execution. Analogous to `kubectl api-resources` which is a read-only introspection command."

## Use case

AI agents call list_k8s_api_resources to retrieve information from Mcp without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Mcp:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "list_k8s_api_resources": {}
  }
}
```

## Other tools on Mcp (22)

- `delete_k8s_resource` — Destructive — https://policylayer.com/tools/com-googleapis-container-mcp/delete-k8s-resource.md
- `cancel_operation` — Execute — https://policylayer.com/tools/com-googleapis-container-mcp/cancel-operation.md
- `check_k8s_auth` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/check-k8s-auth.md
- `describe_k8s_resource` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/describe-k8s-resource.md
- `get_cluster` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-cluster.md
- `get_k8s_cluster_info` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-cluster-info.md
- `get_k8s_logs` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-logs.md
- `get_k8s_resource` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-resource.md
- `get_k8s_rollout_status` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-rollout-status.md
- `get_k8s_version` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-k8s-version.md
- `get_node_pool` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-node-pool.md
- `get_operation` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/get-operation.md
- `list_clusters` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-clusters.md
- `list_k8s_events` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-k8s-events.md
- `list_node_pools` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-node-pools.md
- `list_operations` — Read — https://policylayer.com/tools/com-googleapis-container-mcp/list-operations.md
- `apply_k8s_manifest` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/apply-k8s-manifest.md
- `create_cluster` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/create-cluster.md
- `create_node_pool` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/create-node-pool.md
- `patch_k8s_resource` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/patch-k8s-resource.md
- `update_cluster` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/update-cluster.md
- `update_node_pool` — Write — https://policylayer.com/tools/com-googleapis-container-mcp/update-node-pool.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=com-googleapis-container-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/com-googleapis-container-mcp
