edit_k8s_cluster
Редактирует имя, описание или OIDC-провайдера кластера. Другие параметры (версия, ноды) изменяются отдельными инструментами.
This record as markdown: /tools/timeweb-mcp/edit-k8s-cluster.md
What edit_k8s_cluster does on Timeweb
AI agents use edit_k8s_cluster to create or update resources in Timeweb, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Timeweb environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
name | string | — | Новое имя кластера |
cluster_id | integer | Yes | ОБЯЗАТЕЛЬНОЕ ПОЛЕ - ID кластера |
description | string | — | Новое описание |
oidc_provider | object | — | OIDC-провайдер: name, issuer_url, client_id (+ опц. username_claim, groups_claim) |
Parameters from the server's own tool schema.
Why edit_k8s_cluster is rated Medium
Инструмент позволяет модифицировать параметры Kubernetes кластера (имя, описание, OIDC-провайдер). Это обратимые изменения конфигурации без удаления ресурсов, что соответствует категории Write. Severity - medium, так как неправильное изменение OIDC-провайдера может нарушить аутентификацию кластера, но это не является финансовым убытком или необратимым удалением.
From the tool's definition edit_k8s_cluster: описание указывает на редактирование (Редактирует) имени, описания и OIDC-провайдера кластера. Это изменение конфигурации, а не удаление.
Attacks that exploit this kind of access
The rule that runs edit_k8s_cluster safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Timeweb, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For edit_k8s_cluster, this is the rule to start with:
edit_k8s_cluster stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Timeweb, apply this rule, and every edit_k8s_cluster call is checked against it from then on.
Questions about edit_k8s_cluster
Редактирует имя, описание или OIDC-провайдера кластера. Другие параметры (версия, ноды) изменяются отдельными инструментами. It is categorised as a Write tool in the Timeweb MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
edit_k8s_cluster accepts 4 parameters: name, cluster_id, description, oidc_provider. Required: cluster_id. The full parameter table on this page comes from the server's own tool schema.
Register the Timeweb MCP server in PolicyLayer and add a rule for edit_k8s_cluster: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Timeweb. Nothing to install.
edit_k8s_cluster is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the edit_k8s_cluster rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for edit_k8s_cluster. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
edit_k8s_cluster is provided by the Timeweb MCP server (timeweb-mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Timeweb, and thousands of servers like it.
This server
Across the catalogue