Building MCP Servers for Ops Systems
Learn to build an MCP server that gives AI agents safe, read-only access to Kubernetes, Prometheus, and runbooks, with least-privilege RBAC.
What You'll Learn
Understanding Why an Ops Agent Needs an MCP Server
What an MCP server is and what problem it solves An MCP server is a small program that exposes tools to AI applications over one standard protocol...
Designing a Safe Tool Surface
Read, write, and escalate: the three kinds of tool A tool surface should separate tools that only look from tools that change things.
Giving the Server Least-Privilege Access
Why Kubernetes RBAC only adds permissions Kubernetes RBAC (role-based access control) is a list of things an identity is allowed to do.
Building the Server with FastMCP
Installing the SDK and choosing a version The official MCP Python SDK includes a high-level server class that turns ordinary Python functions into...
Testing the Server Before Any Agent Touches It
Checking tools with the MCP Inspector The MCP Inspector is a browser tool that connects to your server, lists its tools, and lets you call each one...
Connecting an Agent Through llm.py
Turning MCP tools into model tool definitions An MCP tool carries a name, a description, and a JSON schema.
Skills You'll Master
Curriculum Index9 topics
Understanding Why an Ops Agent Needs an MCP Server
What an MCP server is and what problem it solves An MCP server is a small program that exposes tools to AI applications...
Designing a Safe Tool Surface
Read, write, and escalate: the three kinds of tool A tool surface should separate tools that only look from tools that...
Giving the Server Least-Privilege Access
Why Kubernetes RBAC only adds permissions Kubernetes RBAC (role-based access control) is a list of things an identity...
Building the Server with FastMCP
Installing the SDK and choosing a version The official MCP Python SDK includes a high-level server class that turns...
Testing the Server Before Any Agent Touches It
Checking tools with the MCP Inspector The MCP Inspector is a browser tool that connects to your server, lists its...
Connecting an Agent Through llm.py
Turning MCP tools into model tool definitions An MCP tool carries a name, a description, and a JSON schema.
Adding the Optional Write Tool
Why restart_deployment is off by default The server only registers restart_deployment when ENABLE_WRITES=1 is set, and...
Hands-on Lab: Investigate a Pool Exhaustion Through MCP
This lab runs on the aiops-lab kit. If it is not running, set it up first by following Data Pipelines for AIOps (Apache...
Quick Reference and Common Mistakes
Quick reference Common mistakes when building MCP servers Treating an RBAC rule as a deny rule.
Career Impact
Roles that use the skills in this module.
- High Demand
AIOps Engineer
₹18L - ₹35L a year
- High Demand
AI Platform Engineer
₹20L - ₹40L a year
- Growing
Platform Engineer
₹15L - ₹28L a year
Next Modules
Related Guides
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding Sheet