MCP Kubernetes tools fail to authenticate in EKS environments due to missing aws CLI in distroless image
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 48/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Tranquilla
- Stack tecnologico
- aws, docker, kubernetes
- Ambito
- authentication, cloud, devops
Direzione di ricerca
Inizia riproducendo il malfunzionamento con l’immagine ghcr.io/kagent-dev/kagent/tools:0.1.3 e un kubeconfig che utilizzi il comando exec aws eks get-token. Controlla i binari disponibili nell’immagine e i log del server MCP; il lavoro è completato quando un’immagine completa o di strumenti cloud può eseguire aws e scoprire strumenti tramite l’API EKS.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Description
When using the official Kagent tools image (ghcr.io/kagent-dev/kagent/tools) in an EKS environment to manage remote or cross-account clusters, authentication fails because the image lacks the necessary binary dependencies.
Most EKS kubeconfig configurations rely on the client.authentication.k8s.io/v1 exec plugin to dynamically fetch authentication tokens using the AWS CLI (e.g., command: aws). Because the current official image is distroless, it does not include the aws binary, preventing the MCP server from authenticating with the target Kubernetes API.
Steps to Reproduce
Deploy an MCPServer using the ghcr.io/kagent-dev/kagent/tools image.
Provide a kubeconfig via a Secret that uses the aws eks get-token exec command for authentication.
Observe the Kagent Dashboard or logs shows 0 tools
Expected Behavior
The MCP server should be able to execute the aws command defined in the kubeconfig to retrieve a valid token and connect to the cluster.
Actual Behavior
The MCP server fails to authenticate because the aws binary is not found in the container's $PATH. As a result, the server reports 0 tools discovered because it cannot reach the Kubernetes API.
Impact
Users are unable to use the native Kagent tools image for managing EKS clusters without building a custom image that includes the AWS CLI and its dependencies.
Suggested Fix/Workaround
Feature Request: Provide a "full" or "cloud" version of the tools image (e.g., tools:0.1.3-full) that includes common cloud CLIs like aws, gcloud, and az.
Current Workaround: Users must manually use a base image like debian or golang, install the AWS CLI at runtime, and download the tools binary.
Technical Summary for Maintainers
Image: ghcr.io/kagent-dev/kagent/tools:0.1.3
Error Context: exec: "aws": executable file not found in $PATH
Environment: EKS Cross-Account / Remote Cluster Management via IRSA.
- Lingua principale
- Go
- Stelle
- 36
- Fork
- 29
- Merge medio
- 3g 23h
- PR unite (30g)
- 3
Preparare l'ambiente
Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.
- Include un Dockerfile o un file Docker Compose
- Nessun modello di pull request
- Nessuna guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di kagent-dev/tools
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
kagent-dev/tools#87 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
kagent-dev/tools#54 ·
-
[FEATURE] Add a limit parameter to k8s_get_resources to bound context growthForse già presa @anjosluc l’ha presa 20 giorni fa. Aperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
kagent-dev/tools#82 ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 78/100
kagent-dev/tools#80 ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 72/100
kagent-dev/tools#69 · 1 commento ·
Tutte le issue di kagent-dev/tools
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
shukiv/jabali-panel#2029 ·
I maintainer di solito rispondono entro 1 giorno
-
[submenu] nil issue on ubuntu 26.04Forse già presa @egoist l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
prime-radiant-inc/evener#3873 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
v2fly/domain-list-community#4127 ·
I maintainer di solito rispondono entro 2 giorni
-
extract_llm_sweep / cache_aware_summarizer prefix ask 400s when thinking.budget_tokens exceeds PrefixAskMaxTokensForse già presa @amiddavid l’ha presa oggi. Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
rossoctl/context-guru#405 ·
I maintainer di solito rispondono entro 1 giorno