CNCF Tech Advisor MCP Server
A Model Context Protocol server that gives a languagemodel read-only access to the public CNCF Landscape: 2,400+cloud native projects and products with category, maturity, GitHub stars, contributors,latest release, license, homepage and repository.
Java 25 · Quarkus 3.33 LTS · quarkus-mcp-server 2.0.1 (MCP specification 2026-07-28,Streamable HTTP and stdio) · native executable via GraalVM/Mandrel.
Tools
| Tool | What it does |
|---|---|
search_cncf(query?, category?, limit?) |
Keyword and/or exact-category search; popular and graduated projects rank higher. |
get_cncf_project(projectName) |
Full detail of one project by its exact name (case-insensitive). |
list_cncf_categories() |
Every category with its project count. |
refresh_cncf_data() |
Ask the landscape whether the in-memory catalogue is current (updated / unchanged / throttled). |
Every value the landscape publishes is third-party content — the landscape is a publicrepository that accepts pull requests — so every tool renders it sanitized, inside a fencecarrying a per-response nonce, and tells the model not to follow instructions found inside.The same sanitized record feeds the text and the structuredContent channel.
Run
Requires Java 25 (only the build and the JVM run; the native executable needs no Java).
git clone https://github.com/labjp-mcp/cncf-tech-advisor-mcp.git
cd cncf-tech-advisor-mcp
./mvnw package -DskipTests
java -jar target/quarkus-app/quarkus-run.jar # stdio (default): for Claude Desktop, Claude Code, ...
Claude Code: claude mcp add cncf -- java -jar /path/to/target/quarkus-app/quarkus-run.jar.
Streamable HTTP (for the MCP Inspector or a gateway), endpoint http://127.0.0.1:8080/mcp:
java -Dquarkus.http.host-enabled=true -Dquarkus.mcp.server.stdio.enabled=false \
-jar target/quarkus-app/quarkus-run.jar
Native executable (starts in ~30 ms, useful on stdio where the client launches the processper session):
./mvnw package -Pnative -DskipTests # needs GraalVM or Mandrel for Java 25
./target/cncf-tech-advisor-mcp-1.0.0-runner
scripts/mcp-native-parity.sh # proves JVM and native publish the same catalogue
Containers: docker build -t cncf-tech-advisor-mcp . (JVM, builds inside the image) orsrc/main/docker/Dockerfile.native / Dockerfile.native-micro (package a host-builttarget/*-runner). Both images serve HTTP on 0.0.0.0:8080; run them asdocker run --rm -p 127.0.0.1:8080:8080 cncf-tech-advisor-mcp and put a network boundaryin front — the server has no authentication of its own.
Releases: a vX.Y.Z tag runs .github/workflows/release.yml, which attaches aself-contained cncf-tech-advisor-mcp.jar (java -jar, stdio) and native executables forLinux x64 and macOS arm64 to the GitHub Release, and pushes the JVM image toghcr.io/labjp-mcp/cncf-tech-advisor-mcp:X.Y.Z. Assets of releases older than thisworkflow (v1.0.0) were built for the former npm wrapper. There is no npm package to install.
Configuration
All in src/main/resources/application.properties; override with -D or environment.
| Key | Default | Meaning |
|---|---|---|
cncf.landscape.base-url |
https://landscape.cncf.io |
Site root; /data/full.json is fixed in code. |
cncf.landscape.request-timeout |
PT60S |
Deadline for the whole download, body included. |
cncf.landscape.max-bytes |
16777216 |
Largest body accepted, compressed or inflated. |
cncf.landscape.cache-ttl (CNCF_CACHE_TTL) |
PT1H |
How long a loaded catalogue is served without asking upstream. |
cncf.landscape.failure-backoff |
PT30S |
No retry after a failed download for this long. |
cncf.landscape.min-force-interval |
PT30S |
refresh_cncf_data is refused inside this window. |
mcp.rate-limit.calls-per-minute (MCP_RATE_LIMIT) |
120 |
Per caller (remote address); 0 disables. |
quarkus.http.host |
127.0.0.1 |
Loopback by default; the images set 0.0.0.0. |
quarkus.http.cors.origins (MCP_ALLOWED_ORIGINS) |
http://localhost:6274 |
Exact origins, never *. |
The download is conditional (If-None-Match; the landscape's CDN answers 304) andgzip-encoded (≈0.85 MB instead of 3.8 MB). A sequence of tool calls costs one download percache-ttl; see SECURITY-PENTEST.md for the measurements.
Develop
./mvnw clean verify # 172 tests; a WireMock stands in for the landscape, nothing reaches cncf.io
./mvnw quarkus:dev # HTTP on, INFO logs
make help
Logging is INFO on stderr, one audit line per tool call(tool=search_cncf source=127.0.0.1 outcome=ok ms=12 arg="kube"); stdout carries only theprotocol on stdio.
Documents: CLAUDE.md (architecture, conventions, rules), SECURITY-PENTEST.md (threatmodel, attack catalogue with reproducible commands, residual risks), CHANGELOG.md.
Legacy files
npm/, bin/, test/*.js, test-mcp*.js, docker/, install-claude-desktop.*,scripts/{build-npm,cross-build,deploy}.sh, claude-*-config.json and package.jsonbelong to an earlier npm-wrapper distribution that is not built, tested or published bythis repository today. They are kept for reference only.
License
Apache-2.0 — see LICENSE.