Release notes ClusterControl MCP
The ClusterControl MCP Server is versioned and released independently of the main ClusterControl components, as clustercontrol-mcp-1.0.0-N builds. This page is the running release history for the MCP Server. The initial launch (clustercontrol-mcp-1.0.0-5, May 4th, 2026) is documented in the v2.4.0 release notes.
Feature Release: Access controls, audit logging and offline docs
- Build:
- clustercontrol-mcp-1.0.0-90
This release adds the controls needed to connect an AI assistant to a production controller: the server can now refuse actions itself, rather than relying on the client to respect an advisory hint.
- Global read-only mode (
MCP_READ_ONLY) — refuses all 29 state-changing tools for the lifetime of the process. Enforced on two independent layers: the write tools are hidden from the client's tool list, and a direct call on one is refused, so a client that calls a tool it was never shown is still refused. (CLUS-8099) - Per-tool and per-resource scoping (
MCP_TOOL_ALLOW,MCP_TOOL_DENY) — expose only the tools you name. Deny wins over allow, the two compose with read-only mode, and resource surfaces follow their tools automatically. An entry matching no tool is a startup error rather than a silent no-op. (CLUS-8100) - Audit log (
MCP_AUDIT_LOG) — every tool call and resource read recorded twice as JSONL, anintentrecord before the action and acompletionafter, with a thirdacceptancerecord on the background-task path. Raw arguments are never written; what is recorded is a keyed digest, so a reader of the log cannot work backwards to a password. Auditing is fail-closed: if theintentrecord cannot be written, the action does not run. (CLUS-8103) - Export directory containment (
MCP_EXPORT_DIR) — the three tools that write to the MCP Server's own filesystem are confined to one directory, whatever path the client asks for. (CLUS-8581) search_docs— ranked excerpts from a ClusterControl documentation bundle shipped inside the package. No network calls, so it works in an air-gapped installation. (CLUS-8104, CLUS-8105)get_incident_bundle— one read-only call returning alarms, recent jobs, collected log tails, a metric summary with outlier flags, and topology. Every section is always present and explicitly marked[error],[empty]or[truncated], so a section missing because a source failed cannot be mistaken for one that was empty. (CLUS-8106)- The tool registry grows from 70 to 72 tools (43 pure-read, 26 CMON-mutating, 3 local-filesystem-writing; 22 flagged destructive), with 21 resource surfaces unchanged.
- Local file writes are confined by default. A server whose configuration is untouched will begin refusing destination paths outside
/var/lib/cmon-mcp/exports— including paths such as/tmpthat previously worked. SetMCP_EXPORT_DIRto the directory your callers already use to keep their existing paths valid. (CLUS-8581) - A fresh install is audited by default. First installs provision a digest key and switch auditing on. Upgrades enable nothing, because a host that has never been audited has no key and a server told to audit without one refuses to start. Set
MCP_AUDIT_LOG=offin/etc/default/cmon-mcpto opt out. (CLUS-8583) - The configuration file is
/etc/default/cmon-mcp. It follows the service and binary names; the package is stillclustercontrol-mcp. On RPM hosts an earlier build could leave settings behind in a.rpmsavefile during this rename — the installer now reports exactly what it found and where. (CLUS-8601, CLUS-8648)
- A flag-parse error no longer reprints the CMON password and MCP bearer token to the journal. (CLUS-8587)
/etc/default/cmon-mcp, which holdsCMON_PASSWORDandMCP_AUTH_TOKEN, now ships mode0600rather than world-readable, and the installer tightens every copy of it the package manager leaves behind. (CLUS-8594)export_cluster_logis no longer an arbitrary-file write as root; every client-supplied path is confined to the export directory and lands through a staged rename, so a symlink at the destination is never written through. (CLUS-8581)get_controller_configno longer returns live Vault and OpenBao tokens in clear text. (CLUS-8650)- Credentials and key material are held where Go's formatting verbs cannot reach them, so no log line or error message can print them by accident. (CLUS-8595)
- The digest key file is no longer symlink-swappable, and governed mode refuses to write its marker through a dangling symlink. (CLUS-8576, CLUS-8647)
- Every session runs as one CMON identity. The server authenticates as the single configured
CMON_USERNAME, and the audit log attributes every action to it, so two assistants cannot be told apart from the record. Per-session identity is planned for a later release. - Scoping removes a tool, not a data class. Several tools read the same data, so denying one can leave a sibling serving the same rows. The server names each case at startup as
tool scope: WARNING: …. create_jobreaches the whole job surface. Its free-formcommandargument reaches CMON job commands that have no tool of their own and that no deny list can name.- Packages are
x86_64only in this release.
Maintenance Release: September 1st, 2026
- Build:
- clustercontrol-mcp-1.0.0-60
⚠ Breaking change
get_cluster_log no longer accepts output_path and no longer writes files — it is now a pure read that returns log content (the tail of the last 200 lines by default). Callers that used output_path to save a log file locally must switch to the new export_cluster_log tool, which requires output_path and writes the file with mode 0600. (CLUS-8098)
export_cluster_log— exports a collected cluster log file in full to a localoutput_pathon the MCP Server host. The file is written with mode0600, including when overwriting an existing file that had looser permissions. (CLUS-8098)- Tool annotations — all 70 tools now serve the standard MCP
readOnlyHintanddestructiveHintannotations. The annotations are generated at tool registration from a committed, human-reviewed manifest, so the served hints cannot drift from the manifest. Note that annotations are advisory metadata for MCP clients — clients can use them to auto-approve reads and require confirmation before destructive calls — they are not server-side enforcement, anddry_runpreviews remain a client-side safeguard. (CLUS-8098) - The tool registry grows from 69 to 70 tools (41 pure-read, 26 CMON-mutating, 3 local-filesystem-writing; 22 flagged destructive), with 21 resource surfaces (3 static + 18 templates). (CLUS-8098)