Control Plane (controlplane.com): deploy and operate workloads across AWS, GCP, Azure, and more.
MCP Server: io.cpln/control-plane
The io.cpln/control-plane MCP server (Control Plane) provides an interface for running containerized workloads across AWS, GCP, Azure, OCI, and user-owned hardware under one API. It loads Control Plane domain knowledge, production guardrails, and live MCP-related capabilities.
π οΈ Key Features
Multi-cloud workload deployment via a single API
Containerized workloads across AWS, GCP, Azure, and OCI
Uses βControl Plane AI Pluginβ context (domain knowledge and production guardrails)
Includes MCP functionality as referenced in its readme excerpt
Related terms include: kubernetes, platform-engineering, virtual-cloud, serverless, and containers
π Use Cases
Deploying and operating workloads in heterogeneous cloud environments
Managing workloads spanning public clouds and local hardware
Run containerized workloads across AWS, GCP, Azure, OCI, and your own hardware under one API. It loads Control Plane's domain knowledge, production guardrails, and live MCP tools into Claude Code, Codex, and Antigravity CLI so your assistant can deploy, troubleshoot, secure, and migrate workloads with verified cpln commands.
Update with /plugin marketplace update controlplane then /reload-plugins (third-party marketplaces don't auto-update unless you enable it in /plugin β Marketplaces).
Start Codex, open /plugins, and install cpln. Guardrail injection needs plugin hooks, which Codex gates off by default β enable them in ~/.codex/config.toml and restart:
toml
[features]plugins = trueplugin_hooks = true
Update with codex plugin marketplace upgrade controlplane, then restart Codex.
MCP uses OAuth 2.1 + PKCE. Sign in to let the assistant act on your Control Plane organizations β you choose which orgs it may operate on, and the token is scoped to those orgs and enforced server-side on every call. Sign in again to change the grant. Treat MCP access as production access to the orgs you grant. How to sign in:
Claude Code β /mcp, select cpln, sign in (or claude mcp login cpln).
Optional β only for the cpln CLI workflows some skills generate (CI/CD, Terraform, Pulumi). See .env.example.
Variable
Purpose
CPLN_TOKEN
Service-account token for cpln CLI calls (sensitive).
CPLN_ORG
Default organization.
CPLN_GVC
Default GVC.
CPLN_PROFILE
Local cpln CLI profile.
Usage
Ask in natural language β the assistant routes to the right skill or agent:
"Troubleshoot why my payments-api workload in production keeps restarting."
"Put app.example.com in front of my web workload with auto-TLS."
"Give my analytics workload credential-free read access to S3 bucket prod-event-logs β no IAM keys."
"Provision a production Postgres with HA failover and S3 backups."
"Convert this kustomization.yaml to Control Plane and apply it to staging after I confirm."
Two workflows also have slash commands in Claude Code β /cpln:troubleshoot WORKLOAD and /cpln:migrate-k8s FILE; in other clients, ask for the same workflows by name.
What's included
Domain skills across CLI usage, access control, autoscaling, networking, observability, migration, templates, stateful storage, and security.
Two guided agents: workload troubleshooting and Kubernetes / Compose / Helm migration.
An always-on guardrail rule the assistant applies in every session.
Pre-configured access to the hosted Control Plane MCP server.
Security
MCP access is production access β scoped to the orgs you grant and your own RBAC.