Real-time Kubernetes network traffic visibility and API analysis for HTTP, gRPC, Redis, Kafka, DNS.
This MCP server provides real-time Kubernetes network traffic visibility and API analysis. It focuses on multiple protocols and systems, including HTTP, gRPC, Redis, Kafka, and DNS, based on the server description. The project is associated with topics spanning Kubernetes, observability, packet capture, eBPF, and incident response.
Kubeshark indexes cluster-wide network traffic at the kernel level using eBPF โ delivering instant answers to any query using network, API, and Kubernetes semantics.
What you can do:
Download Retrospective PCAPs โ cluster-wide packet captures filtered by nodes, time, workloads, and IPs. Store PCAPs for long-term retention and later investigation.
Visualize Network Data โ explore traffic matching queries with API, Kubernetes, or network semantics through a real-time dashboard.
See Encrypted Traffic in Plain Text โ automatically decrypt TLS/mTLS traffic using eBPF, with no key management or sidecars required.
Integrate with AI โ connect your favorite AI assistant (e.g. Claude, Copilot) to include network data in AI-driven workflows like incident response and root cause analysis.
Kubeshark exposes cluster-wide network data via MCP โ enabling AI agents to query traffic, investigate API calls, and perform root cause analysis through natural language.
"Why did checkout fail at 2:15 PM?""Which services have error rates above 1%?""Show TCP retransmission rates across all node-to-node paths""Trace request abc123 through all services"
Works with Claude Code, Cursor, and any MCP-compatible AI.
Kubeshark indexes cluster-wide network traffic by parsing it according to protocol specifications, with support for HTTP, gRPC, Redis, Kafka, DNS, and more. A single KFL query can combine all three semantic layers โ Kubernetes identity, API context, and network attributes โ to pinpoint exactly the traffic you need. No code instrumentation required.
KFL query combining API, Kubernetes, and network semantics
Capture and retain raw network traffic cluster-wide, including decrypted TLS. Download PCAPs scoped by time range, nodes, workloads, and IPs โ ready for Wireshark or any PCAP-compatible tool. Store snapshots in cloud storage (S3, Azure Blob, GCS) for long-term retention and cross-cluster sharing.