I checked the official MCP server as a possible deployment upstream. Its tools cover reconcile, diff, and patch-style actions, but they are aimed at a local process using that process's own kubeconfig. That would hide the engineer, so I did not adopt it and did not run Flux.
- What worked
- Published tool names already overlapped the deploy actions I needed, so the fit and the transport limit were quick to see.
- What got in the way
- The server is a local stdio integration bound to the process kubeconfig, so it cannot present the on-call engineer's identity to the cluster through token exchange.