MCP Server

CloudCasa server includes an optional MCP (Model Context Protocol) server. MCP is an open standard that lets AI assistants and tools, such as Claude Code, connect to external services. When enabled, the CloudCasa MCP server allows an AI assistant to work with your CloudCasa installation using natural language, for example to check the status of clusters or review recent backup jobs.

The MCP server uses the CloudCasa APIs on behalf of the user and authenticates with a CloudCasa API key. It can only do what the role assigned to that API key allows.

Note

The MCP server currently supports read-only operations only. An AI assistant can view information such as clusters, jobs, and recovery points, but cannot run, create, edit, or delete anything in CloudCasa.

The MCP server is disabled by default.

Enabling the MCP server

To enable the MCP server, set the Helm value mcp.enabled to true:

mcp:
  enabled: true

This deploys a cloudcasa-mcp pod in the CloudCasa server namespace. The MCP server is then available at:

https://<FQDN-OF-CLOUDCASA-SERVICE>/mcp

To verify that the MCP server is running, check that the cloudcasa-mcp pod is in the “Running” state:

kubectl -n cloudcasa-server get pods -l amds.component=cloudcasa-mcp

Note

The default resource and security context settings are suitable for most installations. To change them, use the mcp.resources, mcp.podSecurityContext, and mcp.containerSecurityContext Helm values. See Resource Limits for defaults and examples.

Connecting an AI assistant

Users can connect their AI assistant to the MCP server with their own CloudCasa API key. For client setup instructions, usage examples, and the list of available tools, see MCP Server in the CloudCasa User Guide. When following those instructions, replace https://mcp.cloudcasa.io/mcp with the URL of your MCP server (https://<FQDN-OF-CLOUDCASA-SERVICE>/mcp).

Disabling the MCP server

To disable the MCP server, set mcp.enabled back to false.

This removes the cloudcasa-mcp pod and the /mcp route. Existing API keys are not affected. To fully revoke access, delete the API keys used by AI assistants from the Configuration => API Keys page.