Metadata-Version: 2.4
Name: krutrim-mcp-server
Version: 1.0.1
Summary: MCP server for Krutrim Cloud core infrastructure (VPC, compute, storage, security)
Project-URL: Homepage, https://cloud.olakrutrim.com
Project-URL: Documentation, https://docs.cloud.olakrutrim.com
Project-URL: Source, https://github.com/ola-krutrim/Krutrim-MCP
Project-URL: Issues, https://github.com/ola-krutrim/Krutrim-MCP/issues
Project-URL: Changelog, https://github.com/ola-krutrim/Krutrim-MCP/blob/main/CHANGELOG.md
Project-URL: License, https://github.com/ola-krutrim/Krutrim-MCP/blob/main/LICENSE
Project-URL: Copyright Notice, https://github.com/ola-krutrim/Krutrim-MCP/blob/main/COPYRIGHT.md
Project-URL: Supplemental Terms, https://github.com/ola-krutrim/Krutrim-MCP/blob/main/SUPPLEMENTAL-TERMS.md
Project-URL: Trademark Notice, https://github.com/ola-krutrim/Krutrim-MCP/blob/main/TRADEMARK.md
Author-email: Krutrim Cloud <cloudsupport@olakrutrim.com>
License:                               Apache License
                                Version 2.0, January 2004
                             http://www.apache.org/licenses/
        
        TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
        
        1. Definitions.
        
           "License" shall mean the terms and conditions for use, reproduction,
           and distribution as defined by Sections 1 through 9 of this document.
        
           "Licensor" shall mean the copyright owner or entity authorized by
           the copyright owner that is granting the License.
        
           "Legal Entity" shall mean the union of the acting entity and all
           other entities that control, are controlled by, or are under common
           control with that entity. For the purposes of this definition,
           "control" means (i) the power, direct or indirect, to cause the
           direction or management of such entity, whether by contract or
           otherwise, or (ii) ownership of fifty percent (50%) or more of the
           outstanding shares, or (iii) beneficial ownership of such entity.
        
           "You" (or "Your") shall mean an individual or Legal Entity
           exercising permissions granted by this License.
        
           "Source" form shall mean the preferred form for making modifications,
           including but not limited to software source code, documentation
           source, and configuration files.
        
           "Object" form shall mean any form resulting from mechanical
           transformation or translation of a Source form, including but
           not limited to compiled object code, generated documentation,
           and conversions to other media types.
        
           "Work" shall mean the work of authorship, whether in Source or
           Object form, made available under the License, as indicated by a
           copyright notice that is included in or attached to the work
           (an example is provided in the Appendix below).
        
           "Derivative Works" shall mean any work, whether in Source or Object
           form, that is based on (or derived from) the Work and for which the
           editorial revisions, annotations, elaborations, or other modifications
           represent, as a whole, an original work of authorship. For the purposes
           of this License, Derivative Works shall not include works that remain
           separable from, or merely link (or bind by name) to the interfaces of,
           the Work and Derivative Works thereof.
        
           "Contribution" shall mean any work of authorship, including
           the original version of the Work and any modifications or additions
           to that Work or Derivative Works thereof, that is intentionally
           submitted to Licensor for inclusion in the Work by the copyright owner
           or by an individual or Legal Entity authorized to submit on behalf of
           the copyright owner. For the purposes of this definition, "submitted"
           means any form of electronic, verbal, or written communication sent
           to the Licensor or its representatives, including but not limited to
           communication on electronic mailing lists, source code control systems,
           and issue tracking systems that are managed by, or on behalf of, the
           Licensor for the purpose of discussing and improving the Work, but
           excluding communication that is conspicuously marked or otherwise
           designated in writing by the copyright owner as "Not a Contribution."
        
           "Contributor" shall mean Licensor and any individual or Legal Entity
           on behalf of whom a Contribution has been received by Licensor and
           subsequently incorporated within the Work.
        
        2. Grant of Copyright License. Subject to the terms and conditions of
           this License, each Contributor hereby grants to You a perpetual,
           worldwide, non-exclusive, no-charge, royalty-free, irrevocable
           copyright license to reproduce, prepare Derivative Works of,
           publicly display, publicly perform, sublicense, and distribute the
           Work and such Derivative Works in Source or Object form.
        
        3. Grant of Patent License. Subject to the terms and conditions of
           this License, each Contributor hereby grants to You a perpetual,
           worldwide, non-exclusive, no-charge, royalty-free, irrevocable
           (except as stated in this section) patent license to make, have made,
           use, offer to sell, sell, import, and otherwise transfer the Work,
           where such license applies only to those patent claims licensable
           by such Contributor that are necessarily infringed by their
           Contribution(s) alone or by combination of their Contribution(s)
           with the Work to which such Contribution(s) was submitted. If You
           institute patent litigation against any entity (including a
           cross-claim or counterclaim in a lawsuit) alleging that the Work
           or a Contribution incorporated within the Work constitutes direct
           or contributory patent infringement, then any patent licenses
           granted to You under this License for that Work shall terminate
           as of the date such litigation is filed.
        
        4. Redistribution. You may reproduce and distribute copies of the
           Work or Derivative Works thereof in any medium, with or without
           modifications, and in Source or Object form, provided that You
           meet the following conditions:
        
           (a) You must give any other recipients of the Work or Derivative Works
               a copy of this License; and
        
           (b) You must cause any modified files to carry prominent notices
               stating that You changed the files; and
        
           (c) You must retain, in the Source form of any Derivative Works
               that You distribute, all copyright, patent, trademark, and
               attribution notices from the Source form of the Work, excluding
               those notices that do not pertain to any part of the Derivative
               Works; and
        
           (d) If the Work includes a "NOTICE" text file as part of its
               distribution, then any Derivative Works that You distribute must
               include a readable copy of the attribution notices contained
               within such NOTICE file, excluding those notices that do not
               pertain to any part of the Derivative Works, in at least one
               of the following places: within a NOTICE text file distributed
               as part of the Derivative Works; within the Source form or
               documentation, if provided along with the Derivative Works; or,
               within a display generated by the Derivative Works, if and
               wherever such third-party notices normally appear. The contents
               of the NOTICE file are for informational purposes only and
               do not modify the License. You may add Your own attribution
               notices within Derivative Works that You distribute, alongside
               or as an addendum to the NOTICE text from the Work, provided
               that such additional attribution notices cannot be construed
               as modifying the License.
        
           You may add Your own copyright statement to Your modifications and
           may provide additional or different license terms and conditions
           for use, reproduction, or distribution of Your modifications, or
           for any such Derivative Works as a whole, provided Your use,
           reproduction, and distribution of the Work otherwise complies with
           the conditions stated in this License.
        
        5. Submission of Contributions. Unless You explicitly state otherwise,
           any Contribution intentionally submitted for inclusion in the Work
           by You to the Licensor shall be under the terms and conditions of
           this License, without any additional terms or conditions.
           Notwithstanding the above, nothing herein shall supersede or modify
           the terms of any separate license agreement you may have executed
           with Licensor regarding such Contributions.
        
        6. Trademarks. This License does not grant permission to use the trade
           names, trademarks, service marks, or product names of the Licensor,
           except as required for reasonable and customary use in describing
           the origin of the Work and reproducing the content of the NOTICE file.
        
        7. Disclaimer of Warranty. Unless required by applicable law or
           agreed to in writing, Licensor provides the Work (and each
           Contributor provides its Contributions) on an "AS IS" BASIS,
           WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
           implied, including, without limitation, any warranties or conditions
           of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
           PARTICULAR PURPOSE. You are solely responsible for determining the
           appropriateness of using or redistributing the Work and assume any
           risks associated with Your exercise of permissions under this License.
        
        8. Limitation of Liability. In no event and under no legal theory,
           whether in tort (including negligence), contract, or otherwise,
           unless required by applicable law (such as deliberate and grossly
           negligent acts) or agreed to in writing, shall any Contributor be
           liable to You for damages, including any direct, indirect, special,
           incidental, or consequential damages of any character arising as a
           result of this License or out of the use or inability to use the
           Work (including but not limited to damages for loss of goodwill,
           work stoppage, computer failure or malfunction, or any and all
           other commercial damages or losses), even if such Contributor
           has been advised of the possibility of such damages.
        
        9. Accepting Warranty or Additional Liability. While redistributing
           the Work or Derivative Works thereof, You may choose to offer,
           and charge a fee for, acceptance of support, warranty, indemnity,
           or other liability obligations and/or rights consistent with this
           License. However, in accepting such obligations, You may act only
           on Your own behalf and on Your sole responsibility, not on behalf
           of any other Contributor, and only if You agree to indemnify,
           defend, and hold each Contributor harmless for any liability
           incurred by, or claims asserted against, such Contributor by reason
           of your accepting any such warranty or additional liability.
        
        END OF TERMS AND CONDITIONS
License-File: LICENSE
Keywords: cloud,infrastructure,krutrim,llm,mcp
Classifier: Development Status :: 5 - Production/Stable
Classifier: Intended Audience :: Developers
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Topic :: Software Development :: Libraries
Requires-Python: <3.14,>=3.10
Requires-Dist: httpx<0.29,>=0.28
Requires-Dist: krutrim-client<0.7,>=0.6.0
Requires-Dist: mcp<2,>=1.28.1
Requires-Dist: pydantic<3,>=2.12.0
Requires-Dist: pynacl<2,>=1.5
Provides-Extra: dev
Requires-Dist: pytest-asyncio>=0.24; extra == 'dev'
Requires-Dist: pytest>=8.0; extra == 'dev'
Requires-Dist: ruff>=0.8; extra == 'dev'
Provides-Extra: release
Requires-Dist: build<2,>=1.2; extra == 'release'
Requires-Dist: cyclonedx-bom<8,>=7.3; extra == 'release'
Requires-Dist: hatchling<1.32,>=1.26; extra == 'release'
Requires-Dist: pip-audit<3,>=2.10; extra == 'release'
Requires-Dist: twine<7,>=6; extra == 'release'
Description-Content-Type: text/markdown

# Krutrim Cloud MCP Server

Use Krutrim Cloud from Cursor, Claude Desktop, Claude Code, or Codex. The MCP
server provides discovery and controlled operations for VPCs, compute, storage,
networking, Kubernetes, KPods, and IAM.

## Install

### Recommended: uvx

Run the released stdio package directly from PyPI without installing it into
your current Python environment:

```bash
uvx krutrim-mcp-server --version
```

### Python virtual environment

You can also install and run the package with standard Python tooling:

```bash
python3 -m venv .venv
source .venv/bin/activate
python -m pip install krutrim-mcp-server==1.0.0
python -m krutrim_mcp_server --version
```

On Windows, activate the environment with `.venv\Scripts\activate`.

The current stable release is `1.0.0`. Use
`uvx krutrim-mcp-server@1.0.0 --version` when you need to pin that exact release.
Future releases follow Semantic Versioning: fixes increment the patch version,
backward-compatible features increment the minor version, and breaking changes
increment the major version.

## Connect locally

### Sign in and complete MFA

Sign in as the root user to obtain the access-token and refresh-token pair:

```bash
curl --location \
  'https://cloud.olakrutrim.com/iam/v1/signInAsRootUser' \
  --header 'Content-Type: application/json' \
  --header 'Accept: application/json' \
  --data '{"email":"YOUR_EMAIL","password":"YOUR_PASSWORD"}'
```

For an IAM user, use the account ID with the same flow:

```bash
curl --location \
  'https://cloud.olakrutrim.com/iam/v1/signInAsIAMUser' \
  --header 'Content-Type: application/json' \
  --header 'Accept: application/json' \
  --data '{"accountId":"YOUR_ACCOUNT_ID","email":"YOUR_EMAIL","password":"YOUR_PASSWORD"}'
```

Keep the returned token pair private. If MFA is enabled, verify it with the
returned access token before configuring the MCP client. Set the returned
values in `KRUTRIM_ACCESS_TOKEN` and `KRUTRIM_REFRESH_TOKEN` through a secure
secret manager or protected environment; do not place them in shell history.

```bash
curl --location \
  'https://cloud.olakrutrim.com/iam/v1/mfa/verify' \
  --header 'Content-Type: application/json' \
  --header 'Authorization: Bearer YOUR_ACCESS_TOKEN' \
  --data '{"otp":"YOUR_MFA_OTP"}'
```

MFA verification uses the same access token; it does not rotate the token
pair. Run both commands only from a trusted host and keep credentials, OTPs,
responses, transcripts, and logs private.

You need an IAM access token and refresh token from the same sign-in session.
Set both in the MCP client configuration; do not put token values in source
control.

```json
{
  "mcpServers": {
    "krutrim-cloud": {
      "command": "uvx",
      "args": ["krutrim-mcp-server"],
      "env": {
        "KRUTRIM_ACCESS_TOKEN": "YOUR_IAM_ACCESS_TOKEN",
        "KRUTRIM_REFRESH_TOKEN": "YOUR_IAM_REFRESH_TOKEN"
      }
    }
  }
}
```

For a Python virtual-environment installation, keep the same `env` values and
replace `command` and `args` with the virtual environment's absolute Python
path:

```json
{
  "command": "/absolute/path/to/.venv/bin/python",
  "args": ["-m", "krutrim_mcp_server"]
}
```

On Windows, use the absolute path to `.venv\Scripts\python.exe`.

Restart the client after changing its configuration. The server refreshes the
access token while the refresh token remains valid. When refresh is rejected,
sign in again and replace both values.

For Codex, add this to `~/.codex/config.toml`:

```toml
[mcp_servers.krutrim-cloud]
enabled = true
command = "uvx"
args = ["krutrim-mcp-server"]

[mcp_servers.krutrim-cloud.env]
KRUTRIM_ACCESS_TOKEN = "YOUR_IAM_ACCESS_TOKEN"
KRUTRIM_REFRESH_TOKEN = "YOUR_IAM_REFRESH_TOKEN"
```

For a Python virtual environment, set `command` to its absolute Python path and
set `args = ["-m", "krutrim_mcp_server"]` instead.

## Use the tools

Start with a read operation, select returned identifiers and regions exactly,
then confirm mutations. Examples:

```text
List my VPCs in In-Bangalore-1.
List IAM users.
Create a VPC in In-Hyderabad-1 with CIDR 10.20.0.0/24. Ask for confirmation first.
```

Mutating calls require `confirm=true`. Set `KRUTRIM_MCP_READ_ONLY=true` to block
all mutations on a local installation.

## Verify

```bash
uvx krutrim-mcp-server --list-tools
uvx krutrim-mcp-server --doctor
```

`--list-tools` verifies the installed catalog. `--doctor` verifies local
configuration; use a read-only Cloud tool such as `list_vpcs` to verify your
permissions.

## User guide

### Before you begin

Use an IAM access token and refresh token from the same sign-in session.
Configure both `KRUTRIM_ACCESS_TOKEN` and `KRUTRIM_REFRESH_TOKEN` in your MCP
client.

Always pass one of the supported regions when a tool requires it:

- `In-Bangalore-1`
- `In-Hyderabad-1`

### Recommended workflow

1. List resources before changing them.
2. Select exact identifiers returned by the list call.
3. Review the requested change.
4. Use `confirm=true` only after the review.

For example, use `list_vpcs` before `describe_vpc` or `delete_vpc`; use
`list_subnets` before VM creation; use a listed VM flavor instead of guessing
one.

### Common tasks

| Goal | Start with |
| --- | --- |
| Create a VPC | `list_vpcs`, then `create_vpc` |
| Create a VM | `list_vpcs`, `list_subnets`, and `list_compute_flavors` |
| Create a KPod | `list_kpod_flavors` and `list_kpod_templates` |
| Manage storage | `list_volumes`, `list_volume_types`, or `list_buckets` |
| Manage IAM | `list_iam_users`, `list_iam_groups`, and `list_iam_roles` |

IAM operations require full IAM KRNs. Use the KRN returned by a list operation;
do not use a UUID, a display name, or a partial identifier.

### Safety controls

- Mutations require `confirm=true`.
- `KRUTRIM_MCP_READ_ONLY=true` blocks every mutation.
- Do not retry a timed-out create immediately. List by name or identifier first
  to determine whether the resource was created.
- For destructive operations, inspect the selected identifier before confirming.
- The `create_iam_user` password is sensitive. Use it only from a trusted MCP
  host because tool-call transcripts and host logs are outside this package's
  control. Use the approved encrypted credential-delivery or out-of-band
  process where applicable.

### Troubleshooting

| Problem | What to do |
| --- | --- |
| MCP server does not start | Check that both token variables are configured. |
| Refresh is rejected | Sign in again, replace both tokens, and restart the client. |
| `401` or `403` from a Cloud tool | For MFA-enabled sessions, verify MFA with the existing access token first; then verify the IAM user, service policy, and region. |
| Required identifier is rejected | List the resource again and use its complete KRN. |
| Tools are not visible | Restart the MCP client and run `--list-tools` locally. |

For object-storage access keys, follow
[Encrypted storage access-key delivery](#encrypted-storage-access-key-delivery).

## Encrypted storage access-key delivery

`create_storage_access_key` delivers a ciphertext bundle, not a plaintext
secret. Generate a recipient key on the device that will use the key:

```bash
krutrim-mcp-credentials init
```

Use the printed `public_key` and `fingerprint` in the MCP request. Ask the
client to show the name, region, and fingerprint before you confirm creation.

After the tool returns a bundle, decrypt it locally:

```bash
krutrim-mcp-credentials decrypt \
  --bundle /path/to/storage-key.bundle.json \
  --output ~/.config/krutrim-mcp/storage-key.json
```

Keep the private key and decrypted output on your device. Do not paste either
into an MCP prompt, repository, ticket, or chat message. If creation times out,
list existing keys before retrying.
