Skip to main content

kafka-sentinel-mcp

CI PyPI Python License: MIT

Give AI agents safe, read-only eyes on your Kafka clusters.

An MCP (Model Context Protocol) server that exposes Kafka cluster health, consumer lag, partition state, and replay-readiness as structured tools — so LLM agents (Claude, or any MCP client) can diagnose streaming incidents without ever being able to break anything.

Built by an engineer who spent a decade running Kafka-based financial messaging at 99.999% availability, and got tired of every "AI + Kafka" demo assuming write access to production.

Why this exists

When a consumer group stalls at 3 a.m., the questions are always the same: Is it lag? A stuck partition? A rebalance storm? An offset reset gone wrong? These are pattern-matching questions — exactly what LLM agents are good at — but no operator will hand an agent admin rights on a production cluster.

kafka-sentinel-mcp draws a hard line: every tool is read-only by design, enforced at the client-config level (no admin operations are even imported). The agent can observe, correlate, and recommend; a human executes.

Tools

Tool What it returns
list_topics All non-internal topics with partition count and replication factor — start here if you don't know a topic name
list_consumer_groups All consumer group IDs with state — start here if you don't know a group name
cluster_health Broker count, controller status, under-replicated / offline partition counts
consumer_lag Per-group, per-topic, per-partition lag with committed vs end offsets
topic_audit Replication factor, min.insync.replicas, retention, and flags configs that violate durability best practice
partition_state Leaders, ISR shrinkage, skew across brokers
replay_readiness For a group + topic: earliest available offsets vs committed, i.e., "can we still replay what we missed?"
incident_snapshot One-call bundle of all the above, timestamped — designed for pasting into a postmortem

Quick start

pip install kafka-sentinel-mcp   # (or: uv tool install)

# Run against your cluster (read-only credentials!)
KAFKA_BOOTSTRAP=localhost:9092 kafka-sentinel-mcp

Add to Claude Desktop / any MCP client:

{
  "mcpServers": {
    "kafka-sentinel": {
      "command": "kafka-sentinel-mcp",
      "env": { "KAFKA_BOOTSTRAP": "broker1:9092,broker2:9092" }
    }
  }
}

Then ask your agent: "Why is the payments-consumer group falling behind, and can we still replay from where it stalled?"

Security posture

  • Read-only by construction: no produce, no topic/config mutation, no offset commits, no ACL ops. The mutation APIs are never imported, and a test in CI greps the server source on every run to keep it that way.

  • The observer consumer runs with enable.auto.commit=False and never commits — verified against a real broker, not just asserted.

  • Supports SASL/SSL; credentials are read from the environment only and never logged.

  • Every tool call is logged with its parameters for audit.

  • Least privilege: run with a principal that has only Describe on the cluster and topics, and Describe on consumer groups. When an ACL denies an operation the tool returns a structured result rather than a stack trace:

    {
      "error": "permission_denied",
      "operation": "list_consumer_groups",
      "detail": "...",
      "hint": "The Kafka principal in use lacks the ACL required for this operation. ..."
    }
    

    The agent can then tell the operator which ACL is missing instead of appearing broken. Non-authorization failures are deliberately not swallowed — they propagate, because silently degrading on an unrelated error would hide real problems.

Testing

pip install -e ".[dev]"

pytest -m "not integration"   # fast, fully mocked — no Docker needed
pytest -m integration         # starts a real Kafka via testcontainers (needs Docker)
pytest                        # both

The unit suite mocks librdkafka entirely and covers tool logic. The integration suite starts an actual broker, produces real records, and asserts the tools return correct lag, ISR state, durability flags, and replay-readiness — including that the observer leaves no committed offsets behind. Both run in CI.

Status

Early but tested. See ROADMAP.md. Issues and PRs welcome — especially war stories about what you wish an agent could have told you during an incident.

Citing this work

If you reference this project in academic work, see CITATION.cff, or use the "Cite this repository" button on GitHub.

License

MIT

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

kafka_sentinel_mcp-0.1.4.tar.gz (107.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

kafka_sentinel_mcp-0.1.4-py3-none-any.whl (9.3 kB view details)

Uploaded Python 3

File details

Details for the file kafka_sentinel_mcp-0.1.4.tar.gz.

File metadata

  • Download URL: kafka_sentinel_mcp-0.1.4.tar.gz
  • Upload date:
  • Size: 107.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for kafka_sentinel_mcp-0.1.4.tar.gz
Algorithm Hash digest
SHA256 7b7b1328056717b31f776aa0a8c55891027797752f33cf3c4f95d216b5556ad3
MD5 600491462a8e24a1071988cb6d75412a
BLAKE2b-256 8b76fa3df6beaabb1b7f3dcd10743c314da4f5825f5948239994f65f58ee3e43

See more details on using hashes here.

Provenance

The following attestation bundles were made for kafka_sentinel_mcp-0.1.4.tar.gz:

Publisher: publish.yml on sanjay-amu/kafka-sentinel-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file kafka_sentinel_mcp-0.1.4-py3-none-any.whl.

File metadata

File hashes

Hashes for kafka_sentinel_mcp-0.1.4-py3-none-any.whl
Algorithm Hash digest
SHA256 66e5a9aad748fc0e890cecd2b234553785ff166d0e6396e5d62b803b89bc5760
MD5 3166beebe21eb67fb6c5a75daa9e061a
BLAKE2b-256 c67334af383417f3cfa47dda4976d13bf539f37198c7e02d799d98ff21fbb875

See more details on using hashes here.

Provenance

The following attestation bundles were made for kafka_sentinel_mcp-0.1.4-py3-none-any.whl:

Publisher: publish.yml on sanjay-amu/kafka-sentinel-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.1.5

2 files

This release

0.1.4 This release

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page