# Kubernetes Audit Logs

> Use this tool when you need to unify and analyze Kubernetes audit logs across multiple cloud providers, solving the problem of fragmented log management and providing a single interface for querying and filtering logs by user, namespace, and resource type. It takes in cluster configurations and query parameters as inputs and outputs normalized and filtered audit logs, supporting flexible time ranges and intelligent parameter normalization. Use it in hybrid cloud environments to streamline DevOps and security monitoring without requiring separate tooling for each provider.

Canonical page: https://skillsregistry.net/skills/kube-audit  
JSON: https://api.skillsregistry.net/v1/skills/kube-audit

## Description

A Go-based MCP server that provides unified access to Kubernetes audit logs across multiple cloud providers including Alibaba Cloud SLS, AWS CloudWatch Logs, and Google Cloud Logging. Built by mozillazg with a provider-agnostic architecture, it offers three core tools for listing clusters, discovering common resource types, and querying audit logs with flexible filtering by user, namespace, verbs, resource types, and time ranges. The implementation features intelligent parameter normalization (resource type mapping, verb expansion), configurable cluster management with aliases and defaults, and comprehensive time parsing supporting both absolute timestamps and relative durations. Designed for DevOps teams and security engineers who need to analyze Kubernetes audit trails across hybrid cloud environments without managing separate tooling for each provider.

## Trust

- **Trust score (0–1):** 0.78
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** cloud-infra
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/kube-audit)
- **Repository:** <https://github.com/mozillazg/kube-audit-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "kube-audit"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/kube-audit` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/kube-audit/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
