Your developers are already running MCP servers you don’t know about

· Source: Stacklok · Field: Technology & Digital — Artificial Intelligence & Machine Learning, Cloud Computing & IT Infrastructure, Cybersecurity & Data Privacy · Depth: Intermediate, medium

Summary

Developers are deploying ungoverned Model Context Protocol (MCP) servers, creating significant security and compliance vulnerabilities akin to the early days of unmanaged containers. These servers often operate without proper logging, access controls, or inventory, posing a substantial blast radius risk. Stacklok addresses this by providing a governance layer built on Kubernetes principles. Its solution includes the Stacklok Registry Server for an authoritative catalog, the Stacklok Gateway for central policy enforcement and scoped access, structured logging for auditability, and isolated containers for blast radius containment. Stacklok's platform is vendor-neutral and model-agnostic, leveraging existing Kubernetes primitives like RBAC and network policy. For instance, one platform engineering team used Stacklok's Kubernetes Operator to govern over 50 MCP servers, quickly identifying uninventoried servers with production database access. The company was founded by Kubernetes co-creators Craig McLuckie and Joe Beda.

Key takeaway

For AI Security Engineers or MLOps teams deploying AI agents, you must proactively govern Model Context Protocol (MCP) servers to avoid significant compliance failures and security vulnerabilities. Waiting to implement controls will lead to a degrading security posture and a harder remediation path when audits occur. You should establish an authoritative registry and central policy enforcement, leveraging existing Kubernetes infrastructure, to gain immediate visibility, control access, and ensure audit readiness for your AI agent deployments.

Key insights

Ungoverned Model Context Protocol (MCP) servers create security and compliance risks, demanding proactive governance.

Principles

Method

Establish governance via an authoritative server registry, central policy gateway, and structured logging, leveraging Kubernetes primitives.

In practice

Topics

Best for: CTO, VP of Engineering/Data, Director of AI/ML, MLOps Engineer, AI Security Engineer, AI Architect

Related on AIssential

Open in AIssential →

Editorial summary, takeaway, and curation by AIssential. Original article published by Stacklok.