
Stacklok

Run AI agents securely on your Kubernetes with full governance, control, and OTel instrumentation. Trusted by Fortune 500, built by Kubernetes co-founders.
Editor's Verdict
Key Takeaways
- Registry
- Runtime
- Gateway
- Portal
In-Depth Review: What is Stacklok?
Stacklok extends Kubernetes into a first-class MCP runtime, enabling enterprises to deploy, manage, and govern AI agents and MCP servers with security guardrails. Founded by Kubernetes co-creators Craig McLuckie and Joe Beda, Stacklok provides a platform with a curated registry, runtime, gateway, and portal. Based on open source ToolHive, it offers zero lock-in, policy-as-code, IdP integration, and native observability. Ideal for platform engineering and AI enablement teams in financial services, manufacturing, retail, and more.
Core Features
Registry
Curate a catalog of trusted MCP servers that teams can quickly discover and deploy.
Runtime
Deploy, run and manage MCP servers in a Kubernetes cluster with security guardrails.
Gateway
Provide a single endpoint to safely and efficiently access all your MCP tools.
Portal
Give admins full control and knowledge workers frictionless access to context.
Oversight
Native OTel instrumentation for end-to-end observability of agent actions.
Control
Apply existing Kubernetes networking and security policies to MCP servers.
Policy-as-code
Govern MCP servers using the same GitOps workflows and policies as the rest of your platform.
IdP Integration
Map Kubernetes ServiceAccounts and OIDC claims to MCP permissions for consistent authentication.
Pricing
ToolHive (Open Source)
- Open source MCP platform (Apache 2.0)
- Self-hosted deployment
- Community support
- GitHub and Docs access
Stacklok Enterprise
- All ToolHive features
- Enterprise-grade security and governance
- Forward deployed engineers for support
- Integration with enterprise systems
- Full observability and control
Pros and Cons
Pros
- Kubernetes-nativeBuilt on Kubernetes patterns by Kubernetes co-creators, ensuring seamless integration with existing infrastructure.
- Security-first designPasses rigorous security reviews and provides full control over data with no vendor lock-in.
- Open source coreToolHive is Apache 2.0 licensed, guaranteeing interoperability and community-driven development.
- ObservabilityNative OTel instrumentation gives a single pane of glass for both services and agents.
- Policy-as-codeApply consistent governance through GitOps workflows, extending existing platform policies to AI agents.
Cons
- Requires Kubernetes expertiseOrganizations need familiarity with Kubernetes to deploy and manage the platform effectively.
- New technologyMCP is an emerging standard; the ecosystem and tooling are still evolving.
- Dedicated infrastructureRunning MCP servers on Kubernetes may require dedicated cluster resources.
- Learning curveTeams need to adopt new patterns for agent governance and MCP server management.
- Limited community sizeWhile growing, the open source community is smaller compared to more established projects.
Use Cases & Recommended Professions
Platform Engineer→ View Toolkit
Needs to integrate AI agent infrastructure with existing Kubernetes platforms and enforce governance.
AI Enablement Engineer→ View Toolkit
Responsible for deploying and managing MCP servers securely for knowledge workers.
Security Engineer→ View Toolkit
Requires a solution that applies existing security policies to AI tool calls and prevents shadow MCP.
DevOps Engineer→ View Toolkit
Looking to extend GitOps and observability practices to AI workflows.
IT Manager→ View Toolkit
Seeks control and visibility over AI agents connected to enterprise data.
Data Engineer→ View Toolkit
Needs to curate and provide trusted data sources as MCP servers for AI agents.
Frequently Asked Questions
Alternative AI Tools
View Detailed Comparison →ℹ️ Curation Disclosure: The overview and features of Stacklok were synthesized using AI and fact-checked by our curation team to ensure accuracy.












