- Home
- Resources
- Integrations
- Control Plane
Claude Control Plane connectorWhat Claude can do in your Control Plane account.
The Claude Control Plane connector exposes 55 tools: 26 read, 29 write. Claude deploys, configures, and debugs your cloud apps there; 15 destructive operations ask for your confirmation. Below: what it reads, what it changes, and who sets the limits.
Verified Trustpilot reviews · AI, automation & growth agency
What changes for your ops team
Control Plane runs containerized apps across several clouds and your own hardware as one platform. With the connector, you describe the outcome to Claude: it picks the tools, chains the calls, deploys or fixes. You stay the one who signs off on the heaviest operations.
Ship a service. build_image builds the image from your repo, create_workload deploys it, create_domain and add_domain_route give it an address, and list_deployments confirms every location is ready.
Make sense of an outage. get_workload_events surfaces startup failures, get_workload_logs and query_traces dig through logs and slow requests, and query_metrics charts the load.
Keep a paper trail. export_terraform generates infrastructure code for what's already running, and query_audit_events finds out who touched what.
What Claude won't do here: the directory connector stays on the default tool profile, without Kubernetes cluster management or full administration, which require a custom connection. No secret can be deleted, and no secret value ever comes back. Nothing runs by itself either: no alert wakes Claude up at night. That always-on watch belongs to an automation tool, a different job covered on the Integrations hub.
The vocabulary in one minute
Five words before you plug in Control Plane.
- Connector
- The link you set up once between Claude and an account you already have, so Claude can work in it while it answers you.
- Tool
- A named capability the connector opens to Claude. Claude picks the ones it needs by itself; the directory sheet lists them by name.
- Authorization
- The service's sign-in screen, where you pick the organizations you hand over to Claude. Given once per person, revocable any time.
- Approval
- The confirmation Claude waits for before completing anything that changes an account, shown in the conversation at the right moment.
- MCP
- The shared standard behind connectors: it's what lets an assistant like Claude talk to an outside service.
Plug Control Plane into Claude in three steps
- 01
Find Control Plane
In Claude's settings, open Customize, then Connectors, and look for Control Plane. On a Team or Enterprise workspace, an Owner or Primary Owner enables it for the organization first.
- 02
Start the connection
Click Connect on its row, then sign in through the window the service opens itself. If the link breaks, Disconnect followed by a fresh connection sets things right.
- 03
Approve the authorization
Read the authorization screen before you accept. It's Control Plane's screen, not Claude's, and it sets what the access covers. You can also revoke it later from your account.
The 55 tools of the Claude Control Plane connector
Control Plane gives Claude 55 tools: 26 that read your account, 29 that change something in it.
Twenty-six tools that read, twenty-nine that create, modify, or delete. Names stay exactly as Claude shows them.
- 26 read
- 29 write
Tools index
- browse_templates
- convert_to_terraform
- export_terraform
- get_command
- get_cpln_rules
- get_cpln_skill
- get_image_build
- get_installed_template
- get_permissions
- get_resource
- get_resource_schema
- get_template
- get_trace
- get_workload_events
- get_workload_logs
- list_commands
- list_deployments
- list_installed_templates
- list_metrics
- list_quotas
- list_resources
- list_workload_replicas
- query_audit_events
- query_metrics
- query_traces
- search_control_plane
- add_domain_port
- add_domain_route
- build_image
- clear_domain_tls
- create_domain
- create_gvc
- create_identity
- create_policy
- create_volumeset
- create_workload
- delete_resource
- expand_volumeset
- grant_workload_secret_access
- install_template
- mount_volumeset_to_workload
- remove_domain_port
- remove_domain_route
- set_domain_tls
- uninstall_template
- update_domain
- update_domain_route
- update_gvc
- update_identity
- update_policy
- update_volumeset
- update_workload
- upgrade_template
- workload_start_cron
- workload_stop_replica
What Claude looks up (26)
26 toolsTwenty-six tools that read state, logs, and documentation without touching anything.
browse_templates
Browses the catalog of ready-to-install templates: name, category, latest version, and whether each one brings its own GVC.
convert_to_terraform
Translates a resource manifest into Terraform code, after a dry-run check against the API.
export_terraform
Generates Terraform code for resources already in place, one at a time or in bulk, from their link.
get_command
Fetches one asynchronous command by its ID, to see where a long-running operation stands: in progress, done, or failed, without relaunching anything.
get_cpln_rules
Loads the platform's operating guide: its resource model, production defaults, and how to verify that an operation actually landed.
get_cpln_skill
Loads the runbook for one family of tasks: how to use a feature properly, the constraints that are easy to miss, and when it's the wrong tool.
get_image_build
Reads a build's status, progress events, and log from its build ID.
get_installed_template
Shows an installed template's status, its revision number, and the full set of resources tied to it on the platform.
get_permissions
Lists the permissions that can be granted on a resource kind, to build an accurate access policy.
get_resource
Fetches one resource by kind and name, with its full definition in JSON, so Claude sees every setting exactly as the platform stores it.
get_resource_schema
Returns the exact schema of a resource kind and its API endpoints, for drafting a correct manifest.
get_template
Shows a catalog template's available versions, its prerequisites, and an example values file to start from.
get_trace
Fetches one trace by ID and summarizes its span tree, durations, and errors.
get_workload_events
Fetches a workload's event log to diagnose a failed start, a failing health check, or a stuck deployment.
get_workload_logs
Queries a workload's logs through simple parameters or a raw LogQL query.
list_commands
Lists the asynchronous commands issued against a workload or a volume set: cron runs, replica stops, volume operations. Claude finds the ID to follow up on there.
list_deployments
Reports a workload's rollout status location by location. It's the first check after going live.
list_installed_templates
Lists the template releases present in an organization, so Claude can tell what came from the catalog and what was set up another way.
list_metrics
Catalogs the metrics and labels you can query, each with a correct PromQL template, the query language for metrics. Claude starts there so it doesn't aim at a metric that doesn't exist.
list_quotas
Lists the organization's resource quotas and current usage, with a filter for those close to the limit.
list_resources
Builds a summary table of the resources of one kind, workloads, domains, or volumes, to give Claude the big picture before digging in.
list_workload_replicas
Lists a workload's running replicas in one location, meaning the copies of the app actually serving traffic right now.
query_audit_events
Queries the audit trail of operations performed on a resource kind, with who did what and when.
query_metrics
Runs a PromQL query against the platform's metrics and returns the values, which Claude can then comment on, compare, or sum up in one sentence.
query_traces
Searches distributed traces, in TraceQL, for slow or failing requests. A trace follows a request's full path through your services.
search_control_plane
Searches Control Plane's documentation base: guides, examples, and API references. Claude leans on it so it doesn't answer about the platform from memory.
What Claude changes (29)
29 toolsTwenty-nine tools that act on your resources. Fifteen are flagged destructive by the publisher and go through your confirmation; for the rest, the general rule below applies.
add_domain_port
Approval: see the ruleOpens a new listening port on a domain, such as 443 over HTTP/2, so it accepts that kind of traffic.
add_domain_route
Approval: see the ruleMaps a path or address prefix on a domain to a workload, the app that should answer.
build_image
Approval: see the ruleBuilds a container image from a GitHub or GitLab repository and pushes it to your organization's private registry. The tool hands back a build ID.
clear_domain_tls
Asks you firstStrips the TLS configuration, the part that encrypts traffic, from a domain listener.
create_domain
Approval: see the ruleRegisters a custom domain on the platform, in cname or ns DNS mode.
create_gvc
Approval: see the ruleCreates a GVC, the space that groups one or more cloud locations where your workloads will run.
create_identity
Approval: see the ruleCreates a GVC-scoped identity that gives a workload access to secrets, cloud resources, or private networks.
create_policy
Approval: see the ruleCreates a policy that grants permissions on resources to people or services.
create_volumeset
Approval: see the ruleCreates a volume set for your workloads' persistent storage.
create_workload
Approval: see the ruleCreates a workload, serverless, standard, cron, stateful, or VM, with its containers and exposure.
delete_resource
Asks you firstDeletes one resource identified by kind and name. It's the single delete tool for everything that can be deleted.
expand_volumeset
Approval: see the ruleGrows a volume's capacity, with no downtime or data loss according to the publisher.
grant_workload_secret_access
Approval: see the ruleGives an existing workload access to a secret by wiring up its identity and access policy. The secret's value never comes back.
install_template
Approval: see the ruleInstalls a catalog template as a new release.
mount_volumeset_to_workload
Approval: see the ruleAttaches a volume set to a workload at a given path, so it can read and store its files there.
remove_domain_port
Asks you firstTakes a listening port off a domain.
remove_domain_route
Asks you firstTakes a route off a domain listener.
set_domain_tls
Asks you firstSets the TLS configuration on a domain listener, the part that encrypts traffic.
uninstall_template
Asks you firstUninstalls a template release and takes down the resources it had put in place.
update_domain
Asks you firstUpdates a domain's metadata, its host and subdomain acceptance flags, and its binding to a GVC or workload.
update_domain_route
Asks you firstUpdates an existing route on a domain listener.
update_gvc
Asks you firstUpdates a GVC's settings, such as its description, tags, or registry pull secrets.
update_identity
Asks you firstAdjusts an existing identity: its settings and the cloud credentials bound to it.
update_policy
Asks you firstUpdates a policy's bindings, targets, or permissions.
update_volumeset
Asks you firstRevises the configuration of a volume set that already exists.
update_workload
Asks you firstReworks a running workload's definition: image, resources, scaling, environment variables, and more.
upgrade_template
Asks you firstMoves a template release to a new version or to updated values.
workload_start_cron
Approval: see the ruleTriggers an immediate run of a cron workload, without waiting for its schedule.
workload_stop_replica
Asks you firstTerminates one running replica of a workload; the platform schedules a replacement according to its scaling settings.
What Claude asks before it acts
By default, Claude stops and asks for your go-ahead before any action it takes on an account for you. Control Plane adds its own rule for its 15 destructive operations.
According to Control Plane's documentation, tools that delete, remove, or overwrite data make the assistant present the impact and then ask for your confirmation. On a Team or Enterprise workspace, owners decide whether a member can let certain actions through, and they can cap what the connector does for the whole organization. And Claude works with your permissions: an organization you didn't tick on the consent screen stays closed to it.
Which plans it's available on
None of the 819 sheets in the official directory shows availability by plan. A connector-by-connector answer isn't published anywhere.
The general rule is sourced: remote connectors are open to all users on Claude, Cowork, Claude Desktop, and mobile. On Team and Enterprise, an Owner or Primary Owner enables the connector for the organization before each member connects. For the current status, check the Control Plane sheet in the official directory.
Where Control Plane stops
A connector isn't an automation. Claude calls these tools while it answers you: no deployment goes out on its own when a repo changes.
Only the publisher documents this connector: neither Claude's help center nor Anthropic's documentation has a page about it. The directory version is locked to the default tool profile, which has 55 tools; the broader profiles, with 77 and 131 tools, require a custom connection. The directory badge isn't a security audit. To compare with another sheet, see the Claude activecampaign connector page.
Need help connecting Control Plane to Claude?
A person reads every message.