Cloud DevOps MCP Server

io.github.alexcgodwinv0.3.1Updated Oct 1, 2026

Cloud DevOps risk review with cross-domain IaC, IAM, Kubernetes and CI/CD correlation.

Overview

AI-generated overview

A local MCP server that reviews cloud DevOps risk across Terraform, IAM, Kubernetes and CI/CD evidence.

What it does
It exposes eight advisory tools for cloud DevOps review: assess_cloud_change_bundle correlates Terraform, IAM, Kubernetes and GitHub Actions evidence into one deployment-risk view; assess_terraform_change scores IaC risk from Terraform plan JSON; review_iam_policy detects wildcard scope and privilege-escalation paths; review_kubernetes_deployment checks probes, resources, disruption protection, image and exposure risks; review_github_actions_workflow checks triggers, action pins, permissions, caching and concurrency; review_cicd_pipeline reviews delivery maturity; build_incident_runbook drafts an incident response runbook; and estimate_slo_error_budget calculates downtime and…
When to use it
Useful when an assistant is asked to review a planned infrastructure or release change, check IAM or Kubernetes configuration before deployment, prepare an incident runbook, or reason about SLO error budgets. It suits engineers who want structured, evidence-backed risk guidance inside an MCP client rather than ad hoc prompting.
Requirements
Runs locally as a stdio process, typically via npx cloud-devops-mcp-server or a global npm install, so Node.js and npm are needed. An MCP client that supports local stdio servers is required. The README states it needs no cloud credentials, no hosted endpoint and no external API access.
Before you install
The server returns advisory guidance only; engineers remain responsible for review, approval and execution. It is described as not writing to infrastructure or mutating user systems, and as not calling external APIs, so inputs such as Terraform plan JSON, IAM policy JSON and Kubernetes or workflow YAML are analysed locally. Treat its risk scores as advice, not as an approval gate.

Installation

In SourceWeft

  1. Open Cloud DevOps MCP Server in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

Cloud DevOps MCP Server

[CI] [npm version] [MCP Registry] [License: MIT] [MCP]

Cloud DevOps MCP Server is a Model Context Protocol v2 server by Alex C. Godwin. It gives MCP clients practical Cloud DevOps tools for infrastructure risk review, incident response, CI/CD readiness and SLO error budget analysis.

The v0.3 line adds cross-domain change correlation on top of evidence-backed analysis. Tools can inspect Terraform plan JSON, AWS IAM policy JSON, Kubernetes YAML and GitHub Actions workflow YAML directly, while assess_cloud_change_bundle connects those findings into one release-risk view with domain summaries, correlated findings and potential change paths.

Table of contents

Why this exists

AI assistants are more useful in engineering work when they can call focused tools with clear inputs and consistent outputs. This server provides a Cloud DevOps tool layer for:

  • Cross-domain release-risk correlation across infrastructure, identity, runtime and delivery.
  • Infrastructure-as-code deployment risk analysis.
  • Production incident runbook generation.
  • CI/CD delivery readiness review.
  • SLO error budget calculations.
  • AWS IAM least-privilege review.
  • Kubernetes workload production readiness review.
  • GitHub Actions workflow security and deployment review.

Tools

ToolPurpose
assess_cloud_change_bundleCorrelates Terraform, IAM, Kubernetes and GitHub Actions evidence into one deployment-risk assessment with cross-domain change paths.
assess_terraform_changeScores Terraform/IaC risk and can derive evidence from raw Terraform plan JSON.
build_incident_runbookProduces a practical incident response runbook for a service, symptom, environment and severity.
review_cicd_pipelineReviews CI/CD maturity while separating failed controls from unknown evidence.
estimate_slo_error_budgetCalculates downtime and request-failure budgets with consistency validation.
review_iam_policyParses IAM policy JSON and detects wildcard scope and privilege-escalation paths.
review_kubernetes_deploymentParses Kubernetes YAML for probes, resources, disruption protection, image and exposure risks.
review_github_actions_workflowParses workflow YAML for triggers, immutable action pins, permissions, caching and concurrency.

Architecture

mermaid
flowchart TD  Client["MCP client"] --> Transport["stdio transport"]  Transport --> Server["Cloud DevOps MCP server"]  Server --> DomainTools["Domain analyzers"]  DomainTools --> Correlator["Cross-domain correlation engine"]  DomainTools --> Output["Structured guidance"]  Correlator --> Output

Quickstart

Run the published MCP server directly from npm:

On Windows PowerShell systems where script execution policy blocks npx.ps1, use:

powershell

Install from npm

Install the CLI globally if you prefer a persistent local command:

bash
npm install -g [email protected]cloud-devops-mcp-server

The package is published on npm as cloud-devops-mcp-server and registered in the official MCP Registry as io.github.alexcgodwin/cloud-devops-mcp-server.

MCP clients

Cloud DevOps MCP Server is designed for MCP clients that support stdio servers, including:

  • Cursor
  • Claude Desktop
  • VS Code with MCP support
  • Claude Code
  • Other clients that follow the Model Context Protocol stdio transport

Use any MCP host that supports local stdio servers. The server does not require cloud credentials or a hosted endpoint.

Configuration

For MCP clients that support local stdio servers, the recommended public configuration is:

json
{  "mcpServers": {    "cloud-devops": {      "command": "npx",      "args": ["-y", "[email protected]"]    }  }}

Windows clients can use npx.cmd if npx resolves through a blocked PowerShell wrapper:

json
{  "mcpServers": {    "cloud-devops": {      "command": "npx.cmd",      "args": ["-y", "[email protected]"]    }  }}

See docs/configuration.md for npm, global-install and source-development configuration options.

Public release verification

The published 0.3.1 package was acceptance-tested from a clean directory using both the npm-installed CLI and the exact public npx command. The test discovered all eight tools, executed all eight successfully through stdio, verified the new cross-domain bundle analysis, rejected malformed input, and found no credential, private-key, token or .env files in the published package. npm also exposes SLSA provenance for the trusted GitHub Actions publish.

See docs/public-acceptance.md for the verification record.

Example tool input

json
{  "changedResources": ["network", "iam", "kubernetes"],  "includesIamChanges": true,  "includesPublicIngress": true,  "modifiesStatefulResources": false,  "hasRollbackPlan": true,  "hasPeerReview": true,  "hasTerraformPlan": true}

Example output shape:

json
{  "riskScore": 78,  "riskLevel": "critical",  "changedResources": ["network", "iam", "kubernetes"],  "recommendedReleasePath": "Change-advisory review, maintenance window and staged execution are recommended."}

Demo outputs

See docs/demo.md for practical sample inputs and outputs across the toolset.

Docker

Build and run the server in a container:

bash
docker build -t cloud-devops-mcp-server .docker run --rm -i cloud-devops-mcp-server

Development

bash
npm run devnpm run buildnpm testnpm run check

The core decision logic lives in src/logic.ts and the MCP tool registration lives in src/index.ts.

More project notes are available in DEVELOPMENT.md, RELEASE.md and docs/architecture.md.

Security model

  • The server runs locally over stdio.
  • It does not require cloud credentials.
  • It does not call external APIs.
  • It does not write to infrastructure or mutate user systems.
  • It returns advisory guidance only; engineers remain responsible for review, approval and execution.

Roadmap

  • Expand Terraform plan evidence rules across AWS, Azure and Google Cloud resources.
  • Add read-only cloud inventory checks with explicitly scoped credentials.
  • Add hosted Streamable HTTP transport with authentication and tenant isolation.
  • Add signed release provenance, SBOM generation and automated npm/MCP Registry publication.
  • Expand cross-domain correlation with policy packs for identity, data, networking and supply-chain risk.
  • Add machine-readable policy profiles for production, staging and regulated workloads.

Author

Built by Alex C. Godwin, Cloud DevOps Engineer.

Source: README.md at commit b9ee696

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.3.1LatestOct 1, 2026