Cloud DevOps MCP Server

io.github.alexcgodwinv0.7.0更新于 Oct 2, 2026

Cloud DevOps analysis plus opt-in Git, Terraform, Kubernetes and multi-cloud inventory.

概览

AI 生成的概览

一个本地 MCP 服务器,针对 Terraform、IAM、Kubernetes 与 CI/CD 证据进行云 DevOps 风险审查。

功能
它提供八个咨询类工具:assess_cloud_change_bundle 将 Terraform、IAM、Kubernetes 与 GitHub Actions 证据关联为一份部署风险视图;assess_terraform_change 依据 Terraform plan JSON 评估 IaC 风险;review_iam_policy 检测通配符范围与权限提升路径;review_kubernetes_deployment 检查探针、资源、中断保护、镜像与暴露风险;review_github_actions_workflow 检查触发器、动作固定版本、权限、缓存与并发;review_cicd_pipeline 评估交付成熟度;build_incident_runbook 生成事件响应手册;estimate_slo_error_budget 计算停机与请求失败预算。
适用场景
适合在助手需要审查计划中的基础设施或发布变更、在部署前检查 IAM 或 Kubernetes 配置、编写事件响应手册,或分析 SLO 错误预算时使用。面向希望在 MCP 客户端中获得结构化、有证据支撑的风险建议的工程师。
运行要求
以 stdio 本地进程运行,通常通过 npx cloud-devops-mcp-server 或全局 npm 安装启动,因此需要 Node.js 与 npm。需要支持本地 stdio 服务器的 MCP 客户端。README 说明无需云凭证、无需托管端点,也不访问外部 API。
安装前请注意
该服务器仅返回咨询性建议,审查、批准与执行仍由工程师负责。说明中称其不会写入基础设施或改动用户系统,也不调用外部 API,因此 Terraform plan JSON、IAM 策略 JSON 以及 Kubernetes 或工作流 YAML 等输入均在本地分析。其风险评分应视为建议,而非审批门槛。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Cloud DevOps MCP Server,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

Cloud DevOps MCP Server

[CI] [npm version] [MCP Registry] [License: MIT] [MCP]

Cloud DevOps MCP Server is a Model Context Protocol v2 server by Alex C. Godwin. It gives MCP clients practical Cloud DevOps tools for infrastructure risk review, incident response, CI/CD readiness and SLO error budget analysis.

The v0.3 line adds cross-domain change correlation on top of evidence-backed analysis. Tools can inspect Terraform plan JSON, AWS IAM policy JSON, Kubernetes YAML and GitHub Actions workflow YAML directly, while assess_cloud_change_bundle connects those findings into one release-risk view with domain summaries, correlated findings and potential change paths.

Table of contents

Why this exists

AI assistants are more useful in engineering work when they can call focused tools with clear inputs and consistent outputs. This server provides a Cloud DevOps tool layer for:

  • Cross-domain release-risk correlation across infrastructure, identity, runtime and delivery.
  • Infrastructure-as-code deployment risk analysis.
  • Production incident runbook generation.
  • CI/CD delivery readiness review.
  • SLO error budget calculations.
  • AWS IAM least-privilege review.
  • Kubernetes workload production readiness review.
  • GitHub Actions workflow security and deployment review.

Tools

ToolPurpose
assess_cloud_change_bundleCorrelates Terraform, IAM, Kubernetes and GitHub Actions evidence into one deployment-risk assessment with cross-domain change paths.
assess_terraform_changeScores Terraform/IaC risk and can derive evidence from raw Terraform plan JSON.
build_incident_runbookProduces a practical incident response runbook for a service, symptom, environment and severity.
review_cicd_pipelineReviews CI/CD maturity while separating failed controls from unknown evidence.
estimate_slo_error_budgetCalculates downtime and request-failure budgets with consistency validation.
review_iam_policyParses IAM policy JSON and detects wildcard scope and privilege-escalation paths.
review_kubernetes_deploymentParses Kubernetes YAML for probes, resources, disruption protection, image and exposure risks.
review_github_actions_workflowParses workflow YAML for triggers, immutable action pins, permissions, caching and concurrency.

Architecture

mermaid
flowchart TD  Client["MCP client"] --> Transport["stdio transport"]  Transport --> Server["Cloud DevOps MCP server"]  Server --> DomainTools["Domain analyzers"]  DomainTools --> Correlator["Cross-domain correlation engine"]  DomainTools --> Output["Structured guidance"]  Correlator --> Output

Quickstart

Run the published MCP server directly from npm:

On Windows PowerShell systems where script execution policy blocks npx.ps1, use:

powershell

Install from npm

Install the CLI globally if you prefer a persistent local command:

bash
npm install -g [email protected]cloud-devops-mcp-server

The package is published on npm as cloud-devops-mcp-server and registered in the official MCP Registry as io.github.alexcgodwin/cloud-devops-mcp-server.

MCP clients

Cloud DevOps MCP Server is designed for MCP clients that support stdio servers, including:

  • Cursor
  • Claude Desktop
  • VS Code with MCP support
  • Claude Code
  • Other clients that follow the Model Context Protocol stdio transport

Use any MCP host that supports local stdio servers. The server does not require cloud credentials or a hosted endpoint.

Configuration

For MCP clients that support local stdio servers, the recommended public configuration is:

json
{  "mcpServers": {    "cloud-devops": {      "command": "npx",      "args": ["-y", "[email protected]"]    }  }}

Windows clients can use npx.cmd if npx resolves through a blocked PowerShell wrapper:

json
{  "mcpServers": {    "cloud-devops": {      "command": "npx.cmd",      "args": ["-y", "[email protected]"]    }  }}

See docs/configuration.md for npm, global-install and source-development configuration options.

Public release verification

The published 0.3.1 package was acceptance-tested from a clean directory using both the npm-installed CLI and the exact public npx command. The test discovered all eight tools, executed all eight successfully through stdio, verified the new cross-domain bundle analysis, rejected malformed input, and found no credential, private-key, token or .env files in the published package. npm also exposes SLSA provenance for the trusted GitHub Actions publish.

See docs/public-acceptance.md for the verification record.

Example tool input

json
{  "changedResources": ["network", "iam", "kubernetes"],  "includesIamChanges": true,  "includesPublicIngress": true,  "modifiesStatefulResources": false,  "hasRollbackPlan": true,  "hasPeerReview": true,  "hasTerraformPlan": true}

Example output shape:

json
{  "riskScore": 78,  "riskLevel": "critical",  "changedResources": ["network", "iam", "kubernetes"],  "recommendedReleasePath": "Change-advisory review, maintenance window and staged execution are recommended."}

Demo outputs

See docs/demo.md for practical sample inputs and outputs across the toolset.

Docker

Build and run the server in a container:

bash
docker build -t cloud-devops-mcp-server .docker run --rm -i cloud-devops-mcp-server

Development

bash
npm run devnpm run buildnpm testnpm run check

The core decision logic lives in src/logic.ts and the MCP tool registration lives in src/index.ts.

More project notes are available in DEVELOPMENT.md, RELEASE.md and docs/architecture.md.

Security model

  • The server runs locally over stdio.
  • It does not require cloud credentials.
  • It does not call external APIs.
  • It does not write to infrastructure or mutate user systems.
  • It returns advisory guidance only; engineers remain responsible for review, approval and execution.

Roadmap

  • Expand Terraform plan evidence rules across AWS, Azure and Google Cloud resources.
  • Add read-only cloud inventory checks with explicitly scoped credentials.
  • Add hosted Streamable HTTP transport with authentication and tenant isolation.
  • Add signed release provenance, SBOM generation and automated npm/MCP Registry publication.
  • Expand cross-domain correlation with policy packs for identity, data, networking and supply-chain risk.
  • Add machine-readable policy profiles for production, staging and regulated workloads.

Author

Built by Alex C. Godwin, Cloud DevOps Engineer.

来源:README.md,提交 b9ee696

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.3.1Oct 1, 2026