Cloud DevOps MCP Server

io.github.alexcgodwinv0.3.1更新於 Oct 1, 2026

Cloud DevOps risk review with cross-domain IaC, IAM, Kubernetes and CI/CD correlation.

概覽

AI 產生的概覽

一個本機 MCP 伺服器,針對 Terraform、IAM、Kubernetes 與 CI/CD 證據進行雲端 DevOps 風險審查。

功能
它提供八個諮詢類工具:assess_cloud_change_bundle 將 Terraform、IAM、Kubernetes 與 GitHub Actions 證據關聯成一份部署風險檢視;assess_terraform_change 依 Terraform plan JSON 評估 IaC 風險;review_iam_policy 偵測萬用字元範圍與權限提升路徑;review_kubernetes_deployment 檢查探針、資源、中斷保護、映像與暴露風險;review_github_actions_workflow 檢查觸發條件、動作固定版本、權限、快取與並行;review_cicd_pipeline 評估交付成熟度;build_incident_runbook 產生事件回應手冊;estimate_slo_error_budget 計算停機與請求失敗預算。
適用情境
適合在助理需要審查規劃中的基礎設施或發布變更、在部署前檢查 IAM 或 Kubernetes 設定、撰寫事件回應手冊,或分析 SLO 錯誤預算時使用。適合希望在 MCP 用戶端中取得結構化、有證據支撐之風險建議的工程師。
執行需求
以 stdio 本機程序執行,通常透過 npx cloud-devops-mcp-server 或全域 npm 安裝啟動,因此需要 Node.js 與 npm。需要支援本機 stdio 伺服器的 MCP 用戶端。README 說明無需雲端憑證、無需託管端點,也不存取外部 API。
安裝前請注意
此伺服器僅回傳諮詢性建議,審查、核准與執行仍由工程師負責。說明中稱其不會寫入基礎設施或變更使用者系統,也不呼叫外部 API,因此 Terraform plan JSON、IAM 政策 JSON 以及 Kubernetes 或工作流程 YAML 等輸入都在本機分析。其風險評分應視為建議,而非核准關卡。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Cloud DevOps MCP Server,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

Cloud DevOps MCP Server

[CI] [npm version] [MCP Registry] [License: MIT] [MCP]

Cloud DevOps MCP Server is a Model Context Protocol v2 server by Alex C. Godwin. It gives MCP clients practical Cloud DevOps tools for infrastructure risk review, incident response, CI/CD readiness and SLO error budget analysis.

The v0.3 line adds cross-domain change correlation on top of evidence-backed analysis. Tools can inspect Terraform plan JSON, AWS IAM policy JSON, Kubernetes YAML and GitHub Actions workflow YAML directly, while assess_cloud_change_bundle connects those findings into one release-risk view with domain summaries, correlated findings and potential change paths.

Table of contents

Why this exists

AI assistants are more useful in engineering work when they can call focused tools with clear inputs and consistent outputs. This server provides a Cloud DevOps tool layer for:

  • Cross-domain release-risk correlation across infrastructure, identity, runtime and delivery.
  • Infrastructure-as-code deployment risk analysis.
  • Production incident runbook generation.
  • CI/CD delivery readiness review.
  • SLO error budget calculations.
  • AWS IAM least-privilege review.
  • Kubernetes workload production readiness review.
  • GitHub Actions workflow security and deployment review.

Tools

ToolPurpose
assess_cloud_change_bundleCorrelates Terraform, IAM, Kubernetes and GitHub Actions evidence into one deployment-risk assessment with cross-domain change paths.
assess_terraform_changeScores Terraform/IaC risk and can derive evidence from raw Terraform plan JSON.
build_incident_runbookProduces a practical incident response runbook for a service, symptom, environment and severity.
review_cicd_pipelineReviews CI/CD maturity while separating failed controls from unknown evidence.
estimate_slo_error_budgetCalculates downtime and request-failure budgets with consistency validation.
review_iam_policyParses IAM policy JSON and detects wildcard scope and privilege-escalation paths.
review_kubernetes_deploymentParses Kubernetes YAML for probes, resources, disruption protection, image and exposure risks.
review_github_actions_workflowParses workflow YAML for triggers, immutable action pins, permissions, caching and concurrency.

Architecture

mermaid
flowchart TD  Client["MCP client"] --> Transport["stdio transport"]  Transport --> Server["Cloud DevOps MCP server"]  Server --> DomainTools["Domain analyzers"]  DomainTools --> Correlator["Cross-domain correlation engine"]  DomainTools --> Output["Structured guidance"]  Correlator --> Output

Quickstart

Run the published MCP server directly from npm:

On Windows PowerShell systems where script execution policy blocks npx.ps1, use:

powershell

Install from npm

Install the CLI globally if you prefer a persistent local command:

bash
npm install -g [email protected]cloud-devops-mcp-server

The package is published on npm as cloud-devops-mcp-server and registered in the official MCP Registry as io.github.alexcgodwin/cloud-devops-mcp-server.

MCP clients

Cloud DevOps MCP Server is designed for MCP clients that support stdio servers, including:

  • Cursor
  • Claude Desktop
  • VS Code with MCP support
  • Claude Code
  • Other clients that follow the Model Context Protocol stdio transport

Use any MCP host that supports local stdio servers. The server does not require cloud credentials or a hosted endpoint.

Configuration

For MCP clients that support local stdio servers, the recommended public configuration is:

json
{  "mcpServers": {    "cloud-devops": {      "command": "npx",      "args": ["-y", "[email protected]"]    }  }}

Windows clients can use npx.cmd if npx resolves through a blocked PowerShell wrapper:

json
{  "mcpServers": {    "cloud-devops": {      "command": "npx.cmd",      "args": ["-y", "[email protected]"]    }  }}

See docs/configuration.md for npm, global-install and source-development configuration options.

Public release verification

The published 0.3.1 package was acceptance-tested from a clean directory using both the npm-installed CLI and the exact public npx command. The test discovered all eight tools, executed all eight successfully through stdio, verified the new cross-domain bundle analysis, rejected malformed input, and found no credential, private-key, token or .env files in the published package. npm also exposes SLSA provenance for the trusted GitHub Actions publish.

See docs/public-acceptance.md for the verification record.

Example tool input

json
{  "changedResources": ["network", "iam", "kubernetes"],  "includesIamChanges": true,  "includesPublicIngress": true,  "modifiesStatefulResources": false,  "hasRollbackPlan": true,  "hasPeerReview": true,  "hasTerraformPlan": true}

Example output shape:

json
{  "riskScore": 78,  "riskLevel": "critical",  "changedResources": ["network", "iam", "kubernetes"],  "recommendedReleasePath": "Change-advisory review, maintenance window and staged execution are recommended."}

Demo outputs

See docs/demo.md for practical sample inputs and outputs across the toolset.

Docker

Build and run the server in a container:

bash
docker build -t cloud-devops-mcp-server .docker run --rm -i cloud-devops-mcp-server

Development

bash
npm run devnpm run buildnpm testnpm run check

The core decision logic lives in src/logic.ts and the MCP tool registration lives in src/index.ts.

More project notes are available in DEVELOPMENT.md, RELEASE.md and docs/architecture.md.

Security model

  • The server runs locally over stdio.
  • It does not require cloud credentials.
  • It does not call external APIs.
  • It does not write to infrastructure or mutate user systems.
  • It returns advisory guidance only; engineers remain responsible for review, approval and execution.

Roadmap

  • Expand Terraform plan evidence rules across AWS, Azure and Google Cloud resources.
  • Add read-only cloud inventory checks with explicitly scoped credentials.
  • Add hosted Streamable HTTP transport with authentication and tenant isolation.
  • Add signed release provenance, SBOM generation and automated npm/MCP Registry publication.
  • Expand cross-domain correlation with policy packs for identity, data, networking and supply-chain risk.
  • Add machine-readable policy profiles for production, staging and regulated workloads.

Author

Built by Alex C. Godwin, Cloud DevOps Engineer.

來源:README.md,提交 b9ee696

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.3.1最新Oct 1, 2026