MCP v2 server for Cloud DevOps analysis, guarded Git/GitHub and infrastructure operations, plus live AWS/Azure/GCP inventory.
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
claude mcp add cloud-devops -- npx -y cloud-devops-mcp-server{
"mcpServers": {
"cloud-devops": {
"command": "npx",
"args": ["-y", "cloud-devops-mcp-server"],
"env": {
"CLOUD_DEVOPS_MCP_BEARER_TOKEN": "<cloud_devops_mcp_bearer_token>"
}
}
}
}CLOUD_DEVOPS_MCP_BEARER_TOKENResumen de MCP Servers
# Cloud DevOps MCP Server
<!-- mcp-name: io.github.alexcgodwin/cloud-devops-mcp-server -->
[](https://github.com/alexcgodwin/cloud-devops-mcp-server/actions/workflows/ci.yml)
[](https://www.npmjs.com/package/cloud-devops-mcp-server)
[](https://registry.modelcontextprotocol.io/v0.1/servers?search=io.github.alexcgodwin%2Fcloud-devops-mcp-server)
[](LICENSE)
[](server.json)
Cloud DevOps MCP Server is a Model Context Protocol v2 server by Alex C. Godwin. It provides evidence-backed Cloud DevOps analysis across infrastructure, identity, Kubernetes, CI/CD, SRE and software supply-chain controls.
The v0.7 line adds an opt-in live multi-cloud read plane for AWS, Azure and GCP: identity verification, bounded inventory, EKS/AKS/GKE discovery, observability summaries, FinOps waste signals and expected-vs-live drift reporting. Cloud mutation remains intentionally unavailable.
## Table of contents
- [Why this exists](#why-this-exists)
- [Tools](#tools)
- [Architecture](#architecture)
- [Quickstart](#quickstart)
- [Install from npm](#install-from-npm)
- [MCP clients](#mcp-clients)
- [Configuration](#configuration)
- [Authenticated Streamable HTTP](#authenticated-streamable-http)
- [Public release verification](#public-release-verification)
- [Example tool input](#example-tool-input)
- [Demo outputs](#demo-outputs)
- [Docker](#docker)
- [Development](#development)
- [Security model](#security-model)
- [Roadmap](#roadmap)
- [Author](#author)
## Why this exists
AI assistants are more useful in engineering work when they can call focused tools with clear inputs and consistent outputs. This server provides a Cloud DevOps tool layer for:
- Cross-domain release-risk correlation across infrastructure, identity, runtime and delivery.
- Infrastructure-as-code deployment risk analysis.
- Production incident runbook generation.
- CI/CD delivery readiness review.
- SLO error budget calculations.
- AWS IAM least-privilege review.
- AWS, Azure and GCP identity policy packs.
- Terraform destructive-change, public exposure and encryption security analysis.
- Kubernetes workload production readiness and security-policy analysis.
- GitHub Actions workflow security and deployment review.
- CycloneDX/SPDX SBOM quality and software supply-chain correlation.
- Optional authenticated Streamable HTTP serving for self-hosted remote access.
- Optional allowlisted live AWS/Azure/GCP inventory, observability, FinOps and drift signals.
## Tools
| Tool | Purpose |
| --- | --- |
| `assess_cloud_change_bundle` | Correlates Terraform, IAM, Kubernetes and GitHub Actions evidence into one deployment-risk assessment with cross-domain change paths. |
| `assess_terraform_change` | Scores Terraform/IaC risk and can derive evidence from raw Terraform plan JSON. |
| `build_incident_runbook` | Produces a practical incident response runbook for a service, symptom, environment and severity. |
| `review_cicd_pipeline` | Reviews CI/CD maturity while separating failed controls from unknown evidence. |
| `estimate_slo_error_budget` | Calculates downtime and request-failure budgets with consistency validation. |
| `review_iam_policy` | Parses IAM policy JSON and detects wildcard scope and privilege-escalation paths. |
| `review_kubernetes_deployment` | Parses Kubernetes YAML for probes, resources, disruption protection, image and exposure risks. |
| `review_github_actions_workflow` | Parses workflow YAML for triggers, immutable action pins, permissions, caching and concurrency. |
| `review_cloud_identity_policy` | Applies AWS IAM, Azure RBAC or GCP IAM policy packs to raw policy JSON. |
| `review_terraform_security` | Reviews Terraform plan JSON for destructive changes, public exposure, encryption, deletion protection and wildcard IAM. |
| `review_kubernetes_security` | Reviews privileged mode, host access, service accounts, capabilities, seccomp, root filesystems and NetworkPolicy. |
| `review_software_supply_chain` | Correlates CycloneDX/SPDX SBOM quality with CI action pinning, image immutability, signatures and provenance. |
### Optional live multi-cloud reads
When explicitly enabled, six additional tools provide allowlisted AWS/Azure/GCP identity verification, bounded inventory, managed Kubernetes discovery, observability configuration summaries, FinOps waste signals and drift reporting. No cloud mutation commands are exposed. AWS general inventory is sourced from the Resource Groups Tagging API, so untagged AWS resources may not appear in that inventory or AWS drift comparison.
### Optional infrastructure operations
When explicitly enabled, six additional tools provide Terraform format/validation/plan summaries and Kubernetes read-only runtime inspection. These operations use repository, context, namespace and resource allowlists. Full Terraform plan JSON, Kubernetes Secrets, arbitrary shell execution, Terraform apply and Kubernetes mutation are deliberately excluded.
## Architecture
```mermaid
flowchart TD
LocalClient["Local MCP client"] --> Stdio["stdio"]
RemoteClient["Remote MCP client"] --> HTTPS["HTTPS reverse proxy / gateway"]
HTTPS --> AuthHTTP["Bearer-authenticated Streamable HTTP"]
Stdio --> Server["Cloud DevOps MCP server"]
AuthHTTP --> Server
Server --> DomainTools["Domain + policy-pack analyzers"]
DomainTools --> Correlator["Cross-domain and supply-chain correlation"]
DomainTools --> Output["Structured guidance"]
Correlator --> Output
```
## Quickstart
Run the published MCP server directly from npm:
```bash
npx -y cloud-devops-mcp-server@0.7.0
```
On Windows PowerShell systems where script execution policy blocks `npx.ps1`, use:
```powershell
npx.cmd -y cloud-devops-mcp-server@0.7.0
```
## Install from npm
Install the CLI globally if you prefer a persistent local command:
```bash
npm install -g cloud-devops-mcp-server@0.7.0
cloud-devops-mcp-server
```
The package is published on npm as `cloud-devops-mcp-server` and registered in the official MCP Registry as `io.github.alexcgodwin/cloud-devops-mcp-server`.
## MCP clients
Cloud DevOps MCP Server supports local stdio clients and MCP clients capable of connecting to Streamable HTTP endpoints. Common local clients include:
- Cursor
- Claude Desktop
- VS Code with MCP support
- Claude Code
- Other clients that follow the Model Context Protocol stdio transport
Use stdio for normal local operation. For self-hosted remote access, start the optional authenticated Streamable HTTP endpoint and place non-local deployments behind an HTTPS reverse proxy or gateway.
## Configuration
For MCP clients that support local stdio servers, the recommended public configuration is:
```json
{
"mcpServers": {
"cloud-devops": {
"command": "npx",
"args": ["-y", "cloud-devops-mcp-server@0.7.0"]
}
}
}
```
Windows clients can use `npx.cmd` if `npx` resolves through a blocked PowerShell wrapper:
```json
{
"mcpServers": {
"cloud-devops": {
"command": "npx.cmd",
"args": ["-y", "cloud-devops-mcp-server@0.7.0"]
}
}
}
```
See [docs/configuration.md](docs/configuration.md) for npm, global-install, source-development and authenticated Streamable HTTP configuration options.
## Authenticated Streamable HTTP
Local loopback example:
```powershell
$env:CLOUD_DEVOPS_MCP_BEARER_TOKEN="<random secret at least 32 characters>"
npm run start:http
```
The MCP endpoint is `http://127.0.0.1:3000/mcp` and requires `Authorization: Bearer <token>`. A non-local bind additionally requires `CLOUD_DEVOPS_MCP_ALLOWED_HOSTS` and an HTTPS `CLOUD_DEVOPS_MCP_PUBLIC_BASE_URL` so remote traffic is expected to terminate TLS at a reverse proxy or gateway.
## Public release verification
The v0.7.0 release candidate passes 57 automated tests, the full coverage gate and a production dependency audit with zero vulnerabilities. Public clean-install acceptance is recorded after npm and MCP Registry publication.
See [docs/public-acceptance.md](docs/public-acceptance.md) for the verification record.
## Example tool input
```json
{
"changedResources": ["network", "iam", "kubernetes"],
"includesIamChanges": true,
"includesPublicIngress": true,
"modifiesStatefulResources": false,
"hasRollbackPlan": true,
"hasPeerReview": true,
"hasTerraformPlan": true
}
```
Example output shape:
```json
{
"riskScore": 78,
"riskLevel": "critical",
"changedResources": ["network", "iam", "kubernetes"],
"recommendedReleasePath": "Change-advisory review, maintenance window and staged execution are recommended."
}
```
## Demo outputs
See [docs/demo.md](docs/demo.md) for practical sample inputs and outputs across the toolset.
## Docker
Build and run the server in a container:
```bash
docker build -t cloud-devops-mcp-server .
docker run --rm -i cloud-devops-mcp-server
```
## Development
```bash
npm run dev
npm run build
npm test
npm run check
```
The core decision logic lives in `src/logic.ts` and the MCP tool registration lives in `src/index.ts`.
More project notes are available in [DEVELOPMENT.md](DEVELOPMENT.md), [RELEASE.md](RELEASE.md) and [docs/architecture.md](docs/architecture.md).
## Security model
- Stdio remains the default and requires no secrets.
- Optional Streamable HTTP requires a bearer token of at least 32 characters.
- Non-local HTTP binds require an explicit Host allowlist and an HTTPS public base URL for reverse-proxy/gateway termination.
- Host and Origin validation are enabled through the official MCP Fastify adapter.
- The default analysis tools do not require cloud credentials or call cloud APIs.
- Optional Terraform/Kubernetes operations may use locally configured providLo que la gente pregunta sobre cloud-devops-mcp-server
¿Qué es alexcgodwin/cloud-devops-mcp-server?
+
alexcgodwin/cloud-devops-mcp-server es mcp servers para el ecosistema de Claude AI. MCP v2 server for Cloud DevOps analysis, guarded Git/GitHub and infrastructure operations, plus live AWS/Azure/GCP inventory. Tiene 0 estrellas en GitHub y su última actualización registrada es del 2026-10-02.
¿Cómo se instala cloud-devops-mcp-server?
+
Puedes instalar cloud-devops-mcp-server clonando el repositorio (https://github.com/alexcgodwin/cloud-devops-mcp-server) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar alexcgodwin/cloud-devops-mcp-server?
+
Nuestro agente de seguridad ha analizado alexcgodwin/cloud-devops-mcp-server y le ha asignado un Trust Score de 95/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene alexcgodwin/cloud-devops-mcp-server?
+
alexcgodwin/cloud-devops-mcp-server es mantenido por alexcgodwin. La última actividad registrada en GitHub es del 2026-10-02, con 0 issues abiertos.
¿Hay alternativas a cloud-devops-mcp-server?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega cloud-devops-mcp-server en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/alexcgodwin-cloud-devops-mcp-server)<a href="https://claudewave.com/repo/alexcgodwin-cloud-devops-mcp-server"><img src="https://claudewave.com/api/badge/alexcgodwin-cloud-devops-mcp-server" alt="Featured on ClaudeWave: alexcgodwin/cloud-devops-mcp-server" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.