Cloud DevOps analysis with guarded Git, infrastructure, cloud and observability operations.
Cloud DevOps MCP Server is a Model Context Protocol v2 server by Alex C. Godwin. It provides evidence-backed Cloud DevOps analysis across infrastructure, identity, Kubernetes, CI/CD, SRE and software supply-chain controls.
The v0.12 line adds an opt-in OpsChugex cloud security posture gateway. The public MCP forwards bounded cloud asset, identity, secret and network-reachability evidence to a host-configured private OpsChugex service and returns security score, risk level, ordered findings, attack paths, evidence gaps and recommendations. Proprietary security rules, severity thresholds, scoring and attack-path correlation are not included in this public MIT repository.
The v0.11 line adds an opt-in OpsChugex policy and governance gateway. The public MCP sends bounded resource evidence and approved exception metadata to a host-configured private OpsChugex service and returns pass, review or block decisions with control findings and evidence gaps. Proprietary profiles, rules, weights and exception-processing logic are not included in this public MIT repository.
The v0.10 line adds an opt-in OpsChugex root-cause intelligence gateway. The public MCP sends bounded incident evidence to a host-configured private OpsChugex service and returns evidence-ranked probable causes, contradictions, limitations and next checks. Proprietary ranking and correlation rules are not included in this public MIT repository.
The v0.9 line adds an opt-in distributed-tracing and SLO-intelligence plane for Grafana Tempo and Jaeger v3 trace reads, service dependency mapping, tracing coverage assessment, multi-window SLO burn-rate analysis and trace/SLO incident correlation. The v0.8 production-observability and operations-intelligence plane remains available for Prometheus, Grafana, CloudWatch Logs Insights, Kubernetes health, GitHub Actions diagnosis, cloud health, FinOps and drift. Live AWS, Azure and GCP access remains bounded and read-only. Cloud mutation remains intentionally unavailable.
AI assistants are more useful in engineering work when they can call focused tools with clear inputs and consistent outputs. This server provides a Cloud DevOps tool layer for:
| Tool | Purpose |
|---|---|
assess_cloud_change_bundle | Correlates Terraform, IAM, Kubernetes and GitHub Actions evidence into one deployment-risk assessment with cross-domain change paths. |
assess_terraform_change | Scores Terraform/IaC risk and can derive evidence from raw Terraform plan JSON. |
build_incident_runbook | Produces a practical incident response runbook for a service, symptom, environment and severity. |
review_cicd_pipeline | Reviews CI/CD maturity while separating failed controls from unknown evidence. |
estimate_slo_error_budget | Calculates downtime and request-failure budgets with consistency validation. |
review_iam_policy | Parses IAM policy JSON and detects wildcard scope and privilege-escalation paths. |
review_kubernetes_deployment | Parses Kubernetes YAML for probes, resources, disruption protection, image and exposure risks. |
review_github_actions_workflow | Parses workflow YAML for triggers, immutable action pins, permissions, caching and concurrency. |
review_cloud_identity_policy | Applies AWS IAM, Azure RBAC or GCP IAM policy packs to raw policy JSON. |
review_terraform_security | Reviews Terraform plan JSON for destructive changes, public exposure, encryption, deletion protection and wildcard IAM. |
review_kubernetes_security | Reviews privileged mode, host access, service accounts, capabilities, seccomp, root filesystems and NetworkPolicy. |
review_software_supply_chain | Correlates CycloneDX/SPDX SBOM quality with CI action pinning, image immutability, signatures and provenance. |
When explicitly enabled, six additional tools provide allowlisted AWS/Azure/GCP identity verification, bounded inventory, managed Kubernetes discovery, observability configuration summaries, FinOps waste signals and drift reporting. No cloud mutation commands are exposed. AWS general inventory is sourced from the Resource Groups Tagging API, so untagged AWS resources may not appear in that inventory or AWS drift comparison.
When explicitly enabled, twelve additional tools provide bounded Prometheus queries, Grafana alert summaries, CloudWatch Logs Insights queries, Kubernetes pod-health summaries, GitHub Actions failure diagnosis, cross-signal incident correlation, cloud-health assessment, deployment/incident correlation, observability coverage assessment, FinOps correlation, cross-runtime drift analysis and operations briefs. Endpoints, cloud scopes, log groups, cluster contexts, namespaces and repositories are allowlisted. The layer is read-only and exposes no alert mutation, deployment mutation or arbitrary shell execution.
When explicitly enabled, six additional v0.9 tools provide bounded Tempo/Jaeger trace search and retrieval, service dependency mapping, tracing coverage assessment, multi-window SLO burn-rate analysis and trace/SLO incident correlation. Remote tracing endpoints must be allowlisted and use HTTPS unless loopback. Backend credentials stay in host environment variables. Trace search windows and result sizes are bounded, and the plane exposes no trace ingestion, sampling mutation or telemetry deletion.
When explicitly enabled, v0.10 exposes diagnose_root_cause. The tool accepts bounded evidence from metrics, logs, traces, Kubernetes, cloud, Terraform and CI/CD, then calls a host-configured private OpsChugex service. The public MCP contains no proprietary ranking rules, accepts no service URL or credential as tool input, and performs no remediation. Evidence scores represent evidence strength rather than statistical probability.
When explicitly enabled, v0.11 exposes assess_governance_policy. The tool accepts bounded factual resource evidence plus optional owner-attributed, time-bounded exceptions and forwards them to the private OpsChugex policy engine. It returns pass, review, or block with control findings and evidence gaps.
The public MCP contains no proprietary governance profiles, policy rules, scoring weights, exception evaluation logic or enforcement capability. The service URL and token remain host-side and cannot be supplied as MCP arguments.
When explicitly enabled, v0.12 exposes assess_cloud_security_posture. The tool accepts bounded asset, identity, secret and network-reachability evidence and forwards it to the private OpsChugex security engine. It returns a security score, risk level, ordered findings, correlated attack paths, evidence gaps and recommended next actions.
The public MCP contains no proprietary security detection thresholds, severity rules, scoring logic or attack-path algorithm. It cannot rotate credentials, change IAM, modify network controls, alter encryption settings or remediate infrastructure.
When explicitly enabled, six additional tools provide Terraform format/validation/plan summaries and Kubernetes read-only runtime inspection. These operations use repository, context, namespace and resource allowlists. Full Terraform plan JSON, Kubernetes Secrets, arbitrary shell execution, Terraform apply and Kubernetes mutation are deliberately excluded.
flowchart TD
LocalClient["Local MCP client"] --> Stdio["stdio"]
RemoteClient["Remote MCP client"] --> HTTPS["HTTPS reverse proxy / gateway"]
HTTPS --> AuthHTTP["Bearer-authenticated Streamable HTTP"]
Stdio --> Server["Cloud DevOps MCP server"]
AuthHTTP --> Server
Server --> DomainTools["Domain + policy-pack analyzers"]
DomainTools --> Correlator["Cross-domain and supply-chain correlation"]
DomainTools --> Output["Structured guidance"]
Correlator --> Output
Run the published MCP server directly from npm:
npx -y cloud-devops-mcp-server@0.12.0
On Windows PowerShell systems where script execution policy blocks npx.ps1, use:
npx.cmd -y cloud-devops-mcp-server@0.12.0
Install the CLI globally if you prefer a persistent local command:
npm install -g cloud-devops-mcp-server@0.12.0
cloud-devops-mcp-server
The package is published on npm as cloud-devops-mcp-server and registered in the official MCP Registry as io.github.alexcgodwin/cloud-devops-mcp-server.
Cloud DevOps MCP Server supports local stdio clients and MCP clients capable of connecting to Streamable HTTP endpoints. Common local clients include:
Use stdio for normal local operation. For self-hosted remote access, start the optional authenticated Streamable HTTP endpoint and place non-local deployments behind an HTTPS reverse proxy or gateway.
For MCP clients that support local stdio servers, the recommended public configuration is:
{
"mcpServers": {
"cloud-devops": {
"command": "npx",
"args": ["-y", "cloud-devops-mcp-server@0.12.0"]
}
}
}
Windows clients can use npx.cmd if npx resolves through a blocked PowerShell wrapper:
{
"mcpServers": {
"cloud-devops": {
"command": "npx.cmd",
"args": ["-y", "cloud-devops-mcp-server@0.12.0"]
}
}
}
See docs/configuration.md for npm, global-install, source-development and authenticated Streamable HTTP configuration options.
Local loopback example:
$env:CLOUD_DEVOPS_MCP_BEARER_TOKEN="<random secret at least 32 characters>"
npm run start:http
The MCP endpoint is http://127.0.0.1:3000/mcp and requires Authorization: Bearer <token>. A non-local bind additionally requires CLOUD_DEVOPS_MCP_ALLOWED_HOSTS and an HTTPS CLOUD_DEVOPS_MCP_PUBLIC_BASE_URL so remote traffic is expected to terminate TLS at a reverse proxy or gateway.
The v0.12.0 release candidate passes 106 automated tests, with 85.71% statement, 72.10% branch, 85.49% function and 89.10% line coverage. The production dependency audit reports zero vulnerabilities. Public clean-install and MCP Registry acceptance are recorded after publication.
See docs/public-acceptance.md for the verification record.
{
"changedResources": ["network", "iam", "kubernetes"],
"includesIamChanges": true,
"includesPublicIngress": true,
"modifiesStatefulResources": false,
"hasRollbackPlan": true,
"hasPeerReview": true,
"hasTerraformPlan": true
}
Example output shape:
{
"riskScore": 78,
"riskLevel": "critical",
"changedResources": ["network", "iam", "kubernetes"],
"recommendedReleasePath": "Change-advisory review, maintenance window and staged execution are recommended."
}
See docs/demo.md for practical sample inputs and outputs across the toolset.
Build and run the server in a container:
docker build -t cloud-devops-mcp-server .
docker run --rm -i cloud-devops-mcp-server
npm run dev
npm run build
npm test
npm run check
The core decision logic lives in src/logic.ts and the MCP tool registration lives in src/index.ts.
More project notes are available in DEVELOPMENT.md, RELEASE.md and docs/architecture.md.
Built by Alex C. Godwin, Cloud DevOps Engineer.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y cloud-devops-mcp-serverMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-alexcgodwin-cloud-devops-mcp-server": {
"command": "npx",
"args": [
"-y",
"cloud-devops-mcp-server"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referencecloud-devops-mcp-servernpmCloud DevOps MCP Server works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.