Vendor status pages, TLS cert inspection, DNS propagation checks, and incident-response playbooks.
Check vendor status pages, inspect SSL/TLS certificates, verify DNS propagation, and get incident-response playbooks via MCP. STDIO or Streamable HTTP.
Public Hosted Server: https://devops-status.caseyjhand.com/mcp
Vendor status pages, SSL/TLS certificates, and DNS propagation — normalized across Atlassian Statuspage, Status.io, Slack, AWS Health, Google Cloud Service Health, and Firehydrant backends, plus direct TLS/DNS checks for any domain. List and check 51 built-in vendors, fetch incident timelines, watch a persisted stack, and get a tailored incident-response playbook, all without API keys. Runs as a stdio process, a local Streamable HTTP server, or the public hosted endpoint above.
| Tool | Description |
|---|---|
devops_list_vendors | List vendors in the built-in registry, optionally filtered by name or category. Returns slug, display name, category, and status page URL. |
devops_status_check | Check the current health status for one or more vendors. Returns per-vendor indicator (none / minor / major / critical / maintenance), degraded components, and active incident summaries. |
devops_get_incidents | Fetch incident history for a vendor — active, resolved, or scheduled maintenance. Returns the full incident timeline with per-update bodies and affected components. |
devops_watch_stack | Check the health of a named vendor stack persisted in session state. Pass vendors once to save the list; subsequent calls reuse it. Returns an aggregate health rollup plus per-vendor detail. |
devops_check_certs | Inspect SSL/TLS certificate health for one or more domains via a real TLS handshake. Reports expiry, chain depth, protocol version, cipher suite, and HSTS presence. Pure TypeScript — no external API. |
devops_check_dns | Resolve DNS records and verify propagation for one or more domains across Google (8.8.8.8), Cloudflare (1.1.1.1), and Quad9 (9.9.9.9). Reports per-resolver latency and resolver discrepancies. Pure TypeScript — no external API. |
devops_suggest_action | Instruction tool — returns a tailored incident-response playbook and pre-filled follow-up tool calls given a vendor name and optional incident context. No external calls; fully deterministic. |
| Resource | Description |
|---|---|
devops-status://vendors/{name} | Full registry entry for a vendor by slug — status page URL, category, and API type. |
All resource data is also reachable via tools. Tool-only agents are fully supported.
devops_list_vendors toolquery (matches name and slug, case-insensitive) and an optional category filter — eight categories: cloud, cdn-edge, dev-platform, data, comms, auth, monitoring, aiaws, gcp, gitlab, neon, slack, and redis-cloud route through native-API adapters normalized to the same shapeBuilt-in vendor registry:
| Category | Vendors |
|---|---|
cloud | digitalocean, linode, aws, gcp |
cdn-edge | cloudflare, akamai |
dev-platform | gitlab, github, npm, vercel, netlify, render, fly-io, circleci, travis-ci, snyk, atlassian, figma, launchdarkly |
data | mongodb-atlas, planetscale, supabase, neon, redis-cloud, elastic, influxdb, upstash, cloudinary, segment |
comms | slack, discord, twilio, sendgrid, mailgun, hubspot, brevo, courier, loops |
auth | auth0, clerk, workos |
monitoring | datadog, sentry, new-relic, grafana-cloud, honeycomb |
ai | openai, anthropic, elevenlabs, pinecone, cohere |
devops_status_check toolgithub, aws) or raw Atlassian Statuspage base URLs, mixed freely — up to 20 per callmode: "summary" (default): indicator + degraded components + active incidents; mode: "detailed" adds the full component list (capped at component_limit, default 50, max 500) and scheduled maintenance windowsPromise.allSettled fan-out — one failing vendor never blocks the rest; failures surface as a per-vendor error fieldcached: true on each resultsummary partitions the batch into operational / degraded / down / maintenance / unavailable countsdevops_get_incidents toolfilter: all (default, incidents + scheduled maintenances), active (investigating/identified/monitoring), resolved (fully resolved), or scheduled (maintenance windows only)limit (1–50) with offset for paging; a truncated result discloses the total and the next offset to fetchupstreamCeiling) — incidents older than that ceiling are reachable only on the vendor's own status pagefilter: "resolved" and filter: "scheduled" are always empty for itdevops_watch_stack toolvendors to define the stack — it is saved to tenant-scoped session state under stack_namevendors; the saved list is reused automaticallystack_name values (e.g., "production", "data-layer") — letters, digits, hyphens, and underscores, optionally separated by single dots or slashes, 1-64 charactershealth rollup: all_operational / maintenance (a vendor in a scheduled window, nothing worse open) / degraded / partial_outage / major_outage / unknown (a vendor could not be reached) — never all_operational when any vendor errored or is in a windowdevops_check_certs toolhttps:// prefix) — up to 10 per callwarning at < 30 days, critical at < 7), certificate subject and SANs, issuer common name, chain depth, negotiated TLS version (flags 1.0 and 1.1 as insecure), cipher suiteStrict-Transport-Security response headerstatus: "critical" distinguishes a hostname mismatch (hostname_verification_error) from an untrusted chain (authorization_error) — both would be rejected by ordinary clientsstatus: "error") rather than throwing — useful partial results when checking multiple domainsdevops_check_dns toolpartial_resolution (some resolvers answered, others didn't) signals a real problem; value_variation (all answered, different values) is normal for anycast/geo-steered domainsdevops_suggest_action toolincident_summary / affected_components prepend a targeted subsystem section (e.g. GitHub Actions → CI/CD steps, Cloudflare DNS → DNS/TTL guidance); optional vendor_indicator leads with severity-tailored urgency framingnextToolSuggestions pre-fills follow-up tool calls, including cert/DNS checks when your_domain is given — execute in sequenceDEVOPS_STATUS_DISABLE_ACTIVE_PROBES=true, guidance swaps the unregistered probe tools for equivalent manual commands (dig, openssl s_client)devops-status://vendors/{name} resourcestatuspage, statusio, slack, aws, gcp, firehydrant)devops_list_vendors — tool-only agents are fully supportedBuilt on @cyanheads/mcp-ts-core: stdio and Streamable HTTP transports, pluggable auth (none / jwt / oauth), swappable storage (in-memory, filesystem, Supabase, Cloudflare KV/R2/D1), structured logging with optional OpenTelemetry tracing.
DevOps-status-specific:
node:tls, node:dns)devops_watch_stack persists named vendor lists in tenant-scoped state for repeat morning checks or pre-deploy sweepsdevops_suggest_action dispatches category-specific playbooks deterministically — no LLM sampling dependency, works in all clientsAgent-friendly output:
devops_status_check, devops_watch_stack, devops_check_certs, devops_check_dns) use Promise.allSettled — one failing target never blocks the rest; errors surface as inline error fieldscached: true / checked_at on every status result — agents know when data was fetchednone / minor / major / critical / maintenance; operational / degraded_performance / partial_outage / major_outage / under_maintenance) — callers branch on data, not string parsingnextToolSuggestions in devops_suggest_action pre-fills tool arguments from incident context — agents can execute the playbook mechanicallyA public instance is available at https://devops-status.caseyjhand.com/mcp — no installation required. Point any MCP client at it via Streamable HTTP:
{
"mcpServers": {
"devops-status-mcp-server": {
"type": "streamable-http",
"url": "https://devops-status.caseyjhand.com/mcp"
}
}
}
No API key required. Add the following to your MCP client configuration file:
{
"mcpServers": {
"devops-status-mcp-server": {
"type": "stdio",
"command": "bunx",
"args": ["@cyanheads/devops-status-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}
Or with npx (no Bun required):
{
"mcpServers": {
"devops-status-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@cyanheads/devops-status-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}
Or with Docker:
{
"mcpServers": {
"devops-status-mcp-server": {
"type": "stdio",
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "MCP_TRANSPORT_TYPE=stdio",
"ghcr.io/cyanheads/devops-status-mcp-server:latest"
]
}
}
}
For Streamable HTTP, set the transport and start the server:
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http
# Server listens at http://localhost:3010/mcp
git clone https://github.com/cyanheads/devops-status-mcp-server.git
cd devops-status-mcp-server
bun install
cp .env.example .env
# edit .env if you want to override defaults
No API keys required. All environment variables are optional.
| Variable | Description | Default |
|---|---|---|
DEVOPS_STATUS_CACHE_TTL_MS | In-memory cache TTL for vendor status reads (all backends) in milliseconds. | 60000 |
DEVOPS_STATUS_FETCH_TIMEOUT_MS | Per-request timeout for vendor status API calls (all backends) in milliseconds. | 8000 |
DEVOPS_STATUS_CERT_TIMEOUT_MS | Default timeout_ms for devops_check_certs (per-domain TLS handshake, milliseconds). A caller-passed timeout_ms overrides it. | 5000 |
DEVOPS_STATUS_DNS_TIMEOUT_MS | Default timeout_ms for devops_check_dns (per domain+resolver query, milliseconds). A caller-passed timeout_ms overrides it. | 3000 |
DEVOPS_STATUS_ALLOW_PRIVATE_TARGETS | When true, disables SSRF guards for user-supplied URLs and domains. For trusted local/intranet deployments only. | false |
DEVOPS_STATUS_DISABLE_ACTIVE_PROBES | When true, omits the arbitrary-target probe tools (devops_check_dns, devops_check_certs) from the registered tool surface; the five vendor-registry/incident tools remain. For shared/public multi-tenant instances. | false |
MCP_TRANSPORT_TYPE | Transport: stdio or http. | stdio |
MCP_HTTP_PORT | Port for HTTP server. | 3010 |
MCP_SESSION_MODE | HTTP session handling: stateless, stateful, or auto. The server declares stateless in source — it holds no per-session state — so setting this is only needed to override that. | stateless |
MCP_AUTH_MODE | Auth mode: none, jwt, or oauth. | none |
MCP_LOG_LEVEL | Log level (RFC 5424). | info |
LOGS_DIR | Directory for log files (Node.js only). | <project-root>/logs |
OTEL_ENABLED | Enable OpenTelemetry instrumentation. | false |
See .env.example for the full list of optional overrides.
Build and run:
bun run rebuild
bun run start:stdio
# or
bun run start:http
Run checks and tests:
bun run devcheck # Lint, format, typecheck, security
bun run test # Vitest test suite
bun run lint:mcp # Validate MCP definitions against spec
docker build -t devops-status-mcp-server .
docker run --rm -p 3010:3010 devops-status-mcp-server
The Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/devops-status-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.
| Path | Purpose |
|---|---|
src/index.ts | createApp() entry point — registers tools, resources, and inits services. |
src/config/ | Server-specific environment variable parsing and validation with Zod. |
src/mcp-server/tools/ | Tool definitions (*.tool.ts). |
src/mcp-server/resources/ | Resource definitions (*.resource.ts). |
src/services/cert/ | node:tls — TLS handshake, X.509 parsing, expiry and protocol flagging. |
src/services/dns/ | node:dns — multi-resolver DNS fan-out, propagation discrepancy detection. |
src/services/statuspage/ | Statuspage public API client with 60-second in-memory cache. |
src/services/status-adapters/ | Native-API adapters (Status.io, Slack, AWS Health, Google Cloud Service Health, Firehydrant) + api_type dispatch, normalizing into the Statuspage shapes. |
src/services/vendor-registry/ | In-memory vendor registry loaded from src/data/vendor-registry.ts. |
src/data/ | Static vendor registry data file (vendor-registry.ts). |
tests/ | Vitest tests mirroring src/. |
See CLAUDE.md for development guidelines and architectural rules. The short version:
try/catch in tool logicctx.log for request-scoped logging, ctx.state for tenant-scoped storagesrc/mcp-server/*/definitions/index.tsdevops_check_certs and devops_check_dns use only Node.js stdlib — add no external deps for these pathsIssues are welcome. Run checks and tests before submitting:
bun run devcheck
bun run test
Apache-2.0 — see LICENSE for details.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y @cyanheads/devops-status-mcp-serverMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-cyanheads-devops-status-mcp-server": {
"command": "npx",
"args": [
"-y",
"@cyanheads/devops-status-mcp-server"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referenceio.github.cyanheads/devops-status-mcp-server works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.