floci-mcp
floci-mcp
로컬 Floci 인스턴스에서 AI 에이전트가 AWS 형태의 리소스를 배포하고 관리할 수 있게 해주는 MCP 서버입니다. — "이 파라미터로 EC2 인스턴스를 띄워줘", "S3 버킷과 DynamoDB 테이블을 만들어줘" 같은 요청을 처리합니다.
기능
Floci는 http://localhost:4566에서 76개의 AWS 서비스를 에뮬레이션합니다. floci-mcp는 이 엔드포인트를 MCP 호환 클라이언트에 세 가지 도구로 노출합니다:
aws_call(service, action, params)— Floci에 대해 모든 AWS API 작업(모든 서비스, 모든 액션)을 호출합니다. 핵심 도구입니다. AWS API에 대한 얇은 패스스루이므로 작업별로 수제 도구를 만들 필요 없이 76개 서비스를 모두 커버합니다.floci_status()— Floci에 연결 가능한지 확인합니다.floci_inventory()— S3, DynamoDB, Lambda, EC2, SQS, SNS, ECS, RDS에 현재 배포된 리소스를 한 번의 호출로 요약합니다.
Related MCP server: AWS MCP Server
사전 요구 사항
Python 3.10+
실행 중인 Floci 인스턴스 —
floci start또는 Docker 설정은 Floci README를 참조하세요.
설치
클론에서 설치 (아직 PyPI에 게시되지 않음):
git clone https://github.com/Awilliv/floci-mcp.git
cd floci-mcp
pip install -e .PyPI에 게시된 후:
pip install floci-mcp구성
환경 변수, 모두 선택 사항:
변수 | 기본값 | 용도 |
|
| Floci의 HTTP 엔드포인트 |
|
| 모든 boto3 클라이언트에 전달되는 리전 |
|
| 자격 증명; 12자리 값은 Floci 계정을 선택합니다 (멀티 계정 격리) |
|
| 자격 증명 (비어 있지 않은 값이면 Floci에서 작동) |
사용 예시
MCP 클라이언트에 등록한 후 에이전트에게 다음과 같이 요청할 수 있습니다:
"t3.micro 인스턴스 유형으로 ami-00000000을 사용해 EC2 인스턴스를 띄워줘"
"
reports라는 S3 버킷과 파티션 키가id인users라는 DynamoDB 테이블을 만들어줘"
에이전트는 aws_call을 통해 이를 수행합니다. 에이전트는 이미 AWS API 파라미터 형태를 알고 있으므로 서비스별 도구가 없어도 작동합니다.
MCP 클라이언트에 등록
Claude Code
여기서 AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY를 명시적으로 설정하면(실행 셸의 환경에 의존하는 대신) 다른 곳에 실제 AWS 자격 증명이 내보내져 있어도 실수로 실제 AWS 자격 증명으로 요청에 서명하는 것을 방지할 수 있습니다.
claude mcp add floci -- floci-mcp또는 .mcp.json에 추가:
{
"mcpServers": {
"floci": {
"command": "floci-mcp",
"env": {
"FLOCI_ENDPOINT_URL": "http://localhost:4566",
"AWS_ACCESS_KEY_ID": "test",
"AWS_SECRET_ACCESS_KEY": "test"
}
}
}
}Claude Desktop
claude_desktop_config.json에 추가:
{
"mcpServers": {
"floci": {
"command": "floci-mcp",
"env": {
"FLOCI_ENDPOINT_URL": "http://localhost:4566",
"AWS_ACCESS_KEY_ID": "test",
"AWS_SECRET_ACCESS_KEY": "test"
}
}
}
}Open WebUI (mcpo 경유)
Open WebUI는 MCP가 아닌 OpenAPI/도구 호출을 사용합니다. floci-mcp를 mcpo로 감싸 OpenAPI 서버로 노출합니다:
pip install mcpo
mcpo --port 8000 -- floci-mcp그런 다음 Open WebUI에서 설정 → 도구 → 도구 서버 추가로 이동하여 http://localhost:8000을 추가합니다. mcpo는 환경 변수를 실행하는 floci-mcp 프로세스에 전달하므로 mcpo를 시작하기 전에 셸에서 FLOCI_ENDPOINT_URL 등을 설정하세요.
개발
pip install -e ".[test]"
pytesttests/test_integration.py의 통합 테스트는 실행 중인 Floci 인스턴스가 필요하며, 연결할 수 없으면 자동으로 건너뜁니다.
라이선스
MIT
Available Tools
3 toolsaws_callA
Call any AWS API operation against the local Floci instance. service: boto3 service name (e.g. 'ec2', 's3', 'lambda', 'rds'). action: the AWS API operation name, e.g. 'RunInstances' or 'run_instances'. params: a JSON object of API parameters exactly as AWS documents them, e.g. {"Bucket": "my-bucket"}.
| Name | Required | Description | Default |
|---|---|---|---|
| action | Yes | ||
| params | No | ||
| service | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description reveals that parameters are passed exactly as AWS documents them, indicating a passthrough to the AWS API. However, with no annotations provided, it fails to disclose potential side effects (e.g., mutating resources), authentication requirements, or what happens on errors or returns, leaving the agent without a full picture of the tool's behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is three sentences, front-loading the core purpose and then explaining each parameter in a clear, linear structure. While it could be slightly more compact, it is efficient and well-organized, with no unnecessary filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's generic nature (any AWS API call) and the absence of an output schema, the description does not explain what the tool returns after execution, how to interpret errors, or any prerequisites like authentication. These gaps leave the agent under-informed for a potentially complex operation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Each parameter is explained in detail: service includes boto3 service name examples (ec2, s3, lambda, rds); action provides both PascalCase and snake_case examples (RunInstances vs run_instances); params is defined as a JSON object exactly as AWS documents, with a bucket example. This substantially adds meaning beyond the schema's bare types and required flags, fully compensating for the 0% schema description coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states that the tool calls any AWS API operation against a local Floci instance, specifying the verb 'Call' and the resource 'any AWS API operation' on the target. It distinguishes itself from sibling tools by being generic, though it doesn't explicitly compare, the purpose is unambiguous and specific.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no guidance on when to use this tool versus the sibling tools (floci_status, floci_inventory). The description does not mention alternatives, exclusions, or prior conditions, leaving the agent to infer that it's for arbitrary AWS calls without knowing when the siblings would be more appropriate.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
floci_inventoryA
Summarize resources currently deployed on Floci across common services: S3, DynamoDB, Lambda, EC2, SQS, SNS, ECS, RDS.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full disclosure burden. 'Summarize' inherently signals a safe, non-destructive read operation, which is adequate basic transparency. However, it does not disclose details an agent might need — whether results are scoped to a specific account/region, whether there are pagination or rate limits, or what a 'summary' contains (counts vs. names vs. configurations).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single, tightly-wound sentence that leads with the verb, names the resource scope, and enumerates the services. Every clause earns its place and there is zero filler or redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a zero-parameter inventory tool with no output schema and no annotations, the description covers the essential ground: what it does, its scope, and the eight services covered. A minor gap is that it does not describe the return shape of the summary, but since the agent is not required to construct any arguments, nothing is missing for correct invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
With zero parameters, there is no schema meaning for the description to supplement, so the baseline of 4 applies. The description adds genuine value by specifying exactly which services are included in the inventory and by clarifying that the output is a summary of currently deployed resources rather than a full configuration dump.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description names a specific verb ('Summarize'), a precise resource ('resources currently deployed on Floci'), and enumerates the covered services (S3, DynamoDB, Lambda, EC2, SQS, SNS, ECS, RDS). This clearly distinguishes it from the sibling aws_call (an execution tool) and floci_status (a status check) — an agent can tell it apart without opening either schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The verb 'Summarize' and the term 'inventory' imply this is a read-only overview used when a user wants an at-a-glance resource listing rather than executing operations (aws_call) or checking status (floci_status). However, the description never explicitly states when to prefer this tool over the alternatives, nor does it state exclusions or prerequisites. Usage context is implied, not stated.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
floci_statusA
Check whether the configured Floci instance is reachable.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries full burden. It states the tool checks reachability but does not disclose what 'reachable' entails (e.g., HTTP status, latency, auth requirements) or the exact return format. For a health-check tool, this is acceptable but minimal.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single sentence that is efficient and front-loaded, with no wasted words. It states the action and target clearly.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool has no parameters and no output schema, the description is mostly complete. However, it does not specify the nature of the result (e.g., boolean, status message) or any error handling. A slight gap, but acceptable for a simple health check.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has no parameters, and schema coverage is 100% (trivially). Per guidelines, zero parameters warrant a baseline of 4. The description adds no param-specific details because none exist.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Check') and resource ('configured Floci instance'), clearly distinguishing this status-check tool from siblings like aws_call and floci_inventory. The purpose is unambiguous and actionable.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description clearly indicates its use case (verifying reachability) which naturally separates it from inventory or calls. It does not explicitly name alternatives or exclusions, but the context is clear enough for an agent to select it when connectivity is in question.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
3 tool updates
v0.1.0- First observed
aws_call - First observed
floci_inventory - First observed
floci_status
TDQS
Scored across 3 tools
The three tools have clearly distinct purposes: aws_call for arbitrary AWS operations, floci_status for connectivity checks, and floci_inventory for resource summaries. There is no overlap or ambiguity between them.
Two tools follow a `floci_` snake_case prefix pattern, but `aws_call` uses camelCase and doesn't follow the same convention. The mixed naming style is noticeable but still readable.
With only 3 tools, the set is tightly scoped and every tool earns its place. The number is appropriate for a server that provides a generic AWS API pass-through plus convenience utilities.
The `aws_call` tool covers the full AWS API surface, so any operation can be performed. `floci_status` and `floci_inventory` fill specific monitoring and overview gaps, providing a complete workflow without dead ends.
Maintenance
Related MCP Connectors
Your AI Agent's Infrastructure Layer. Connect Claude, Copilot, Codex, or ChatGPT to 200+ managed open source services. Start databases, pipelines, and applications through natural language.
Unified API to query AWS, GCP, Azure and generate Terraform/CLI execution kits for AI agents.
Provides capabilities that let LLM agents perform a range of infrastructure management tasks.
Deploy and manage your apps, databases, storage, and scheduled jobs from your AI agent
Related MCP Servers
- AlicenseBqualityCmaintenanceEnables AI agents to deploy applications to AWS with DevOps capabilities by automatically inferring infrastructure needs from code and generating inspectable Infrastructure as Code specifications.1515Apache 2.0
- AlicenseBqualityDmaintenanceEnables management and provisioning of AWS resources like EC2, S3, and RDS using natural language prompts through the Model Context Protocol. It allows users to automate complex infrastructure tasks, such as setting up VPCs and security groups, via a chat interface.5411 npm27MIT
- FlicenseNot gradedqualityDmaintenanceEnables interaction with AWS services (EC2, S3, Lambda, DynamoDB, etc.) through the Model Context Protocol, allowing natural language management of cloud resources.2-
- AlicenseNot gradedqualityFmaintenanceProvides conversational access to LocalStack AWS services (S3, DynamoDB, Lambda, SQS) through natural language, enabling local cloud infrastructure management without real AWS costs.MIT