Skip to main content
Glama

BedrockOps — Autonomous Cloud Operations & Audit Agent

Open-source (MIT) cloud operations agent scaffold for the Build, Ship, Shape: Amazon Developer Hackathon (Alexa+ track; AWS Builder + Open Source mini-challenges).

Status — read this first (2026-10-06)

  • server.py is built on the official MCP Python SDK (mcp==2.3.0, MCPServer — the v2 name for FastMCP) and serves Streamable HTTP at /mcp. Verified on this machine:

    • python -m unittest tests/test_mcp.py → exit 0, 8 tests OK, including raw JSON-RPC initialize negotiating 2025-11-25, tools/list, and tools/call for both tools.

    • A live server + the official SDK client (ClientSession over streamable_http_client) listed both tools and called both successfully, also negotiating protocol 2025-11-25.

    • Full proof in TEST_RECEIPT.md.

  • Wired 2026-10-06, proven locally where possible: bedrock_route tool calls bedrock_agent.invoke() — gated prompts stop at requires_approval; with no AWS credentials in this environment it honestly returns "live": false (fallback_reason NoCredentialsError), tested. system_probe with BEDROCKOPS_LIVE=1 makes one real read-only AWS call and, in this credential-less environment, correctly returns UNREACHABLE / live_failed instead of faking HEALTHY, tested. audit_ledger persists to DynamoDB when AUDIT_TABLE_NAME is set: the PutItem path is proven against a fake client in tests, and a failing client is reported (persisted: false), never faked.

  • Not yet proven, because this VM has no AWS credentials (checked: no ~/.aws, no AWS env keys, SDK raises NoCredentialsError): a live Bedrock InvokeModel call, a live AWS probe succeeding, and a real DynamoDB write. Those need one run at Ricket's PC with his own AWS login. See .env.example for the exact switches.

  • Terraform now defines the DynamoDB table plus a least-privilege IAM policy matching exactly what the code calls (Bedrock invoke/list, Lambda/DynamoDB list, DynamoDB PutItem to the one table). HCL files parse (python-hcl2); terraform validate/apply has not run — no terraform binary on this VM. There is deliberately no Lambda function: the code has no Lambda handler, so none is claimed.

  • The /mcp/v1/* REST/SSE routes and /health are a legacy compatibility shim from the first prototype, kept working and tested, but they are not part of MCP. The MCP endpoint is /mcp.

Related MCP server: aws-readonly-mcp

Layout

server.py            Official MCP SDK server (Streamable HTTP, /mcp) + legacy shim
bedrock_agent.py     Bedrock router + read-only AWS probes (lazy boto3, offline fallback)
ledger.py            SHA-256 audit ledger (memory + optional DynamoDB persistence)
terraform/main.tf    DynamoDB audit table + least-privilege IAM policy
terraform/outputs.tf Table name / ARN, policy ARN outputs
tests/test_mcp.py    unittest: MCP protocol, tools, gate, ledger, DynamoDB fake client
.env.example         Runtime switches (no secrets)
requirements.txt
LICENSE              MIT

Setup

python3 -m venv .venv
. .venv/bin/activate
pip install -r requirements.txt

Run the tests

python -m unittest discover -s tests -v
# or, from the repo root:
python -m unittest tests/test_mcp.py

Run the server

python server.py
# MCP (Streamable HTTP): http://127.0.0.1:8000/mcp
# Health:                http://127.0.0.1:8000/health
# Legacy shim:           GET /mcp/v1/tools, POST /mcp/v1/execute

Or uvicorn server:app --host 0.0.0.0 --port 8000 for the ASGI app.

Note for this VM only: local HTTP clients must run with the proxy vars unset (env -u http_proxy -u https_proxy -u no_proxy ...), or httpx misroutes localhost. This is an environment quirk, not an app setting.

Demo

See demo/RECORDING_RUNBOOK.md for the one-take, under-3-minute recording script, demo/demo_client.py for the client that drives the six narrated steps, and demo/demo_transcript_2026-10-06.txt for a real offline run (stub/memory/live:false labels and all).

Infrastructure (optional, requires an AWS account)

cd terraform
terraform init
terraform plan   # review before any apply; apply creates real resources

What a judge should not yet conclude

The tests prove a real official-SDK MCP server speaking 2025-11-25 with three working tools, an approval gate, and a DynamoDB write path proven against a fake client. They do not prove a live Bedrock call, a successful live AWS probe, or a real DynamoDB write — this build VM has no AWS credentials, and the code says so in every result ("live": false, persisted: false, UNREACHABLE). One credentialed run at the owner's PC closes those three, using .env.example.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    A local MCP server that parses Terraform .tfstate files and lets AI agents audit enterprise infrastructure for security misconfigurations without requiring direct cloud credentials.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    A read-only MCP server that lets an LLM inspect an AWS account — list EC2 instances, S3 buckets, IAM users, and cost — with a structural guarantee against any mutations.
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    A self-hosted MCP server providing a governed interface for AI agents to interact with local Docker infrastructure, featuring a two-phase confirm protocol for state-changing operations and append-only audit logging.
    4
    -
  • -
    license
    Not graded
    quality
    Not graded
    maintenance
    An MCP server that validates tool calls against JSON Schema, performs deterministic repair, redacts secrets, and maintains a hash-chained audit ledger.
    -