Skip to main content
Glama
abhi-d-git

mcp-server-azure-devops

by abhi-d-git
README.md
# mcp-server-azure-devops

Azure DevOps MCP server aligned with your `mcp-platform-gateway` and `@abhinav-dev/mcp-platform-kit` pattern.

This server follows the same structure as `mcp-server-git`:

```txt
src/index.ts
src/config/env.ts
src/tools/registerAzureDevOpsTools.ts
src/azuredevops/azureDevOpsClient.ts
```

It does not use the raw MCP SDK directly. It extends `McpServerBase` from `@abhinav-dev/mcp-platform-kit` and registers tools through `PlatformToolServer`.

## Capabilities

- List Azure DevOps pipelines
- List pipeline runs
- Get pipeline run details
- List pipeline logs
- Read pipeline log text
- List pipeline artifacts
- Download pipeline artifacts
- Collect security reports from artifacts
- Normalize Trivy, SARIF, Veracode-like JSON, and Aqua-like JSON reports
- Generate `normalized-vulnerability-report.json`
- Generate `copilot-fix-prompt.md`
- Trigger allowed pipelines with safety controls

## Install

```bash
npm install
npm run build
```

## Configure

Copy `.env.example` to `.env`.

```env
MCP_NAME=azure-devops
MCP_VERSION=1.0.0
MCP_PORT=3005
MCP_SELF_URL=http://localhost:3005
GATEWAY_URL=http://localhost:3000

AZDO_ORG=your-organization
AZDO_PROJECT=your-project
AZDO_PAT=your-personal-access-token
AZDO_API_VERSION=7.1
AZDO_ENABLE_TRIGGER=false
AZDO_ALLOWED_PIPELINES=12,15,20
AZDO_ALLOWED_BRANCHES=refs/heads/main,refs/heads/dev
AZDO_DOWNLOAD_DIR=.azdo-downloads
AZDO_REPORT_DIR=.azdo-reports
```

## Run

```bash
npm run dev
```

## Important tools

```txt
azure_list_pipelines
azure_list_pipeline_runs
azure_get_pipeline_run
azure_list_pipeline_logs
azure_get_pipeline_log_text
azure_list_pipeline_artifacts
azure_download_pipeline_artifact
azure_collect_security_reports
azure_normalize_local_security_reports
azure_trigger_pipeline
```

## Security report workflow

Recommended Azure Pipeline artifact layout:

```txt
security-reports/
  trivy/
    trivy-fs.json
    trivy-image.json
  veracode/
    veracode-findings.json
  aqua/
    aqua-report.json
```

Then call:

```json
{
  "pipelineId": 12,
  "runId": 345,
  "artifactName": "security-reports"
}
```

using `azure_collect_security_reports`.

Output:

```txt
.azdo-reports/<pipelineId>/<runId>/normalized-vulnerability-report.json
.azdo-reports/<pipelineId>/<runId>/copilot-fix-prompt.md
```

Open `copilot-fix-prompt.md` in VS Code and ask GitHub Copilot to implement the fixes.

## Pipeline trigger safety

Pipeline trigger is disabled by default.

Enable only after configuring allowed pipelines and branches:

```env
AZDO_ENABLE_TRIGGER=true
AZDO_ALLOWED_PIPELINES=12,15,20
AZDO_ALLOWED_BRANCHES=refs/heads/main,refs/heads/dev
```