Skip to main content
Glama
ahmedselimmansor-ctrl

Alibaba Cloud MCP Server

README.md
# Alibaba Cloud MCP Server

A comprehensive, high-performance [Model Context Protocol (MCP)](https://modelcontextprotocol.io/) server for managing Alibaba Cloud resources.

This server enables AI assistants (like Claude, Cursor, and others) to seamlessly interact with Alibaba Cloud infrastructure using natural language. It features a **Hybrid Architecture**:
1. **Explicit Service Tools**: Pre-configured, typed handlers for the most common services (ECS, VPC, RDS, RAM, ACK, SLB) to ensure rapid, error-free AI interactions.
2. **Universal API Invoker**: A dynamic tool built on `@alicloud/pop-core` that can invoke *any* of the 10,000+ API endpoints across all Alibaba Cloud services, giving you true 100% cloud management coverage.

## Features

- 🚀 **Zero-Config Universal Management**: Dynamically call any Alibaba Cloud RPC/ROA API.
- 📦 **Explicit Typed Tools**:
  - **ECS**: Manage Compute Instances (`ecs_list_instances`, `ecs_start_instance`)
  - **VPC**: Manage Networking (`vpc_list`, `vpc_create`)
  - **RDS**: Manage Databases (`rds_list_instances`)
  - **RAM**: Manage IAM & Security (`ram_list_users`)
  - **ACK**: Manage Kubernetes Clusters (`ack_list_clusters`)
  - **SLB**: Manage Load Balancers (`slb_list`)
- 🐳 **Docker Ready**: Run safely in an isolated container.
- 🛡️ **Secure**: Uses Zod for strict parameter validation and environment variables for credentials.

## Prerequisites

- Node.js 18+ (if running locally)
- Docker (optional, for containerized execution)
- Alibaba Cloud Access Key ID and Secret with appropriate IAM permissions.

## Setup & Installation

### Option 1: Running Locally

1. Clone the repository and install dependencies:
   ```bash
   npm install
   ```

2. Build the TypeScript source:
   ```bash
   npm run build
   ```

3. Create a `.env` file in the root directory:
   ```env
   ALIBABA_CLOUD_ACCESS_KEY_ID="your_access_key"
   ALIBABA_CLOUD_ACCESS_KEY_SECRET="your_access_secret"
   ALIBABA_CLOUD_REGION_ID="cn-hangzhou"
   ```

### Option 2: Running with Docker

1. Build the Docker image:
   ```bash
   docker build -t alibaba-cloud-mcp .
   ```

## Configuring Your MCP Client

### Claude Desktop

To integrate this server with Claude Desktop, add the following to your `claude_desktop_config.json` (usually located at `%APPDATA%\Claude\claude_desktop_config.json` on Windows or `~/Library/Application Support/Claude/claude_desktop_config.json` on Mac):

**If using Node.js locally:**
```json
{
  "mcpServers": {
    "alibaba-cloud": {
      "command": "node",
      "args": ["/absolute/path/to/Alibaba_cloud_MCP_server/dist/index.js"],
      "env": {
        "ALIBABA_CLOUD_ACCESS_KEY_ID": "your_access_key",
        "ALIBABA_CLOUD_ACCESS_KEY_SECRET": "your_access_secret",
        "ALIBABA_CLOUD_REGION_ID": "cn-hangzhou"
      }
    }
  }
}
```

**If using Docker:**
```json
{
  "mcpServers": {
    "alibaba-cloud": {
      "command": "docker",
      "args": [
        "run", 
        "-i", 
        "--rm", 
        "-e", "ALIBABA_CLOUD_ACCESS_KEY_ID", 
        "-e", "ALIBABA_CLOUD_ACCESS_KEY_SECRET", 
        "-e", "ALIBABA_CLOUD_REGION_ID", 
        "alibaba-cloud-mcp"
      ],
      "env": {
        "ALIBABA_CLOUD_ACCESS_KEY_ID": "your_access_key",
        "ALIBABA_CLOUD_ACCESS_KEY_SECRET": "your_access_secret",
        "ALIBABA_CLOUD_REGION_ID": "cn-hangzhou"
      }
    }
  }
}
```

*Note: Restart Claude Desktop after updating the configuration.*

## Security Warning

> **⚠️ IMPORTANT:** This MCP server is incredibly powerful, especially due to the `aliyun_invoke_api` tool which can manage *any* resource. Always adhere to the Principle of Least Privilege. Ensure that the IAM/RAM user associated with your Access Keys only has the minimum permissions necessary for the tasks you intend the AI to perform.

## Architecture

Built using:
- `@modelcontextprotocol/sdk`
- `@alicloud/pop-core`
- `zod` for validation
- `TypeScript`

TDQS

C2.8/5.0

Scored across 9 tools

Disambiguation4/5

Most tools target distinct services (ECS, VPC, RDS, etc.), but the generic 'aliyun_invoke_api' can overlap with any specific tool, causing potential confusion. Within services, actions like 'ecs_list_instances' and 'ecs_start_instance' are clearly distinct.

Naming Consistency3/5

Tools generally follow a service_verb_noun pattern (e.g., ecs_list_instances), but some omit the resource noun (slb_list, vpc_create) and 'aliyun_invoke_api' uses a different format, leading to inconsistency.

Tool Count4/5

9 tools for a cloud provider is reasonable; the generic API invocation tool extends capability. However, the scope is broad, and a few more targeted tools could improve coverage without being excessive.

Completeness2/5

The tool set is very incomplete for most services—only list operations for RAM, RDS, SLB; no update, delete, or advanced actions. The generic API tool is a workaround but indicates significant gaps in native coverage.

Maintenance

ActivityInactive
ResponsivenessSyncing