GitOps Safe MCP
GitOps Safe MCP
一个刻意精简的 stdio MCP 服务器,提取自 spectrenet-mcp 提交 2e63f009d8f4642e17398685baef0251811d6637。它仅暴露:
repository_status:Git 状态和最近五次提交(只读)。diff_summary:未暂存差异统计和工作树名称(只读)。tofu_validate:tofu fmt -check -recursive和tofu validate -no-color。ansible_syntax:通过固定的、由运维管理的ansible-playbook --syntax-check命令检查一个受控的 YAML playbook。
没有 Git 写入、OpenTofu plan/apply、Ansible playbook 运行、shell 或任意命令工具。
重要的 Ansible 警告
Ansible 语法检查不能保证是惰性的:查找插件以及某些集合/插件加载在解析 playbook 时可能执行代码。 将配置的仓库和依赖视为受信任的代码。在专用的非特权账户下运行此服务器,使用经过清理的环境、只读的仓库挂载、无生产凭据,并限制网络/文件系统访问。可执行文件必须配置为由运维管理的绝对路径(或由运维拥有的绝对路径包装器);绝不接受来自工具参数的值。
Related MCP server: Gumi-MCP
安全边界
所有配置的子路径和请求的 playbook 都会被解析(包括符号链接),必须是相对路径,必须存在,并且必须严格保持在允许的解析根目录之下。每个子进程都接收相同的显式最小允许列表(PATH、基本的用户/区域设置/终端/临时变量和 XDG_*);仅 Ansible 额外接收受控的 ANSIBLE_CONFIG。不相关的进程凭据、云令牌和提供程序密钥不会被继承。子进程使用 argv 数组、固定的动词/标志、超时和有界的 stdout/stderr。审计 JSONL 包括时间戳、UUID 请求 ID、工具/目标、非变更标记、退出代码、超时状态和持续时间——但不包括命令输出或环境值。
安装和运行
推荐使用 Python 3.11+ 和 uv:
uv sync --extra test
cp .env.example .env.reference # reference only; the package does not load dotenv files
uv run gitops-safe-mcp使用服务管理器或密钥/配置管理器注入设置。确保审计目录仅对服务/运维可写。
验证
uv run --extra test pytest
uv run python -m compileall -q src tests
uv build测试使用临时假仓库和假可执行文件。它们不会针对真实基础设施运行 OpenTofu 或 Ansible。
This server cannot be deployed
Maintenance
Related MCP Connectors
Run verified read-only code tools: quant diagnostics + agent-ops preflight, no source exposure.
Read-only AI coding tools for change verification, release readiness, capacity, and guidance.
Read-only MCP access to a documented IT fleet: state, changes, posture. 15 tools.
Detects database migration table locks, terraform cost leaks, and OWASP API flaws.
Related MCP Servers
- FlicenseNot gradedqualityBmaintenanceEnables AI agents to inspect Git repositories for changes across committed, staged, unstaged, and untracked scopes, and run allowlisted validation commands with structured results.-
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to safely inspect a local repository's code and metadata while blocking private data from leaving the machine, providing read-only tools for search, change tracking, and integrity verification.MIT
- FlicenseAqualityBmaintenanceEnables AI assistants to securely inspect local Git repositories and perform restricted write operations in isolated worktrees, with sandboxed script execution and limited GitHub repository management.24-
- AlicenseAqualityCmaintenanceEnables AI clients to securely inspect local source repositories with read-only tools for listing files, reading files, and searching text, while enforcing path traversal protection and sensitive-file filtering.3MIT