Agentic CI/CD MCP Orchestrator
Allows for automated pull request creation and repository management as part of an auto-repair and release orchestration workflow.
Provides tools to inspect failed workflow runs, analyze logs, and diagnose CI/CD failures for automated remediation.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Agentic CI/CD MCP Orchestratoranalyze the failure in run 882233 for acme/web-app and open a repair PR"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Agentic CI/CD MCP Orchestrator
Python MCP server for GitHub Actions failure diagnosis, LLM-driven unified-diff auto-repair PR creation, and governed release orchestration.
What this provides
MCP tooling to inspect failed workflow runs using commit, logs, and test signals.
LLM diagnosis flow powered by OpenAI
gpt-4o-mini.Governance layer to auto-fix low-risk issues and require human review for risky changes.
Generic model-driven repair loop (up to 3 attempts) using unified diff patches.
GitHub Actions workflows for CI, repair orchestration, and release policy gating.
Related MCP server: GitHub Actions MCP Server
Project layout
mcp_server/main.py- MCP tools and orchestration entrypointsmcp_server/host_http.py- streamable HTTP MCP server for browser clientsmcp_server/run_repair.py- workflow-safe command runnerfrontend/- Vite + React MCP client UImcp_server/config.py- typed environment configmcp_server/tools/*- GitHub, diagnosis, risk, and PR automation modules.github/workflows/*- CI/CD automation workflows
Setup
Create and activate a virtual environment.
Install dependencies:
pip install -r requirements.txt
Copy environment defaults:
cp .env.example .env(or create.envmanually on Windows)
Fill in required values (
OPENAI_API_KEY,GITHUB_TOKEN).
Run MCP server locally
stdio (Cursor / Claude Desktop):
python -m mcp_server.main
Web UI (browser MCP client + hosted server)
The frontend app is a real MCP client using streamable HTTP. Secrets stay on the server; the browser only talks MCP.
Terminal A — MCP over HTTP (from repo root, with
.envconfigured):python -m mcp_server.host_httpListens on
0.0.0.0andPORTfrom the environment (Render sets this). Path:/mcp.Terminal B — SPA dev server:
cd frontend npm install cp .env.example .env npm run devConfigure
frontend/.env:VITE_MCP_URLis the MCP endpoint (defaulthttp://127.0.0.1:8000/mcp). It pre-fills the UI and sets the Vite dev proxy target origin. Clear the field to use same-origin/mcp(proxied to that origin).Open the Vite URL (usually
http://localhost:5173).
Production CORS: the browser sends an Origin header; the MCP server must allow it or preflight (OPTIONS) fails (often surfaced as Failed to fetch).
Set
MCP_CORS_ORIGINSto a comma-separated list of exact SPA origins (for examplehttps://your-frontend.onrender.com).Or set
MCP_CORS_ORIGIN_REGEX(for examplehttps://.*\.onrender\.com) to allow all Render app URLs without listing each one (tighter regex is better for production).
Render (two services): one Web Service should run python -m mcp_server.host_http (the MCP API). A second service or Static Site can serve the built SPA (npm run build output). Set VITE_MCP_URL at frontend build time to the MCP service URL (for example https://your-mcp-api.onrender.com/mcp), not the static site URL, unless you use a reverse proxy that mounts both. If you only run vite preview on Render, that process does not expose the Python MCP server — /mcp will not work there.
GET /mcp → 406 in logs usually means something opened /mcp in a normal browser tab (wrong Accept header); the MCP client uses POST/SSE and is unaffected.
MCP tools exposed: resolve_latest_failed_run, inspect_pipeline_failure, orchestrate_autofix (same behavior as the CLI, with resolve_latest_failed_run matching run_repair when RUN_ID is omitted).
Client timeouts: The MCP TypeScript SDK defaults to 60 seconds per request. orchestrate_autofix often runs longer (LLMs, GitHub). The SPA uses 15 minutes for orchestrate_autofix and 2 minutes for resolve_latest_failed_run unless you set VITE_MCP_ORCHESTRATE_TIMEOUT_MS / VITE_MCP_RESOLVE_TIMEOUT_MS in frontend/.env (milliseconds).
Use in Cursor as MCP
MCP config is included at
.cursor/mcp.json.Restart Cursor so it loads the MCP server definition.
Ensure your
.envhasOPENAI_API_KEYandGITHUB_TOKEN.In Cursor chat, call tools from
agentic-cicd-orchestratorwith:repository:owner/reporun_id: workflow run id (integer)
Main tools:
inspect_pipeline_failureresolve_latest_failed_runorchestrate_autofix
Run repair orchestration manually
Set
REPOSITORY(for exampleorg/repo).Optional:
RUN_ID(if omitted, latest failed run is auto-selected)WORKFLOW_NAME(filter latest failed run by workflow name, e.g.ci)BASE_BRANCH(defaultmain)
Execute:
python -m mcp_server.run_repair
LLM auto-repair controls
MAX_REPAIR_ATTEMPTS- number of patch generation/application retries (default3).PATCH_STRATEGY- patch format expected from model (must beunified_diff).LLM_PATCH_MAX_CHARS- upper bound on patch payload size.
Governance model
risk_score < RISK_AUTO_FIX_THRESHOLD-> autonomous auto-fix PR path.RISK_AUTO_FIX_THRESHOLD <= risk_score < RISK_HUMAN_REVIEW_THRESHOLD-> human approval required.risk_score >= RISK_HUMAN_REVIEW_THRESHOLDor high-risk file categories -> blocked/review-only path.FORCE_AUTOFIX_ALL=true-> bypass thresholds and force auto-fix path (dangerous; use only in controlled testing).
Security notes
Use least-privilege GitHub credentials.
Keep production deployment credentials separate from auto-repair identity.
Review generated PRs and audit artifacts before enabling automerge in production.
This server cannot be deployed
Maintenance
Related MCP Connectors
MCP-native AI SRE: ask what's broken in production, get a reviewed GitHub fix PR.
MCP server for your apps' tools and custom tools, plus hosted AI agents and approval-gated workflows
AI-native git hosting — repos, PRs, issues, CI gates, and AI code review over MCP (60 tools).
A Model Context Protocol (MCP) application for automated GitHub PR analysis and issue management.…
Related MCP Servers
- AlicenseAqualityBmaintenanceAn MCP server that enables autonomous code development by pulling GitHub issues, fixing them in a sandboxed environment, running tests, opening PRs, and promoting to production upon human approval.3AGPL 3.0
- AlicenseAqualityDmaintenanceAn intelligent MCP server that gives AI agents full control over GitHub Actions CI/CD pipelines, including real-time monitoring, log analysis, AI-powered failure diagnosis, and deployment management.13480 npm1ISC
- AlicenseAqualityBmaintenanceMCP server for autonomous MLOps incident response, enabling drift detection, deployment history analysis, and human-approved rollback execution via gated tools.7MIT
- FlicenseAqualityCmaintenanceAn MCP server that enables AI clients to autonomously discover, analyze, fix, test, submit, and track open-source contributions on GitHub through specialized tools.12-