AWS Infrastructure MCP Server
AWS Infrastructure MCP Server
ローカルで動作するFastMCPサーバー(Python 3.12+、stdioトランスポート)で、サーバーレスアプリケーション向けのAWS診断ツールをIDEのAIエージェントに直接公開します。Model Context Protocolを介して、Cursor、VS Code Copilot、またはClaude CodeをCloudWatch、Lambda、DynamoDB、IAM、Bedrockに接続します。
アーキテクチャと設計方針
トランスポートとスタック
構成要素 | 選択肢 |
ランタイム | Python 3.12+ |
MCPフレームワーク | FastMCP 3.x |
パッケージマネージャ | uv |
AWS SDK | boto3 |
スキーマ検証 | Pydantic 2.x |
トランスポート | stdio(IDEがサーバープロセスを起動します) |
認証
boto3のデフォルトの認証情報チェーンを使用し、カスタム認証ロジックはありません。チェーンは、次の順序で確認します: 環境変数(AWS_ACCESS_KEY_ID、AWS_SECRET_ACCESS_KEY)→ ~/.aws/credentials → ~/.aws/config → インスタンスメタデータ。AWS_PROFILE を設定すると、特定の名前付きプロファイルを対象にできます。
ツールサーフェス
4つのモジュールにわたる15種類のツール:
CloudWatch & Lambda — サービス診断 (tools/cloudwatch.py, tools/lambda_ops.py)
ツール | 説明 |
| Lambda関数の一覧を取得します(名前のプレフィックスでフィルタリング可能)。 |
| Lambdaのロググループから最新のCloudWatchログイベントを取得します。 |
| ログイベントをERROR/例外/Traceback行のみにフィルタリングします。 |
| 呼び出し、エラー、所要時間、スロットリングのメトリクスを取得します。 |
| 同期呼び出し( |
DynamoDB — データヘルス (tools/dynamodb.py)
ツール | 説明 |
| DynamoDBのテーブル一覧を、名前プレフィックスによるフィルタリング付きで取得します。 |
| キースキーマ、属性、GSI、項目数、サイズ、ステータスを返します。 |
| 主キー条件でクエリを実行します。上限は25項目に固定されています。 |
| オプションのフィルターでスキャンします。上限は25項目に固定されています。 |
| ReadThrottleEvents、WriteThrottleEvents、UserErrors を CloudWatch に問い合わせます。 |
IAM — セキュリティガバナンス (tools/iam.py)
ツール | 説明 |
| IAMロールを一覧、名前のプレフィックスでフィルタリング可能。 |
| 信頼ポリシーと、アタッチ済み・インラインの全ポリシードキュメントを返します。 |
| 各Lambda関数をその実行ロールARNに対応付けます。 |
| 3つのハイリスクパターンを検出します(下記参照)。 |
validate_least_privilege は以下をチェックします:
ワイルドカード権限 —
"Action": "*"または"Resource": "*"を含むステートメント危険な管理ポリシー —
AdministratorAccessまたはPowerUserAccessがアタッチされているスコープ未指定のデータアクセス — 特定のリソースARNを指定しないS3またはDynamoDBの読み取り・書き込みアクション
Bedrock — AIによる根本原因分析 (tools/bedrock.py)
ツール | 説明 |
| 診断コンテキストをBedrockに送信、構造化された分析結果を返します。 |
生のテキスト(ログ、スタックトレース、メトリクスの要約)を受け取ります。検証済みのPydanticオブジェクトを返します:
class IncidentAnalysis(BaseModel):
severity: Literal["LOW", "MEDIUM", "HIGH", "CRITICAL"]
root_cause_summary: str
affected_components: list[str]
recommended_fix: strmodel_id パラメータは、Bedrockで利用可能な任意のモデルを受け付けます(例: meta.llama3-2-3b)。
セキュリティ境界
すべてのツールは読み取り専用です。ただし、
invoke_lambdaは例外で、同期呼び出しのみ行います。どのツールもLambda関数、DynamoDBアイテム、IAMポリシー、その他のAWSリソースを作成・更新・削除しません。
グローバルな認証情報スクラバー (
utils/scrubber.py) が、データがLLMコンテキストに到達する前に、すべてのツール出力からAWSアクセスキーID、シークレットアクセスキー、セッショントークンを除去します。ログメッセージ、呼び出しレスポンス、エラー出力に適用されます。
Related MCP server: AWS MCP Server
プロジェクト構造
mcpserver/
├── app.py # FastMCP instance (single shared object)
├── server.py # Entry point — imports tool modules, runs stdio
├── tools/
│ ├── __init__.py
│ ├── cloudwatch.py # get_lambda_logs, get_lambda_errors, get_lambda_metrics
│ ├── lambda_ops.py # list_lambdas, invoke_lambda
│ ├── dynamodb.py # list_tables, describe_table, query_table, scan_table, get_table_metrics
│ ├── iam.py # list_roles, get_role_policy, validate_least_privilege, list_lambda_roles
│ └── bedrock.py # analyze_incident + IncidentAnalysis schema
├── utils/
│ ├── __init__.py
│ └── scrubber.py # Credential redaction regex patterns
├── tests/
│ ├── test_scrubber.py
│ ├── test_cloudwatch.py
│ ├── test_lambda_ops.py
│ ├── test_dynamodb.py
│ ├── test_iam.py
│ └── test_bedrock.py
├── pyproject.toml
└── uv.lockインストールとローカルセットアップ
前提条件:
Python 3.12+
uv パッケージマネージャ
AWS CLI が設定済み(
~/.aws/credentialsまたは環境変数)
# Clone and install dependencies
cd mcpserver
uv sync
# Run the server locally (stdio)
uv run python server.pyIDE構成
VS Code / Cursor
プロジェクトルートに .vscode/mcp.json を作成します:
{
"servers": {
"aws-infra-mcp": {
"type": "stdio",
"command": "uv",
"args": ["--directory", "/absolute/path/to/mcpserver", "run", "server.py"]
}
}
}/absolute/path/to/mcpserver を、このディレクトリの実際のパスに置き換えてください。Windowsでは、フォワードスラッシュを使用します(C:/Users/.../mcpserver)。
Claude Desktop
claude_desktop_config.json に追加します:
{
"mcpServers": {
"aws-infra-mcp": {
"command": "uv",
"args": ["--directory", "/absolute/path/to/mcpserver", "run", "server.py"]
}
}
}テスト戦略
テストはシングルシーム設計を採用しています。各 @mcp.tool() 関数は、unittest.mock.patch で下層のboto3をモックして、その公開境界でテストされます。テストは、実際のAWS認証情報やネットワーク呼び出しを必要としません。ツールの変換ロジック(ログのフィルタリング、ハード上限の適用、認証情報のスクラビング、Pydanticの検証)を検証します。
6つのテストファイルにわたる57の単体テスト:
# Run the full suite
uv run pytest
# Run a single cluster's tests
uv run pytest tests/test_iam.py -vThis server cannot be deployed
Maintenance
Related MCP Connectors
The AWS Knowledge MCP server is a fully managed remote Model Context Protocol server that provides real-time access to official AWS content in an LLM-compatible format. It offers structured access to AWS documentation, code samples, blog posts, What's New announcements, Well-Architected best practices, and regional availability information for AWS APIs and CloudFormation resources. Key capabilities include searching and reading documentation in markdown format, getting content recommendations, listing AWS regions, and checking regional availability for services and features.
AWS cloud security scanners for AI agents — S3, IAM, EC2, EKS, RDS, CloudTrail, CloudWatch Logs
Governed app access for AI agents: 1,000+ apps & 12,000+ tools via Code Mode MCP.
Outcome-based infrastructure for agents — verified AWS deployments, metered billing
Related MCP Servers
- AlicenseBqualityDmaintenanceEnables management and provisioning of AWS resources like EC2, S3, and RDS using natural language prompts through the Model Context Protocol. It allows users to automate complex infrastructure tasks, such as setting up VPCs and security groups, via a chat interface.5411 npm27MIT
- AlicenseNot gradedqualityDmaintenanceA read-only Model Context Protocol server that exposes over 60 AWS tools across services like EC2, S3, and IAM for AI agent interaction. It features multi-region support, resource caching, and audit logging to provide secure, AI-ready access to AWS infrastructure data.100 npmISC
- AlicenseNot gradedqualityDmaintenanceEnables LLMs to autonomously query AWS CloudWatch Logs and perform structured root-cause analysis via natural language prompts, using MCP tools for log group listing and Insights queries.MIT
- FlicenseNot gradedqualityDmaintenanceEnables interaction with AWS services (EC2, S3, Lambda, DynamoDB, etc.) through the Model Context Protocol, allowing natural language management of cloud resources.2-