AWS Infrastructure MCP Server
AWS Infrastructure MCP Server
一个本地 FastMCP 服务器(Python 3.12+,stdio 传输),将面向无服务器应用的 AWS 诊断工具直接暴露给 IDE AI 代理。它通过 Model Context Protocol 将 Cursor、VS Code Copilot 或 Claude Code 连接到 CloudWatch、Lambda、DynamoDB、IAM 和 Bedrock。
架构与设计选择
传输与技术栈
组件 | 选择 |
运行时 | Python 3.12+ |
MCP 框架 | FastMCP 3.x |
包管理器 | uv |
AWS SDK | boto3 |
模式验证 | Pydantic 2.x |
传输 | stdio(由 IDE 启动服务器进程) |
身份验证
使用 boto3 的默认凭证链,不包含自定义身份验证逻辑。该链按顺序检查:环境变量(AWS_ACCESS_KEY_ID、AWS_SECRET_ACCESS_KEY)→ ~/.aws/credentials → ~/.aws/config → 实例元数据。设置 AWS_PROFILE 以指定特定的命名配置文件。
工具集
4 个模块共 15 个工具:
CloudWatch 与 Lambda — 服务诊断(tools/cloudwatch.py、tools/lambda_ops.py)
工具 | 描述 |
| 列出 Lambda 函数,可选按名称前缀过滤 |
| 拉取 Lambda 日志组最近的 CloudWatch 日志事件 |
| 仅将日志事件过滤为 ERROR/异常/Traceback 行 |
| 获取调用次数、错误、时长和限流指标 |
| 同步调用( |
DynamoDB — 数据健康(tools/dynamodb.py)
工具 | 描述 |
| 列出 DynamoDB 表,可选按名称前缀过滤 |
| 返回键架构、属性、GSI、项目数、大小和状态 |
| 按主键条件查询;硬上限为 25 个项目 |
| 使用可选过滤器扫描;硬上限为 25 个项目 |
| 查询 CloudWatch 以获取 ReadThrottleEvents、WriteThrottleEvents、UserErrors |
IAM — 安全治理(tools/iam.py)
工具 | 描述 |
| 列出 IAM 角色,可选按名称前缀过滤 |
| 返回信任策略以及所有附加/内联策略文档 |
| 将每个 Lambda 函数映射到其执行角色 ARN |
| 标记三种高风险模式(见下文) |
validate_least_privilege 检查:
通配符权限 — 包含
"Action": "*"或"Resource": "*"的语句危险托管策略 — 附加了
AdministratorAccess或PowerUserAccess未限定范围的数据访问 — 未指定具体资源 ARN 的 S3 或 DynamoDB 读写操作
Bedrock — AI 根因分析(tools/bedrock.py)
工具 | 描述 |
| 将诊断上下文发送到 Bedrock;返回结构化分析 |
接受原始文本(日志、堆栈跟踪、指标摘要)。返回经过验证的 Pydantic 对象:
class IncidentAnalysis(BaseModel):
severity: Literal["LOW", "MEDIUM", "HIGH", "CRITICAL"]
root_cause_summary: str
affected_components: list[str]
recommended_fix: strmodel_id 参数接受任何 Bedrock 可用的模型(例如:meta.llama3-2-3b)。
安全边界
除
invoke_lambda(仅同步调用)外,所有工具均为只读。没有任何工具会创建、更新或删除 Lambda 函数、DynamoDB 项目、IAM 策略或任何其他 AWS 资源。
全局凭证清洗器(
utils/scrubber.py)会在数据进入 LLM 上下文之前,从所有工具输出中删除 AWS 访问密钥 ID、秘密访问密钥和会话令牌。适用于日志消息、调用响应和错误输出。
Related MCP server: AWS MCP Server
项目结构
mcpserver/
├── app.py # FastMCP instance (single shared object)
├── server.py # Entry point — imports tool modules, runs stdio
├── tools/
│ ├── __init__.py
│ ├── cloudwatch.py # get_lambda_logs, get_lambda_errors, get_lambda_metrics
│ ├── lambda_ops.py # list_lambdas, invoke_lambda
│ ├── dynamodb.py # list_tables, describe_table, query_table, scan_table, get_table_metrics
│ ├── iam.py # list_roles, get_role_policy, validate_least_privilege, list_lambda_roles
│ └── bedrock.py # analyze_incident + IncidentAnalysis schema
├── utils/
│ ├── __init__.py
│ └── scrubber.py # Credential redaction regex patterns
├── tests/
│ ├── test_scrubber.py
│ ├── test_cloudwatch.py
│ ├── test_lambda_ops.py
│ ├── test_dynamodb.py
│ ├── test_iam.py
│ └── test_bedrock.py
├── pyproject.toml
└── uv.lock安装与本地设置
前提条件:
Python 3.12+
uv 包管理器
已配置 AWS CLI(
~/.aws/credentials或环境变量)
# Clone and install dependencies
cd mcpserver
uv sync
# Run the server locally (stdio)
uv run python server.pyIDE 配置
VS Code / Cursor
在项目根目录创建 .vscode/mcp.json:
{
"servers": {
"aws-infra-mcp": {
"type": "stdio",
"command": "uv",
"args": ["--directory", "/absolute/path/to/mcpserver", "run", "server.py"]
}
}
}将 /absolute/path/to/mcpserver 替换为此目录的实际路径。在 Windows 上,使用正斜杠(C:/Users/.../mcpserver)。
Claude Desktop
添加到 claude_desktop_config.json:
{
"mcpServers": {
"aws-infra-mcp": {
"command": "uv",
"args": ["--directory", "/absolute/path/to/mcpserver", "run", "server.py"]
}
}
}测试策略
测试采用单接缝设计:每个 @mcp.tool() 函数都在其公共边界处进行测试,使用 unittest.mock.patch 在其下方模拟 boto3。测试验证工具的转换逻辑 — 日志过滤、硬上限执行、凭证清洗、Pydantic 验证 — 无需真实的 AWS 凭证,也不会发起网络调用。
6 个测试文件中共 57 个单元测试:
# Run the full suite
uv run pytest
# Run a single cluster's tests
uv run pytest tests/test_iam.py -vThis server cannot be deployed
Maintenance
Related MCP Connectors
The AWS Knowledge MCP server is a fully managed remote Model Context Protocol server that provides real-time access to official AWS content in an LLM-compatible format. It offers structured access to AWS documentation, code samples, blog posts, What's New announcements, Well-Architected best practices, and regional availability information for AWS APIs and CloudFormation resources. Key capabilities include searching and reading documentation in markdown format, getting content recommendations, listing AWS regions, and checking regional availability for services and features.
AWS cloud security scanners for AI agents — S3, IAM, EC2, EKS, RDS, CloudTrail, CloudWatch Logs
Governed app access for AI agents: 1,000+ apps & 12,000+ tools via Code Mode MCP.
Outcome-based infrastructure for agents — verified AWS deployments, metered billing
Related MCP Servers
- AlicenseBqualityDmaintenanceEnables management and provisioning of AWS resources like EC2, S3, and RDS using natural language prompts through the Model Context Protocol. It allows users to automate complex infrastructure tasks, such as setting up VPCs and security groups, via a chat interface.5411 npm27MIT
- AlicenseNot gradedqualityDmaintenanceA read-only Model Context Protocol server that exposes over 60 AWS tools across services like EC2, S3, and IAM for AI agent interaction. It features multi-region support, resource caching, and audit logging to provide secure, AI-ready access to AWS infrastructure data.100 npmISC
- AlicenseNot gradedqualityDmaintenanceEnables LLMs to autonomously query AWS CloudWatch Logs and perform structured root-cause analysis via natural language prompts, using MCP tools for log group listing and Insights queries.MIT
- FlicenseNot gradedqualityDmaintenanceEnables interaction with AWS services (EC2, S3, Lambda, DynamoDB, etc.) through the Model Context Protocol, allowing natural language management of cloud resources.2-