Enterprise Secure AWS MCP Server
Provides tools for querying CloudWatch logs and managing AWS resources, deployed on AWS Lambda with IAM role-based access control.
Provides tools for provisioning and managing AWS infrastructure via Terraform, with single-command deployment and teardown.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Enterprise Secure AWS MCP ServerShow recent errors from payment Lambda logs."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Enterprise Secure AWS Model Context Protocol (MCP) Server
Production-grade Model Context Protocol (MCP) Server deployed on AWS Lambda & API Gateway with 100% Terraform IaC, zero-trust IAM RBAC, and OWASP LLM Top 10 defense guardrails.
AWS Architecture Overview

Related MCP server: AWS Sage
Features
Standard MCP Specs: Full support for Anthropic Model Context Protocol (MCP) Tool Discovery (
/mcp/tools) and Tool Execution (/mcp/tools/call).IAM Role-Based Access Control (RBAC): Restricts tool execution by role (
sre_read_only,security_auditor,sre_admin).OWASP LLM02 Defense: Edge sanitization blocking subshell metacharacter injections (
[;&|'$]).OWASP LLM06 Defense: Automatic output buffer redactor scrubbing AWS access keys (
AKIA...) and PII.Interactive Web UI Playground: Dark-mode test interface running on
http://localhost:8080(make ui).Zero Idle Cloud Cost: Provisioned via Terraform with single-command deployment (
make deploy) and instant teardown (make destroy).
Web UI Playground Demo
Below is the automated high-definition interactive demonstration showing RBAC access denial, command injection defense, and successful server restart execution under the sre_admin role:

Prerequisites & System Setup
Before setting up the project, ensure your environment has Python 3.11+, Terraform, and AWS CLI installed.
1. System Dependencies (Linux / Ubuntu / Debian)
sudo apt update && sudo apt install python3-venv python3-pip terraform awscli -y2. Environment Setup
Clone the repository and install project dependencies into an isolated virtual environment (.venv):
git clone https://github.com/patelketul1230/aws-mcp-enterprise-server.git
cd aws-mcp-enterprise-server
# Create .venv and install dependencies
make installRepository Structure
aws-mcp-enterprise-server/
├── docs/
│ ├── assets/ # Centralized PNG images & HD animations
│ │ ├── mcp_aws_figma_architecture_diagram.png
│ │ ├── mcp_ui_testing_demo.webp
│ │ ├── mcp_ui_testing_demo.gif
│ │ ├── mcp_ui_playground_success_screenshot.png
│ │ ├── mcp_ui_playground_admin_success_screenshot.png
│ │ └── mcp_ui_playground_blocked_screenshot.png
│ ├── blogs/ # 3 Medium Sub-Blogs ready for publication
│ │ ├── blog_1_1_mcp_decoded.md
│ │ ├── blog_1_2_mcp_rbac_python.md
│ │ └── blog_1_3_mcp_tool_poisoning.md
│ ├── architecture.md # Figma diagrams & sequence flows
│ ├── 5w_and_how.md # 5 Ws + 1 H problem statement & threat model
│ └── demo_execution.log # Verified test execution log
├── src/
│ ├── clients/ # AWS Bedrock Converse API integration client
│ ├── middleware/ # MCPSecurityValidator (RBAC & DLP)
│ ├── tools/ # CloudWatch & Terraform tool modules
│ ├── ui/ # Interactive Web UI Playground (index.html)
│ └── server.py # AWS Lambda & FastAPI server handler
├── terraform/ # 100% Terraform IaC (API Gateway, IAM, Lambda)
├── tests/ # Pytest suite & live verification scripts
├── Makefile # Lifecycle hooks (make deploy / make destroy / make ui)
└── README.md # Project documentationQuick Start Guide
1. Install Dependencies
make install2. Run Tests
make test3. Deploy Infrastructure to AWS
make deployOutputs:
API Endpoint: Dynamic output generated by Terraform
CloudWatch Log Group:
/aws/mcp/aws-mcp-enterprise-server-dev
4. Launch Interactive Web UI Playground
make uiOpen http://localhost:8080 in your web browser to test tool calls, RBAC roles, and injection defenses visually!
5. Test via Terminal (curl)
# Health Check
curl -s <YOUR_API_ENDPOINT>/health
# Tool Discovery Catalog
curl -s <YOUR_API_ENDPOINT>/mcp/tools
# Valid Tool Call (CloudWatch Query)
curl -s -X POST <YOUR_API_ENDPOINT>/mcp/tools/call \
-H "Content-Type: application/json" \
-H "X-User-Role: sre_read_only" \
-d '{"tool_name": "query_cloudwatch_logs", "arguments": {"log_group": "/aws/lambda/payment-dev", "filter_pattern": "ERROR"}}'
# Command Injection Attack (Returns 403 Forbidden)
curl -s -X POST <YOUR_API_ENDPOINT>/mcp/tools/call \
-H "Content-Type: application/json" \
-H "X-User-Role: sre_read_only" \
-d '{"tool_name": "query_cloudwatch_logs", "arguments": {"log_group": "/aws/lambda/payment-dev; rm -rf /", "filter_pattern": "ERROR"}}'6. Tear Down AWS Resources
make destroyTechnical Documentation Links
License & Enterprise Inquiries
This project is Dual-Licensed:
Open Source / Non-Commercial Use: Licensed under the GNU Affero General Public License v3.0 (AGPL-3.0). Free for open-source projects, personal evaluation, and educational use.
Enterprise / Commercial Production Use: Requires a paid Enterprise Commercial License. If your company intends to deploy or integrate this MCP server inside proprietary commercial applications, SaaS platforms, or private cloud infrastructure without open-sourcing the surrounding codebase, please contact the author for licensing terms.
Licensing Requests & Inquiries:
Author & Copyright Holder: Ketul Patel
Licensing Request Email: kpsub786@gmail.com
This server cannot be deployed
Maintenance
Related MCP Connectors
- gatewayOAuthai.sealgate
MCP gateway with runtime security policy, tool-call-level control, and audit of agent actions.
Security & DLP proxy for MCP: tool-poisoning scans, PII redaction on tool args/results. Beta.
Remote MCP for Copilot CLI switch gate MCP, structured receipts, audit logs, and reviewer-ready evid
Hosted MCP catalog with 30 tenant-isolated browser, RAG, AI, mail and media tools.
1
Related MCP Servers
- AlicenseBqualityDmaintenanceEnables AI models to interact with AWS Lambda functions via the MCP protocol, allowing access to private resources, real-time data, and custom computation in a secure environment.2109MIT
- AlicenseNot gradedqualityCmaintenanceA unified MCP server for AWS that enables natural language infrastructure management, cross-service resource discovery, and dependency mapping. It features 30 intelligent tools for cost optimization, incident investigation, and multi-account operations protected by a robust safety system.5MIT
- AlicenseCqualityDmaintenanceEnables secure, zero-trust access to MCP tools through short-lived, signed capability leases that bind tool execution to specific sessions, intents, and constraints. Prevents prompt injection attacks and privilege escalation with dynamic risk scoring, policy enforcement, and tamper-evident audit logging.41MIT
- AlicenseNot gradedqualityDmaintenanceBridges MCP clients and AWS Lambda functions, enabling generative AI models to invoke Lambda functions as tools without code changes.Apache 2.0