Skip to main content
Glama
patelketul1230

Enterprise Secure AWS MCP Server

エンタープライズ向けセキュア AWS Model Context Protocol (MCP) サーバー

AWS Lambda と API Gateway にデプロイされた本番グレードの Model Context Protocol (MCP) サーバー。100% Terraform IaC、ゼロトラスト IAM RBAC、そして OWASP LLM Top 10 防御ガードレールを備えています。


AWS アーキテクチャ概要

AWS Enterprise MCP Server Figma アーキテクチャ図


Related MCP server: AWS Sage

機能

  • 標準 MCP 仕様: Anthropic Model Context Protocol (MCP) のツールディスカバリ (/mcp/tools) とツール実行 (/mcp/tools/call) を完全サポート。

  • IAM ロールベースアクセス制御 (RBAC): ロール (sre_read_onlysecurity_auditorsre_admin) に基づいてツール実行を制限します。

  • OWASP LLM02 防御: サブシェルのメタキャラクタインジェクション ([;&|'$]) をブロックするエッジサニタイゼーション。

  • OWASP LLM06 防御: AWS アクセスキー (AKIA...) と PII をスクラブする自動出力バッファレダクター。

  • インタラクティブな Web UI プレイグラウンド: http://localhost:8080 (make ui) で動作するダークモードのテストインターフェース。

  • アイドル時のクラウドコストゼロ: Terraform によるプロビジョニングで、単一コマンドのデプロイ (make deploy) と即時ティアダウン (make destroy) を実現。


Web UI プレイグラウンドデモ

以下は、RBAC アクセス拒否、コマンドインジェクション防御、および sre_admin ロールでのサーバー再起動の成功実行を示す、自動化された高解像度のインタラクティブデモです。

AWS MCP Server Web UI セキュリティテストデモ


前提条件とシステムセットアップ

プロジェクトをセットアップする前に、環境に Python 3.11+、Terraform、AWS CLI がインストールされていることを確認してください。

1. システム依存関係 (Linux / Ubuntu / Debian)

sudo apt update && sudo apt install python3-venv python3-pip terraform awscli -y

2. 環境セットアップ

リポジトリをクローンし、プロジェクトの依存関係を分離された仮想環境 (.venv) にインストールします:

git clone https://github.com/patelketul1230/aws-mcp-enterprise-server.git
cd aws-mcp-enterprise-server

# Create .venv and install dependencies
make install

リポジトリ構造

aws-mcp-enterprise-server/
├── docs/
│   ├── assets/                    # Centralized PNG images & HD animations
│   │   ├── mcp_aws_figma_architecture_diagram.png
│   │   ├── mcp_ui_testing_demo.webp
│   │   ├── mcp_ui_testing_demo.gif
│   │   ├── mcp_ui_playground_success_screenshot.png
│   │   ├── mcp_ui_playground_admin_success_screenshot.png
│   │   └── mcp_ui_playground_blocked_screenshot.png
│   ├── blogs/                     # 3 Medium Sub-Blogs ready for publication
│   │   ├── blog_1_1_mcp_decoded.md
│   │   ├── blog_1_2_mcp_rbac_python.md
│   │   └── blog_1_3_mcp_tool_poisoning.md
│   ├── architecture.md            # Figma diagrams & sequence flows
│   ├── 5w_and_how.md              # 5 Ws + 1 H problem statement & threat model
│   └── demo_execution.log         # Verified test execution log
├── src/
│   ├── clients/                   # AWS Bedrock Converse API integration client
│   ├── middleware/                # MCPSecurityValidator (RBAC & DLP)
│   ├── tools/                     # CloudWatch & Terraform tool modules
│   ├── ui/                        # Interactive Web UI Playground (index.html)
│   └── server.py                  # AWS Lambda & FastAPI server handler
├── terraform/                     # 100% Terraform IaC (API Gateway, IAM, Lambda)
├── tests/                         # Pytest suite & live verification scripts
├── Makefile                       # Lifecycle hooks (make deploy / make destroy / make ui)
└── README.md                      # Project documentation

クイックスタートガイド

1. 依存関係のインストール

make install

2. テストの実行

make test

3. AWS へのインフラストラクチャのデプロイ

make deploy

出力:

  • API エンドポイント: Terraform によって生成される動的出力

  • CloudWatch ロググループ: /aws/mcp/aws-mcp-enterprise-server-dev

4. インタラクティブな Web UI プレイグラウンドの起動

make ui

Web ブラウザで http://localhost:8080 を開き、ツール呼び出し、RBAC ロール、インジェクション防御を視覚的にテストしてください!

5. ターミナル (curl) でのテスト

# Health Check
curl -s <YOUR_API_ENDPOINT>/health

# Tool Discovery Catalog
curl -s <YOUR_API_ENDPOINT>/mcp/tools

# Valid Tool Call (CloudWatch Query)
curl -s -X POST <YOUR_API_ENDPOINT>/mcp/tools/call \
  -H "Content-Type: application/json" \
  -H "X-User-Role: sre_read_only" \
  -d '{"tool_name": "query_cloudwatch_logs", "arguments": {"log_group": "/aws/lambda/payment-dev", "filter_pattern": "ERROR"}}'

# Command Injection Attack (Returns 403 Forbidden)
curl -s -X POST <YOUR_API_ENDPOINT>/mcp/tools/call \
  -H "Content-Type: application/json" \
  -H "X-User-Role: sre_read_only" \
  -d '{"tool_name": "query_cloudwatch_logs", "arguments": {"log_group": "/aws/lambda/payment-dev; rm -rf /", "filter_pattern": "ERROR"}}'

6. AWS リソースのティアダウン

make destroy

技術ドキュメントリンク

F
license - not found
Not graded
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    B
    quality
    D
    maintenance
    Enables AI models to interact with AWS Lambda functions via the MCP protocol, allowing access to private resources, real-time data, and custom computation in a secure environment.
    2
    109
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    A unified MCP server for AWS that enables natural language infrastructure management, cross-service resource discovery, and dependency mapping. It features 30 intelligent tools for cost optimization, incident investigation, and multi-account operations protected by a robust safety system.
    5
    MIT
  • A
    license
    C
    quality
    D
    maintenance
    Enables secure, zero-trust access to MCP tools through short-lived, signed capability leases that bind tool execution to specific sessions, intents, and constraints. Prevents prompt injection attacks and privilege escalation with dynamic risk scoring, policy enforcement, and tamper-evident audit logging.
    4
    1
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    A read-only MCP server for safe, structured investigation of AWS serverless resources, providing curated tools for tracing dependencies, permissions, and failures without exposing raw SDK access.
    MIT

View all related MCP servers

Related MCP Connectors

  • Remote MCP for Copilot CLI switch gate MCP, structured receipts, audit logs, and reviewer-ready evid

  • A paid remote MCP for AI SDK eval dashboard, built to return verdicts, receipts, usage logs, and aud

  • A paid remote MCP for ClawManager, built to return verdicts, receipts, usage logs, and audit-ready J

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/patelketul1230/aws-mcp-enterprise-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server