Enterprise Secure AWS MCP Server
エンタープライズ向けセキュア AWS Model Context Protocol (MCP) サーバー
AWS Lambda と API Gateway にデプロイされた本番グレードの Model Context Protocol (MCP) サーバー。100% Terraform IaC、ゼロトラスト IAM RBAC、そして OWASP LLM Top 10 防御ガードレールを備えています。
AWS アーキテクチャ概要

Related MCP server: AWS Sage
機能
標準 MCP 仕様: Anthropic Model Context Protocol (MCP) のツールディスカバリ (
/mcp/tools) とツール実行 (/mcp/tools/call) を完全サポート。IAM ロールベースアクセス制御 (RBAC): ロール (
sre_read_only、security_auditor、sre_admin) に基づいてツール実行を制限します。OWASP LLM02 防御: サブシェルのメタキャラクタインジェクション (
[;&|'$]) をブロックするエッジサニタイゼーション。OWASP LLM06 防御: AWS アクセスキー (
AKIA...) と PII をスクラブする自動出力バッファレダクター。インタラクティブな Web UI プレイグラウンド:
http://localhost:8080(make ui) で動作するダークモードのテストインターフェース。アイドル時のクラウドコストゼロ: Terraform によるプロビジョニングで、単一コマンドのデプロイ (
make deploy) と即時ティアダウン (make destroy) を実現。
Web UI プレイグラウンドデモ
以下は、RBAC アクセス拒否、コマンドインジェクション防御、および sre_admin ロールでのサーバー再起動の成功実行を示す、自動化された高解像度のインタラクティブデモです。

前提条件とシステムセットアップ
プロジェクトをセットアップする前に、環境に Python 3.11+、Terraform、AWS CLI がインストールされていることを確認してください。
1. システム依存関係 (Linux / Ubuntu / Debian)
sudo apt update && sudo apt install python3-venv python3-pip terraform awscli -y2. 環境セットアップ
リポジトリをクローンし、プロジェクトの依存関係を分離された仮想環境 (.venv) にインストールします:
git clone https://github.com/patelketul1230/aws-mcp-enterprise-server.git
cd aws-mcp-enterprise-server
# Create .venv and install dependencies
make installリポジトリ構造
aws-mcp-enterprise-server/
├── docs/
│ ├── assets/ # Centralized PNG images & HD animations
│ │ ├── mcp_aws_figma_architecture_diagram.png
│ │ ├── mcp_ui_testing_demo.webp
│ │ ├── mcp_ui_testing_demo.gif
│ │ ├── mcp_ui_playground_success_screenshot.png
│ │ ├── mcp_ui_playground_admin_success_screenshot.png
│ │ └── mcp_ui_playground_blocked_screenshot.png
│ ├── blogs/ # 3 Medium Sub-Blogs ready for publication
│ │ ├── blog_1_1_mcp_decoded.md
│ │ ├── blog_1_2_mcp_rbac_python.md
│ │ └── blog_1_3_mcp_tool_poisoning.md
│ ├── architecture.md # Figma diagrams & sequence flows
│ ├── 5w_and_how.md # 5 Ws + 1 H problem statement & threat model
│ └── demo_execution.log # Verified test execution log
├── src/
│ ├── clients/ # AWS Bedrock Converse API integration client
│ ├── middleware/ # MCPSecurityValidator (RBAC & DLP)
│ ├── tools/ # CloudWatch & Terraform tool modules
│ ├── ui/ # Interactive Web UI Playground (index.html)
│ └── server.py # AWS Lambda & FastAPI server handler
├── terraform/ # 100% Terraform IaC (API Gateway, IAM, Lambda)
├── tests/ # Pytest suite & live verification scripts
├── Makefile # Lifecycle hooks (make deploy / make destroy / make ui)
└── README.md # Project documentationクイックスタートガイド
1. 依存関係のインストール
make install2. テストの実行
make test3. AWS へのインフラストラクチャのデプロイ
make deploy出力:
API エンドポイント: Terraform によって生成される動的出力
CloudWatch ロググループ:
/aws/mcp/aws-mcp-enterprise-server-dev
4. インタラクティブな Web UI プレイグラウンドの起動
make uiWeb ブラウザで http://localhost:8080 を開き、ツール呼び出し、RBAC ロール、インジェクション防御を視覚的にテストしてください!
5. ターミナル (curl) でのテスト
# Health Check
curl -s <YOUR_API_ENDPOINT>/health
# Tool Discovery Catalog
curl -s <YOUR_API_ENDPOINT>/mcp/tools
# Valid Tool Call (CloudWatch Query)
curl -s -X POST <YOUR_API_ENDPOINT>/mcp/tools/call \
-H "Content-Type: application/json" \
-H "X-User-Role: sre_read_only" \
-d '{"tool_name": "query_cloudwatch_logs", "arguments": {"log_group": "/aws/lambda/payment-dev", "filter_pattern": "ERROR"}}'
# Command Injection Attack (Returns 403 Forbidden)
curl -s -X POST <YOUR_API_ENDPOINT>/mcp/tools/call \
-H "Content-Type: application/json" \
-H "X-User-Role: sre_read_only" \
-d '{"tool_name": "query_cloudwatch_logs", "arguments": {"log_group": "/aws/lambda/payment-dev; rm -rf /", "filter_pattern": "ERROR"}}'6. AWS リソースのティアダウン
make destroy技術ドキュメントリンク
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseBqualityDmaintenanceEnables AI models to interact with AWS Lambda functions via the MCP protocol, allowing access to private resources, real-time data, and custom computation in a secure environment.2109MIT
- AlicenseNot gradedqualityCmaintenanceA unified MCP server for AWS that enables natural language infrastructure management, cross-service resource discovery, and dependency mapping. It features 30 intelligent tools for cost optimization, incident investigation, and multi-account operations protected by a robust safety system.5MIT
- AlicenseCqualityDmaintenanceEnables secure, zero-trust access to MCP tools through short-lived, signed capability leases that bind tool execution to specific sessions, intents, and constraints. Prevents prompt injection attacks and privilege escalation with dynamic risk scoring, policy enforcement, and tamper-evident audit logging.41MIT
- AlicenseNot gradedqualityCmaintenanceA read-only MCP server for safe, structured investigation of AWS serverless resources, providing curated tools for tracing dependencies, permissions, and failures without exposing raw SDK access.MIT
Related MCP Connectors
Remote MCP for Copilot CLI switch gate MCP, structured receipts, audit logs, and reviewer-ready evid
A paid remote MCP for AI SDK eval dashboard, built to return verdicts, receipts, usage logs, and aud
A paid remote MCP for ClawManager, built to return verdicts, receipts, usage logs, and audit-ready J
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/patelketul1230/aws-mcp-enterprise-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server