Enterprise Secure AWS MCP Server
エンタープライズ向けセキュア AWS Model Context Protocol (MCP) サーバー
AWS Lambda と API Gateway にデプロイされた本番グレードの Model Context Protocol (MCP) サーバー。100% Terraform IaC、ゼロトラスト IAM RBAC、そして OWASP LLM Top 10 防御ガードレールを備えています。
AWS アーキテクチャ概要

Related MCP server: MCP Airlock
機能
標準 MCP 仕様: Anthropic Model Context Protocol (MCP) のツールディスカバリ (
/mcp/tools) とツール実行 (/mcp/tools/call) を完全サポート。IAM ロールベースアクセス制御 (RBAC): ロール (
sre_read_only、security_auditor、sre_admin) に基づいてツール実行を制限します。OWASP LLM02 防御: サブシェルのメタキャラクタインジェクション (
[;&|'$]) をブロックするエッジサニタイゼーション。OWASP LLM06 防御: AWS アクセスキー (
AKIA...) と PII をスクラブする自動出力バッファレダクター。インタラクティブな Web UI プレイグラウンド:
http://localhost:8080(make ui) で動作するダークモードのテストインターフェース。アイドル時のクラウドコストゼロ: Terraform によるプロビジョニングで、単一コマンドのデプロイ (
make deploy) と即時ティアダウン (make destroy) を実現。
Web UI プレイグラウンドデモ
以下は、RBAC アクセス拒否、コマンドインジェクション防御、および sre_admin ロールでのサーバー再起動の成功実行を示す、自動化された高解像度のインタラクティブデモです。

前提条件とシステムセットアップ
プロジェクトをセットアップする前に、環境に Python 3.11+、Terraform、AWS CLI がインストールされていることを確認してください。
1. システム依存関係 (Linux / Ubuntu / Debian)
sudo apt update && sudo apt install python3-venv python3-pip terraform awscli -y2. 環境セットアップ
リポジトリをクローンし、プロジェクトの依存関係を分離された仮想環境 (.venv) にインストールします:
git clone https://github.com/patelketul1230/aws-mcp-enterprise-server.git
cd aws-mcp-enterprise-server
# Create .venv and install dependencies
make installリポジトリ構造
aws-mcp-enterprise-server/
├── docs/
│ ├── assets/ # Centralized PNG images & HD animations
│ │ ├── mcp_aws_figma_architecture_diagram.png
│ │ ├── mcp_ui_testing_demo.webp
│ │ ├── mcp_ui_testing_demo.gif
│ │ ├── mcp_ui_playground_success_screenshot.png
│ │ ├── mcp_ui_playground_admin_success_screenshot.png
│ │ └── mcp_ui_playground_blocked_screenshot.png
│ ├── blogs/ # 3 Medium Sub-Blogs ready for publication
│ │ ├── blog_1_1_mcp_decoded.md
│ │ ├── blog_1_2_mcp_rbac_python.md
│ │ └── blog_1_3_mcp_tool_poisoning.md
│ ├── architecture.md # Figma diagrams & sequence flows
│ ├── 5w_and_how.md # 5 Ws + 1 H problem statement & threat model
│ └── demo_execution.log # Verified test execution log
├── src/
│ ├── clients/ # AWS Bedrock Converse API integration client
│ ├── middleware/ # MCPSecurityValidator (RBAC & DLP)
│ ├── tools/ # CloudWatch & Terraform tool modules
│ ├── ui/ # Interactive Web UI Playground (index.html)
│ └── server.py # AWS Lambda & FastAPI server handler
├── terraform/ # 100% Terraform IaC (API Gateway, IAM, Lambda)
├── tests/ # Pytest suite & live verification scripts
├── Makefile # Lifecycle hooks (make deploy / make destroy / make ui)
└── README.md # Project documentationクイックスタートガイド
1. 依存関係のインストール
make install2. テストの実行
make test3. AWS へのインフラストラクチャのデプロイ
make deploy出力:
API エンドポイント: Terraform によって生成される動的出力
CloudWatch ロググループ:
/aws/mcp/aws-mcp-enterprise-server-dev
4. インタラクティブな Web UI プレイグラウンドの起動
make uiWeb ブラウザで http://localhost:8080 を開き、ツール呼び出し、RBAC ロール、インジェクション防御を視覚的にテストしてください!
5. ターミナル (curl) でのテスト
# Health Check
curl -s <YOUR_API_ENDPOINT>/health
# Tool Discovery Catalog
curl -s <YOUR_API_ENDPOINT>/mcp/tools
# Valid Tool Call (CloudWatch Query)
curl -s -X POST <YOUR_API_ENDPOINT>/mcp/tools/call \
-H "Content-Type: application/json" \
-H "X-User-Role: sre_read_only" \
-d '{"tool_name": "query_cloudwatch_logs", "arguments": {"log_group": "/aws/lambda/payment-dev", "filter_pattern": "ERROR"}}'
# Command Injection Attack (Returns 403 Forbidden)
curl -s -X POST <YOUR_API_ENDPOINT>/mcp/tools/call \
-H "Content-Type: application/json" \
-H "X-User-Role: sre_read_only" \
-d '{"tool_name": "query_cloudwatch_logs", "arguments": {"log_group": "/aws/lambda/payment-dev; rm -rf /", "filter_pattern": "ERROR"}}'6. AWS リソースのティアダウン
make destroy技術ドキュメントリンク
This server cannot be deployed
Maintenance
Related MCP Connectors
Find, vet, and run MCP tools through a secure audited gateway with prompt-injection risk scoring
- gatewayOAuthai.sealgate
MCP gateway with runtime security policy, tool-call-level control, and audit of agent actions.
Security & DLP proxy for MCP: tool-poisoning scans, PII redaction on tool args/results. Beta.
Remote MCP for Copilot CLI switch gate MCP, structured receipts, audit logs, and reviewer-ready evid
Related MCP Servers
- AlicenseBqualityDmaintenanceEnables AI models to interact with AWS Lambda functions via the MCP protocol, allowing access to private resources, real-time data, and custom computation in a secure environment.2109MIT
- AlicenseCqualityDmaintenanceEnables secure, zero-trust access to MCP tools through short-lived, signed capability leases that bind tool execution to specific sessions, intents, and constraints. Prevents prompt injection attacks and privilege escalation with dynamic risk scoring, policy enforcement, and tamper-evident audit logging.41MIT
- AlicenseNot gradedqualityDmaintenanceBridges MCP clients and AWS Lambda functions, enabling generative AI models to invoke Lambda functions as tools without code changes.Apache 2.0
- AlicenseBqualityBmaintenanceEnables LLM clients to access DevSecOps tooling such as CI/CD pipeline status, vulnerability triage, log search, and dependency scanning through MCP, turning AI copilots into security-aware engineering partners.6MIT