terraform-mcp
Provides the same state-aware blast-radius and FinOps verification capabilities for OpenTofu infrastructure-as-code plans.
Provides state-aware blast-radius analysis and FinOps verification for Terraform plans, detecting live infrastructure impacts such as severed ENIs/ECS tasks and wasteful cloud spending.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@terraform-mcpCheck my Terraform plan for reliability blast radius and FinOps waste before merge"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Terraform MCP: State-Aware Blast-Radius Analysis & FinOps Verification
State-Aware Blast-Radius Analysis: Dual-Objective Reliability and FinOps Verification for Infrastructure-as-Code via MCP-Governed Agentic Meshes
Author: Ashish Kumar
Systems Research White Paper: WHITE_PAPER.md
๐ Overview
Modern Continuous Integration and Delivery (CI/CD) pipelines for Infrastructure-as-Code (Terraform / OpenTofu) rely on static policy engines (Checkov, Trivy, OPA) and speculative execution plans (terraform plan). However, static analyzers operate in total isolation from live runtime state.
This creates two critical blind spots in cloud engineering:
The Reliability Blind Spot: A syntactically valid pull request modifying an
aws_security_groupor route table can instantly sever bindings to active, auto-scaled Elastic Network Interfaces (ENIs) and live ECS Fargate container tasks, causing immediate Sev-1 outages.The FinOps Blind Spot: Static cost estimators (e.g. Infracost) calculate flat rate deltas but are blind to live P99 CPU/memory utilization and cross-AZ data egress leaks ($0.01/GB).
terraform-mcp bridges declarative IaC intent with live operational realities using the Model Context Protocol (MCP) across a decoupled, least-privilege discovery mesh:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ CI/CD Pipeline Runner (GitHub Actions / GitLab CI) โ
โ โ
โ 1. terraform show -json tfplan.binary โโ> AST Extraction โ
โ 2. Ephemeral OIDC Token Exchange โโโโโโโ> Read-Only AWS STS Token โ
โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ MCP ORCHESTRATION MESH โ โ
โ โ - Concurrent FastMCP Queries (asyncio.gather) โ โ
โ โ - Deterministic Gating Rules (Zero Token Hallucinations) โ โ
โ โโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโ โ
โโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโ
โ JSON-RPC โ JSON-RPC
โ tools/call โ tools/call
โผ โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ AWS Live-Topology MCP Server โ โ FinOps Telemetry MCP Server โ
โ โ โ โ
โ - Tool: inspect_security_group โ โ - Tool: inspect_cost_waste โ
โ - Boto3 EC2/VPC Discovery Engine โ โ - CloudWatch P99 & Egress โ
โ - IAM: ec2:Describe* โ โ - IAM: cloudwatch:GetMetric* โ
โโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโ
โ โ
โผ โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Live AWS Cloud Infrastructure / Local Emulation Harness (Floci / Moto) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ๐ก Looking for local emulator testing without AWS costs? See our dedicated Floci Local Emulation Guide.
Related MCP server: Strata MCP Server
โก Key Features
Transitive Blast-Radius Tracing: Recursively discovers ephemeral ENIs, ECS container tasks, and Application Load Balancers bound to modified Security Groups.
Usage-Correlated FinOps Telemetry: Samples 14-day CloudWatch P99 metrics ($\text{P99} < 20%$) to block wasteful instance up-sizing and flags unrouted cross-AZ egress.
Dynamic Live AWS Discovery: Automatically inspects live EC2 instance types and CloudWatch telemetry directly from AWS APIs in real time.
Model Context Protocol (MCP) Decoupling: Topology discovery and FinOps telemetry execute across independent, least-privilege FastMCP servers.
Sub-150ms Pre-Merge Gate Latency: Deterministic async Python orchestration meeting strict sub-second CI gate performance SLA.
Spec-Compliant Markdown Reporting: Generates rich PR review comments with actionable severity levels (
CRITICAL,WARNING,SAFE).
๐ Quick Start on Real AWS Infrastructure
1. Prerequisites & Installation
# Clone the repository
git clone https://github.com/imashish-in/terraform-mcp.git
cd terraform-mcp
# Create and activate virtual environment
python3 -m venv .venv
source .venv/bin/activate
# Install terraform-mcp in editable development mode
pip install -e ".[dev]"2. Configure AWS Authentication
terraform-mcp uses standard boto3 and automatically discovers credentials from your AWS environment:
# Option A: Standard AWS Environment Variables
export AWS_ACCESS_KEY_ID="AKIA..."
export AWS_SECRET_ACCESS_KEY="..."
export AWS_DEFAULT_REGION="us-east-1"
# Option B: AWS CLI Profile / AWS SSO
export AWS_PROFILE="production"
# or: aws sso login --profile productionRequired IAM Permissions (Read-Only)
terraform-mcp strictly requires read-only / describe permissions:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "TerraformMCPStateDiscovery",
"Effect": "Allow",
"Action": [
"ec2:DescribeNetworkInterfaces",
"ec2:DescribeSecurityGroups",
"ec2:DescribeInstances",
"cloudwatch:GetMetricData",
"cloudwatch:GetMetricStatistics",
"elasticloadbalancing:DescribeTargetHealth",
"elasticloadbalancing:DescribeTargetGroups"
],
"Resource": "*"
}
]
}3. Remote S3 State Backend Setup
In your terraform/main.tf, configure an S3 backend to store your Terraform state remotely in AWS:
terraform {
required_version = ">= 1.5.0"
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 5.0"
}
}
backend "s3" {
bucket = "terraform-mcp-state-<YOUR_ACCOUNT_ID>"
key = "production/terraform.tfstate"
region = "us-east-1"
encrypt = true
}
}
provider "aws" {
region = "us-east-1"
}4. Running the Pre-Merge Verification Gate Locally
cd terraform
# 1. Initialize backend and generate plan binary
terraform init
terraform plan -out=tfplan.binary
# 2. Extract JSON AST diff from binary plan
terraform show -json tfplan.binary > tfplan.json
# 3. Evaluate plan against Real AWS Topology and CloudWatch Telemetry
terraform-mcp evaluate \
--plan tfplan.json \
--region us-east-1 \
--markdown-out pr_report.md \
--json-out eval_report.jsonSample Terminal Output:
โญโโโโโโโโโโโโโโโโโโโโ Terraform MCP Pre-Merge Gate Report โโโโโโโโโโโโโโโโโโโโโโฎ
โ Verdict: BLOCK_PR_CRITICAL_BLAST_RADIUS โ
โ Evaluation Latency: 142.34 ms โ
โ Topology Checks: 1 resource(s) โ
โ FinOps Checks: 0 resource(s) โ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
Dynamic Topology Blast-Radius Findings
โโโโโโโโโโโโโโโโโโโณโโโโโโโโโโโณโโโโโโโโโโโโโณโโโโโโโโโโโโโโโโโโโโโณโโโโโโโโโโโโโโโโ
โ Security Group โ Severity โ Live ENIs โ Severed Workloads โ Verdict โ
โกโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฉ
โ sg-081716c242cโฆ โ CRITICAL โ 3 direct โ 3 ECS microservice โ BLOCK_PR_CRIโฆ โ
โ โ โ โ tasks โ โ
โโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโดโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโ
Saved PR markdown summary to: pr_report.md๐ค Antigravity IDE & Claude Desktop MCP Registration
You can register both MCP servers directly in Google Antigravity IDE (~/.gemini/config/mcp_config.json) or Claude Desktop (claude_desktop_config.json):
{
"mcpServers": {
"aws-live-topology-inspector": {
"command": "terraform-mcp",
"args": ["serve-topology"],
"env": {
"AWS_REGION": "us-east-1"
}
},
"aws-finops-cost-inspector": {
"command": "terraform-mcp",
"args": ["serve-finops"],
"env": {
"AWS_REGION": "us-east-1"
}
}
}
}๐ GitHub Actions CI/CD Pipeline Setup
The repository includes a ready-to-use GitHub Actions workflow .github/workflows/real-aws-terraform-gate.yml:
1. Add Repository Secrets in GitHub
Go to Settings โ Secrets and variables โ Actions and add:
AWS_ACCESS_KEY_ID:AKIA...AWS_SECRET_ACCESS_KEY:...(Or use AWS OIDC
AWS_ROLE_ARNfor keyless authentication)
2. Automated PR Verification & Continuous Deployment
On Pull Request (
pull_request):Runs
terraform initandterraform planagainst your remote S3 backend.Runs
terraform-mcp evaluateagainst live AWS ENIs, ECS tasks, and CloudWatch metrics.Automatically posts the formatted audit report directly onto the Pull Request.
Fails the check (Red โ) to block the merge if a critical blast radius or waste is detected.
On Merge to Main (
push: [main]):Automatically executes
terraform apply -auto-approveto deploy verified changes to your live AWS account.
๐งช Real-World Verification Scenarios
Scenario A: Reliability Gate (Sev-1 Port Revocation)
Developer opens a PR removing port
8080fromaws_security_group.order_service_sg.terraform-mcpinspects live AWS ENIs bound to that security group in real-time.If active microservice ENIs are bound, it blocks the PR with
BLOCK_PR_CRITICAL_BLAST_RADIUS.
Scenario B: FinOps Gate (Structural Cloud Waste)
Developer opens a PR upsizing an EC2 instance from
t3.microtot3.xlarge.AWS-FinOps-Cost-Inspectorsamples live CloudWatch P99 CPU metrics over the lookback window.If peak utilization is low ($\text{P99} = 14.2% < 20%$), it calculates projected monthly waste (
+$113.88/mo) and blocks the PR withBLOCK_PR_FINOPS_WASTE.
๐ Benchmarks & Empirical Evaluation
To reproduce the benchmark suite from Section 5 of the white paper:
pytest -v -s --durations=10 tests/Metric | Measured Value | SLA Target | Status |
Case A (18 Live ENIs Blast Radius) |
|
| โ PASSED |
Case B (CloudWatch P99 Waste Audit) |
|
| โ PASSED |
Case C (Multi-AZ Route Severance) |
|
| โ PASSED |
Hermetic Multi-OS Test Suite | 10 / 10 Passing | 100% | โ PASSED |
๐ Research White Paper & Citations
For detailed formal proofs, mathematical formulations, and comparative architectural analysis with static analyzers, read the full white paper:
๐ WHITE_PAPER.md: "State-Aware Blast-Radius Analysis: Dual-Objective Reliability and FinOps Verification for Infrastructure-as-Code via MCP-Governed Agentic Meshes"
BibTeX Citation
@article{kumar2026stateaware,
title={State-Aware Blast-Radius Analysis: Dual-Objective Reliability and FinOps Verification for Infrastructure-as-Code via MCP-Governed Agentic Meshes},
author={Kumar, Ashish},
journal={Cloud Systems & Infrastructure Architecture Research},
year={2026}
}๐ License
Distributed under the Apache 2.0 License. See LICENSE for details.
This server cannot be deployed
Maintenance
Related MCP Connectors
- ZopDev MCPOAuthdev.zop
Cloud cost, inventory and governance on AWS/Azure/GCP. Read-only by default, optional scoped writes
Detects database migration table locks, terraform cost leaks, and OWASP API flaws.
IaC attack-path auditor: finds internet-to-crown-jewel chains in Terraform/CFN/K8s.
Screens public GitHub repos and PRs to generate risk maps, findings, and merge-readiness signals.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables visualization of Terraform plan changes as interactive cloud architecture diagrams with official AWS, Azure, and GCP icons, showing resource dependencies and changes.7MIT
- AlicenseNot gradedqualityBmaintenanceEnables LLMs to model, validate, and analyze multi-cloud infrastructure as a typed graph, with tools for IaC import/export, cost estimation, and architecture review.812 npmApache 2.0
- AlicenseNot gradedqualityBmaintenanceAutonomous multi-agent pipeline that analyzes Terraform files for cost, governance, and compliance issues, providing real-time remediation and XAI console for human-in-the-loop approval.MIT
- FlicenseNot gradedqualityBmaintenanceEnables AI to scan AWS accounts, analyze attack paths, and verify security fixes on a read-only graph of cloud resources.4-