Skip to main content
Glama
zhifengjin050-arch

Enterprise DevOps MCP Server

Enterprise DevOps MCP Server

MCP server for governed AI Agent tool calling over Linux, Docker, Kubernetes, and SSH.

让 AI Agent 在安全边界内做基础设施自动化——而不是拿到不受限的 shell。

English · Architecture · Security · Contributing

Python Tests MCP License

AI Agent → MCP Protocol → Security Layer → Infrastructure


Positioning

Enterprise AIOps building block: Cursor / Claude / any MCP client calls 18 tools through module whitelist, execute protection, command filtering, and audit logging.

Default posture: read-only (EXECUTE_TOOLS_ENABLED=false).


Related MCP server: SSH Vault MCP

Demo

Demo video

点击封面在线播放(中文旁白 + 底部字幕)。GitHub 文件页无法内嵌 mp4,演示页托管在 GitHub Pages。


Features

Feature

Status

Linux monitoring

Docker management

Kubernetes read APIs

SSH automation

Permission control

Execute protection

Audit logging

Docker Compose deploy

GitHub Actions CI


MCP tool catalog

Tool

Category

Risk

Permission

get_server_health

system

safe

viewer

get_system_info

system

safe

viewer

get_cpu_usage

system

safe

viewer

get_memory_usage

system

safe

viewer

get_disk_usage

system

safe

viewer

list_processes

system

safe

viewer

confirm_execute_action

system

moderate

viewer

get_audit_logs

system

moderate

admin

docker_list

docker

safe

viewer

docker_logs

docker

safe

viewer

docker_restart

docker

dangerous

admin

k8s_get_pods

kubernetes

safe

viewer

k8s_get_deployments

kubernetes

safe

viewer

k8s_get_services

kubernetes

safe

viewer

k8s_logs

kubernetes

safe

viewer

ssh_check_connection

ssh

safe

viewer

ssh_execute_command

ssh

dangerous

admin

ssh_upload_file

ssh

dangerous

admin


Architecture

flowchart TB
    Client[Cursor / Claude / AI Agent]
    Client --> MCP[MCP Protocol]
    MCP --> Server[Enterprise DevOps MCP Server]
    Server --> Sec[Security Layer]
    Sec --> Sys[Linux]
    Sec --> Dock[Docker]
    Sec --> K8s[Kubernetes]
    Sec --> SSH[SSH]
    subgraph sec [Controls]
      P[Module ACL]
      E[Execute gate]
      F[Command filter]
      A[Audit log]
    end
    Server -.-> P

Screenshots

MCP tools

Cursor / Claude

Tools

Cursor MCP

Architecture

Architecture

Cursor / Claude 图为 Product Preview(能力示意)。将本仓库配置进 MCP 后即可在 IDE 中真实调用。


Quick Start

git clone https://github.com/zhifengjin050-arch/enterprise-devops-mcp-server.git
cd enterprise-devops-mcp-server
cp .env.example .env
pip install -r requirements.txt
python scripts/demo_list_tools.py
./scripts/demo_start.sh          # Windows: .\scripts\demo_start.ps1

Keep EXECUTE_TOOLS_ENABLED=false. See demo/README.md. Do not commit .env, kubeconfig, or SSH keys.

Docker

docker compose up -d --build

Cursor MCP

{
  "mcpServers": {
    "enterprise-devops": {
      "command": "python",
      "args": ["scripts/run_devops_mcp.py"],
      "cwd": "YOUR_PROJECT_PATH",
      "env": {
        "EXECUTE_TOOLS_ENABLED": "false"
      }
    }
  }
}

Example: mcp_config_examples/cursor_mcp.json

pytest

Deployment

Mode

Command

Local

python -m app.server

Docker

docker compose up -d --build

Never enable execute tools in production without an explicit change-control process.


Roadmap

v1.0.x (current): 18 tools, security layer, audit, Docker, CI.

Later: more cloud providers, finer-grained policy packs, signed audit export.


License

MIT

CONTRIBUTING.md · CODE_OF_CONDUCT.md · SECURITY.md · CHANGELOG.md

Disclaimer: with execute enabled, this software can change hosts and containers. Validate in non-production first.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

No tool schema history has been recorded yet.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server that enforces runtime governance on AI agent actions — file access, command execution, delegation chains, and permission escalation.
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables AI agents to securely access encrypted secrets (SSH keys, API tokens, passwords) with real-time user approval via Passkey, and supports SSH remote execution through the MCP protocol.
    -

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/zhifengjin050-arch/enterprise-devops-mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server