Token导航 LogoToken导航TokenDH.com
MCP Aws Manager logo
运维云端未说明官方级别未说明来源级核验

MCP Aws Manager

MCP Server

一个用于AWS操作(库存/运行时/修复)的CLI工具,提供标准化输出和操作指导,支持多服务和SSM优先的工作流。

工具数

3

提示词数

0

GitHub Stars

0

资源数

0
JavaScriptClaude云端部署ClaudeCursor

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

作者 / 组织

Soy-Bin

提供方

Soy-Bin

最后核验

2026/5/17 20:23

快速接入

先看主来源和安装命令,再打开仓库或文档;下面只保留这个条目的关键接入事实。

详细介绍

mcp aws经理

AWS操作CLI+MCP stdio服务器(SSM优先)。

此包使用规范化的输出模式编排AWS操作(库存/运行时/补救) ACTION_REQUIRED 指导。它不是一个简单的AWS CLI包装器。

Agent First快速入门

将此用作代理环境的默认流:

npm install -g mcp-aws-manager
mcp-aws-manager --version
mcp-aws-manager setup --force
mcp-aws-manager doctor

代理提示示例:

用自然语言提问,如下所示;代理应根据需要运行获取/分析步骤。

Give me a fresh full AWS server status summary.

然后尝试以下请求:

Compare current AWS server status with the previous check and show only what changed.
Summarize AWS server status with required actions and high-impact warnings in priority order.

它的作用

  • 多服务库存:EC2、Lambda、ALB/NLB、ASG、RDS、ElastiCache、Route53、VPC/Subnet/SecurityGroup、ECS、S3、IAM、KMS、CloudWatch、CloudTrail、Config、Secrets Manager、ECR、DynamoDB、SNS、EventBridge、SQS、ACM、Kinesis、MSK、Budgets、Cost Anomaly、EBS、EFS、EKS、API Gateway(REST/v2)、CloudFront、WAF、Shield、Step Functions、CloudWatch Logs、X-Ray、Inspector2、Redshift、OpenSearch、Organizations、ControlTower
  • SSM状态可见性:管理/在线状态
  • 领域分析管道:IaC漂移、CI/CD信号、备份/DR态势、安全态势、FinOps成本信号、应用层健康状况、事件严重性建议
  • 可选的运行时快照和SSM修复
  • 可变表面扩展:EC2+ECS+ASG+RDS+EKS控制的更改工具
  • 策略感知路由:选择模式/表面/模式层以实现更安全的默认值
  • 多帐户扩展控制:组织假设角色扇出+配置文件/区域分片
  • 手动回退模式:JSON/CSV服务器列表+PEM SSH/ProxyJump/Bastion运行时快照(当AWS身份验证不可用时)
  • 人在循环重试流通过 ACTION_REQUIRED
  • 仅限内部执行路径(AWS SDK+AWS CLI)
  • 表示层控件:输出配置文件预设、剖面/场投影和客户端感知默认布局
  • 持久治理日志+拓扑/关系JSON工件
  • 可选的事件升级webhook调度,带有本地事件负载工件

何时使用此项目

使用 mcp-aws-manager 当您需要一个操作工作流程MCP,而不仅仅是通用的AWS API访问。

  • 选择此项目进行确定性清单/运行时/补救循环。
  • 选择此项目时 ACTION_REQUIRED 需要引导和操作员伪影。
  • 仅对于广泛的特定AWS API控制,一个伞式API类型的AWS MCP就足够了。

详细比较和产品边界见:

  • docs/MCP_DIFFERENTIATION.md

快速比较

选择点mcp-aws-manager伞式API型AWS MCP
主要目标确定性操作工作流(库存/运行时/修复)广泛的特定API/工具访问
工具曝光模型固定网关3-Tool(capabilities_summary, capabilities_detail, gateway_execute)许多直接服务/行动工具
更改安全用于更改路径的内置确认/策略门取决于每个工具/服务器策略
响应合同标准化(ok/summary/records/requiredActions/meta)因实施而异
最佳匹配具有操作员指导的可再现操作循环探索性或广泛的API探测

有关完整的原理和边界,请参阅 docs/MCP_DIFFERENTIATION.mddocs/MCP_DIFFERENTIATION_KO.md.

API覆盖率快照

  • AWS API总数:没有固定的官方单一数字,但各服务的行动面约为数万(并不断扩大)。
  • 当前的实施范围并非“所有AWS API”。
  • 使用的AWS SDK服务客户端: 49
  • 使用的AWS SDK操作调用: 95
  • 使用的AWS CLI命令: 1 (`aws sso login --profile

`)

  • 注:企业控制(策略门/回滚/治理验证)仍然存在,而库存覆盖范围已经扩大。

当前95个AWS SDK操作:

  • STS: GetCallerIdentity
  • EC2: DescribeRegions, DescribeInstances, DescribeVpcs, DescribeSubnets, DescribeSecurityGroups, StartInstances, StopInstances, RebootInstances, DescribeIamInstanceProfileAssociations, AssociateIamInstanceProfile, ReplaceIamInstanceProfileAssociation
  • SSM: DescribeInstanceInformation, DescribeParameters, SendCommand, GetCommandInvocation
  • λ: ListFunctions
  • ELBv2: DescribeLoadBalancers, DescribeTargetGroups
  • 自动缩放: DescribeAutoScalingGroups, SetDesiredCapacity
  • RDS: DescribeDBInstances, StartDBInstance, StopDBInstance, RebootDBInstance
  • ElastiCache: DescribeCacheClusters
  • 路线53: ListHostedZones, ListResourceRecordSets
  • ECS: ListClusters, DescribeClusters, ListServices, DescribeServices, UpdateService
  • S3: ListBuckets, GetBucketLocation
  • 国际机械师协会: ListRoles
  • 公里: ListKeys, DescribeKey
  • 云观察: DescribeAlarms
  • CloudTrail: DescribeTrails
  • AWS配置: DescribeConfigurationRecorders, DescribeConfigurationRecorderStatus, DescribeDeliveryChannels, DescribeConfigRules, DescribeComplianceByConfigRule
  • 保密经理: ListSecrets
  • ECR: DescribeRepositories
  • DynamoDB: ListTables, DescribeTable
  • SNS: ListTopics
  • EventBridge: ListEventBuses
  • SQS: ListQueues, GetQueueAttributes
  • 国际计算机学会 ListCertificates, DescribeCertificate
  • 动脉炎: ListStreams, DescribeStreamSummary
  • MSK: ListClustersV2
  • AWS预算: DescribeBudgets
  • EBS: DescribeVolumes
  • EFS: DescribeFileSystems
  • EKS : ListClusters, DescribeCluster, DescribeNodegroup, UpdateNodegroupConfig
  • API网关(REST): GetRestApis
  • API网关v2: GetApis
  • CloudFront: ListDistributions
  • WAFv2: ListWebACLs
  • 防护罩: ListProtections
  • 步骤功能: ListStateMachines
  • CloudWatch日志: DescribeLogGroups
  • X射线: GetGroups
  • 检查员2: ListFindings
  • 红移: DescribeClusters
  • OpenSearch: ListDomainNames, DescribeDomain
  • 组织机构: ListAccounts
  • 控制塔: ListLandingZones
  • 云层形成: DescribeStacks
  • CodePipeline: ListPipelines, ListPipelineExecutions
  • 代码构建: ListProjects, ListBuildsForProject, BatchGetBuilds
  • 代码部署: ListApplications, ListDeploymentGroups, ListDeployments, BatchGetDeployments
  • AWS备份: ListBackupPlans, ListProtectedResources
  • SecurityHub: GetFindings
  • GuardDuty: ListDetectors, ListFindings
  • 成本探索者: GetCostAndUsage, GetAnomalies, GetSavingsPlansUtilization, GetReservationCoverage

二进制文件

  • CLI: mcp-aws-manager
  • MCP stdio服务器(单条目;默认值: --surface all): mcp-aws-manager-mcp

mcp-aws-manager-mcp 使用具有可选表面范围的网关路由:

mcp-aws-manager-mcp --surface all
mcp-aws-manager-mcp --surface readonly
mcp-aws-manager-mcp --surface mutate

代理协助首次设置

将此流用于新用户。

  1. 安装并引导:
npm.cmd install -g mcp-aws-manager@latest
mcp-aws-manager

Bootstrap为检测到的客户端注册默认的单MCP服务器:

  • mcp-aws-manager (单条目, --surface all)
  • 运行时命令会自动解析以确保主机稳定性。
  • Windows优先级:绝对 mcp-aws-manager-mcp.cmd
  • macOS/Linux优先级:绝对 mcp-aws-manager-mcp 二进制
  • 退路: node /bin/mcp-aws-manager-mcp.js
  • 最后回退(临时npx上下文):固定 npx -y -p mcp-aws-manager@ mcp-aws-manager-mcp

可选的显式注册:

mcp-aws-manager setup
mcp-aws-manager setup --clients cursor
mcp-aws-manager setup --clients codex
mcp-aws-manager setup --clients claude

默认行为(setup/bootstrap 没有 --clients)自动检测已安装的客户端,并仅注册检测到的CLI。

兼容性说明:

  • 光标通过MCP配置文件同步注册(~/.cursor/mcp.json 和平台用户配置路径),以避免编辑器选项卡的副作用 cursor mcp ....
  • 即使在以下情况下,Claude也可以通过配置同步进行注册 claude 当Claude配置路径(例如macOS)不在PATH中时 ~/Library/Application Support/Claude/claude_desktop_config.json,Linux ~/.config/Claude/claude_desktop_config.json,或 ~/.claude/claude_desktop_config.json)或者检测到安装足迹。你可以用 CLAUDE_MCP_CONFIG_PATH.
  • 如果另一个编辑器风格的客户端没有公开稳定的CLI mcp 子命令, setup/doctor 回报 manual configuration required 而不是运行不安全的子命令。
  1. 健康检查:
mcp-aws-manager doctor

默认行为(doctor 没有 --clients)自动检测已安装的客户端并跳过未安装的CLI。

  1. 配置AWS身份验证(建议使用SSO):
aws configure sso --profile default
aws sso login --profile default
  1. 验证身份:
aws sts get-caller-identity --profile default
  1. 运行发现:
mcp-aws-manager discover --profiles default --no-progress

如果被阻止,请跟随一个 ACTION_REQUIRED 项,然后重试相同的命令。

如果AWS身份验证不可用,请使用手动回退:

mcp-aws-manager discover --manual-server-list ./servers.csv --pem-paths C:\keys\prod.pem --no-progress

默认情况下生成GUI报告(自动路径:workspace/home aws-inventory.html):

mcp-aws-manager discover --profiles default --no-progress

GUI包括:

  • 摘要卡(记录/服务/配置文件/地区/EC2/SSM/公共IP/问题)
  • 选项卡视图(Report, Diagrams, Evidence, Inventory)
  • 详细降价报告(report.md)按资源类型划分
  • 拓扑图(配置文件->区域->类型->资源)
  • 关系图(DNS/TargetGroup ALB/ASG启发式链接)
  • 具有每个资源详细信息和聚焦关系图的聚焦服务器/资源选择器(focus.svg)
  • 证据查看与导出(evidence.json)
  • 图表导出(diagram.drawio, topology.svg, relationship.svg)
  • 下载的工件在文件名中包含生成时间戳(例如 report-20260304-113000.md)

自定义路径/打开行为:

mcp-aws-manager discover --profiles default --html-out ./inventory.html --open-html --no-progress

默认情况下,启用HTML打开。使用 --no-open-html 禁用。

手动MCP客户端配置(回退)

仅在自动时使用此选项 bootstrap/setup 注册不可用。

  1. 本地存储库(开发):
{
  "mcpServers": {
    "mcp-aws-manager": {
      "command": "node",
      "args": [
        "/bin/mcp-aws-manager-mcp.js",
        "--surface",
        "all"
      ],
      "cwd": ""
    }
  }
}
  1. 全局npm安装(手动回退):

Windows(推荐):

{
  "mcpServers": {
    "mcp-aws-manager": {
      "command": "C:\\Users\\\\AppData\\Roaming\\npm\\mcp-aws-manager-mcp.cmd",
      "args": ["--surface", "all"]
    }
  }
}

macOS/Linux:

{
  "mcpServers": {
    "mcp-aws-manager": {
      "command": "mcp-aws-manager-mcp",
      "args": ["--surface", "all"]
    }
  }
}
  1. npx (无需全局安装):
{
  "mcpServers": {
    "mcp-aws-manager": {
      "command": "npx",
      "args": ["-y", "-p", "mcp-aws-manager", "mcp-aws-manager-mcp", "--surface", "all"]
    }
  }
}

需要用户确认

这些通常是唯一的手动步骤(代理指导):

  • SSO浏览器登录和MFA确认
  • 组织帐户中的IAM权限审批
  • 对于EC2运行时可见性:附加 AmazonSSMManagedInstanceCore 并保持SSM代理/网络健康

代理重试循环(推荐):

  1. 执行工具调用。
  2. 如果 requiresUserAction=false总结并完成。
  3. 如果 requiresUserAction=true,出示一张 requiredActions[] 项目并要求用户完成。
  4. 当用户确认完成时,使用重试 guidance.retryTool + guidance.retryArgs.
  5. 重复直到 requiresUserAction=false.

MCP工具使用

运行单入口MCP服务器(默认: --surface all):

mcp-aws-manager-mcp

选择曝光模式:

  • mcp-aws-manager-mcp --surface all|readonly|mutate (仅网关)

网关模型(tools/list)仅公开了3个工具:

  • capabilities_summary
  • capabilities_detail
  • gateway_execute

网关呼叫流:

  1. 呼叫 capabilities_summary 接收操作类别和 operationId 列表。
  2. 呼叫 capabilities_detail 一起 operationId 检查执行合同。
  3. 呼叫 gateway_execute 随着 { "operationId": "...", "args": { ... } }.

典型的 operationId 家庭:

  • 发现: discover.aws_inventory_basic, discover.aws_inventory_advanced, discover.aws_inventory_summary, discover.aws_inventory_detail, discover.list_bedrock_endpoints, discover.list_sagemaker_endpoints.
  • 突变: mutate.ec2_start_instances, mutate.ec2_stop_instances, mutate.ec2_reboot_instances, mutate.ec2_apply_instance_profile, mutate.ec2_rollback_last_change, mutate.ecs_update_service_desired_count, mutate.asg_set_desired_capacity, mutate.rds_start_instances, mutate.rds_stop_instances, mutate.rds_reboot_instances, mutate.eks_update_nodegroup_scaling.
  • 治理/制度: governance.verify_chain, system.get_server_runtime, system.cli_help.

网关执行示例:

  • 发现摘要: { "operationId": "discover.aws_inventory_summary", "args": { "profiles": ["default"], "regions": ["ap-southeast-1"] } }
  • 发现细节: { "operationId": "discover.aws_inventory_detail", "args": { "profiles": ["default"], "regions": ["ap-southeast-1"], "resourceTypes": ["ec2"], "limit": 50 } }
  • AI/ML读取: { "operationId": "discover.list_bedrock_endpoints", "args": { "profile": "default", "region": "us-east-1", "metricWindowMinutes": 60 } }
  • 突变: { "operationId": "mutate.ec2_start_instances", "args": { "profile": "default", "region": "ap-southeast-1", "instanceIds": ["i-123"], "userConfirmation": "yes" } }

发现操作注意事项:

  • discover.aws_inventory_basic 使用紧凑的输入模式。
  • discover.aws_inventory_advanced 公开完整的库存/运行时选项。
  • discover.aws_inventory_summary 首先是摘要,返回选择器提示。
  • discover.aws_inventory_detail 返回经过筛选/分页的详细记录(resourceTypes, resourceIds, offset, limit).
  • 支持输出布局选项: outputProfile, sections, includeFields, excludeFields, rendererTemplate.
  • 支持路由/控制选项: mode, schemaTier, userConfirmation, profileShard, regionShard, orgRoleName, orgAccountIds, orgIncludeAllAccounts, orgMaxAccounts, enterprisePolicyPath, approvalTicket, changeReason.
  • 支持证据/输出工件选项: topologyOutPath, relationshipsOutPath, governanceLogPath, verifyGovernanceChain, incidentWebhookUrl, incidentWebhookTimeoutMs, incidentWebhookAuthHeader, incidentWebhookToken, incidentOutPath.
  • workingDirectory 对照同种异体根进行检查(cwd、home和可选 MCP_AWS_ALLOWED_WORKDIRS).
  • 结构化JSON日志被发送到stderr;控制冗长 LOG_LEVEL=error|warn|info|debug (默认值: info).

运行时自检:

  • 在网关模式下,使用 gateway_execute 随着 operationId: "system.get_server_runtime".
  • 运行时有效负载包括当前表面、公开的操作/工具、确认策略和响应契约元数据。

示例工具参数:

{
  "profiles": ["default"],
  "regions": ["ap-northeast-2"],
  "profileShard": { "index": 1, "total": 2 },
  "regionShard": { "index": 1, "total": 3 },
  "orgRoleName": "OrganizationAccountAccessRole",
  "orgIncludeAllAccounts": false,
  "orgAccountIds": ["111111111111", "222222222222"],
  "orgMaxAccounts": 25,
  "includeLambda": true,
  "includeIac": true,
  "includeCicd": true,
  "includeBackupDr": true,
  "includeSecurity": true,
  "includeFinops": true,
  "includeApplication": true,
  "includeIncident": true,
  "mode": "observe",
  "schemaTier": "advanced",
  "publicOnly": true,
  "runtimeSnapshot": true,
  "outputProfile": "operator",
  "sections": ["overview", "runtime", "application", "actions"],
  "includeFields": ["resourceType", "resourceId", "state", "ssmOnline", "runtimeSnapshotStatus"],
  "excludeFields": ["runtimeSnapshotOutput"],
  "clientProfile": "codex",
  "rendererTemplate": "compact",
  "userConfirmation": "yes",
  "topologyOutPath": "C:\\tmp\\topology.json",
  "relationshipsOutPath": "C:\\tmp\\relationships.json",
  "governanceLogPath": "C:\\tmp\\governance.jsonl",
  "incidentWebhookUrl": "https://example.com/hooks/oncall",
  "incidentWebhookAuthHeader": "Authorization",
  "incidentWebhookToken": "Bearer ***",
  "incidentOutPath": "C:\\tmp\\incident.json",
  "htmlOutPath": "C:\\tmp\\inventory.html",
  "openHtml": true,
  "manualServerListPath": "C:\\tmp\\servers.csv",
  "pemPaths": ["C:\\keys\\prod.pem"],
  "sshUser": "ec2-user",
  "sshPort": 22,
  "sshConnectTimeoutSec": 8,
  "autoSsoLogin": true,
  "noProgress": true
}

动作代码

共同 ACTION_REQUIRED 代码:

  • SSO_LOGIN_NEEDED
  • AWS_CREDENTIALS_REQUIRED
  • IAM_PERMISSION_REQUIRED
  • AWS_OPERATION_FAILED
  • SSM_ROLE_OR_AGENT_REQUIRED
  • INSTANCE_HAS_PROFILE
  • IAM_PROFILE_ASSOCIATION_FAILED
  • CHANGE_CONFIRMATION_REQUIRED
  • CHANGE_NOT_CONFIRMED
  • APPROVAL_TICKET_REQUIRED
  • APPROVAL_TICKET_INVALID
  • CHANGE_REASON_REQUIRED
  • ENTERPRISE_POLICY_NOT_FOUND
  • ENTERPRISE_POLICY_INVALID
  • ENTERPRISE_POLICY_BLOCKED_ACTION
  • ENTERPRISE_POLICY_DISCOVER_REMEDIATION_BLOCKED
  • ENTERPRISE_POLICY_BLOCKED_PROFILE
  • ENTERPRISE_POLICY_BLOCKED_REGION
  • ENTERPRISE_POLICY_BATCH_TOO_LARGE
  • INCIDENT_WEBHOOK_DISPATCH_FAILED
  • GOVERNANCE_LOG_WRITE_FAILED
  • GOVERNANCE_CHAIN_BROKEN
  • GOVERNANCE_LOG_NOT_FOUND
  • GOVERNANCE_LOG_INVALID_JSON
  • GOVERNANCE_CHAIN_HASH_MISMATCH
  • GOVERNANCE_CHAIN_PREV_HASH_MISMATCH
  • IAC_CLOUDFORMATION_PERMISSION_REQUIRED
  • CICD_CODEPIPELINE_PERMISSION_REQUIRED
  • CICD_CODEBUILD_PERMISSION_REQUIRED
  • CICD_CODEDEPLOY_PERMISSION_REQUIRED
  • BACKUP_PERMISSION_REQUIRED
  • BACKUP_COVERAGE_REVIEW_REQUIRED
  • SECURITY_POSTURE_PERMISSION_REQUIRED
  • SECURITY_CONFIG_PERMISSION_REQUIRED
  • SECURITY_INSPECTOR2_PERMISSION_REQUIRED
  • SECURITY_ACM_PERMISSION_REQUIRED
  • SECURITY_ACM_CERT_EXPIRING
  • FINOPS_COST_EXPLORER_PERMISSION_REQUIRED
  • INCIDENT_ESCALATION_RECOMMENDED
  • WORKING_DIRECTORY_INVALID
  • WORKING_DIRECTORY_NOT_FOUND
  • WORKING_DIRECTORY_NOT_DIRECTORY
  • WORKING_DIRECTORY_NOT_ALLOWED
  • SSM_RUNCOMMAND_PERMISSION_REQUIRED
  • LAMBDA_LIST_PERMISSION_REQUIRED
  • ELBV2_LIST_PERMISSION_REQUIRED
  • ASG_LIST_PERMISSION_REQUIRED
  • RDS_LIST_PERMISSION_REQUIRED
  • ELASTICACHE_LIST_PERMISSION_REQUIRED
  • ROUTE53_LIST_PERMISSION_REQUIRED
  • VPC_LIST_PERMISSION_REQUIRED
  • ECS_LIST_PERMISSION_REQUIRED
  • S3_LIST_PERMISSION_REQUIRED
  • IAM_LIST_PERMISSION_REQUIRED
  • KMS_LIST_PERMISSION_REQUIRED
  • SNS_LIST_PERMISSION_REQUIRED
  • EVENTBRIDGE_LIST_PERMISSION_REQUIRED
  • SQS_LIST_PERMISSION_REQUIRED
  • ACM_LIST_PERMISSION_REQUIRED
  • KINESIS_LIST_PERMISSION_REQUIRED
  • MSK_LIST_PERMISSION_REQUIRED
  • CLOUDWATCH_LIST_PERMISSION_REQUIRED
  • EBS_LIST_PERMISSION_REQUIRED
  • EFS_LIST_PERMISSION_REQUIRED
  • EKS_LIST_PERMISSION_REQUIRED
  • APIGATEWAY_LIST_PERMISSION_REQUIRED
  • APIGATEWAYV2_LIST_PERMISSION_REQUIRED
  • CLOUDFRONT_LIST_PERMISSION_REQUIRED
  • WAF_LIST_PERMISSION_REQUIRED
  • SHIELD_LIST_PERMISSION_REQUIRED
  • STEPFUNCTIONS_LIST_PERMISSION_REQUIRED
  • CLOUDWATCH_LOGS_LIST_PERMISSION_REQUIRED
  • XRAY_LIST_PERMISSION_REQUIRED
  • INSPECTOR2_LIST_PERMISSION_REQUIRED
  • REDSHIFT_LIST_PERMISSION_REQUIRED
  • OPENSEARCH_LIST_PERMISSION_REQUIRED
  • ORGANIZATIONS_LIST_PERMISSION_REQUIRED
  • CONTROLTOWER_LIST_PERMISSION_REQUIRED
  • MANUAL_SERVER_LIST_EMPTY
  • MANUAL_SERVER_HOST_REQUIRED
  • WEB_IDENTITY_CONFIG_REQUIRED
  • WEB_IDENTITY_TOKEN_FILE_NOT_FOUND
  • PEM_KEY_NOT_FOUND
  • BASTION_PEM_KEY_NOT_FOUND
  • PEM_MAPPING_REQUIRED
  • SSH_CLIENT_NOT_FOUND
  • SSH_AUTH_OR_CONNECT_FAILED

ACTION_REQUIRED 元数据包括:

  • severity
  • owner
  • autoFixable

响应合同

  • 运行时合约字段包含在每个工具响应中:

- meta.schemaVersion - meta.compatibility - meta.responseType

  • 查看信封(CLI JSON/MCP解析的有效载荷)包括:

- outputProfile - sections - fields - view.records - rawNormalized (始终包括重新加工稳定性) - schema / schemaVersion

  • 合同架构: schemas/mcp-tool-response.schema.json
  • 兼容性策略: docs/RESPONSE_COMPATIBILITY_POLICY.md

Detailed AWS Auth Setup (SSO vs Access Key)

推荐方法:

  • SSO (IAM Identity Center) 对于人工操作员(推荐)
  • Access Key 仅在SSO不可用时作为本地回退
  • 对于CI/CD自动化,首选IAM Role/OIDC而不是长期用户密钥

为什么首选SSO:

  • 避免在本地计算机上存储长期密钥
  • 使MFA/会话过期行为一致
  • 改进了集中式访问撤销和可审计性

先决条件:

  • AWS CLI v2
  • 在组织帐户中配置IAM身份中心
  • 目标帐户+权限集分配已完成

SSO设置:

aws configure sso --profile default
aws sso login --profile default
aws sts get-caller-identity --profile default

访问密钥设置(回退):

aws configure --profile default
aws sts get-caller-identity --profile default

OIDC/WebIdentity设置(CI/CD或Kubernetes):

export AWS_ROLE_ARN=arn:aws:iam::123456789012:role/oidc-workload-role
export AWS_WEB_IDENTITY_TOKEN_FILE=/var/run/secrets/eks.amazonaws.com/serviceaccount/token
aws sts get-caller-identity

CLI选项等效:

mcp-aws-manager discover \
  --auth-mode web-identity \
  --web-identity-role-arn arn:aws:iam::123456789012:role/oidc-workload-role \
  --web-identity-token-file /var/run/secrets/eks.amazonaws.com/serviceaccount/token

快速检查:

aws configure list-profiles
aws configure list --profile default
aws ec2 describe-regions --profile default

常见错误:

  • Missing the following required SSO configuration values

重新运行 aws configure sso --profile default 并完成所有提示。

  • Unable to locate credentials

SSO会话已过期或缺少凭据。跑 aws sso login --profile default 或重新配置访问密钥。

  • AccessDenied / not authorized

配置文件有效,但IAM权限集/策略不足以用于请求的API。

AWS Access Path Setup (Profile / SSO / OIDC WebIdentity)

身份验证模式:

  • auto (默认):默认情况下使用配置文件,但在提供令牌+角色时可以切换到WebIdentity。
  • profile:始终使用AWS配置文件凭据(fromIni).
  • web-identity:始终使用OIDC/WebIdentity令牌路径(fromTokenFile).

推荐选择:

  • 操作员工作站: profile +SSO登录。
  • CI/CD或Kubernetes工作负载标识: web-identity.
  • 混合环境:保持 auto 并在需要时传递显式字段。

配置文件/SSO路径:

aws configure sso --profile prod-admin
aws sso login --profile prod-admin
mcp-aws-manager discover --profiles prod-admin --regions us-east-1 --auth-mode profile

WebIdentity路径:

export AWS_ROLE_ARN=arn:aws:iam::123456789012:role/oidc-workload-role
export AWS_WEB_IDENTITY_TOKEN_FILE=/var/run/secrets/eks.amazonaws.com/serviceaccount/token
mcp-aws-manager discover --auth-mode web-identity --regions us-east-1

网关/突变和AI读取输入字段:

  • authMode
  • webIdentityRoleArn
  • webIdentityTokenFile
  • webIdentitySessionName (可选)

输入优先级:

  • 显式工具输入/CLI选项
  • MCP_AWS_WEB_IDENTITY_*
  • AWS_ROLE_ARN / AWS_WEB_IDENTITY_TOKEN_FILE

常见的与身份验证相关的操作要求:

  • WEB_IDENTITY_CONFIG_REQUIRED
  • WEB_IDENTITY_TOKEN_FILE_NOT_FOUND
  • AWS_CREDENTIALS_REQUIRED

Server Internal Access Path Setup (SSM / PEM SSH / ProxyJump / Bastion)

运行时快照路由选择:

  • AWS管理的EC2(manualInput=false):SSM运行命令路径。
  • 手动服务器列表(manualInput=true):SSH路径。
  • SSH路径使用:

- ssh-pem (直接键) - ssh-proxyjump (--ssh-proxy-jump) - ssh-bastion (--ssh-bastion-*,内部通过ProxyCommand)

手册列表+直接PEM示例:

mcp-aws-manager discover \
  --manual-server-list ./servers.json \
  --pem-paths ~/.ssh/target.pem \
  --runtime-snapshot

手动列表+ProxyJump示例:

mcp-aws-manager discover \
  --manual-server-list ./servers.json \
  --pem-paths ~/.ssh/target.pem \
  --ssh-proxy-jump ec2-user@bastion.example.com \
  --runtime-snapshot

手动列表+Bastion键拆分示例:

mcp-aws-manager discover \
  --manual-server-list ./servers.json \
  --pem-paths ~/.ssh/target.pem \
  --ssh-bastion-host bastion.example.com \
  --ssh-bastion-user ec2-user \
  --ssh-bastion-port 22 \
  --ssh-bastion-pem-path ~/.ssh/bastion.pem \
  --runtime-snapshot

手动服务器JSON字段(每个主机可选):

  • host/publicIp/privateIp/publicDns
  • sshUser, sshPort, pemPath
  • proxyJumpsshProxyJump
  • bastionHost, bastionUser, bastionPort, bastionPemPath

通用访问路径ACTION_REQUIRED:

  • MANUAL_SERVER_HOST_REQUIRED
  • PEM_MAPPING_REQUIRED
  • BASTION_PEM_KEY_NOT_FOUND
  • SSH_AUTH_OR_CONNECT_FAILED

Integration Connector Management (No-Code)

状态文件默认值:

  • ~/.mcp-aws-manager/integrations.json

列表/显示:

mcp-aws-manager integration list
mcp-aws-manager integration show

配置+启用:

mcp-aws-manager integration configure pagerduty --set routingKey=XXXX --enable

保单包:

mcp-aws-manager integration policy show
mcp-aws-manager integration policy set strict_change

医生:

mcp-aws-manager integration doctor
mcp-aws-manager integration doctor --check-live --timeout-ms 8000

发现时间覆盖:

  • `--integration-config

`

  • --integration-timeout-ms
  • --policy-pack
  • --policy-override

Discover Option Reference

  • --profiles
  • --regions
  • --profile-shard
  • --region-shard
  • --org-role-name
  • --org-account-ids
  • --org-include-all-accounts
  • --org-max-accounts
  • --instance-ids
  • --include-lambda
  • --include-ec2 / --no-ec2
  • --include-alb / --no-include-alb
  • --include-asg / --no-include-asg
  • --include-rds / --no-include-rds
  • --include-elasticache / --no-include-elasticache
  • --include-route53 / --no-include-route53
  • --include-vpc / --no-include-vpc
  • --include-ecs / --no-include-ecs
  • --include-s3 / --no-include-s3
  • --include-iam / --no-include-iam
  • --include-kms / --no-include-kms
  • --include-cloudwatch / --no-include-cloudwatch
  • --include-cloudtrail / --no-include-cloudtrail
  • --include-config / --no-include-config
  • --include-secrets / --no-include-secrets
  • --include-parameter-store / --no-include-parameter-store
  • --include-ecr / --no-include-ecr
  • --include-dynamodb / --no-include-dynamodb
  • --include-sns / --no-include-sns
  • --include-eventbridge / --no-include-eventbridge
  • --include-sqs / --no-include-sqs
  • --include-acm / --no-include-acm
  • --include-kinesis / --no-include-kinesis
  • --include-msk / --no-include-msk
  • --include-budgets / --no-include-budgets
  • --include-cost-anomaly / --no-include-cost-anomaly
  • --include-ebs / --no-include-ebs
  • --include-efs / --no-include-efs
  • --include-eks / --no-include-eks
  • --include-apigateway / --no-include-apigateway
  • --include-apigatewayv2 / --no-include-apigatewayv2
  • --include-cloudfront / --no-include-cloudfront
  • --include-waf / --no-include-waf
  • --include-shield / --no-include-shield
  • --include-step-functions / --no-include-step-functions
  • --include-cloudwatch-logs / --no-include-cloudwatch-logs
  • --include-xray / --no-include-xray
  • --include-inspector2 / --no-include-inspector2
  • --include-redshift / --no-include-redshift
  • --include-opensearch / --no-include-opensearch
  • --include-organizations / --no-include-organizations
  • --include-controltower / --no-include-controltower
  • --include-iac / --no-include-iac
  • --include-cicd / --no-include-cicd
  • --include-backup-dr / --no-include-backup-dr
  • --include-security / --no-include-security
  • --include-finops / --no-include-finops
  • --include-application / --no-include-application
  • --include-incident / --no-include-incident
  • --incident-force-escalate
  • --mode
  • --schema-tier
  • --auth-mode
  • --web-identity-role-arn
  • `--web-identity-token-file

`

  • --web-identity-session-name
  • --user-confirmation
  • `--enterprise-policy

`

  • --approval-ticket
  • --change-reason
  • --policy-pack
  • --policy-override
  • `--integration-config

`

  • --integration-timeout-ms
  • --public-only
  • --managed-only
  • --auto-remediate-ssm
  • --ssm-instance-profile-name / --ssm-instance-profile-arn
  • --allow-replace-profile
  • --runtime-snapshot / --no-runtime-snapshot
  • --snapshot-profile
  • --output-profile
  • --sections
  • --include-fields
  • --exclude-fields
  • --client-profile
  • --renderer-template
  • --snapshot-timeout
  • --snapshot-concurrency
  • --snapshot-max-kb
  • `--manual-server-list

` (JSON/CSV)

  • --pem-paths
  • --ssh-user
  • `--ssh-port

`

  • --ssh-connect-timeout
  • --ssh-proxy-jump
  • --ssh-bastion-host
  • --ssh-bastion-user
  • `--ssh-bastion-port

`

  • `--ssh-bastion-pem-path

`

  • `--html-out

(默认:自动路径、工作区/主页 aws-inventory.html`)

  • `--topology-out

(默认:自动路径、工作区/主页 aws-topology.json`)

  • `--relationships-out

(默认:自动路径、工作区/主页 aws-relationships.json`)

  • `--governance-log

(默认:自动路径、工作区/主页 mcp-aws-governance-log.jsonl`)

  • --verify-governance-chain / --no-verify-governance-chain
  • --incident-webhook-url
  • --incident-webhook-timeout-ms
  • --incident-webhook-auth-header
  • --incident-webhook-token
  • `--incident-out

`

  • --open-html (打开;默认打开)
  • --no-open-html (禁用自动打开)
  • --auto-sso-login / --no-auto-sso-login
  • --format
  • `--out

`

治理验证命令:

mcp-aws-manager governance verify --governance-log ./mcp-aws-governance-log.jsonl --strict

客户烟雾自动化

运行跨客户端烟雾检查:

npm run smoke:clients
npm run smoke:clients:strict
node scripts/smoke-clients.js --clients codex,claude --json-out ./smoke-report.json
  • 默认模式报告状态和退出 0.
  • --strict 当任何选定的客户端不健康时,退出非零。

AWS E2E场景自动化

运行真实帐户场景检查(权限/区域/恢复路径):

npm run e2e:aws -- --profile default --region us-east-1 --out-dir ./.e2e-aws
npm run e2e:aws:strict -- --profile default --region us-east-1

当前场景包括:

  • 基线观测合同(schema + rawNormalized)
  • 无效区域处理
  • 可变确认门(missing / yes)
  • 事件升级工件生成
  • 企业策略审批票执行
  • 治理链验证(governance verify --strict)

E2E跑步者验证:

  • 基线观察流(JSON合约+ rawNormalized)
  • 无效的区域处理路径
  • 可变发现确认门(CHANGE_CONFIRMATION_REQUIRED)
  • 确认批准路径(--user-confirmation yes)
  • 强制事件升级有效载荷伪影(INCIDENT_ESCALATION_RECOMMENDED)

Permission Checklist

最小权限取决于启用的功能。

  • 核心库存: ec2:DescribeRegions, ec2:DescribeInstances
  • λ: lambda:ListFunctions
  • ALB/目标群体: elasticloadbalancing:DescribeLoadBalancers, elasticloadbalancing:DescribeTargetGroups
  • ASG: autoscaling:DescribeAutoScalingGroups
  • RDS: rds:DescribeDBInstances
  • ElastiCache: elasticache:DescribeCacheClusters
  • 路线53: route53:ListHostedZones, route53:ListResourceRecordSets
  • VPC/子网/安全组: ec2:DescribeVpcs, ec2:DescribeSubnets, ec2:DescribeSecurityGroups
  • ECS: ecs:ListClusters, ecs:DescribeClusters, ecs:ListServices, ecs:DescribeServices
  • S3: s3:ListAllMyBuckets, s3:GetBucketLocation
  • 国际机械师协会: iam:ListRoles
  • 公里: kms:ListKeys, kms:DescribeKey
  • 国际计算机学会 acm:ListCertificates, acm:DescribeCertificate
  • 动脉炎: kinesis:ListStreams, kinesis:DescribeStreamSummary
  • MSK: kafka:ListClustersV2
  • 云观察: cloudwatch:DescribeAlarms
  • EBS: ec2:DescribeVolumes
  • EFS: elasticfilesystem:DescribeFileSystems
  • EKS : eks:ListClusters, eks:DescribeCluster
  • API网关: apigateway:GET
  • CloudFront: cloudfront:ListDistributions
  • WAFv2: wafv2:ListWebACLs
  • 防护罩: shield:ListProtections
  • 步骤功能: states:ListStateMachines
  • CloudWatch日志: logs:DescribeLogGroups
  • X射线: xray:GetGroups
  • 检查员2: inspector2:ListFindings
  • 红移: redshift:DescribeClusters
  • OpenSearch: es:ListDomainNames, es:DescribeDomain
  • 组织机构: organizations:ListAccounts
  • 控制塔: controltower:ListLandingZones
  • CI/CD分析: codepipeline:ListPipelines, codepipeline:ListPipelineExecutions, codebuild:ListProjects, codebuild:ListBuildsForProject, codebuild:BatchGetBuilds, codedeploy:ListApplications, codedeploy:ListDeploymentGroups, codedeploy:ListDeployments, codedeploy:BatchGetDeployments
  • 安全分析扩展: config:DescribeConfigRules, config:DescribeComplianceByConfigRule, acm:ListCertificates, acm:DescribeCertificate
  • FinOps分析扩展: ce:GetSavingsPlansUtilization, ce:GetReservationCoverage
  • 运行时快照: ssm:SendCommand, ssm:GetCommandInvocation, ssm:DescribeInstanceInformation
  • 自动修复: ec2:AssociateIamInstanceProfile,可选 ec2:ReplaceIamInstanceProfileAssociation, iam:PassRole
  • 修改工具扩展名:

- ECS: ecs:DescribeServices, ecs:UpdateService - ASG: autoscaling:SetDesiredCapacity - RDS: rds:StartDBInstance, rds:StopDBInstance, rds:RebootDBInstance - EKS : eks:DescribeNodegroup, eks:UpdateNodegroupConfig

  • 组织扇出(可选): organizations:ListAccounts, sts:AssumeRole (需要目标帐户角色信任)

手动回退模式:

  • 库存使用用户提供的服务器列表文件(不需要AWS API)
  • 运行时快照支持直接PEM SSH和ProxyJump/Bastion路由(--ssh-proxy-jump, --ssh-bastion-*)

相关文档

文档状态:

  • Canonical(与实现保持同步): README.md, docs/RESPONSE_COMPATIBILITY_POLICY.md
  • 参考(细节/定位): docs/IMPLEMENTATION_INTEGRATIONS.md, docs/MCP_DIFFERENTIATION.md, docs/MCP_DIFFERENTIATION_KO.md, workflow/AGENT_WORKING_CONTEXT_KO.md, docs/RECORDS_FIELD_REFERENCE_KO.md
  • README_KO.md:韩语概述和快速入门
  • docs/IMPLEMENTATION_INTEGRATIONS.md:API/CLI集成资源清册
  • docs/MCP_DIFFERENTIATION.md:与现有AWS MCP服务器的区别
  • docs/MCP_DIFFERENTIATION_KO.md:韩国差异化指南和选择标准
  • workflow/AGENT_WORKING_CONTEXT_KO.md:以代理为中心的实现不变量、网关循环和操作目录快速参考
  • docs/RECORDS_FIELD_REFERENCE_KO.md:满 records[] 字段参考(292个字段)
  • docs/RESPONSE_COMPATIBILITY_POLICY.md:响应架构/版本兼容性规则
  • schemas/mcp-tool-response.schema.json:规范工具响应JSON模式

目录标签

目录标签

JavaScriptClaude云端部署AWS管理本地部署CLI工具多服务支持SSM集成操作自动化

支持客户端

ClaudeCursor

接入字段

传输方式(transport,传输协议)

未说明

鉴权方式(authType,认证方式)

token

工具数量(toolCount,工具数)

3

资源数量(resourceCount,资源数)

0

提示词数量(promptCount,提示词数)

0

权限和风险

未说明token部署方式未说明

接入前请确认传输方式、认证方式和部署位置,并根据实际工具能力限制访问范围。

安装前确认

不要直接授予不必要的文件、网络或账号权限;先核对安装命令和配置内容。

仍需确认:installCommand

来源信息

继续浏览同类 MCP