mcp aws经理
AWS操作CLI+MCP stdio服务器(SSM优先)。
此包使用规范化的输出模式编排AWS操作(库存/运行时/补救) ACTION_REQUIRED 指导。它不是一个简单的AWS CLI包装器。
Agent First快速入门
将此用作代理环境的默认流:
npm install -g mcp-aws-manager
mcp-aws-manager --version
mcp-aws-manager setup --force
mcp-aws-manager doctor代理提示示例:
用自然语言提问,如下所示;代理应根据需要运行获取/分析步骤。
Give me a fresh full AWS server status summary.然后尝试以下请求:
Compare current AWS server status with the previous check and show only what changed.Summarize AWS server status with required actions and high-impact warnings in priority order.它的作用
- 多服务库存:EC2、Lambda、ALB/NLB、ASG、RDS、ElastiCache、Route53、VPC/Subnet/SecurityGroup、ECS、S3、IAM、KMS、CloudWatch、CloudTrail、Config、Secrets Manager、ECR、DynamoDB、SNS、EventBridge、SQS、ACM、Kinesis、MSK、Budgets、Cost Anomaly、EBS、EFS、EKS、API Gateway(REST/v2)、CloudFront、WAF、Shield、Step Functions、CloudWatch Logs、X-Ray、Inspector2、Redshift、OpenSearch、Organizations、ControlTower
- SSM状态可见性:管理/在线状态
- 领域分析管道:IaC漂移、CI/CD信号、备份/DR态势、安全态势、FinOps成本信号、应用层健康状况、事件严重性建议
- 可选的运行时快照和SSM修复
- 可变表面扩展:EC2+ECS+ASG+RDS+EKS控制的更改工具
- 策略感知路由:选择模式/表面/模式层以实现更安全的默认值
- 多帐户扩展控制:组织假设角色扇出+配置文件/区域分片
- 手动回退模式:JSON/CSV服务器列表+PEM SSH/ProxyJump/Bastion运行时快照(当AWS身份验证不可用时)
- 人在循环重试流通过
ACTION_REQUIRED - 仅限内部执行路径(AWS SDK+AWS CLI)
- 表示层控件:输出配置文件预设、剖面/场投影和客户端感知默认布局
- 持久治理日志+拓扑/关系JSON工件
- 可选的事件升级webhook调度,带有本地事件负载工件
何时使用此项目
使用 mcp-aws-manager 当您需要一个操作工作流程MCP,而不仅仅是通用的AWS API访问。
- 选择此项目进行确定性清单/运行时/补救循环。
- 选择此项目时
ACTION_REQUIRED需要引导和操作员伪影。 - 仅对于广泛的特定AWS API控制,一个伞式API类型的AWS MCP就足够了。
详细比较和产品边界见:
docs/MCP_DIFFERENTIATION.md
快速比较
| 选择点 | mcp-aws-manager | 伞式API型AWS MCP |
|---|---|---|
| 主要目标 | 确定性操作工作流(库存/运行时/修复) | 广泛的特定API/工具访问 |
| 工具曝光模型 | 固定网关3-Tool(capabilities_summary, capabilities_detail, gateway_execute) | 许多直接服务/行动工具 |
| 更改安全 | 用于更改路径的内置确认/策略门 | 取决于每个工具/服务器策略 |
| 响应合同 | 标准化(ok/summary/records/requiredActions/meta) | 因实施而异 |
| 最佳匹配 | 具有操作员指导的可再现操作循环 | 探索性或广泛的API探测 |
有关完整的原理和边界,请参阅 docs/MCP_DIFFERENTIATION.md 和 docs/MCP_DIFFERENTIATION_KO.md.
API覆盖率快照
- AWS API总数:没有固定的官方单一数字,但各服务的行动面约为数万(并不断扩大)。
- 当前的实施范围并非“所有AWS API”。
- 使用的AWS SDK服务客户端:
49 - 使用的AWS SDK操作调用:
95 - 使用的AWS CLI命令:
1(`aws sso login --profile
`)
- 注:企业控制(策略门/回滚/治理验证)仍然存在,而库存覆盖范围已经扩大。
当前95个AWS SDK操作:
- STS:
GetCallerIdentity - EC2:
DescribeRegions,DescribeInstances,DescribeVpcs,DescribeSubnets,DescribeSecurityGroups,StartInstances,StopInstances,RebootInstances,DescribeIamInstanceProfileAssociations,AssociateIamInstanceProfile,ReplaceIamInstanceProfileAssociation - SSM:
DescribeInstanceInformation,DescribeParameters,SendCommand,GetCommandInvocation - λ:
ListFunctions - ELBv2:
DescribeLoadBalancers,DescribeTargetGroups - 自动缩放:
DescribeAutoScalingGroups,SetDesiredCapacity - RDS:
DescribeDBInstances,StartDBInstance,StopDBInstance,RebootDBInstance - ElastiCache:
DescribeCacheClusters - 路线53:
ListHostedZones,ListResourceRecordSets - ECS:
ListClusters,DescribeClusters,ListServices,DescribeServices,UpdateService - S3:
ListBuckets,GetBucketLocation - 国际机械师协会:
ListRoles - 公里:
ListKeys,DescribeKey - 云观察:
DescribeAlarms - CloudTrail:
DescribeTrails - AWS配置:
DescribeConfigurationRecorders,DescribeConfigurationRecorderStatus,DescribeDeliveryChannels,DescribeConfigRules,DescribeComplianceByConfigRule - 保密经理:
ListSecrets - ECR:
DescribeRepositories - DynamoDB:
ListTables,DescribeTable - SNS:
ListTopics - EventBridge:
ListEventBuses - SQS:
ListQueues,GetQueueAttributes - 国际计算机学会
ListCertificates,DescribeCertificate - 动脉炎:
ListStreams,DescribeStreamSummary - MSK:
ListClustersV2 - AWS预算:
DescribeBudgets - EBS:
DescribeVolumes - EFS:
DescribeFileSystems - EKS :
ListClusters,DescribeCluster,DescribeNodegroup,UpdateNodegroupConfig - API网关(REST):
GetRestApis - API网关v2:
GetApis - CloudFront:
ListDistributions - WAFv2:
ListWebACLs - 防护罩:
ListProtections - 步骤功能:
ListStateMachines - CloudWatch日志:
DescribeLogGroups - X射线:
GetGroups - 检查员2:
ListFindings - 红移:
DescribeClusters - OpenSearch:
ListDomainNames,DescribeDomain - 组织机构:
ListAccounts - 控制塔:
ListLandingZones - 云层形成:
DescribeStacks - CodePipeline:
ListPipelines,ListPipelineExecutions - 代码构建:
ListProjects,ListBuildsForProject,BatchGetBuilds - 代码部署:
ListApplications,ListDeploymentGroups,ListDeployments,BatchGetDeployments - AWS备份:
ListBackupPlans,ListProtectedResources - SecurityHub:
GetFindings - GuardDuty:
ListDetectors,ListFindings - 成本探索者:
GetCostAndUsage,GetAnomalies,GetSavingsPlansUtilization,GetReservationCoverage
二进制文件
- CLI:
mcp-aws-manager - MCP stdio服务器(单条目;默认值:
--surface all):mcp-aws-manager-mcp
mcp-aws-manager-mcp 使用具有可选表面范围的网关路由:
mcp-aws-manager-mcp --surface all
mcp-aws-manager-mcp --surface readonly
mcp-aws-manager-mcp --surface mutate代理协助首次设置
将此流用于新用户。
- 安装并引导:
npm.cmd install -g mcp-aws-manager@latest
mcp-aws-managerBootstrap为检测到的客户端注册默认的单MCP服务器:
mcp-aws-manager(单条目,--surface all)- 运行时命令会自动解析以确保主机稳定性。
- Windows优先级:绝对
mcp-aws-manager-mcp.cmd - macOS/Linux优先级:绝对
mcp-aws-manager-mcp二进制 - 退路:
node /bin/mcp-aws-manager-mcp.js - 最后回退(临时npx上下文):固定
npx -y -p mcp-aws-manager@ mcp-aws-manager-mcp
可选的显式注册:
mcp-aws-manager setup
mcp-aws-manager setup --clients cursor
mcp-aws-manager setup --clients codex
mcp-aws-manager setup --clients claude默认行为(setup/bootstrap 没有 --clients)自动检测已安装的客户端,并仅注册检测到的CLI。
兼容性说明:
- 光标通过MCP配置文件同步注册(
~/.cursor/mcp.json和平台用户配置路径),以避免编辑器选项卡的副作用cursor mcp .... - 即使在以下情况下,Claude也可以通过配置同步进行注册
claude当Claude配置路径(例如macOS)不在PATH中时~/Library/Application Support/Claude/claude_desktop_config.json,Linux~/.config/Claude/claude_desktop_config.json,或~/.claude/claude_desktop_config.json)或者检测到安装足迹。你可以用CLAUDE_MCP_CONFIG_PATH. - 如果另一个编辑器风格的客户端没有公开稳定的CLI
mcp子命令,setup/doctor回报manual configuration required而不是运行不安全的子命令。
- 健康检查:
mcp-aws-manager doctor默认行为(doctor 没有 --clients)自动检测已安装的客户端并跳过未安装的CLI。
- 配置AWS身份验证(建议使用SSO):
aws configure sso --profile default
aws sso login --profile default- 验证身份:
aws sts get-caller-identity --profile default- 运行发现:
mcp-aws-manager discover --profiles default --no-progress如果被阻止,请跟随一个 ACTION_REQUIRED 项,然后重试相同的命令。
如果AWS身份验证不可用,请使用手动回退:
mcp-aws-manager discover --manual-server-list ./servers.csv --pem-paths C:\keys\prod.pem --no-progress默认情况下生成GUI报告(自动路径:workspace/home aws-inventory.html):
mcp-aws-manager discover --profiles default --no-progressGUI包括:
- 摘要卡(记录/服务/配置文件/地区/EC2/SSM/公共IP/问题)
- 选项卡视图(
Report,Diagrams,Evidence,Inventory) - 详细降价报告(
report.md)按资源类型划分 - 拓扑图(配置文件->区域->类型->资源)
- 关系图(DNS/TargetGroup ALB/ASG启发式链接)
- 具有每个资源详细信息和聚焦关系图的聚焦服务器/资源选择器(
focus.svg) - 证据查看与导出(
evidence.json) - 图表导出(
diagram.drawio,topology.svg,relationship.svg) - 下载的工件在文件名中包含生成时间戳(例如
report-20260304-113000.md)
自定义路径/打开行为:
mcp-aws-manager discover --profiles default --html-out ./inventory.html --open-html --no-progress默认情况下,启用HTML打开。使用 --no-open-html 禁用。
手动MCP客户端配置(回退)
仅在自动时使用此选项 bootstrap/setup 注册不可用。
- 本地存储库(开发):
{
"mcpServers": {
"mcp-aws-manager": {
"command": "node",
"args": [
"/bin/mcp-aws-manager-mcp.js",
"--surface",
"all"
],
"cwd": ""
}
}
}- 全局npm安装(手动回退):
Windows(推荐):
{
"mcpServers": {
"mcp-aws-manager": {
"command": "C:\\Users\\\\AppData\\Roaming\\npm\\mcp-aws-manager-mcp.cmd",
"args": ["--surface", "all"]
}
}
}macOS/Linux:
{
"mcpServers": {
"mcp-aws-manager": {
"command": "mcp-aws-manager-mcp",
"args": ["--surface", "all"]
}
}
}npx(无需全局安装):
{
"mcpServers": {
"mcp-aws-manager": {
"command": "npx",
"args": ["-y", "-p", "mcp-aws-manager", "mcp-aws-manager-mcp", "--surface", "all"]
}
}
}需要用户确认
这些通常是唯一的手动步骤(代理指导):
- SSO浏览器登录和MFA确认
- 组织帐户中的IAM权限审批
- 对于EC2运行时可见性:附加
AmazonSSMManagedInstanceCore并保持SSM代理/网络健康
代理重试循环(推荐):
- 执行工具调用。
- 如果
requiresUserAction=false总结并完成。 - 如果
requiresUserAction=true,出示一张requiredActions[]项目并要求用户完成。 - 当用户确认完成时,使用重试
guidance.retryTool+guidance.retryArgs. - 重复直到
requiresUserAction=false.
MCP工具使用
运行单入口MCP服务器(默认: --surface all):
mcp-aws-manager-mcp选择曝光模式:
mcp-aws-manager-mcp --surface all|readonly|mutate(仅网关)
网关模型(tools/list)仅公开了3个工具:
capabilities_summarycapabilities_detailgateway_execute
网关呼叫流:
- 呼叫
capabilities_summary接收操作类别和operationId列表。 - 呼叫
capabilities_detail一起operationId检查执行合同。 - 呼叫
gateway_execute随着{ "operationId": "...", "args": { ... } }.
典型的 operationId 家庭:
- 发现:
discover.aws_inventory_basic,discover.aws_inventory_advanced,discover.aws_inventory_summary,discover.aws_inventory_detail,discover.list_bedrock_endpoints,discover.list_sagemaker_endpoints. - 突变:
mutate.ec2_start_instances,mutate.ec2_stop_instances,mutate.ec2_reboot_instances,mutate.ec2_apply_instance_profile,mutate.ec2_rollback_last_change,mutate.ecs_update_service_desired_count,mutate.asg_set_desired_capacity,mutate.rds_start_instances,mutate.rds_stop_instances,mutate.rds_reboot_instances,mutate.eks_update_nodegroup_scaling. - 治理/制度:
governance.verify_chain,system.get_server_runtime,system.cli_help.
网关执行示例:
- 发现摘要:
{ "operationId": "discover.aws_inventory_summary", "args": { "profiles": ["default"], "regions": ["ap-southeast-1"] } } - 发现细节:
{ "operationId": "discover.aws_inventory_detail", "args": { "profiles": ["default"], "regions": ["ap-southeast-1"], "resourceTypes": ["ec2"], "limit": 50 } } - AI/ML读取:
{ "operationId": "discover.list_bedrock_endpoints", "args": { "profile": "default", "region": "us-east-1", "metricWindowMinutes": 60 } } - 突变:
{ "operationId": "mutate.ec2_start_instances", "args": { "profile": "default", "region": "ap-southeast-1", "instanceIds": ["i-123"], "userConfirmation": "yes" } }
发现操作注意事项:
discover.aws_inventory_basic使用紧凑的输入模式。discover.aws_inventory_advanced公开完整的库存/运行时选项。discover.aws_inventory_summary首先是摘要,返回选择器提示。discover.aws_inventory_detail返回经过筛选/分页的详细记录(resourceTypes,resourceIds,offset,limit).- 支持输出布局选项:
outputProfile,sections,includeFields,excludeFields,rendererTemplate. - 支持路由/控制选项:
mode,schemaTier,userConfirmation,profileShard,regionShard,orgRoleName,orgAccountIds,orgIncludeAllAccounts,orgMaxAccounts,enterprisePolicyPath,approvalTicket,changeReason. - 支持证据/输出工件选项:
topologyOutPath,relationshipsOutPath,governanceLogPath,verifyGovernanceChain,incidentWebhookUrl,incidentWebhookTimeoutMs,incidentWebhookAuthHeader,incidentWebhookToken,incidentOutPath. workingDirectory对照同种异体根进行检查(cwd、home和可选MCP_AWS_ALLOWED_WORKDIRS).- 结构化JSON日志被发送到stderr;控制冗长
LOG_LEVEL=error|warn|info|debug(默认值:info).
运行时自检:
- 在网关模式下,使用
gateway_execute随着operationId: "system.get_server_runtime". - 运行时有效负载包括当前表面、公开的操作/工具、确认策略和响应契约元数据。
示例工具参数:
{
"profiles": ["default"],
"regions": ["ap-northeast-2"],
"profileShard": { "index": 1, "total": 2 },
"regionShard": { "index": 1, "total": 3 },
"orgRoleName": "OrganizationAccountAccessRole",
"orgIncludeAllAccounts": false,
"orgAccountIds": ["111111111111", "222222222222"],
"orgMaxAccounts": 25,
"includeLambda": true,
"includeIac": true,
"includeCicd": true,
"includeBackupDr": true,
"includeSecurity": true,
"includeFinops": true,
"includeApplication": true,
"includeIncident": true,
"mode": "observe",
"schemaTier": "advanced",
"publicOnly": true,
"runtimeSnapshot": true,
"outputProfile": "operator",
"sections": ["overview", "runtime", "application", "actions"],
"includeFields": ["resourceType", "resourceId", "state", "ssmOnline", "runtimeSnapshotStatus"],
"excludeFields": ["runtimeSnapshotOutput"],
"clientProfile": "codex",
"rendererTemplate": "compact",
"userConfirmation": "yes",
"topologyOutPath": "C:\\tmp\\topology.json",
"relationshipsOutPath": "C:\\tmp\\relationships.json",
"governanceLogPath": "C:\\tmp\\governance.jsonl",
"incidentWebhookUrl": "https://example.com/hooks/oncall",
"incidentWebhookAuthHeader": "Authorization",
"incidentWebhookToken": "Bearer ***",
"incidentOutPath": "C:\\tmp\\incident.json",
"htmlOutPath": "C:\\tmp\\inventory.html",
"openHtml": true,
"manualServerListPath": "C:\\tmp\\servers.csv",
"pemPaths": ["C:\\keys\\prod.pem"],
"sshUser": "ec2-user",
"sshPort": 22,
"sshConnectTimeoutSec": 8,
"autoSsoLogin": true,
"noProgress": true
}动作代码
共同 ACTION_REQUIRED 代码:
SSO_LOGIN_NEEDEDAWS_CREDENTIALS_REQUIREDIAM_PERMISSION_REQUIREDAWS_OPERATION_FAILEDSSM_ROLE_OR_AGENT_REQUIREDINSTANCE_HAS_PROFILEIAM_PROFILE_ASSOCIATION_FAILEDCHANGE_CONFIRMATION_REQUIREDCHANGE_NOT_CONFIRMEDAPPROVAL_TICKET_REQUIREDAPPROVAL_TICKET_INVALIDCHANGE_REASON_REQUIREDENTERPRISE_POLICY_NOT_FOUNDENTERPRISE_POLICY_INVALIDENTERPRISE_POLICY_BLOCKED_ACTIONENTERPRISE_POLICY_DISCOVER_REMEDIATION_BLOCKEDENTERPRISE_POLICY_BLOCKED_PROFILEENTERPRISE_POLICY_BLOCKED_REGIONENTERPRISE_POLICY_BATCH_TOO_LARGEINCIDENT_WEBHOOK_DISPATCH_FAILEDGOVERNANCE_LOG_WRITE_FAILEDGOVERNANCE_CHAIN_BROKENGOVERNANCE_LOG_NOT_FOUNDGOVERNANCE_LOG_INVALID_JSONGOVERNANCE_CHAIN_HASH_MISMATCHGOVERNANCE_CHAIN_PREV_HASH_MISMATCHIAC_CLOUDFORMATION_PERMISSION_REQUIREDCICD_CODEPIPELINE_PERMISSION_REQUIREDCICD_CODEBUILD_PERMISSION_REQUIREDCICD_CODEDEPLOY_PERMISSION_REQUIREDBACKUP_PERMISSION_REQUIREDBACKUP_COVERAGE_REVIEW_REQUIREDSECURITY_POSTURE_PERMISSION_REQUIREDSECURITY_CONFIG_PERMISSION_REQUIREDSECURITY_INSPECTOR2_PERMISSION_REQUIREDSECURITY_ACM_PERMISSION_REQUIREDSECURITY_ACM_CERT_EXPIRINGFINOPS_COST_EXPLORER_PERMISSION_REQUIREDINCIDENT_ESCALATION_RECOMMENDEDWORKING_DIRECTORY_INVALIDWORKING_DIRECTORY_NOT_FOUNDWORKING_DIRECTORY_NOT_DIRECTORYWORKING_DIRECTORY_NOT_ALLOWEDSSM_RUNCOMMAND_PERMISSION_REQUIREDLAMBDA_LIST_PERMISSION_REQUIREDELBV2_LIST_PERMISSION_REQUIREDASG_LIST_PERMISSION_REQUIREDRDS_LIST_PERMISSION_REQUIREDELASTICACHE_LIST_PERMISSION_REQUIREDROUTE53_LIST_PERMISSION_REQUIREDVPC_LIST_PERMISSION_REQUIREDECS_LIST_PERMISSION_REQUIREDS3_LIST_PERMISSION_REQUIREDIAM_LIST_PERMISSION_REQUIREDKMS_LIST_PERMISSION_REQUIREDSNS_LIST_PERMISSION_REQUIREDEVENTBRIDGE_LIST_PERMISSION_REQUIREDSQS_LIST_PERMISSION_REQUIREDACM_LIST_PERMISSION_REQUIREDKINESIS_LIST_PERMISSION_REQUIREDMSK_LIST_PERMISSION_REQUIREDCLOUDWATCH_LIST_PERMISSION_REQUIREDEBS_LIST_PERMISSION_REQUIREDEFS_LIST_PERMISSION_REQUIREDEKS_LIST_PERMISSION_REQUIREDAPIGATEWAY_LIST_PERMISSION_REQUIREDAPIGATEWAYV2_LIST_PERMISSION_REQUIREDCLOUDFRONT_LIST_PERMISSION_REQUIREDWAF_LIST_PERMISSION_REQUIREDSHIELD_LIST_PERMISSION_REQUIREDSTEPFUNCTIONS_LIST_PERMISSION_REQUIREDCLOUDWATCH_LOGS_LIST_PERMISSION_REQUIREDXRAY_LIST_PERMISSION_REQUIREDINSPECTOR2_LIST_PERMISSION_REQUIREDREDSHIFT_LIST_PERMISSION_REQUIREDOPENSEARCH_LIST_PERMISSION_REQUIREDORGANIZATIONS_LIST_PERMISSION_REQUIREDCONTROLTOWER_LIST_PERMISSION_REQUIREDMANUAL_SERVER_LIST_EMPTYMANUAL_SERVER_HOST_REQUIREDWEB_IDENTITY_CONFIG_REQUIREDWEB_IDENTITY_TOKEN_FILE_NOT_FOUNDPEM_KEY_NOT_FOUNDBASTION_PEM_KEY_NOT_FOUNDPEM_MAPPING_REQUIREDSSH_CLIENT_NOT_FOUNDSSH_AUTH_OR_CONNECT_FAILED
ACTION_REQUIRED 元数据包括:
severityownerautoFixable
响应合同
- 运行时合约字段包含在每个工具响应中:
- meta.schemaVersion - meta.compatibility - meta.responseType
- 查看信封(CLI JSON/MCP解析的有效载荷)包括:
- outputProfile - sections - fields - view.records - rawNormalized (始终包括重新加工稳定性) - schema / schemaVersion
- 合同架构:
schemas/mcp-tool-response.schema.json - 兼容性策略:
docs/RESPONSE_COMPATIBILITY_POLICY.md
Detailed AWS Auth Setup (SSO vs Access Key)
推荐方法:
SSO (IAM Identity Center)对于人工操作员(推荐)Access Key仅在SSO不可用时作为本地回退- 对于CI/CD自动化,首选IAM Role/OIDC而不是长期用户密钥
为什么首选SSO:
- 避免在本地计算机上存储长期密钥
- 使MFA/会话过期行为一致
- 改进了集中式访问撤销和可审计性
先决条件:
- AWS CLI v2
- 在组织帐户中配置IAM身份中心
- 目标帐户+权限集分配已完成
SSO设置:
aws configure sso --profile default
aws sso login --profile default
aws sts get-caller-identity --profile default访问密钥设置(回退):
aws configure --profile default
aws sts get-caller-identity --profile defaultOIDC/WebIdentity设置(CI/CD或Kubernetes):
export AWS_ROLE_ARN=arn:aws:iam::123456789012:role/oidc-workload-role
export AWS_WEB_IDENTITY_TOKEN_FILE=/var/run/secrets/eks.amazonaws.com/serviceaccount/token
aws sts get-caller-identityCLI选项等效:
mcp-aws-manager discover \
--auth-mode web-identity \
--web-identity-role-arn arn:aws:iam::123456789012:role/oidc-workload-role \
--web-identity-token-file /var/run/secrets/eks.amazonaws.com/serviceaccount/token快速检查:
aws configure list-profiles
aws configure list --profile default
aws ec2 describe-regions --profile default常见错误:
Missing the following required SSO configuration values
重新运行 aws configure sso --profile default 并完成所有提示。
Unable to locate credentials
SSO会话已过期或缺少凭据。跑 aws sso login --profile default 或重新配置访问密钥。
AccessDenied/not authorized
配置文件有效,但IAM权限集/策略不足以用于请求的API。
AWS Access Path Setup (Profile / SSO / OIDC WebIdentity)
身份验证模式:
auto(默认):默认情况下使用配置文件,但在提供令牌+角色时可以切换到WebIdentity。profile:始终使用AWS配置文件凭据(fromIni).web-identity:始终使用OIDC/WebIdentity令牌路径(fromTokenFile).
推荐选择:
- 操作员工作站:
profile+SSO登录。 - CI/CD或Kubernetes工作负载标识:
web-identity. - 混合环境:保持
auto并在需要时传递显式字段。
配置文件/SSO路径:
aws configure sso --profile prod-admin
aws sso login --profile prod-admin
mcp-aws-manager discover --profiles prod-admin --regions us-east-1 --auth-mode profileWebIdentity路径:
export AWS_ROLE_ARN=arn:aws:iam::123456789012:role/oidc-workload-role
export AWS_WEB_IDENTITY_TOKEN_FILE=/var/run/secrets/eks.amazonaws.com/serviceaccount/token
mcp-aws-manager discover --auth-mode web-identity --regions us-east-1网关/突变和AI读取输入字段:
authModewebIdentityRoleArnwebIdentityTokenFilewebIdentitySessionName(可选)
输入优先级:
- 显式工具输入/CLI选项
MCP_AWS_WEB_IDENTITY_*AWS_ROLE_ARN/AWS_WEB_IDENTITY_TOKEN_FILE
常见的与身份验证相关的操作要求:
WEB_IDENTITY_CONFIG_REQUIREDWEB_IDENTITY_TOKEN_FILE_NOT_FOUNDAWS_CREDENTIALS_REQUIRED
Server Internal Access Path Setup (SSM / PEM SSH / ProxyJump / Bastion)
运行时快照路由选择:
- AWS管理的EC2(
manualInput=false):SSM运行命令路径。 - 手动服务器列表(
manualInput=true):SSH路径。 - SSH路径使用:
- ssh-pem (直接键) - ssh-proxyjump (--ssh-proxy-jump) - ssh-bastion (--ssh-bastion-*,内部通过ProxyCommand)
手册列表+直接PEM示例:
mcp-aws-manager discover \
--manual-server-list ./servers.json \
--pem-paths ~/.ssh/target.pem \
--runtime-snapshot手动列表+ProxyJump示例:
mcp-aws-manager discover \
--manual-server-list ./servers.json \
--pem-paths ~/.ssh/target.pem \
--ssh-proxy-jump ec2-user@bastion.example.com \
--runtime-snapshot手动列表+Bastion键拆分示例:
mcp-aws-manager discover \
--manual-server-list ./servers.json \
--pem-paths ~/.ssh/target.pem \
--ssh-bastion-host bastion.example.com \
--ssh-bastion-user ec2-user \
--ssh-bastion-port 22 \
--ssh-bastion-pem-path ~/.ssh/bastion.pem \
--runtime-snapshot手动服务器JSON字段(每个主机可选):
host/publicIp/privateIp/publicDnssshUser,sshPort,pemPathproxyJump或sshProxyJumpbastionHost,bastionUser,bastionPort,bastionPemPath
通用访问路径ACTION_REQUIRED:
MANUAL_SERVER_HOST_REQUIREDPEM_MAPPING_REQUIREDBASTION_PEM_KEY_NOT_FOUNDSSH_AUTH_OR_CONNECT_FAILED
Integration Connector Management (No-Code)
状态文件默认值:
~/.mcp-aws-manager/integrations.json
列表/显示:
mcp-aws-manager integration list
mcp-aws-manager integration show配置+启用:
mcp-aws-manager integration configure pagerduty --set routingKey=XXXX --enable保单包:
mcp-aws-manager integration policy show
mcp-aws-manager integration policy set strict_change医生:
mcp-aws-manager integration doctor
mcp-aws-manager integration doctor --check-live --timeout-ms 8000发现时间覆盖:
- `--integration-config
`
--integration-timeout-ms--policy-pack--policy-override
Discover Option Reference
--profiles--regions--profile-shard--region-shard--org-role-name--org-account-ids--org-include-all-accounts--org-max-accounts--instance-ids--include-lambda--include-ec2/--no-ec2--include-alb/--no-include-alb--include-asg/--no-include-asg--include-rds/--no-include-rds--include-elasticache/--no-include-elasticache--include-route53/--no-include-route53--include-vpc/--no-include-vpc--include-ecs/--no-include-ecs--include-s3/--no-include-s3--include-iam/--no-include-iam--include-kms/--no-include-kms--include-cloudwatch/--no-include-cloudwatch--include-cloudtrail/--no-include-cloudtrail--include-config/--no-include-config--include-secrets/--no-include-secrets--include-parameter-store/--no-include-parameter-store--include-ecr/--no-include-ecr--include-dynamodb/--no-include-dynamodb--include-sns/--no-include-sns--include-eventbridge/--no-include-eventbridge--include-sqs/--no-include-sqs--include-acm/--no-include-acm--include-kinesis/--no-include-kinesis--include-msk/--no-include-msk--include-budgets/--no-include-budgets--include-cost-anomaly/--no-include-cost-anomaly--include-ebs/--no-include-ebs--include-efs/--no-include-efs--include-eks/--no-include-eks--include-apigateway/--no-include-apigateway--include-apigatewayv2/--no-include-apigatewayv2--include-cloudfront/--no-include-cloudfront--include-waf/--no-include-waf--include-shield/--no-include-shield--include-step-functions/--no-include-step-functions--include-cloudwatch-logs/--no-include-cloudwatch-logs--include-xray/--no-include-xray--include-inspector2/--no-include-inspector2--include-redshift/--no-include-redshift--include-opensearch/--no-include-opensearch--include-organizations/--no-include-organizations--include-controltower/--no-include-controltower--include-iac/--no-include-iac--include-cicd/--no-include-cicd--include-backup-dr/--no-include-backup-dr--include-security/--no-include-security--include-finops/--no-include-finops--include-application/--no-include-application--include-incident/--no-include-incident--incident-force-escalate--mode--schema-tier--auth-mode--web-identity-role-arn- `--web-identity-token-file
`
--web-identity-session-name--user-confirmation- `--enterprise-policy
`
--approval-ticket--change-reason--policy-pack--policy-override- `--integration-config
`
--integration-timeout-ms--public-only--managed-only--auto-remediate-ssm--ssm-instance-profile-name/--ssm-instance-profile-arn--allow-replace-profile--runtime-snapshot/--no-runtime-snapshot--snapshot-profile--output-profile--sections--include-fields--exclude-fields--client-profile--renderer-template--snapshot-timeout--snapshot-concurrency--snapshot-max-kb- `--manual-server-list
` (JSON/CSV)
--pem-paths--ssh-user- `--ssh-port
`
--ssh-connect-timeout--ssh-proxy-jump--ssh-bastion-host--ssh-bastion-user- `--ssh-bastion-port
`
- `--ssh-bastion-pem-path
`
- `--html-out
(默认:自动路径、工作区/主页 aws-inventory.html`)
- `--topology-out
(默认:自动路径、工作区/主页 aws-topology.json`)
- `--relationships-out
(默认:自动路径、工作区/主页 aws-relationships.json`)
- `--governance-log
(默认:自动路径、工作区/主页 mcp-aws-governance-log.jsonl`)
--verify-governance-chain/--no-verify-governance-chain--incident-webhook-url--incident-webhook-timeout-ms--incident-webhook-auth-header--incident-webhook-token- `--incident-out
`
--open-html(打开;默认打开)--no-open-html(禁用自动打开)--auto-sso-login/--no-auto-sso-login--format- `--out
`
治理验证命令:
mcp-aws-manager governance verify --governance-log ./mcp-aws-governance-log.jsonl --strict客户烟雾自动化
运行跨客户端烟雾检查:
npm run smoke:clients
npm run smoke:clients:strict
node scripts/smoke-clients.js --clients codex,claude --json-out ./smoke-report.json- 默认模式报告状态和退出
0. --strict当任何选定的客户端不健康时,退出非零。
AWS E2E场景自动化
运行真实帐户场景检查(权限/区域/恢复路径):
npm run e2e:aws -- --profile default --region us-east-1 --out-dir ./.e2e-aws
npm run e2e:aws:strict -- --profile default --region us-east-1当前场景包括:
- 基线观测合同(
schema+rawNormalized) - 无效区域处理
- 可变确认门(
missing/yes) - 事件升级工件生成
- 企业策略审批票执行
- 治理链验证(
governance verify --strict)
E2E跑步者验证:
- 基线观察流(JSON合约+
rawNormalized) - 无效的区域处理路径
- 可变发现确认门(
CHANGE_CONFIRMATION_REQUIRED) - 确认批准路径(
--user-confirmation yes) - 强制事件升级有效载荷伪影(
INCIDENT_ESCALATION_RECOMMENDED)
Permission Checklist
最小权限取决于启用的功能。
- 核心库存:
ec2:DescribeRegions,ec2:DescribeInstances - λ:
lambda:ListFunctions - ALB/目标群体:
elasticloadbalancing:DescribeLoadBalancers,elasticloadbalancing:DescribeTargetGroups - ASG:
autoscaling:DescribeAutoScalingGroups - RDS:
rds:DescribeDBInstances - ElastiCache:
elasticache:DescribeCacheClusters - 路线53:
route53:ListHostedZones,route53:ListResourceRecordSets - VPC/子网/安全组:
ec2:DescribeVpcs,ec2:DescribeSubnets,ec2:DescribeSecurityGroups - ECS:
ecs:ListClusters,ecs:DescribeClusters,ecs:ListServices,ecs:DescribeServices - S3:
s3:ListAllMyBuckets,s3:GetBucketLocation - 国际机械师协会:
iam:ListRoles - 公里:
kms:ListKeys,kms:DescribeKey - 国际计算机学会
acm:ListCertificates,acm:DescribeCertificate - 动脉炎:
kinesis:ListStreams,kinesis:DescribeStreamSummary - MSK:
kafka:ListClustersV2 - 云观察:
cloudwatch:DescribeAlarms - EBS:
ec2:DescribeVolumes - EFS:
elasticfilesystem:DescribeFileSystems - EKS :
eks:ListClusters,eks:DescribeCluster - API网关:
apigateway:GET - CloudFront:
cloudfront:ListDistributions - WAFv2:
wafv2:ListWebACLs - 防护罩:
shield:ListProtections - 步骤功能:
states:ListStateMachines - CloudWatch日志:
logs:DescribeLogGroups - X射线:
xray:GetGroups - 检查员2:
inspector2:ListFindings - 红移:
redshift:DescribeClusters - OpenSearch:
es:ListDomainNames,es:DescribeDomain - 组织机构:
organizations:ListAccounts - 控制塔:
controltower:ListLandingZones - CI/CD分析:
codepipeline:ListPipelines,codepipeline:ListPipelineExecutions,codebuild:ListProjects,codebuild:ListBuildsForProject,codebuild:BatchGetBuilds,codedeploy:ListApplications,codedeploy:ListDeploymentGroups,codedeploy:ListDeployments,codedeploy:BatchGetDeployments - 安全分析扩展:
config:DescribeConfigRules,config:DescribeComplianceByConfigRule,acm:ListCertificates,acm:DescribeCertificate - FinOps分析扩展:
ce:GetSavingsPlansUtilization,ce:GetReservationCoverage - 运行时快照:
ssm:SendCommand,ssm:GetCommandInvocation,ssm:DescribeInstanceInformation - 自动修复:
ec2:AssociateIamInstanceProfile,可选ec2:ReplaceIamInstanceProfileAssociation,iam:PassRole - 修改工具扩展名:
- ECS: ecs:DescribeServices, ecs:UpdateService - ASG: autoscaling:SetDesiredCapacity - RDS: rds:StartDBInstance, rds:StopDBInstance, rds:RebootDBInstance - EKS : eks:DescribeNodegroup, eks:UpdateNodegroupConfig
- 组织扇出(可选):
organizations:ListAccounts,sts:AssumeRole(需要目标帐户角色信任)
手动回退模式:
- 库存使用用户提供的服务器列表文件(不需要AWS API)
- 运行时快照支持直接PEM SSH和ProxyJump/Bastion路由(
--ssh-proxy-jump,--ssh-bastion-*)
相关文档
文档状态:
- Canonical(与实现保持同步):
README.md,docs/RESPONSE_COMPATIBILITY_POLICY.md
- 参考(细节/定位):
docs/IMPLEMENTATION_INTEGRATIONS.md,docs/MCP_DIFFERENTIATION.md,docs/MCP_DIFFERENTIATION_KO.md,workflow/AGENT_WORKING_CONTEXT_KO.md,docs/RECORDS_FIELD_REFERENCE_KO.md
README_KO.md:韩语概述和快速入门
docs/IMPLEMENTATION_INTEGRATIONS.md:API/CLI集成资源清册
docs/MCP_DIFFERENTIATION.md:与现有AWS MCP服务器的区别
docs/MCP_DIFFERENTIATION_KO.md:韩国差异化指南和选择标准
workflow/AGENT_WORKING_CONTEXT_KO.md:以代理为中心的实现不变量、网关循环和操作目录快速参考
docs/RECORDS_FIELD_REFERENCE_KO.md:满records[]字段参考(292个字段)
docs/RESPONSE_COMPATIBILITY_POLICY.md:响应架构/版本兼容性规则
schemas/mcp-tool-response.schema.json:规范工具响应JSON模式
