AWS Resources MCP Server

by MCP-Mirror

369 downloads
Not rated
GitHub

About

A Model Context Protocol server that runs generated Python code to query any AWS resources through boto3. It is intended for users who want to interact with AWS services via natural language through an MCP client like Claude Desktop.

Details

Author
MCP-Mirror
Downloads
369
Categories
Cloud Service

- Runs from a Docker image – no git clone required
- Uses Python and boto3 for all AWS resource queries
- Supports Linux/amd64, Linux/arm64, and Linux/arm/v7 platforms
- Sandboxes code execution with a restricted set of allowed imports and built-ins
- Accepts both access key and profile-based AWS authentication

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name AWS Resources MCP Server
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

Install via Smithery (npx -y @smithery/cli install ...) or pull the Docker image from Docker Hub. Configure AWS credentials using environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_DEFAULT_REGION, optional AWS_SESSION_TOKEN) or by mounting a local ~/.aws credentials file and setting AWS_PROFILE. Invoke the query_aws_resources tool with a code_snippet string containing boto3 code that sets a result variable.

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "aws resources mcp server": {
            "baryhuang_mcp-server-aws-resources-python": {
                "command": "npx",
                "args": [
                    "-y",
                    "@smithery/cli",
                    "install",
                    "mcp-server-aws-resources-python",
                    "--client",
                    "claude"
                ]
            }
        }
    }
}

McpServers

{
    "baryhuang_mcp-server-aws-resources-python": {
        "command": "npx",
        "args": [
            "-y",
            "@smithery/cli",
            "install",
            "mcp-server-aws-resources-python",
            "--client",
            "claude"
        ]
    }
}

AWS Resources MCP Server

Docker Hub smithery badge

Overview

A Model Context Protocol (MCP) server implementation that provides running generated python code to query any AWS resources through boto3.

At your own risk:
I didn't limit the operations to ReadyOnly, so that cautious Ops people can be helped using this tool doing management operations. Your AWS user role will dictate the permissions for what you can do.

image

Demo: Fix Dynamodb Permission Error

https://github.com/user-attachments/assets/de88688d-d7a0-45e1-94eb-3f5d71e9a7c7

Why Another AWS MCP Server?

I tried AWS Chatbot with Developer Access. Free Tier has a limit of 25 query/month for resources. Next tier is $19/month include 90% of the features I don't use. And the results are in a fashion of JSON and a lot of restrictions.

I tried using aws-mcp but ran into a few issues:

1. Setup Hassle: Had to clone a git repo and deal with local setup
2. Stability Issues: Wasn't stable enough on my Mac
3. Node.js Stack: As a Python developer, I couldn't effectively contribute back to the Node.js codebase

So I created this new approach that:
- Runs directly from a Docker image - no git clone needed
- Uses Python and boto3 for better stability
- Makes it easy for Python folks to contribute
- Includes proper sandboxing for code execution
- Keeps everything containerized and clean

For more information about the Model Context Protocol and how it works, see Anthropic's MCP documentation.

Components

Resources

The server exposes the following resource:

aws://query_resources: A dynamic resource that provides access to AWS resources through boto3 queries

Example Queries

Here are some example queries you can execute:

s3 = session.client('s3')
result = s3.list_buckets()

2. Get latest CodePipeline deployment:

def get_latest_deployment(pipeline_name):
codepipeline = session.client('codepipeline')

result = codepipeline.list_pipeline_executions(
pipelineName=pipeline_name,
maxResults=5
)

if result['pipelineExecutionSummaries']:
latest_execution = max(
[e for e in result['pipelineExecutionSummaries']
if e['status'] == 'Succeeded'],
key=itemgetter('startTime'),
default=None
)

if latest_execution:
result = codepipeline.get_pipeline_execution(
pipelineName=pipeline_name,
pipelineExecutionId=latest_execution['pipelineExecutionId']
)
else:
result = None
else:
result = None

return result

result = get_latest_deployment("your-pipeline-name")

Tools

The server offers a tool for executing AWS queries:

query_aws_resources
Execute a boto3 code snippet to query AWS resources
Input:
code_snippet (string): Python code using boto3 to query AWS resources
The code must set a result variable with the query output
Allowed imports:
boto3
operator
json
datetime
pytz
Available built-in functions:
Basic types: dict, list, tuple, set, str, int, float, bool
Operations: len, max, min, sorted, filter, map, sum, any, all
Object handling: hasattr, getattr, isinstance
* Other: print, __import__

Setup

Prerequisites

You'll need AWS credentials with appropriate permissions to query AWS resources. You can obtain these by:
1. Creating an IAM user in your AWS account
2. Generating access keys for programmatic access
3. Ensuring the IAM user has necessary permissions for the AWS services you want to query

The following environment variables are required:
- AWS_ACCESS_KEY_ID: Your AWS access key
- AWS_SECRET_ACCESS_KEY: Your AWS secret key
- AWS_SESSION_TOKEN: (Optional) AWS session token if using temporary credentials
- AWS_DEFAULT_REGION: AWS region (defaults to 'us-east-1' if not set)

You can also use a profile stored in the ~/.aws/credentials file. To do this, set the AWS_PROFILE environment variable to the profile name.

Note: Keep your AWS credentials secure and never commit them to version control.

Installing via Smithery

To install AWS Resources MCP Server for Claude Desktop automatically via Smithery:

npx -y @smithery/cli install mcp-server-aws-resources-python --client claude

Docker Installation

You can either build the image locally or pull it from Docker Hub. The image is built for the Linux platform.

Supported Platforms

- Linux/amd64 - Linux/arm64 - Linux/arm/v7

Option 1: Pull from Docker Hub

docker pull buryhuang/mcp-server-aws-resources:latest

Option 2: Build Locally

docker build -t mcp-server-aws-resources .

Run the container:

docker run \
-e AWS_ACCESS_KEY_ID=your_access_key_id_here \
-e AWS_SECRET_ACCESS_KEY=your_secret_access_key_here \
-e AWS_DEFAULT_REGION=your_AWS_DEFAULT_REGION \
buryhuang/mcp-server-aws-resources:latest

Or using stored credentials and a profile:

docker run \
-e AWS_PROFILE=[AWS_PROFILE_NAME] \
-v ~/.aws:/root/.aws \
buryhuang/mcp-server-aws-resources:latest

Cross-Platform Publishing

To publish the Docker image for multiple platforms, you can use the docker buildx command. Follow these steps:

1. Create a new builder instance (if you haven't already):

   docker buildx create --use

2. Build and push the image for multiple platforms:

   docker buildx build --platform linux/amd64,linux/arm64,linux/arm/v7 -t buryhuang/mcp-server-aws-resources:latest --push .

3. Verify the image is available for the specified platforms:

   docker buildx imagetools inspect buryhuang/mcp-server-aws-resources:latest

Usage with Claude Desktop

Running with Docker

Example using ACCESS_KEY_ID and SECRET_ACCESS_KEY

{
  "mcpServers": {
    "aws-resources": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "-e",
        "AWS_ACCESS_KEY_ID=your_access_key_id_here",
        "-e",
        "AWS_SECRET_ACCESS_KEY=your_secret_access_key_here",
        "-e",
        "AWS_DEFAULT_REGION=us-east-1",
        "buryhuang/mcp-server-aws-resources:latest"
      ]
    }
  }
}

Example using PROFILE and mounting local AWS credentials

{
  "mcpServers": {
    "aws-resources": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "-e",
        "AWS_PROFILE=default",
        "-v",
        "~/.aws:/root/.aws",
        "buryhuang/mcp-server-aws-resources:latest"
      ]
    }
  }
}

Running with Git clone

Example running with git clone and profile

{
  "mcpServers": {
    "aws": {
      "command": "/Users/gmr/.local/bin/uv",
      "args": [
        "--directory",
        "/<your-path>/mcp-server-aws-resources-python",
        "run",
        "src/mcp_server_aws_resources/server.py",
        "--profile",
        "testing"
      ]
    }
  }
}
No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.