devops-status-mcp-server
Checks vendor status pages, inspects SSL/TLS certificates, verifies DNS propagation, and provides incident-response playbooks. Includes 7 tools for DevOps health monitoring.
README
<div align="center"> <h1>@cyanheads/devops-status-mcp-server</h1> <p><b>Check vendor status pages, inspect SSL/TLS certificates, verify DNS propagation, and get incident-response playbooks via MCP. STDIO or Streamable HTTP.</b> <div>7 Tools • 1 Resource</div> </p> </div>
<div align="center">
</div>
<div align="center">
</div>
<div align="center">
Public Hosted Server: https://devops-status.caseyjhand.com/mcp
</div>
Tools
Seven tools in three capability groups — vendor status (51 built-in vendors across Atlassian Statuspage, Status.io, Slack, AWS Health, Google Cloud Service Health, and Firehydrant backends, normalized to one shape, + raw Statuspage URL passthrough), pure-TypeScript cert/DNS checks (any domain), and incident-response guidance:
| Tool | Description |
|---|---|
devops_list_vendors |
List vendors in the built-in registry, optionally filtered by name or category. Returns slug, display name, category, and status page URL. |
devops_status_check |
Check the current health status for one or more vendors. Returns per-vendor indicator (none / minor / major / critical), degraded components, and active incident summaries. |
devops_get_incidents |
Fetch incident history for a vendor — active, resolved, or scheduled maintenance. Returns the full incident timeline with per-update bodies and affected components. |
devops_watch_stack |
Check the health of a named vendor stack persisted in session state. Pass vendors once to save the list; subsequent calls reuse it. Returns an aggregate health rollup plus per-vendor detail. |
devops_check_certs |
Inspect SSL/TLS certificate health for one or more domains via a real TLS handshake. Reports expiry, chain depth, protocol version, cipher suite, and HSTS presence. Pure TypeScript — no external API. |
devops_check_dns |
Resolve DNS records and verify propagation for one or more domains across Google (8.8.8.8), Cloudflare (1.1.1.1), and Quad9 (9.9.9.9). Reports per-resolver latency and resolver discrepancies. Pure TypeScript — no external API. |
devops_suggest_action |
Instruction tool — returns a tailored incident-response playbook and pre-filled follow-up tool calls given a vendor name and optional incident context. No external calls; fully deterministic. |
devops_list_vendors
Discover available vendors before running status checks or configuring a stack.
- Accepts an optional free-text
query(matches name and slug, case-insensitive) and an optionalcategoryfilter - Eight categories:
cloud,cdn-edge,dev-platform,data,comms,auth,monitoring,ai - Returns slug (what to pass to other tools), display name, category, and status page URL
- 51 built-in entries — well-known public vendors with verified status endpoints (most on Atlassian Statuspage;
aws,gcp,gitlab,neon,slack, andredis-cloudserved through native-API adapters)
Built-in vendor registry:
| Category | Vendors |
|---|---|
cloud |
digitalocean, linode, aws, gcp |
cdn-edge |
cloudflare, akamai |
dev-platform |
gitlab, github, npm, vercel, netlify, render, fly-io, circleci, travis-ci, snyk, atlassian, figma, launchdarkly |
data |
mongodb-atlas, planetscale, supabase, neon, redis-cloud, elastic, influxdb, upstash, cloudinary, segment |
comms |
slack, discord, twilio, sendgrid, mailgun, hubspot, brevo, courier, loops |
auth |
auth0, clerk, workos |
monitoring |
datadog, sentry, new-relic, grafana-cloud, honeycomb |
ai |
openai, anthropic, elevenlabs, pinecone, cohere |
Most registry entries are Atlassian Statuspage endpoints; aws (AWS Health Dashboard), gitlab / neon (Status.io), slack (Slack's own status API), and redis-cloud (Firehydrant) are served through adapters that normalize into the same shapes, so every tool works identically for them. GCP and Azure publish no keyless machine-readable feed and remain out of the registry — Statuspage-compatible pages can still be reached by passing a raw base URL.
devops_status_check
Batch health snapshot across one or more vendors in a single call.
- Accepts registered vendor slugs (e.g.,
"github","aws") or raw Atlassian Statuspage base URLs (e.g.,"https://www.githubstatus.com") — mix freely mode: "summary"(default): indicator + degraded components + active incidentsmode: "detailed": adds full component list and scheduled maintenance windowsPromise.allSettledfan-out — one failing vendor does not block the rest; errors surface inline- Results served from a 60-second in-memory cache;
cached: trueflag on each result
devops_get_incidents
Full incident timeline for a vendor with filter support.
filter: "all"(default): incidents plus scheduled maintenancesfilter: "active": only incidents with statusinvestigating/identified/monitoringfilter: "resolved": only fully resolved incidentsfilter: "scheduled": only scheduled maintenance windows- Returns per-update bodies in chronological order, affected component names, duration in minutes (resolved incidents), and a direct shortlink to the incident page
- Configurable
limit(1–50) withoffsetfor paging through longer history; a truncated result discloses the total and names the nextoffsetto fetch - AWS exposes only currently-open events (no history feed) —
filter: "resolved"andfilter: "scheduled"are always empty foraws
devops_watch_stack
Named, persisted vendor stack for recurring health sweeps.
- On the first call, provide
vendorsto define the stack — it is saved to tenant-scoped session state understack_name - Subsequent calls can omit
vendors; the saved list is reused automatically - Multiple stacks coexist via distinct
stack_namevalues (e.g.,"production","data-layer") - Aggregate health output:
all_operational/degraded/partial_outage/major_outage/unknown(a vendor could not be reached — errored vendors count asunavailableand never roll up asall_operational) - Note: stack state is in-memory; it does not persist across server restarts
devops_check_certs
Direct TLS handshake inspection — no external API required.
- Accepts bare hostnames (no
https://prefix) — up to 10 per call - Reports: days to expiry (flagged
warningat < 30 days,criticalat < 7), certificate subject and SANs, issuer common name, chain depth, negotiated TLS version (flags 1.0 and 1.1 as insecure), cipher suite - HSTS detection: sends a minimal HTTP/1.1 GET over the same TLS socket, reads the
Strict-Transport-Securityresponse header - Per-domain failures are reported inline (status:
"error") rather than throwing — useful partial results when checking multiple domains - Configurable port (default 443) and timeout per domain
devops_check_dns
Multi-resolver DNS propagation check — no external API required.
- Queries Google (8.8.8.8), Cloudflare (1.1.1.1), and Quad9 (9.9.9.9) in parallel per domain
- Supported record types: A, AAAA, CNAME, MX, TXT, NS (defaults to A, AAAA, MX, TXT)
- Reports per-resolver latency, propagation discrepancies (where resolvers disagree), and human-readable flags
- Custom resolver list supported — pass any IP addresses to test internal DNS or resolver-specific behavior
- Up to 10 domains per call; per-domain timeouts configurable
devops_suggest_action
Deterministic incident-response guidance, no external calls.
- Returns a markdown playbook tailored to the vendor's category (CDN outage vs. CI/CD outage vs. auth provider outage vs. AI service outage)
- Accepts a vendor slug or display name (
awsorAmazon Web Services) — resolved to the canonical slug so the pre-filled follow-up arguments stay valid nextToolSuggestionspre-populated with arguments from the provided context — execute in sequence to gather diagnostic data- Optional
your_domainpopulates cert and DNS check arguments automatically - Optional
incident_summary/affected_componentsprepend a targeted section to the playbook and add a component re-check when they identify a subsystem (e.g. GitHubActions→ CI/CD-prioritized steps; CloudflareDNS→ DNS/TTL guidance) - Optional
vendor_indicator— pass theindicatorfromdevops_status_checkto lead the playbook with severity-tailored urgency guidance (none/minor/major/critical) - Falls back to generic guidance for unrecognized vendors
- When
DEVOPS_STATUS_DISABLE_ACTIVE_PROBES=true, suggestions and playbook text replace the unregistered probe tools with equivalent manual commands (dig,openssl s_client)
Resources and prompts
| Type | Name | Description |
|---|---|---|
| Resource | devops-status://vendors/{name} |
Full registry entry for a vendor by slug — status page URL, category, API type. |
All resource data is also reachable via tools. Tool-only agents are fully supported.
Features
Built on @cyanheads/mcp-ts-core:
- Declarative tool and resource definitions — single file per primitive, framework handles registration and validation
- Unified error handling — handlers throw, framework catches, classifies, and formats
- Pluggable auth:
none,jwt,oauth - Swappable storage backends:
in-memory,filesystem,Supabase,Cloudflare KV/R2/D1 - Structured logging with optional OpenTelemetry tracing
- STDIO and Streamable HTTP transports
DevOps-status-specific:
- No API keys required — every status backend is a public API; TLS and DNS use Node.js stdlib (
node:tls,node:dns) - 51-vendor built-in registry covering cloud, CDN, dev-platform, data, comms, auth, monitoring, and AI categories; adapter layer normalizes Status.io, Slack, AWS Health, Google Cloud Service Health, and Firehydrant backends into the Statuspage shapes; extendable via raw Statuspage URL passthrough
- 60-second in-memory cache on status reads shared across all tenants — prevents thundering-herd on batch calls
devops_watch_stackpersists named vendor lists in tenant-scoped state for repeat morning checks or pre-deploy sweepsdevops_suggest_actiondispatches category-specific playbooks deterministically — no LLM sampling dependency, works in all clients
Agent-friendly output:
- Batch tools (
devops_status_check,devops_watch_stack,devops_check_certs,devops_check_dns) usePromise.allSettled— one failing target never blocks the rest; errors surface as inlineerrorfields cached: true/checked_aton every status result — agents know when data was fetched- Discriminated indicator and status enums (
none/minor/major/critical;operational/degraded_performance/partial_outage/major_outage/under_maintenance) — callers branch on data, not string parsing nextToolSuggestionsindevops_suggest_actionpre-fills tool arguments from incident context — agents can execute the playbook mechanically
Getting started
Public Hosted Instance
A public instance is available at https://devops-status.caseyjhand.com/mcp — no installation required. Point any MCP client at it via Streamable HTTP:
{
"mcpServers": {
"devops-status-mcp-server": {
"type": "streamable-http",
"url": "https://devops-status.caseyjhand.com/mcp"
}
}
}
Self-Hosted / Local
No API key required. Add the following to your MCP client configuration file:
{
"mcpServers": {
"devops-status-mcp-server": {
"type": "stdio",
"command": "bunx",
"args": ["@cyanheads/devops-status-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}
Or with npx (no Bun required):
{
"mcpServers": {
"devops-status-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@cyanheads/devops-status-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}
Or with Docker:
{
"mcpServers": {
"devops-status-mcp-server": {
"type": "stdio",
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "MCP_TRANSPORT_TYPE=stdio",
"ghcr.io/cyanheads/devops-status-mcp-server:latest"
]
}
}
}
For Streamable HTTP, set the transport and start the server:
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http
# Server listens at http://localhost:3010/mcp
Prerequisites
- Bun v1.3.0 or higher (or Node.js v24+).
- No API keys or external accounts required.
Installation
- Clone the repository:
git clone https://github.com/cyanheads/devops-status-mcp-server.git
- Navigate into the directory:
cd devops-status-mcp-server
- Install dependencies:
bun install
- Configure environment:
cp .env.example .env
# edit .env if you want to override defaults
Configuration
No API keys required. All environment variables are optional.
| Variable | Description | Default |
|---|---|---|
DEVOPS_STATUS_CACHE_TTL_MS |
In-memory cache TTL for vendor status reads (all backends) in milliseconds. | 60000 |
DEVOPS_STATUS_FETCH_TIMEOUT_MS |
Per-request timeout for vendor status API calls (all backends) in milliseconds. | 8000 |
DEVOPS_STATUS_CERT_TIMEOUT_MS |
Default timeout_ms for devops_check_certs (per-domain TLS handshake, milliseconds). A caller-passed timeout_ms overrides it. |
5000 |
DEVOPS_STATUS_DNS_TIMEOUT_MS |
Default timeout_ms for devops_check_dns (per domain+resolver query, milliseconds). A caller-passed timeout_ms overrides it. |
3000 |
DEVOPS_STATUS_ALLOW_PRIVATE_TARGETS |
When true, disables SSRF guards for user-supplied URLs and domains. For trusted local/intranet deployments only. |
false |
DEVOPS_STATUS_DISABLE_ACTIVE_PROBES |
When true, omits the arbitrary-target probe tools (devops_check_dns, devops_check_certs) from the registered tool surface; the five vendor-registry/incident tools remain. For shared/public multi-tenant instances. |
false |
MCP_TRANSPORT_TYPE |
Transport: stdio or http. |
stdio |
MCP_HTTP_PORT |
Port for HTTP server. | 3010 |
MCP_AUTH_MODE |
Auth mode: none, jwt, or oauth. |
none |
MCP_LOG_LEVEL |
Log level (RFC 5424). | info |
LOGS_DIR |
Directory for log files (Node.js only). | <project-root>/logs |
OTEL_ENABLED |
Enable OpenTelemetry instrumentation. | false |
See .env.example for the full list of optional overrides.
Running the server
Local development
-
Build and run:
bun run rebuild bun run start:stdio # or bun run start:http -
Run checks and tests:
bun run devcheck # Lint, format, typecheck, security bun run test # Vitest test suite bun run lint:mcp # Validate MCP definitions against spec
Docker
docker build -t devops-status-mcp-server .
docker run --rm -p 3010:3010 devops-status-mcp-server
The Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/devops-status-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.
Project structure
| Path | Purpose |
|---|---|
src/index.ts |
createApp() entry point — registers tools, resources, and inits services. |
src/config/ |
Server-specific environment variable parsing and validation with Zod. |
src/mcp-server/tools/ |
Tool definitions (*.tool.ts). |
src/mcp-server/resources/ |
Resource definitions (*.resource.ts). |
src/services/cert/ |
node:tls — TLS handshake, X.509 parsing, expiry and protocol flagging. |
src/services/dns/ |
node:dns — multi-resolver DNS fan-out, propagation discrepancy detection. |
src/services/statuspage/ |
Statuspage public API client with 60-second in-memory cache. |
src/services/status-adapters/ |
Native-API adapters (Status.io, Slack, AWS Health, Google Cloud Service Health, Firehydrant) + api_type dispatch, normalizing into the Statuspage shapes. |
src/services/vendor-registry/ |
In-memory vendor registry loaded from src/data/vendor-registry.ts. |
src/data/ |
Static vendor registry data file (vendor-registry.ts). |
tests/ |
Vitest tests mirroring src/. |
Development guide
See CLAUDE.md for development guidelines and architectural rules. The short version:
- Handlers throw, framework catches — no
try/catchin tool logic - Use
ctx.logfor request-scoped logging,ctx.statefor tenant-scoped storage - Register new tools and resources via the barrels in
src/mcp-server/*/definitions/index.ts devops_check_certsanddevops_check_dnsuse only Node.js stdlib — add no external deps for these paths
Contributing
Issues and pull requests are welcome. Run checks and tests before submitting:
bun run devcheck
bun run test
License
Apache-2.0 — see LICENSE for details.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。