nautobot-mcp

nautobot-mcp

A read-only MCP server for interacting with Nautobot, enabling network source of truth queries, device management, IPAM, and data quality audits via tools and prompts.

Category
访问服务器

README

nautobot-mcp

A read-only, production-shaped Model Context Protocol server for Nautobot — the network source of truth (DCIM + IPAM). Same architecture as the sibling meraki-mcp: one response contract, one lifecycle owner, one API seam, resolution baked in, response-size budget, read-only by default.

Built on the MCP Python SDK (FastMCP) over Nautobot's REST API via httpx.

Coverage strategy (grounded in the API)

Nautobot's OpenAPI schema (v3.1) has 678 GET operations across ~100 object types. Wrapping each as a tool would wreck LLM selection, so coverage is layered:

  • Power tools (the breadth): nautobot_graphql (run a read-only GraphQL query — the ideal way to traverse the source of truth in one call), nautobot_graphql_schema (introspect root query fields / a type's fields so the model writes a correct query first), nautobot_saved_query (run a stored GraphQL query by name), and nautobot_query (generic reader over 75 curated object types via the uniform REST interface — including plugin apps: golden-config compliance, Device Lifecycle CVE/hardware/software, VPN, load-balancers — with q search + filter passthrough).
  • Workflow tools (job-driven, multi-endpoint — the real value): nautobot_data_quality_audit (SoT hygiene: what's undocumented — missing primary IPs/racks/platforms/software, unassigned IPs), nautobot_site_report (one-call site picture: devices by role/status + IPAM + racks + gaps), nautobot_device_readiness (deployment/documentation checklist, GO/NO-GO), nautobot_rack (elevation + free U), nautobot_ip_allocate (next free IP/subnet suggestion).
  • Sharp purpose tools (the common intents): nautobot_find, nautobot_device, nautobot_device_interfaces, nautobot_interface (single-interface detail), nautobot_device_config_context, nautobot_cabling, nautobot_list_devices (filter by location/role/status/manufacturer/model/platform/software_version — "which devices run 17.12.3?"), nautobot_location, nautobot_ip_lookup, nautobot_prefix (+ available IPs/prefixes), nautobot_list_prefixes, nautobot_list_vlans, nautobot_vlan (single-VLAN detail + mapped prefixes), nautobot_vlan_allocate (next free VID), nautobot_status_overview, nautobot_object_changes (SoT audit log).
  • Optional (flagged, network-automation apps): nautobot_jobs, nautobot_circuits, nautobot_lifecycle_report (EoX/end-of-support, Device Lifecycle app), and the Golden Config layer — nautobot_config_compliance (per-device or per-site compliance), nautobot_device_config (stored backup/intended/compliance text), and nautobot_config_search (grep config text across the fleet — "who still runs telnet?"). Enable with NAUTOBOT_MCP_ENABLE_OPTIONAL_TOOLS=true.

Tool-structure ergonomics (for the LLM): every list tool returns a uniform envelope ({kind, count, items}) with cursor pagination (next_offset → pass back as offset); an unknown filter is a self-correcting error that returns the valid filter names for that type (not a hard failure); nautobot_query defers to the sharp tools when one exists.

Resources: nautobot://locations, nautobot://device-roles, nautobot://statuses, nautobot://manufacturers (titled). Prompts (12 playbooks): /find, /device_report, /ip_lookup, /site_inventory, /data_quality, /device_readiness, /prefix_report, /vlan_report, /connectivity, /capacity, /change_history, /compliance_check — with argument completion (location/device autocomplete from live Nautobot data). Every tool + power endpoint was validated live against demo.nautobot.com.

LLM-facing conformance (MCP SDK): every tool parameter carries a Field(description=…) and closed sets are Literal enums, so the generated inputSchema guides the model on every argument; tools return a Pydantic ToolResult, so each also advertises an outputSchema + structuredContent; read-only tools are annotated readOnlyHint/idempotentHint/openWorldHint; genuine failures set the protocol isError (self-correcting ambiguity/not-found do not); fan-out tools report progress. Covered by in-memory client-session tests (tests/test_server_session.py). Scored ≈94/100 against MCP_ENGINEERING_STANDARD.md.

Shape (mirrors meraki-mcp)

  • One contract — every tool returns ToolResult{summary, data, meta, error}; payloads projected to declared fields (nested objects compacted via ref), arrays capped.
  • Response-size budget — the registrar runs enforce_budget so no result overflows the agent context (flagged in meta.truncated/meta.note).
  • One seam — all REST calls go through NautobotGateway (httpx + concurrency limit + timeout + bounded retry on transient timeout/502-504 + error normalization + logging); one _send owns the HTTP call site.
  • One catalog — core/catalog.py is the single registry of object-type→REST-path knowledge; the generic query tool, the resolver, and the change-audit aliases all derive from it, so adding an object type or plugin app is a one-file edit.
  • Names in, IDs never invented — the Resolver turns "ams01"/"AMS"/"10.0.0.0/24" into objects; ambiguity returns the candidate list.
  • Read-only — no write tools.

Run

uv sync                       # or: pip install -e ".[dev]"
cp .env.example .env          # NAUTOBOT_URL + NAUTOBOT_TOKEN (read-only)
uv run python -m nautobot_mcp # stdio (waits for an MCP client — normal)
# HTTP:  $env:NAUTOBOT_MCP_TRANSPORT="streamable-http"; uv run python -m nautobot_mcp
# Inspector:  uv run mcp dev src/nautobot_mcp/server.py:build_server

Prefer python -m nautobot_mcp over the nautobot-mcp console script: on locked-down Windows, Application Control (Smart App Control / WDAC) can block the generated nautobot-mcp.exe shim (OS error 4551). python -m runs the trusted interpreter directly.

Test it

  1. Offline gates: pytest -q · lint ruff check src tests scripts · types mypy (strict-ish: check_untyped_defs, clean across all modules).
  2. Live smoke (public demo): with NAUTOBOT_URL=https://demo.nautobot.com and the demo token in .env: python scripts/smoke_test.py (add a device name, e.g. python scripts/smoke_test.py ams01-edge-01).
  3. HTTP / Copilot Studio: NAUTOBOT_MCP_TRANSPORT=streamable-http nautobot-mcp → http://127.0.0.1:8000/mcp (or docker build -t nautobot-mcp . && docker run -p 8000:8000 -e NAUTOBOT_URL=... -e NAUTOBOT_TOKEN=... nautobot-mcp). No auth yet (OAuth planned) — keep behind a tunnel/gateway.

Never commit a real token. .env is git-ignored; .env.example holds a placeholder.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选