Observability Agent MCP

Observability Agent MCP

A portable, read-only Model Context Protocol server for turning observability data into bounded evidence that AI agents can inspect safely.

Category
访问服务器

README

<div align="center">

Pak Satpam

The bounded observability and CI guard for AI agents

Pak Satpam gives an AI agent the evidence it needs to understand infrastructure health, investigate incidents, inspect CI failures, and show Grafana visuals without handing the model a shell or unrestricted infrastructure access.

Validate License Node.js MCP

</div>

Pak Satpam means the security guard. It watches, reports, and follows a strict access policy. It does not become the infrastructure administrator.

This is the production-ready evolution of the original Pak Satpam prototype: a portable Model Context Protocol server with deterministic provider adapters, bounded responses, redaction, and approval-gated CI operations. The agent and chat experience remain separate, so the same MCP can serve Hermes/Tabby, desktop agents, CI assistants, or another MCP-compatible client.

What It Does

Engineer
   |
   v
AI agent (Hermes, Tabby, desktop client, or another MCP client)
   |
   |  stdio or authenticated private HTTP
   v
Pak Satpam
   |-- validates every request against a strict schema
   |-- bounds queries, time windows, output size, and labels
   |-- normalizes and redacts provider evidence
   |
   +--> Grafana panels and dashboard PNGs
   +--> Prometheus / VictoriaMetrics metrics
   +--> VictoriaMetrics alert state
   +--> GitHub Actions evidence

The default server exposes seven read-only observability tools. An optional CI module adds four read-only tools and one tightly scoped operation that can rerun failed GitHub Actions jobs only after a fresh, one-time operator approval.

Pak Satpam does not run an LLM, receive chat messages, execute arbitrary shell commands, modify source, deploy workloads, read secrets, or silently expand its own permissions.

Tool Surface

Observability

Tool What the agent receives
observability.capabilities Configured providers, features, and safety limits
observability.health_snapshot Bounded service and scrape-target health
observability.active_alerts Normalized active-alert metadata
observability.query_metrics Allowlisted instant or range metrics results
observability.render_panel One allowlisted Grafana panel as PNG evidence
observability.render_dashboard One allowlisted Grafana dashboard as PNG evidence
observability.incident_context A compact evidence bundle for an alert or service

CI/CD (optional)

Tool What the agent receives or may request
ci.workflow_status Status for one allowlisted workflow run
ci.failed_job_analysis Deterministic failure classification
ci.log_evidence Bounded and redacted job-log evidence
ci.remediation_plan A runbook-backed dry-run plan
ci.rerun_failed_workflow Approved rerun of failed jobs only

The CI module stays disabled until the deployment provides repository and workflow allowlists, a GitHub App identity, a replay-safe approval key, and metadata-only audit storage. The public .github/workflows/goal14-controlled-fixture.yml workflow provides a bounded failure-and-rerun test. See the CI/CD runbook.

Run It

Pak Satpam requires Node.js 22 or newer.

npm ci
npm run build
node dist/cli.js

The command speaks MCP over stdio. Configure it in a compatible client instead of typing into the process directly:

{
  "command": "node",
  "args": ["/absolute/path/to/pak-satpam/dist/cli.js"]
}

Run the complete local verification suite with:

npm run validate

Container

The public non-root image supports linux/amd64 and linux/arm64:

ghcr.io/hamardikan/observability-agent-mcp

Production deployments should pin the image by immutable @sha256: digest. For a local build and stdio smoke run:

npm run container:build
docker run --rm -i observability-agent-mcp:local

Connect It to an Agent

Client location Recommended transport Intended use
Same machine stdio Desktop and CLI agents
Private network Streamable HTTP Shared Hermes/Tabby or agent runtime
OCI host stdio or private HTTP Podman/Docker deployments
Public network Not ready Requires OAuth and tenant isolation first

Private HTTP mode uses a file-injected bearer credential and an exact Host allowlist. It is designed for a private, single-operator network. Publishing the repository or image does not make an unauthenticated public endpoint safe. See Client compatibility and the Security model before deployment.

Visual Evidence

Grafana visuals are first-class MCP evidence. Panel and dashboard tools return PNG ImageContent together with structured metadata: source, observation window, dimensions, byte size, freshness, truncation, and warnings.

Rendering is opt-in. Normal health and metrics requests do not spend browser, renderer, or image-context resources. If rendering is unavailable, Pak Satpam fails to a structured evidence response instead of inventing a graph.

Why Not Just Use Grafana MCP?

The official Grafana MCP is the right choice for broad Grafana-native queries and administration. Pak Satpam owns a narrower boundary intended for operational agents:

Capability Grafana MCP Pak Satpam
Grafana administration Primary owner Not implemented
Grafana datasource queries Broad support Narrow allowlisted adapter
Direct Prometheus-compatible backend Secondary path Supported
Provider-neutral incident evidence Provider-specific Primary contract
Conservative read-only default Configurable Required
Approval-gated CI evidence Not its scope Optional module

Both servers can be offered to one agent, but every request must have one clear owner. Pak Satpam never silently delegates to another MCP server.

Project Boundary

This public repository owns the portable protocol, schemas, provider adapters, redaction, tests, npm package, and OCI image. A deployment repository should own private endpoints, network policy, provider allowlists, credentials, and runtime configuration. Private topology and secrets do not belong here.

Documentation

License

Apache License 2.0. See LICENSE.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选