openstack-mcp

openstack-mcp

Enables AI assistants to inspect and manage OpenStack clouds, including listing instances, checking quotas, and retrieving console logs. It supports opt-in write operations for creating and deleting servers, with a read-only default.

Category
访问服务器

README

openstack-mcp

An MCP server that lets an AI assistant inspect and operate an OpenStack cloud — list instances, check quotas, read a stuck VM's console log, and (if you allow it) create and delete servers.

Works with any OpenStack deployment: CloudPe, OVHcloud, Infomaniak, university and research clouds, or a local DevStack. Anything openstacksdk can reach, this can drive.

Read-only by default. Writes require an explicit opt-in, and deletes require a second one. An assistant that can list your project cannot tear it down unless you decided it should be able to.

Quick start

Install from source (not yet on PyPI):

pipx install git+https://github.com/abhishekambad-leapswitch/openstack-mcp

Point it at a cloud. openstacksdk reads standard OpenStack config, so either a clouds.yaml:

# ~/.config/openstack/clouds.yaml
clouds:
  cloudpe:
    auth_type: v3applicationcredential
    auth:
      auth_url: https://<your-region>.cloudpe.com:5000/v3
      application_credential_id: <id>
      application_credential_secret: <secret>
    region_name: RegionOne

...or the usual environment variables (OS_AUTH_URL, OS_APPLICATION_CREDENTIAL_ID, OS_APPLICATION_CREDENTIAL_SECRET). This server never stores or transmits your credentials itself — it hands off to openstacksdk, which resolves them the same way the openstack CLI does.

Claude Code

claude mcp add openstack --env OS_CLOUD=cloudpe -- openstack-mcp

Claude Desktop / Cursor / any MCP client

{
  "mcpServers": {
    "openstack": {
      "command": "openstack-mcp",
      "env": { "OS_CLOUD": "cloudpe" }
    }
  }
}

Then ask things like "which VMs are down?", "do I have quota for three more m1.large?", or "web-03 won't accept SSH — check its console log."

To confirm what you've wired up before trusting it, run a dry check — it prints the resolved config and exactly which tools are exposed, without serving or connecting:

openstack-mcp --check
openstack-mcp 0.1.0
cloud: cloudpe
mode: read-only
max items per list: 50
12 tools: check_capacity, cloud_info, get_console_output, get_quotas, get_server,
list_flavors, list_images, list_keypairs, list_networks, list_security_groups,
list_servers, list_volumes

The safety model

Most cloud MCP servers hand an assistant the full API and hope for the best. This one is gated, because "delete the test VMs" is a sentence a model can misread.

Environment variable Effect
(nothing set) Read-only. 12 inspection tools. Write tools are not registered at all — the model cannot see or call them.
OPENSTACK_MCP_ALLOW_WRITE=true Adds create_servers and power_action (14 tools).
OPENSTACK_MCP_ALLOW_DELETE=true Adds delete_server (15 tools). Requires ALLOW_WRITE too — delete-without-write is treated as a config mistake and ignored.
OPENSTACK_MCP_MAX_ITEMS=50 Caps how many items any list tool returns.
OPENSTACK_MCP_CLOUD / OS_CLOUD Which clouds.yaml entry to use.

Two further guardrails:

  • delete_server demands confirmation. You must pass confirm_name matching the resolved instance's exact name. Ask it to delete web-1 when the VM is called web-01 and it refuses rather than guessing.
  • Tools carry MCP annotations (read_only_hint, destructive_hint), so clients that surface risk to the user before running a tool can do so correctly.

Tool gating is enforced at registration, not by asking the model nicely — verified over a real stdio session in the test suite.

Tools

Read (always available)

Tool Purpose
cloud_info Which cloud, region, and project you're pointed at, and which operations are enabled
list_servers Instances with status and IPs; filter by status or name substring
get_server Full detail for one instance: flavor, image, key pair, security groups, addresses
list_flavors Instance sizes with vCPU, RAM, disk
list_images Bootable images
list_networks Networks, flagging which are external
list_security_groups Security groups and rule counts
list_keypairs Registered SSH key pairs
list_volumes Block storage volumes and what they're attached to
get_quotas Compute quota usage vs limits
check_capacity Whether N instances of a flavor fit in remaining quota, and what blocks it if not
get_console_output Serial console log — for VMs that boot but are unreachable

Write (opt-in)

Tool Purpose
create_servers Create one or many instances; count > 1 names them <prefix>-01, -02, …
power_action start / stop / reboot
delete_server Delete one instance, with name confirmation (needs ALLOW_DELETE)

Two design choices worth knowing

Responses are deliberately small. openstacksdk returns 60+ attributes per server. Feeding all of that to a model is slow, expensive, and buries the useful fields, so every tool returns a trimmed projection — for a server that's id, name, status, and a flattened {network: [ips]} map instead of nova's nested address structure.

check_capacity exists so batches fail early. Asking for eight VMs and discovering the quota ceiling on the fifth leaves a half-built mess. This reports which of instances/vCPUs/RAM binds first, before anything is created. create_servers also reports partial failures per instance rather than throwing away what succeeded.

Development

git clone https://github.com/abhishekambad-leapswitch/openstack-mcp
cd openstack-mcp
python -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"
pytest && ruff check .

The suite runs entirely offline against a fake openstacksdk connection — no cloud, no credentials, no charges. It covers the tool gating, the trimming, quota arithmetic, partial-failure reporting, and the delete confirmation.

Provisioning at scale

For standing up fleets declaratively rather than conversationally, see cloudpe-terraform-bulk-vm — Terraform for bulk VM creation on the same API.

License

MIT

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选