openstack-mcp
Enables AI assistants to inspect and manage OpenStack clouds, including listing instances, checking quotas, and retrieving console logs. It supports opt-in write operations for creating and deleting servers, with a read-only default.
README
openstack-mcp
An MCP server that lets an AI assistant inspect and operate an OpenStack cloud — list instances, check quotas, read a stuck VM's console log, and (if you allow it) create and delete servers.
Works with any OpenStack deployment: CloudPe, OVHcloud, Infomaniak, university and research clouds, or a local DevStack. Anything openstacksdk can reach, this can drive.
Read-only by default. Writes require an explicit opt-in, and deletes require a second one. An assistant that can list your project cannot tear it down unless you decided it should be able to.
Quick start
Install from source (not yet on PyPI):
pipx install git+https://github.com/abhishekambad-leapswitch/openstack-mcp
Point it at a cloud. openstacksdk reads standard OpenStack config, so either a clouds.yaml:
# ~/.config/openstack/clouds.yaml
clouds:
cloudpe:
auth_type: v3applicationcredential
auth:
auth_url: https://<your-region>.cloudpe.com:5000/v3
application_credential_id: <id>
application_credential_secret: <secret>
region_name: RegionOne
...or the usual environment variables (OS_AUTH_URL, OS_APPLICATION_CREDENTIAL_ID, OS_APPLICATION_CREDENTIAL_SECRET). This server never stores or transmits your credentials itself — it hands off to openstacksdk, which resolves them the same way the openstack CLI does.
Claude Code
claude mcp add openstack --env OS_CLOUD=cloudpe -- openstack-mcp
Claude Desktop / Cursor / any MCP client
{
"mcpServers": {
"openstack": {
"command": "openstack-mcp",
"env": { "OS_CLOUD": "cloudpe" }
}
}
}
Then ask things like "which VMs are down?", "do I have quota for three more m1.large?", or "web-03 won't accept SSH — check its console log."
To confirm what you've wired up before trusting it, run a dry check — it prints the resolved config and exactly which tools are exposed, without serving or connecting:
openstack-mcp --check
openstack-mcp 0.1.0
cloud: cloudpe
mode: read-only
max items per list: 50
12 tools: check_capacity, cloud_info, get_console_output, get_quotas, get_server,
list_flavors, list_images, list_keypairs, list_networks, list_security_groups,
list_servers, list_volumes
The safety model
Most cloud MCP servers hand an assistant the full API and hope for the best. This one is gated, because "delete the test VMs" is a sentence a model can misread.
| Environment variable | Effect |
|---|---|
| (nothing set) | Read-only. 12 inspection tools. Write tools are not registered at all — the model cannot see or call them. |
OPENSTACK_MCP_ALLOW_WRITE=true |
Adds create_servers and power_action (14 tools). |
OPENSTACK_MCP_ALLOW_DELETE=true |
Adds delete_server (15 tools). Requires ALLOW_WRITE too — delete-without-write is treated as a config mistake and ignored. |
OPENSTACK_MCP_MAX_ITEMS=50 |
Caps how many items any list tool returns. |
OPENSTACK_MCP_CLOUD / OS_CLOUD |
Which clouds.yaml entry to use. |
Two further guardrails:
delete_serverdemands confirmation. You must passconfirm_namematching the resolved instance's exact name. Ask it to deleteweb-1when the VM is calledweb-01and it refuses rather than guessing.- Tools carry MCP annotations (
read_only_hint,destructive_hint), so clients that surface risk to the user before running a tool can do so correctly.
Tool gating is enforced at registration, not by asking the model nicely — verified over a real stdio session in the test suite.
Tools
Read (always available)
| Tool | Purpose |
|---|---|
cloud_info |
Which cloud, region, and project you're pointed at, and which operations are enabled |
list_servers |
Instances with status and IPs; filter by status or name substring |
get_server |
Full detail for one instance: flavor, image, key pair, security groups, addresses |
list_flavors |
Instance sizes with vCPU, RAM, disk |
list_images |
Bootable images |
list_networks |
Networks, flagging which are external |
list_security_groups |
Security groups and rule counts |
list_keypairs |
Registered SSH key pairs |
list_volumes |
Block storage volumes and what they're attached to |
get_quotas |
Compute quota usage vs limits |
check_capacity |
Whether N instances of a flavor fit in remaining quota, and what blocks it if not |
get_console_output |
Serial console log — for VMs that boot but are unreachable |
Write (opt-in)
| Tool | Purpose |
|---|---|
create_servers |
Create one or many instances; count > 1 names them <prefix>-01, -02, … |
power_action |
start / stop / reboot |
delete_server |
Delete one instance, with name confirmation (needs ALLOW_DELETE) |
Two design choices worth knowing
Responses are deliberately small. openstacksdk returns 60+ attributes per server. Feeding all of that to a model is slow, expensive, and buries the useful fields, so every tool returns a trimmed projection — for a server that's id, name, status, and a flattened {network: [ips]} map instead of nova's nested address structure.
check_capacity exists so batches fail early. Asking for eight VMs and discovering the quota ceiling on the fifth leaves a half-built mess. This reports which of instances/vCPUs/RAM binds first, before anything is created. create_servers also reports partial failures per instance rather than throwing away what succeeded.
Development
git clone https://github.com/abhishekambad-leapswitch/openstack-mcp
cd openstack-mcp
python -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"
pytest && ruff check .
The suite runs entirely offline against a fake openstacksdk connection — no cloud, no credentials, no charges. It covers the tool gating, the trimming, quota arithmetic, partial-failure reporting, and the delete confirmation.
Provisioning at scale
For standing up fleets declaratively rather than conversationally, see cloudpe-terraform-bulk-vm — Terraform for bulk VM creation on the same API.
License
MIT
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。