Infrastructure and DevOps MCP Servers
16 infrastructure and devops MCP servers are cataloged, 3 with verified current-spec support.
MCP servers that operate infrastructure: container platforms, CI/CD, deployment and hosting providers, monitoring, and observability tooling.
- Apache SkyWalking MCP
- Spec Support Unverified
The Apache SkyWalking project's own MCP server, a Go binary named swmcp that queries a SkyWalking OAP backend for traces, logs, metrics, topology and alarms. It serves stdio, streamable HTTP and legacy SSE, and authenticates to OAP rather than to its own callers. The 0.3.0 changelog entry on master says the server migrated to the official Go SDK and added support for the 2026-07-28 revision, but no 0.3.0 release is tagged: the newest tag is v0.2.0, so revision support is not yet recorded as shipped.
- argocd-mcp
- Spec Support Unverified
MCP server for Argo CD, distributed as npm:argocd-mcp and run over stdio, HTTP stream, or SSE; it is self-hosted only, with no vendor-managed remote endpoint. It lives in argoproj-labs, which the Argo Project's own governance README describes as "a separate GitHub org that we setup for community contributions related to the Argoproj ecosystem," administered by each project's owners and, per the labs org's own profile, "not part of the CNCF Argo umbrella projects." Argo CD's own repository and docs do not link the server. Its creators are named engineers from Akuity, a company founded by Argo CD's co-founders, but Akuity is not the vendor of Argo CD, which is a CNCF project. Authority is therefore community: verified maintainers, outside the project that owns the fronted service. No documentation names a supported MCP specification revision; the README's own curl example and a security-advisory proof of concept both hard-code protocolVersion 2024-11-05 in sample JSON-RPC payloads, which is example boilerplate rather than a stated capability. Auth is dual and asymmetric: ARGOCD_API_TOKEN authenticates the server outbound to Argo CD, while MCP_AUTH_TOKEN, added in v0.9.0, is an optional inbound bearer token required only once the listener binds beyond loopback; recorded here as api_key for the closest enum fit, since the enum has no dual-credential option. CVE-2026-82456 (CVSS 3.1 and 4.0 both 10.0, record published 2026-08-29) affected v0.8.0's unauthenticated, all-interfaces HTTP bind and is fixed in v0.9.0, released 2026-08-11, advisory GHSA-rp45-5x3v-48mr.
- Azure MCP Server
- Current Spec Verified
Microsoft's first-party Azure MCP server, distributed from the microsoft/mcp monorepo. The CHANGELOG records the migration to the 2026-07-28 stateless protocol in prerelease 3.0.0-beta.29 dated 2026-07-23. No stable 3.0.0 has shipped and no vendor-hosted remote endpoint is published; the README documents self-hosting only.
- Cloudflare MCP servers
- Current Spec Verified
Cloudflare's product-specific MCP servers, sixteen Cloudflare-hosted endpoints on mcp.cloudflare.com subdomains. Each request runs on a fresh stateless server with no protocol session. Historical /sse URLs survive as aliases to the same Streamable HTTP handler but no longer serve the deprecated HTTP+SSE transport. Authorization is OAuth with scope selection; the docs endpoint answers unauthenticated. A 2026-08-07 probe of docs.mcp.cloudflare.com/mcp answered server/discover at 2026-07-28 over streamable-http. Endpoint probe confirmed support for 2026-07-28 via server/discover.
- coolify
- Earlier Revision
Distributed as npm:@masonator/coolify-mcp. Resolved from the published package: @masonator/coolify-mcp 2.19.3 depends on @modelcontextprotocol/sdk@1.30.0, whose artifact implements 2025-11-25. This records what the artifact implements, not what a deployment negotiates.
- Coroot
- Spec Support Unverified
Coroot's MCP surface is a built-in feature of the Coroot product itself, not a separate package; it is served at /mcp on a customer's own Coroot instance, so no public remote_url applies. Coroot's docs describe the exposed surface (application topology, health signals, distributed traces, raw telemetry) and list 19 distinct tools, 2 marked Enterprise-Edition-only, without naming each tool individually on the fetched page, so key_tools is left empty here rather than guessed. Authentication is OAuth 2.0 with dynamic client registration (/oauth/register, /oauth/authorize, /oauth/token, /oauth/revoke, /.well-known/oauth-authorization-server), confirmed both in the docs ("Each user signs in with their own Coroot account on first connect, and the agent runs with that user's RBAC permissions") and in source. No fetched page names an MCP protocol revision; the go.mod dependency on github.com/mark3labs/mcp-go v0.45.0 is an SDK version, not evidence of revision support. CVE-2026-79786 (VulnCheck CNA, published 2026-08-25, CVSS 3.1 7.1 high) documents that the MCP OAuth registration endpoint validates redirect_uris with Go's url.Parse only, with no scheme or host allowlist, enabling open-redirect consent-phishing against authenticated users; affected versions 1.20.2 through 1.24.5. As of 2026-09-15 there is still no fix: api/mcp_oauth.go is unchanged at release v1.26.1 (published 2026-09-14) and on the current main branch (pushed 2026-09-15), and the file's last commit remains the 2026-05-05 change that introduced the MCP server. A proposed fix, PR #960, opened 2026-08-13 to add a scheme/host allowlist, was closed without merging. The public tracking issue, coroot/coroot#929, opened 2026-07-01, remains open with no maintainer fix committed.
- Dynatrace-mcp
- Spec Support Unverified
Distributed as npm:@dynatrace-oss/dynatrace-mcp-server. DEPRECATED by the vendor, recorded 2026-08-25: the README states "This repository is deprecated. Version 2.1.2 was the final release" and directs users to Dynatrace-for-ai with dtctl or the Dynatrace Remote MCP Server. v2.1.2 published 2026-07-20. Authority: the dynatrace-oss organization describes itself as "Open Source projects maintained by Dynatrace".
- gitlab-mcp
- Earlier Revision
Community MCP server (by independent developer zereight) fronting the GitLab API: projects, merge requests, issues, pipelines, wiki, releases. Requires a GitLab personal access token by default, with OAuth modes for self-hosted remote deployments. Not published by GitLab, which operates its own official MCP server. No surface names a supported MCP revision. Resolved from the published package: @zereight/mcp-gitlab 2.1.49 depends on @modelcontextprotocol/sdk@1.30.0, whose artifact implements 2025-11-25. This records what the artifact implements, not what a deployment negotiates.
- homebutler
- Current Spec Verified
Homelab management tool distributed as npm:homebutler, a thin installer (bin homebutler-mcp) that downloads a compiled Go binary rather than shipping an SDK-based JavaScript server; the package declares no @modelcontextprotocol/sdk dependency. It runs the MCP interface over stdio only, with no network port opened and no auth token, since the README states only the parent AI process can reach it over stdin/stdout. Vendor docs (docs/mcp-server.md, "Protocol versions") state that homebutler implements MCP revisions 2026-07-28, 2025-11-25, 2025-06-18, 2025-03-26 and 2024-11-05, which grounds spec_status as current with legacy support recorded for the four earlier revisions via matching support atoms.
- Hostinger API MCP Server
- Earlier Revision
Hostinger's first-party MCP server for the Hostinger API, run locally from npm or used via the hosted remote at mcp.hostinger.com, which requires OAuth. No vendor surface names a supported MCP revision; a 2026-08-14 probe of the remote returned an OAuth challenge, so revision behavior is not observable without credentials. Resolved from the published package: hostinger-api-mcp 1.45.3 depends on @modelcontextprotocol/sdk@1.30.0, whose artifact implements 2025-11-25. This records what the artifact implements, not what a deployment negotiates.
- kubernetes-mcp-server
- Spec Support Unverified
Distributed as npm:kubernetes-mcp-server. Hand check 2026-08-25: no MCP revision statement in README or docs; go.mod pins modelcontextprotocol/go-sdk v1.7.0, which can prove capability but never a served revision (2026-07-28 support there is conditional on StreamableHTTPOptions.Stateless). Native Go binary; the npm package is a wrapper.
- mcp-ssh-manager
- Spec Support Unverified
Community SSH management server distributed as npm:mcp-ssh-manager, giving Claude Code and OpenAI Codex 37 tools across command execution, file transfer, backups, database operations and health monitoring on operator-configured remote hosts. It runs over stdio only; MCP-level auth is none, while a separate per-server security mode (unrestricted, readonly, or restricted with allow/deny regex patterns) gates which commands each configured SSH connection accepts. No documentation or dependency file names a supported MCP specification revision; the package's @modelcontextprotocol/sdk ^1.30.0 dependency is a version range, not evidence of a specific revision, so spec_status is unknown.
- MCPHub
- Spec Support Unverified
MCPHub is a self-hosted MCP gateway and control plane: it both consumes upstream MCP servers, configured through data/mcp_settings.json, and exposes its own MCP endpoints to AI clients. This atom describes the exposed surface only. Authority is recorded as first_party under the self-owned-project precedent: the repository, the docs site (docs.mcphub.app), and the product site (mcphub.app, listed as the repo's own homepage) are all controlled by the same individual maintainer, so MCPHub fronts no separate third-party vendor relationship for this record to misrepresent. The README describes the exposed routes generically as supporting "SSE / Streamable HTTP / stdio" without pinning transport to a single value; transports here record both streamable-http and sse-legacy rather than asserting one exclusively. Auth on the exposed endpoints is layered: a built-in OAuth 2.0 authorization server ("Both client and server modes for secure authentication"), bearer keys, and JWT + bcrypt for local dashboard accounts, with MCP endpoints requiring authentication by default unless Bearer Authentication is explicitly disabled. oauth is recorded as the primary auth value because the exposed endpoints carry a real embedded OAuth 2.0 authorization server, not only static bearer keys. As a client, MCPHub can also connect to upstream MCP servers over stdio, SSE, or streamable HTTP; that consumer role is not otherwise assessed here.
- Sentry MCP Server
- Earlier Revision
Sentry's first-party MCP server for error monitoring and issue data, hosted at mcp.sentry.dev with OAuth, plus a work-in-progress local stdio transport using a Sentry user auth token. A 2026-08-07 probe confirmed the OAuth requirement first-hand; no vendor documentation surface names a supported MCP revision. Resolved from the published package: @sentry/mcp-server 0.37.0 depends on @modelcontextprotocol/sdk@1.30.0, whose artifact implements 2025-11-25. This records what the artifact implements, not what a deployment negotiates.
- ssh-mcp
- Spec Support Unverified
Community SSH server distributed as npm:ssh-mcp, running over stdio by default with an optional bearer-token HTTP transport. Destructive and privileged commands are gated behind an MCP elicitation prompt, and the README states that a client without elicitation support has every such command refused rather than silently allowed. No documentation names a supported MCP specification revision; the package depends on @modelcontextprotocol/sdk ^1.30.0, which is an SDK range rather than a revision. The repository has published six security advisories between 2026-08-09 and 2026-09-02, five of them variations on the same defect: the command classifier that enforces read-only mode and the approval gate can be fed a command it misreads.
- Yaw MCP
- Spec Support Unverified
Distributed as npm:@yawlabs/mcp. First-party: the server is YawLabs' own product (yaw.sh/mcp documents it as "A CLI that runs MCP servers on your machine"). An orchestrator that fronts other MCP servers from one connection; local-first, no account. No MCP revision statement found on yaw.sh/mcp or in the README (checked 2026-08-27).