Suggest a server AI tools directory →

MCP servers for cloud and infra

Last verified: 2026-09

Most of these are admin APIs. Docker talks to the daemon socket (root-equivalent). Kubernetes uses your kubeconfig. AWS/GCP/Azure use whatever identity is on the machine. Cloudflare and Vercel tokens can change DNS and ship deploys. Treat this category like handing over a console session, because that is what it is.

What to look for

  • Use a locked-down IAM role or API token with one action on one resource. Never a long-lived admin key in mcp.json.
  • Do not expose Docker or a cluster-admin kubeconfig to a chat that also has Fetch (prompt injection → kubectl).
  • Grafana/Prometheus/Datadog: a Viewer or query-only key is enough for 'what broke'.

Side-by-side

ServerOfficial?Needs a secret?Best for
DockerNoNoList containers and images on the local daemon.
KubernetesNoYeskubectl-style cluster access.
TerraformNoNoInspect Terraform plans and state.
AWSNoYesCall AWS APIs with the default credential chain.
AWS Knowledge BaseYesYesQuery an Amazon Bedrock knowledge base.
CloudflareNoYesWorkers, KV, R2, and DNS via Cloudflare.
VercelNoYesProjects and deployments on Vercel.
NetlifyNoYesSites and deploys on Netlify.
GrafanaNoYesDashboards and datasources.
DatadogNoYesMetrics, logs, and monitors.
PagerDutyNoYesIncidents and on-call.
PrometheusNoYesInstant queries against Prometheus.
Google CloudNoYesCall selected GCP APIs.
AzureNoYesAzure Resource Manager via MCP.
PostHogNoYesEvents and insights from PostHog.

All 15 servers

FAQ

Can I install AWS and Kubernetes together?

Yes, if both identities are read-only. Two admin identities in one chat is how accidents spread.

Is Terraform safer than clicking apply in the cloud console?

Only if you review the plan. The server can still apply if you let it.

What about AWS Knowledge Base?

That one is retrieval, not account admin. Different risk: it surfaces internal docs, it does not create VPCs.