MCP servers for cloud and infra
Last verified: 2026-09
Most of these are admin APIs. Docker talks to the daemon socket (root-equivalent). Kubernetes uses your kubeconfig. AWS/GCP/Azure use whatever identity is on the machine. Cloudflare and Vercel tokens can change DNS and ship deploys. Treat this category like handing over a console session, because that is what it is.
What to look for
- Use a locked-down IAM role or API token with one action on one resource. Never a long-lived admin key in mcp.json.
- Do not expose Docker or a cluster-admin kubeconfig to a chat that also has Fetch (prompt injection → kubectl).
- Grafana/Prometheus/Datadog: a Viewer or query-only key is enough for 'what broke'.
Side-by-side
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| Docker | No | No | List containers and images on the local daemon. |
| Kubernetes | No | Yes | kubectl-style cluster access. |
| Terraform | No | No | Inspect Terraform plans and state. |
| AWS | No | Yes | Call AWS APIs with the default credential chain. |
| AWS Knowledge Base | Yes | Yes | Query an Amazon Bedrock knowledge base. |
| Cloudflare | No | Yes | Workers, KV, R2, and DNS via Cloudflare. |
| Vercel | No | Yes | Projects and deployments on Vercel. |
| Netlify | No | Yes | Sites and deploys on Netlify. |
| Grafana | No | Yes | Dashboards and datasources. |
| Datadog | No | Yes | Metrics, logs, and monitors. |
| PagerDuty | No | Yes | Incidents and on-call. |
| Prometheus | No | Yes | Instant queries against Prometheus. |
| Google Cloud | No | Yes | Call selected GCP APIs. |
| Azure | No | Yes | Azure Resource Manager via MCP. |
| PostHog | No | Yes | Events and insights from PostHog. |
All 15 servers
Cloud & infraDockerList containers and images on the local daemon.
Cloud & infraKuberneteskubectl-style cluster access.
Cloud & infraTerraformInspect Terraform plans and state.
Cloud & infraAWSCall AWS APIs with the default credential chain.
OfficialAWS Knowledge BaseQuery an Amazon Bedrock knowledge base.
Cloud & infraCloudflareWorkers, KV, R2, and DNS via Cloudflare.
Cloud & infraVercelProjects and deployments on Vercel.
Cloud & infraNetlifySites and deploys on Netlify.
Cloud & infraGrafanaDashboards and datasources.
Cloud & infraDatadogMetrics, logs, and monitors.
Cloud & infraPagerDutyIncidents and on-call.
Cloud & infraPrometheusInstant queries against Prometheus.
Cloud & infraGoogle CloudCall selected GCP APIs.
Cloud & infraAzureAzure Resource Manager via MCP.
Cloud & infraPostHogEvents and insights from PostHog.
FAQ
Can I install AWS and Kubernetes together?
Yes, if both identities are read-only. Two admin identities in one chat is how accidents spread.
Is Terraform safer than clicking apply in the cloud console?
Only if you review the plan. The server can still apply if you let it.
What about AWS Knowledge Base?
That one is retrieval, not account admin. Different risk: it surfaces internal docs, it does not create VPCs.