MCP OpsBridge
Unified MCP server exposing 12 DevOps tools across GitHub, PostgreSQL, Slack, and Google Calendar for AI agents, with rate limiting, input validation, and per-service scoped tokens.
README
MCP OpsBridge
Production MCP (Model Context Protocol) server exposing 30 DevOps tools for AI agents with a user approval system that prevents unauthorized write/destructive operations.
What It Does
Exposes 29 tools + 1 approve_action tool across 4 services, guarded by a risk-based permission gate:
| Service | Tools | Read (Auto) | Write (Gated) | Destructive (Double Approval) |
|---|---|---|---|---|
| GitHub | 7 | All 7 | — | — |
| Calendar | 8 | 4 (list_calendars, query_events, get_event_details, find_free_slots) |
3 (create_event, update_event, add_attendee) |
1 (delete_event) |
| Database | 9 | 3 (execute_query, list_tables, describe_table) |
2 auto + 1 gated (insert_row, update_rows auto; delete_rows gated) |
3 (truncate_table, drop_table, migrate_schema) |
| Slack | 5 | 3 (list_channels, get_thread, get_channel_history) |
2 (send_message, send_thread_reply) |
— |
User Approval System
The permission gate intercepts medium+ risk tool calls and returns pending_approval instead of executing. The agent presents a structured request to the user, who confirms via the approve_action tool.
- Low risk → Auto-execute (reads)
- Medium/High → Single approval required
- Critical → Double approval required (two separate confirms)
- Timeout → Stale approvals auto-expire after 5 minutes
Architecture
┌──────────────────────────────────────────────────┐
│ CLIENTS │
│ Claude Desktop (stdio) │ Custom Client (HTTP) │
└────────────┬─────────────────────┬───────────────┘
│ │
▼ ▼
┌──────────────────────────────────────────────────┐
│ MCP SERVER │
│ ┌────────────────────────────────────────────┐ │
│ │ Transport: stdio | Streamable HTTP │ │
│ │ Rate Limiter: 100 req/min user, 1000/hr IP│ │
│ │ Permission Gate: Risk → Pending/Execute │ │
│ │ Validation: Zod schemas on all inputs │ │
│ └────────────────────────────────────────────┘ │
└────────────┬─────────────────────┬───────────────┘
│ │
▼ ▼
┌──────────────────────────────────────────────────┐
│ EXTERNAL APIs │
│ GitHub │ Google Calendar │ PostgreSQL │ Slack │
└──────────────────────────────────────────────────┘
Quick Start
Local Development
npm install
npm run dev # stdio mode (default)
TRANSPORT=http PORT=3099 npm run dev # HTTP mode
With Claude Desktop
Add to claude_desktop_config.json:
{
"mcpServers": {
"opsbridge": {
"command": "npx",
"args": ["tsx", "src/cli.ts"],
"env": {
"GITHUB_TOKEN": "ghp_...",
"DATABASE_URL": "postgresql://...",
"SLACK_TOKEN": "xoxb-...",
"CALENDAR_TOKEN": "ya29..."
}
}
}
}
With Docker
cp .env.example .env
# Edit .env with your tokens
docker compose up -d
Environment Variables
| Variable | Required | Description |
|---|---|---|
GITHUB_TOKEN |
No* | GitHub token (*required for private repos; public repos work without) |
DATABASE_URL |
No* | PostgreSQL connection string (*required for DB tools) |
SLACK_TOKEN |
No* | Slack bot token (xoxb-...) (*required for Slack tools) |
CALENDAR_TOKEN |
No* | Google Calendar OAuth token (*required for Calendar tools) |
TRANSPORT |
No | stdio (default) or http |
PORT |
No | HTTP port (default: 3002) |
Security
- Permission gate: Risk-based approval for write/destructive operations; critical ops require double approval
- Read-only database: PostgreSQL session set to
READ ONLY+ write keyword blocklist - Rate limiting: LRU cache, 100 requests/minute per user, 1000/hour per IP
- Scoped tokens: Each service requires its own token
- Input validation: All tool inputs validated with Zod schemas
- No secrets in code: All tokens loaded from environment variables
- 5-minute approval timeout: Stale pending approvals auto-expire
Development
npm run build # Compile TypeScript
npm run dev # Start dev server (stdio)
npm test # Run Vitest (71 tests)
npm run lint # Type check
npm run format # Prettier format
Tech Stack
- TypeScript 5.5+
@modelcontextprotocol/sdkv1.29 (MCP protocol)- Zod (input validation)
@octokit/rest(GitHub API)pg(PostgreSQL)lru-cache(rate limiting + approval store)- Vitest (testing)
License
MIT
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.