dockndevai/mcp-azure
БесплатноПоддерживаетсяAzure Resource Manager inventory, tags, VM power & lifecycle — governed with subscription/resource-group allowlists, protected groups, location allowlist, delet
Описание
Azure Resource Manager inventory, tags, VM power & lifecycle — governed with subscription/resource-group allowlists, protected groups, location allowlist, delete gating, and typed confirmation. npx -y @dockndevai/mcp-azure
README
A Model Context Protocol server for Azure (via the Azure Resource Manager API — the programmatic layer behind the Azure Portal). It lets an MCP-capable client (Claude Desktop, Claude Code, Cursor, Codex, …) inventory and operate Azure resources — with a governance layer that keeps an AI agent inside safe boundaries.
What this offers
- Inventory — list subscriptions, locations, resource groups, and resources; get any resource by ARM id.
- Operations — create resource groups (in approved regions), merge tags onto any resource, and control VM power state (start / stop / restart / deallocate).
- Lifecycle — delete resource groups and individual resources, guarded.
- Governance built in — access modes, subscription/resource-group allowlists, protected resource groups, a location allowlist for new groups, delete gating, typed confirmation for high-impact deletes, dry-run, and JSON audit logging.
Governance & security model
| Concern | Flag | Default | Effect |
|---|---|---|---|
| What can the server do? | AZURE_MODE |
read-only |
read-only → inventory; read-write → create RG, tag, VM power; admin → deletes. Tools above the mode are never registered. |
| Which subscriptions? | AZURE_SUBSCRIPTION_ALLOWLIST |
(all) | Operations on other subscriptions are refused. |
| Which resource groups? | AZURE_RESOURCE_GROUP_ALLOWLIST |
(all) | Operations outside the list are refused. |
| Read-only-forever groups | AZURE_PROTECTED_RESOURCE_GROUPS |
(none) | Readable, never mutable. |
| Approved regions | AZURE_LOCATION_ALLOWLIST |
(any) | New resource groups may only be created here. |
| Can it delete? | AZURE_ALLOW_DELETE |
false |
Deletes need this and admin mode. |
| Typed confirmation | AZURE_REQUIRE_CONFIRMATION |
true |
Deletes require confirm to equal the target name — not just a boolean. |
| Preview | AZURE_DRY_RUN |
false |
Write/admin tools validate + log intent, then return. |
| Audit trail | AZURE_AUDIT_LOG |
true |
JSON line to stderr per guarded operation. |
Tools
Read (read-only+): list_subscriptions, list_locations, list_resource_groups, list_resources, get_resource
Write (read-write+): create_resource_group, tag_resource, control_vm
Admin (admin): delete_resource_group, delete_resource (both need AZURE_ALLOW_DELETE + typed confirm)
Quickstart — add to your agent
Published on npm as @dockndevai/mcp-azure. Runs via npx with an Entra ID service principal. See docs/CLIENTS.md for every client and .env.example for all variables.
Claude Code
claude mcp add azure -e AZURE_TENANT_ID="…" -e AZURE_CLIENT_ID="…" -e AZURE_CLIENT_SECRET="…" -e AZURE_SUBSCRIPTION_ID="…" -e AZURE_MODE="read-only" -- npx -y @dockndevai/mcp-azure
Claude Desktop · Cursor · Windsurf
{
"mcpServers": {
"azure": {
"command": "npx",
"args": ["-y", "@dockndevai/mcp-azure"],
"env": {
"AZURE_TENANT_ID": "…",
"AZURE_CLIENT_ID": "…",
"AZURE_CLIENT_SECRET": "…",
"AZURE_SUBSCRIPTION_ID": "…",
"AZURE_MODE": "read-only"
}
}
}
}
Example prompts
- "List all resource groups in my subscription and which region each is in"
- "Show every resource in the rg-web group"
- "Tag the app-plan resource with env=prod and owner=team-a" (needs read-write)
- "Stop the build-agent VM in rg-ci" (needs read-write)
Run from source (development)
npm install
npm run build
node dist/index.js # with the environment variables set
Develop
npm run dev
npm test # governance policy: modes, scoping, location allowlist, delete + confirmation
npm run typecheck
Publishing
Ships a server.json for the official MCP registry and an mcpName for npm ownership validation. See PUBLISHING.md.
License
MIT
Установка dockndevai/mcp-azure
У этого сервера нет опубликованного пакета — он собирается из исходников. Открой репозиторий и следуй инструкции в README.
▸ github.com/dockndevai/mcp-azureFAQ
dockndevai/mcp-azure MCP бесплатный?
Да, dockndevai/mcp-azure MCP бесплатный — установка в пару кликов через Unyly без оплаты.
Нужен ли API-ключ для dockndevai/mcp-azure?
Да, требуются переменные окружения: AZURE_CLIENT_ID, AZURE_CLIENT_SECRET, AZURE_MODE, AZURE_SUBSCRIPTION_ID, AZURE_TENANT_ID. Unyly подставит их в конфиг при установке.
dockndevai/mcp-azure — hosted или self-hosted?
Self-hosted: сервер запускается локально на твоей машине командой из раздела установки.
Как установить dockndevai/mcp-azure в Claude Desktop, Claude Code или Cursor?
Открой dockndevai/mcp-azure на unyly.org, выбери вкладку своего клиента (Claude Desktop, Claude Code, Cursor) и нажми Install — конфиг сгенерируется автоматически, без правки JSON.
Похожие MCP
GitHub
PRs, issues, code search, CI status
автор: GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
автор: mcpdotdirectAmap Maps Mcp Server
MCP server for using the AMap Maps API
автор: duxiaohuiSupabase
Database, auth and storage
автор: SupabaseEverything
Reference / test server with prompts, resources, and tools.
Git
Tools to read, search, and manipulate Git repositories.
Sequential Thinking
Dynamic and reflective problem-solving through thought sequences.
Time
Time and timezone conversion capabilities.
Compare dockndevai/mcp-azure with
Не уверен что выбрать?
Найди свой стек за 60 секунд
Автор?
Embed-бейдж для README
Похожее
Все в категории development
