Content
# Alibaba Cloud MCP Server
A comprehensive, high-performance [Model Context Protocol (MCP)](https://modelcontextprotocol.io/) server for managing Alibaba Cloud resources.
This server enables AI assistants (like Claude, Cursor, and others) to seamlessly interact with Alibaba Cloud infrastructure using natural language. It features a **Hybrid Architecture**:
1. **Explicit Service Tools**: Pre-configured, typed handlers for the most common services (ECS, VPC, RDS, RAM, ACK, SLB) to ensure rapid, error-free AI interactions.
2. **Universal API Invoker**: A dynamic tool built on `@alicloud/pop-core` that can invoke *any* of the 10,000+ API endpoints across all Alibaba Cloud services, giving you true 100% cloud management coverage.
## Features
- 🚀 **Zero-Config Universal Management**: Dynamically call any Alibaba Cloud RPC/ROA API.
- 📦 **Explicit Typed Tools**:
- **ECS**: Manage Compute Instances (`ecs_list_instances`, `ecs_start_instance`)
- **VPC**: Manage Networking (`vpc_list`, `vpc_create`)
- **RDS**: Manage Databases (`rds_list_instances`)
- **RAM**: Manage IAM & Security (`ram_list_users`)
- **ACK**: Manage Kubernetes Clusters (`ack_list_clusters`)
- **SLB**: Manage Load Balancers (`slb_list`)
- 🐳 **Docker Ready**: Run safely in an isolated container.
- 🛡️ **Secure**: Uses Zod for strict parameter validation and environment variables for credentials.
## Prerequisites
- Node.js 18+ (if running locally)
- Docker (optional, for containerized execution)
- Alibaba Cloud Access Key ID and Secret with appropriate IAM permissions.
## Setup & Installation
### Option 1: Running Locally
1. Clone the repository and install dependencies:
```bash
npm install
```
2. Build the TypeScript source:
```bash
npm run build
```
3. Create a `.env` file in the root directory:
```env
ALIBABA_CLOUD_ACCESS_KEY_ID="your_access_key"
ALIBABA_CLOUD_ACCESS_KEY_SECRET="your_access_secret"
ALIBABA_CLOUD_REGION_ID="cn-hangzhou"
```
### Option 2: Running with Docker
1. Build the Docker image:
```bash
docker build -t alibaba-cloud-mcp .
```
## Configuring Your MCP Client
### Claude Desktop
To integrate this server with Claude Desktop, add the following to your `claude_desktop_config.json` (usually located at `%APPDATA%\Claude\claude_desktop_config.json` on Windows or `~/Library/Application Support/Claude/claude_desktop_config.json` on Mac):
**If using Node.js locally:**
```json
{
"mcpServers": {
"alibaba-cloud": {
"command": "node",
"args": ["/absolute/path/to/Alibaba_cloud_MCP_server/dist/index.js"],
"env": {
"ALIBABA_CLOUD_ACCESS_KEY_ID": "your_access_key",
"ALIBABA_CLOUD_ACCESS_KEY_SECRET": "your_access_secret",
"ALIBABA_CLOUD_REGION_ID": "cn-hangzhou"
}
}
}
}
```
**If using Docker:**
```json
{
"mcpServers": {
"alibaba-cloud": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e", "ALIBABA_CLOUD_ACCESS_KEY_ID",
"-e", "ALIBABA_CLOUD_ACCESS_KEY_SECRET",
"-e", "ALIBABA_CLOUD_REGION_ID",
"alibaba-cloud-mcp"
],
"env": {
"ALIBABA_CLOUD_ACCESS_KEY_ID": "your_access_key",
"ALIBABA_CLOUD_ACCESS_KEY_SECRET": "your_access_secret",
"ALIBABA_CLOUD_REGION_ID": "cn-hangzhou"
}
}
}
}
```
*Note: Restart Claude Desktop after updating the configuration.*
## Security Warning
> **⚠️ IMPORTANT:** This MCP server is incredibly powerful, especially due to the `aliyun_invoke_api` tool which can manage *any* resource. Always adhere to the Principle of Least Privilege. Ensure that the IAM/RAM user associated with your Access Keys only has the minimum permissions necessary for the tasks you intend the AI to perform.
## Architecture
Built using:
- `@modelcontextprotocol/sdk`
- `@alicloud/pop-core`
- `zod` for validation
- `TypeScript`