Loading languages...
AW

awslabs.cdk-mcp-server

@awslabs8007

MCP server for AWS Cloud Development Kit (CDK) best practices, infrastructure as code patterns, and security compliance with CDK Nag.

aws
cdk
infrastructure-as-code
security
generative-ai
cloud-development-kit

Markdown Content: mcp/src/cdk-mcp-server at main · awslabs/mcp · GitHub

===============

Skip to content Navigation Menu

Toggle navigation

Sign in

Appearance settings

  • Product
*   [GitHub Copilot Write better code with AI](https://github.com/features/copilot)
*   [GitHub Spark New Build and deploy intelligent apps](https://github.com/features/spark)
*   [GitHub Models New Manage and compare prompts](https://github.com/features/models)
*   [GitHub Advanced Security Find and fix vulnerabilities](https://github.com/security/advanced-security)
*   [Actions Automate any workflow](https://github.com/features/actions)

*   [Codespaces Instant dev environments](https://github.com/features/codespaces)
*   [Issues Plan and track work](https://github.com/features/issues)
*   [Code Review Manage code changes](https://github.com/features/code-review)
*   [Discussions Collaborate outside of code](https://github.com/features/discussions)
*   [Code Search Find more, search less](https://github.com/features/code-search)

Explore * Why GitHub * All features * Documentation * GitHub Skills * Blog

  • Solutions

By company size * Enterprises * Small and medium teams * Startups * Nonprofits

By use case * DevSecOps * DevOps * CI/CD * View all use cases

By industry * Healthcare * Financial services * Manufacturing * Government * View all industries

View all solutions

  • Resources

Topics * AI * DevOps * Security * Software Development * View all

Explore * Learning Pathways * Events & Webinars * Ebooks & Whitepapers * Customer Stories * Partners * Executive Insights

  • Open Source
*   [GitHub Sponsors Fund open source developers](https://github.com/sponsors)

*   [The ReadME Project GitHub community articles](https://github.com/readme)

Repositories * Topics * Trending * Collections

  • Enterprise
*   [Enterprise platform AI-powered developer platform](https://github.com/enterprise)

Available add-ons * GitHub Advanced Security Enterprise-grade security features * Copilot for business Enterprise-grade AI features * Premium Support Enterprise-grade 24/7 support

Search or jump to...

Search code, repositories, users, issues, pull requests...

Search

Clear

Search syntax tips

Provide feedback

We read every piece of feedback, and take your input very seriously.

  • [x] Include my email address so I can be contacted

Cancel Submit feedback

Saved searches

Use saved searches to filter your results more quickly

Name

Query

To see all available qualifiers, see our documentation.

Cancel Create saved search

Sign in

Sign up

Appearance settings

Resetting focus

You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert

{{ message }}

awslabs/**mcp**Public

Additional navigation options

Collapse file tree

Files

main

Search this repository

  •     .devcontainer  
    
  •     .github  
    
  •     docs  
    
  •     docusaurus  
    
  •     samples  
    
  •     src  
    
    •      amazon-kendra-index-mcp-server  
      
    •      amazon-keyspaces-mcp-server  
      
    •      amazon-mq-mcp-server  
      
    •      amazon-neptune-mcp-server  
      
    •      amazon-qbusiness-anonymous-mcp-server  
      
    •      amazon-qindex-mcp-server  
      
    •      amazon-rekognition-mcp-server  
      
    •      amazon-sns-sqs-mcp-server  
      
    •      aurora-dsql-mcp-server  
      
    •      aws-api-mcp-server  
      
    •      aws-bedrock-data-automation-mcp-server  
      
    •      aws-dataprocessing-mcp-server  
      
    •      aws-diagram-mcp-server  
      
    •      aws-documentation-mcp-server  
      
    •      aws-healthomics-mcp-server  
      
    •      aws-knowledge-mcp-server  
      
    •      aws-location-mcp-server  
      
    •      aws-msk-mcp-server  
      
    •      aws-pricing-mcp-server  
      
    •      aws-serverless-mcp-server  
      
    •      aws-support-mcp-server  
      
    •      bedrock-kb-retrieval-mcp-server  
      
    •      cdk-mcp-server  
      
      •       awslabs  
        
      •       tests  
        
      •     .gitignore  
        
      •     .python-version  
        
      •     CHANGELOG.md  
        
      •     Dockerfile  
        
      •     LICENSE  
        
      •     NOTICE  
        
      •     README.md  
        
      •     docker-healthcheck.sh  
        
      •     pyproject.toml  
        
      •     uv-requirements.txt  
        
      •     uv.lock  
        
    •      cfn-mcp-server  
      
    •      cloudwatch-appsignals-mcp-server  
      
    •      cloudwatch-logs-mcp-server  
      
    •      cloudwatch-mcp-server  
      
    •      code-doc-gen-mcp-server  
      
    •      core-mcp-server  
      
    •      cost-explorer-mcp-server  
      
    •      documentdb-mcp-server  
      
    •      dynamodb-mcp-server  
      
    •      ecs-mcp-server  
      
    •      eks-mcp-server  
      
    •      elasticache-mcp-server  
      
    •      finch-mcp-server  
      
    •      frontend-mcp-server  
      
    •      git-repo-research-mcp-server  
      
    •      iam-mcp-server  
      
    •      lambda-tool-mcp-server  
      
    •      mcp-lambda-handler  
      
    •      memcached-mcp-server  
      
    •      mysql-mcp-server  
      
    •      nova-canvas-mcp-server  
      
    •      openapi-mcp-server  
      
    •      postgres-mcp-server  
      
    •      prometheus-mcp-server  
      
    •      redshift-mcp-server  
      
    •      s3-tables-mcp-server  
      
    •      stepfunctions-tool-mcp-server  
      
    •      syntheticdata-mcp-server  
      
    •      terraform-mcp-server  
      
    •      timestream-for-influxdb-mcp-server  
      
    •      valkey-mcp-server  
      
  •   .gitignore  
    
  •   .pre-commit-config.yaml  
    
  •   .python-version  
    
  •   .ruff.toml  
    
  •   .secrets.baseline  
    
  •   CODE_OF_CONDUCT.md  
    
  •   CONTRIBUTING.md  
    
  •   DESIGN_GUIDELINES.md  
    
  •   DEVELOPER_GUIDE.md  
    
  •   LICENSE  
    
  •   NOTICE  
    
  •   README.md  
    
  •   VIBE_CODING_TIPS_TRICKS.md  
    

Breadcrumbs

  1. mcp
  2. /src

/ cdk-mcp-server

/

Copy path

Directory actions

More options

More options

Directory actions

More options

More options

Latest commit

Image 3: awslabs-mcpawslabs-mcp

Automatic update of packages

success

Jul 18, 2025

cebabf7·Jul 18, 2025

History

History

Open commit details

Breadcrumbs

  1. mcp
  2. /src

/ cdk-mcp-server

/

Top

Folders and files

Name Name Last commit message Last commit date
### parent directory ..
awslabs awslabs fix: updated CDK solutions constructs parsing (#581) Jun 12, 2025
tests tests fix: updated CDK solutions constructs parsing (#581) Jun 12, 2025
.gitignore .gitignore chore(cdk server): add unit tests (#150) Apr 16, 2025
.python-version .python-version [Update project to support Python 3.10 and above (](https://github.com/awslabs/mcp/commit/f979d1f832fabcacd83166a292a09a547287735e "Update project to support Python 3.10 and above (#57) * Update project to support Python 3.10 and above - Tested functionality on Python 3.10 and newer version - Aligned project with MCP Python SDK requirements Quality assurance steps: - Ran 'ruff check .' to identify and fix linting issues - Applied 'ruff format .' to ensure consistent code formatting - Executed 'uv run --frozen pyright' for type checking * feat(.ruff.toml): adds shared ruff at the root of the repo\" --------- Co-authored-by: laithalsaadoon [email protected]")#57[)](https://github.com/awslabs/mcp/commit/f979d1f832fabcacd83166a292a09a547287735e "Update project to support Python 3.10 and above (#57) * Update project to support Python 3.10 and above - Tested functionality on Python 3.10 and newer version - Aligned project with MCP Python SDK requirements Quality assurance steps: - Ran 'ruff check .' to identify and fix linting issues - Applied 'ruff format .' to ensure consistent code formatting - Executed 'uv run --frozen pyright' for type checking * feat(.ruff.toml): adds shared ruff at the root of the repo\" --------- Co-authored-by: laithalsaadoon [email protected]") Apr 2, 2025
CHANGELOG.md CHANGELOG.md fix: remove sse from multiple mcp servers (#421) May 27, 2025
Dockerfile Dockerfile feat: shrink dockerfile (#833) Jul 18, 2025
LICENSE LICENSE feat: update project meta data (#121) Apr 13, 2025
NOTICE NOTICE feat: update project meta data (#121) Apr 13, 2025
README.md README.md chore: Adding VS code link to the readme (#823) Jul 16, 2025
docker-healthcheck.sh docker-healthcheck.sh feat: shrink dockerfile (#833) Jul 18, 2025
pyproject.toml pyproject.toml Automatic update of packages Jul 18, 2025
uv-requirements.txt uv-requirements.txt fix: pin pip via hashes in Dockerfile (#642) Jun 24, 2025
uv.lock uv.lock chore(deps): upgrade mcp dep (#851) Jul 17, 2025
View all files

README.md

Outline

AWS CDK MCP Server

MCP server for AWS Cloud Development Kit (CDK) best practices, infrastructure as code patterns, and security compliance with CDK Nag.

Features

CDK General Guidance

  • Prescriptive patterns with AWS Solutions Constructs and GenAI CDK libraries
  • Structured decision flow for choosing appropriate implementation approaches
  • Security automation through CDK Nag integration and Lambda Powertools

CDK Nag Integration

  • Work with CDK Nag rules for security and compliance
  • Explain specific CDK Nag rules with AWS Well-Architected guidance
  • Check if CDK code contains Nag suppressions that require human review

AWS Solutions Constructs

  • Search and discover AWS Solutions Constructs patterns
  • Find recommended patterns for common architecture needs
  • Get detailed documentation on Solutions Constructs

Generative AI CDK Constructs

  • Search for GenAI CDK constructs by name or type
  • Discover specialized constructs for AI/ML workloads
  • Get implementation guidance for generative AI applications

Lambda Layer Documentation Provider

  • Access comprehensive documentation for AWS Lambda layers
  • Get code examples for generic Lambda layers and Python-specific layers
  • Retrieve directory structure information and implementation best practices
  • Seamless integration with AWS Documentation MCP Server for detailed documentation

Amazon Bedrock Agent Schema Generation

  • Use this tool when creating Bedrock Agents with Action Groups that use Lambda functions
  • Streamline the creation of Bedrock Agent schemas
  • Convert code files to compatible OpenAPI specifications

Developer Notes

  • Requirements: Your Lambda function must use BedrockAgentResolver from AWS Lambda Powertools
  • Lambda Dependencies: If schema generation fails, a fallback script will be generated. If you see error messages about missing dependencies, install them and then run the script again.
  • Integration: Use the generated schema with bedrock.ApiSchema.fromLocalAsset() in your CDK code

CDK Implementation Workflow

This diagram provides a comprehensive view of the recommended CDK implementation workflow:

Loading

graph TD Start([Start]) --> A["CDKGeneralGuidance"] A --> Init["cdk init app"]

Init --> B{Choose Approach}
B -->|"Common Patterns"| C1["GetAwsSolutionsConstructPattern"]
B -->|"GenAI Features"| C2["SearchGenAICDKConstructs"]
B -->|"Custom Needs"| C3["Custom CDK Code"]

C1 --> D1["Implement Solutions Construct"]
C2 --> D2["Implement GenAI Constructs"]
C3 --> D3["Implement Custom Resources"]

%% Bedrock Agent with Action Groups specific flow
D2 -->|"For Bedrock Agents<br/>with Action Groups"| BA["Create Lambda with<br/>BedrockAgentResolver"]

%% Schema generation flow
BA --> BS["GenerateBedrockAgentSchema"]
BS -->|"Success"| JSON["openapi.json created"]
BS -->|"Import Errors"| BSF["Tool generates<br/>generate_schema.py"]
BSF -->|"Missing dependencies?"| InstallDeps["Install dependencies"]
InstallDeps --> BSR["Run script manually:<br/>python generate_schema.py"]
BSR --> JSON["openapi.json created"]

%% Use schema in Agent CDK
JSON --> AgentCDK["Use schema in<br/>Agent CDK code"]
AgentCDK --> D2

%% Conditional Lambda Powertools implementation
D1 & D2 & D3 --> HasLambda{"Using Lambda<br/>Functions?"}
HasLambda --> UseLayer{"Using Lambda<br/>Layers?"}
UseLayer -->|"Yes"| LLDP["LambdaLayerDocumentationProvider"]

HasLambda -->|"No"| SkipL["Skip"]

%% Rest of workflow
LLDP["LambdaLayerDocumentationProvider"] --> Synth["cdk synth"]
SkipL --> Synth

Synth --> Nag{"CDK Nag<br/>warnings?"}
Nag -->|Yes| E["ExplainCDKNagRule"]
Nag -->|No| Deploy["cdk deploy"]

E --> Fix["Fix or Add Suppressions"]
Fix --> CN["CheckCDKNagSuppressions"]
CN --> Synth

%% Styling with darker colors
classDef default fill:#424242,stroke:#ffffff,stroke-width:1px,color:#ffffff;
classDef cmd fill:#4a148c,stroke:#ffffff,stroke-width:1px,color:#ffffff;
classDef tool fill:#01579b,stroke:#ffffff,stroke-width:1px,color:#ffffff;
classDef note fill:#1b5e20,stroke:#ffffff,stroke-width:1px,color:#ffffff;
classDef output fill:#006064,stroke:#ffffff,stroke-width:1px,color:#ffffff;
classDef decision fill:#5d4037,stroke:#ffffff,stroke-width:1px,color:#ffffff;

class Init,Synth,Deploy,BSR cmd;
class A,C1,C2,BS,E,CN,LLDP tool;
class JSON output;
class HasLambda,UseLayer,Nag decision;

Available MCP Tools

  • CDKGeneralGuidance: Get prescriptive advice for building AWS applications with CDK
  • GetAwsSolutionsConstructPattern: Find vetted architecture patterns combining AWS services
  • SearchGenAICDKConstructs: Discover GenAI CDK constructs by name or features
  • GenerateBedrockAgentSchema: Create OpenAPI schemas for Bedrock Agent action groups
  • LambdaLayerDocumentationProvider: Access documentation for Lambda layers implementation
  • ExplainCDKNagRule: Get detailed guidance on CDK Nag security rules
  • CheckCDKNagSuppressions: Validate CDK Nag suppressions in your code

Available MCP Resources

  • CDK Nag Rules: Access rule packs via cdk-nag://rules/{rule_pack}
  • AWS Solutions Constructs: Access patterns via aws-solutions-constructs://{pattern_name}
  • GenAI CDK Constructs: Access documentation via genai-cdk-constructs://{construct_type}/{construct_name}
  • Lambda Powertools: Get guidance on Lambda Powertools via lambda-powertools://{topic}

Prerequisites

  1. Install uv from Astral or the GitHub README
  2. Install Python using uv python install 3.10
  3. Install AWS CDK CLI using npm install -g aws-cdk (Note: The MCP server itself doesn't use the CDK CLI directly, but it guides users through CDK application development that requires the CLI)

Installation

Cursor VS Code
Image 4: Install MCP Server Image 5: Install on VS Code

Configure the MCP server in your MCP client configuration (e.g., for Amazon Q Developer CLI, edit ~/.aws/amazonq/mcp.json):

undefinedjson { "mcpServers": { "awslabs.cdk-mcp-server": { "command": "uvx", "args": ["awslabs.cdk-mcp-server@latest"], "env": { "FASTMCP_LOG_LEVEL": "ERROR" }, "disabled": false, "autoApprove": [] } } } undefined

or docker after a successful docker build -t awslabs/cdk-mcp-server .:

undefinedjson { "mcpServers": { "awslabs.cdk-mcp-server": { "command": "docker", "args": [ "run", "--rm", "--interactive", "--env", "FASTMCP_LOG_LEVEL=ERROR", "awslabs/cdk-mcp-server:latest" ], "env": {}, "disabled": false, "autoApprove": [] } } } undefined

Security Considerations

When using this MCP server, you should consider:

  • Reviewing all CDK Nag warnings and errors manually
  • Fixing security issues rather than suppressing them whenever possible
  • Documenting clear justifications for any necessary suppressions
  • Using the CheckCDKNagSuppressions tool to verify no unauthorized suppressions exist

Before applying CDK NAG Suppressions, you should consider conducting your own independent assessment to ensure that your use would comply with your own specific security and quality control practices and standards, as well as the local laws, rules, and regulations that govern you and your content.

Footer

© 2025 GitHub,Inc.

Footer navigation

You can’t perform that action at this time.

# mcpServer Config

{
  "mcpServers": {
    "awslabs.cdk-mcp-server": {
      "command": "uvx",
      "args": [
        "awslabs.cdk-mcp-server@latest"
      ],
      "env": {
        "FASTMCP_LOG_LEVEL": "ERROR"
      },
      "disabled": false,
      "autoApprove": []
    }
  }
}

# stdio

uvx awslabs.cdk-mcp-server@latest
Transport:
stdio
Language:
python
Created: 3/21/2025
Updated: 1/31/2026