Install
$ agentstack add mcp-call518-mcp-ambari-api β scanned Β· β verified, works with Claude Code, Cursor, and more.
Security review
β PassedNo issues found. Passed automated security review. Β· v0.1.0 How review works β
- β Prompt-injection patterns
- β Secret / credential exfiltration
- β Dangerous shell & filesystem operations
- β Untrusted network calls
- β Known-malicious package signatures
What it can access
- β Network access No
- β Filesystem access No
- β Shell / process execution No
- β Environment & secrets Used
- β Dynamic code execution No
From automated source analysis of v0.1.0. βUsedβ means the capability is present in the source β more access means more to trust, not that itβs unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work βAbout
MCP Ambari API - Apache Hadoop Cluster Management Automation
> π Automate Apache Ambari operations with AI/LLM: Conversational control for Hadoop cluster management, service monitoring, configuration inspection, and precise Ambari Metrics queries via Model Context Protocol (MCP) tools.
[](https://opensource.org/licenses/MIT)
[](https://www.buymeacoffee.com/call518)
[](https://github.com/call518/MCP-Ambari-API/actions/workflows/pypi-publish.yml)
Architecture & Internal (DeepWiki)
[](https://deepwiki.com/call518/MCP-Ambari-API)
π Overview
MCP Ambari API is a powerful Model Context Protocol (MCP) server that enables seamless Apache Ambari cluster management through natural language commands. Built for DevOps engineers, data engineers, and system administrators who work with Hadoop ecosystems.
Features
- β Interactive Ambari Operations Hub β Provides an MCP-based foundation for querying and managing services through natural language instead of console or UI interfaces.
- β Real-time Cluster Visibility β Comprehensive view of key metrics including service status, host details, alert history, and ongoing requests in a single interface.
- β Metrics Intelligence Pipeline β Dynamically discovers and filters AMS appIds and metric names, connecting directly to time-series analysis workflows.
- β Automated Operations Workflow β Consolidates repetitive start/stop operations, configuration checks, user queries, and request tracking into consistent scenarios.
- β Built-in Operational Reports β Instantly delivers dfsadmin-style HDFS reports, service summaries, and capacity metrics through LLM or CLI interfaces.
- β Safety Guards and Guardrails β Requires user confirmation before large-scale operations and provides clear guidance for risky commands through prompt templates.
- β LLM Integration Optimization β Includes natural language examples, parameter mapping, and usage guides to ensure stable AI agent operations.
- β Flexible Deployment Models β Supports stdio/streamable-http transport, Docker Compose, and token authentication for deployment across development and production environments.
- β Performance-Oriented Caching Architecture β Built-in AMS metadata cache and request logging ensure fast responses even in large-scale clusters.
- β Scalable Code Architecture β Asynchronous HTTP, structured logging, and modularized tool layers enable easy addition of new features.
- β Production-Validated β Based on tools validated in test Ambari clusters, ready for immediate use in production environments.
- β Diversified Deployment Channels β Available through PyPI packages, Docker images, and other preferred deployment methods.
Docuement for Airflow REST-API
Topics
apache-ambari hadoop-cluster mcp-server cluster-automation devops-tools big-data infrastructure-management ai-automation llm-tools python-mcp
Example Queries - Cluster Info/Status
[Go to More Example Queries](./src/mcpambariapi/prompt_template.md#9-example-queries)
π QuickStart Guide /w Docker
> Note: The following instructions assume you are using the streamable-http mode for MCP Server.
Flow Diagram of Quickstart/Tutorial
1. Prepare Ambari Cluster (Test Target)
To set up a Ambari Demo cluster, follow the guide at: Install Ambari 3.0 with Docker
2. Run Docker-Compose
Start the MCP-Server, MCPO(MCP-Proxy for OpenAPI), and OpenWebUI.
- Ensure Docker and Docker Compose are installed on your system.
- Clone this repository and navigate to its root directory.
- Set up environment configuration:
``bash # Copy environment template and configure your settings cp .env.example .env # Edit .env with your Ambari cluster information ``
- Configure your Ambari connection in
.envfile:
```bash # Ambari cluster connection AMBARIHOST=host.docker.internal AMBARIPORT=7070 AMBARIUSER=admin AMBARIPASS=admin AMBARICLUSTERNAME=TEST-AMBARI
# Ambari Metrics (AMS) collector AMBARIMETRICSHOST=host.docker.internal AMBARIMETRICSPORT=16188 AMBARIMETRICSPROTOCOL=http AMBARIMETRICSTIMEOUT=15
# (Optional) Enable authentication for streamable-http mode # Recommended for production environments REMOTEAUTHENABLE=false REMOTESECRETKEY=your-secure-secret-key-here ```
- Run:
``bash docker-compose up -d ``
- OpenWebUI will be available at:
http://localhost:${DOCKER_EXTERNAL_PORT_OPENWEBUI}(default: 3001) - The MCPO-Proxy will be accessible at:
http://localhost:${DOCKER_EXTERNAL_PORT_MCPO_PROXY}(default: 8001) - The MCPO API Docs:
http://localhost:${DOCKER_EXTERNAL_PORT_MCPO_PROXY}/mcp-ambari-api/docs
3. Registering the Tool in OpenWebUI
> π Note: Web-UI configuration instructions are based on OpenWebUI v0.6.22. Menu locations and settings may differ in newer versions.
- logging in to OpenWebUI with an admin account
- go to "Settings" β "Tools" from the top menu.
- Enter the
mcp-ambari-apiTool address (e.g.,http://localhost:8000/mcp-ambari-api) to connect MCP Tools with your Ambari cluster.
4. More Examples: Using MCP Tools to Query Ambari Cluster
Below is an example screenshot showing how to query the Ambari cluster using MCP Tools in OpenWebUI:
Example Query - Cluster Configuration Review & Recommendations
Example Query - Restart HDFS Service
π Metrics & Trends
- Terminology quick reference
- appId: Ambari Metrics Service groups every metric under an application identifier (e.g.,
namenode,datanode,ambari_server,HOST). Think of it as the component or service emitting that timeseries. - metric name: The fully qualified string Ambari uses for each timeseries (e.g.,
jvm.JvmMetrics.MemHeapUsedM,dfs.datanode.BytesWritten). Exact names are required when querying AMS.
list_common_metrics_catalog: keyword search against the live metadata-backed metric catalog (cached locally). Usesearch="heap"or similar to narrow suggestions before running a time-series query.
Example: βShow the heap-related metrics available for the NameNode appId.β
list_ambari_metric_apps: list discovered AMSappIdvalues, optionally including metric counts; passrefresh=trueorlimitto control output.
Example: βList every appId currently exposed by AMS.β
- The natural-language query βAMSμμ μ¬μ© κ°λ₯ν appId λͺ©λ‘λ§ λ³΄μ¬μ€β maps to
list_ambari_metric_appsand returns the exact identifiers you can copy into other tools. list_ambari_metrics_metadata: raw AMS metadata explorer (supportsapp_id,metric_name_filter,host_filter,search, adjustablelimit, default 50).
Example: βGive me CPU-related metric metadata under HOST.β
query_ambari_metrics: fetch time-series data; the tool auto-selects curated metric names, falls back to metadata search when needed, and honors Ambari's default precision unless you explicitly supplyprecision="SECONDS", etc.
Examples: βPlot the last 30 minutes of jvm.JvmMetrics.MemHeapUsedM for the NameNode.β / βCompare jvm.JvmMetrics.MemHeapUsedM for DataNode hosts bigtop-hostname0.demo.local and bigtop-hostname1.demo.local over the past 30 minutes.β
hdfs_dfadmin_report: produce a DFSAdmin-style capacity/DataNode summary (mirrorshdfs dfsadmin -report).
Live Metric Catalog (via AMS metadata)
- Metric names are discovered on demand from
/ws/v1/timeline/metrics/metadataand cached for quick reuse. - Use
list_common_metrics_catalogor theambari-metrics://catalog/allresource (append?refresh=trueto bypass the cache) to inspect the latestappId β metricmapping. Queryambari-metrics://catalog/appsto list appIds orambari-metrics://catalog/for a single app. - Typical appIds include
ambari_server,namenode,datanode,nodemanager,resourcemanager, andHOST, but the list adapts to whatever the Ambari Metrics service advertises in your cluster.
π Ambari Metrics Query Requirements (Exact-Match Workflow)
Recent updates removed natural-language metric guessing in favor of deterministic, catalog-driven lookups. Keep the following rules in mind when you (or an LLM agent) call query_ambari_metrics:
- Always pass an explicit
app_id. If it is missing or unsupported, the tool returns a list of valid appIds and aborts so you can choose one manually. - Specify exact metric names. Use
list_common_metrics_catalog(app_id="", search="keyword"),list_ambari_metric_apps(to discover appIds), or theambari-metrics://catalog/resource to browse the live per-app metric set and copy the identifier (e.g.,jvm.JvmMetrics.MemHeapUsedM). - Host-scope behavior: When
hostnamesis omitted the API returns cluster-wide aggregates. Provide one or more hosts (comma-separated) to focus on specific nodes. - No fuzzy matches. The server now calls Ambari exactly as requested. If the metric is wrong or empty, Ambari will simply return no datapointsβdouble-check the identifier via
/ws/v1/timeline/metrics/metadata.
Example invocation:
query_ambari_metrics(
metric_names="jvm.JvmMetrics.MemHeapUsedM",
app_id="nodemanager",
duration="1h",
group_by_host=true
)
For multi-metric lookups, pass a comma-separated list of exact names. Responses document any auto-applied host filters so you can copy/paste them into subsequent requests.
π Usage & Configuration
This MCP server supports two connection modes: stdio (traditional) and streamable-http (Docker-based). You can configure the transport mode using CLI arguments or environment variables.
Configuration Priority: CLI arguments > Environment variables > Default values
CLI Arguments
--type(-t): Transport type (stdioorstreamable-http) - Default:stdio--host: Host address for HTTP transport - Default:127.0.0.1--port(-p): Port number for HTTP transport - Default:8000--auth-enable: Enable Bearer token authentication for streamable-http mode - Default:false--secret-key: Secret key for Bearer token authentication (required when auth enabled)
Environment Variables
| Variable | Description | Default | Project Default | |----------|-------------|---------|-----------------| | PYTHONPATH | Python module search path for MCP server imports | - | /app/src | | MCP_LOG_LEVEL | Server logging verbosity (DEBUG, INFO, WARNING, ERROR) | INFO | INFO | | FASTMCP_TYPE | MCP transport protocol (stdio for CLI, streamable-http for web) | stdio | streamable-http | | FASTMCP_HOST | HTTP server bind address (0.0.0.0 for all interfaces) | 127.0.0.1 | 0.0.0.0 | | FASTMCP_PORT | HTTP server port for MCP communication | 8000 | 8000 | | REMOTE_AUTH_ENABLE | Enable Bearer token authentication for streamable-http modeDefault: false (if undefined, empty, or null) | false | false | | REMOTE_SECRET_KEY | Secret key for Bearer token authenticationRequired when REMOTEAUTHENABLE=true | - | your-secret-key-here | | AMBARI_HOST | Ambari server hostname or IP address | 127.0.0.1 | host.docker.internal | | AMBARI_PORT | Ambari server port number | 8080 | 8080 | | AMBARI_USER | Username for Ambari server authentication | admin | admin | | AMBARI_PASS | Password for Ambari server authentication | admin | admin | | AMBARI_CLUSTER_NAME | Name of the target Ambari cluster | TEST-AMBARI | TEST-AMBARI | | DOCKER_EXTERNAL_PORT_OPENWEBUI | Host port mapping for Open WebUI container | 8080 | 3001 | | DOCKER_EXTERNAL_PORT_MCP_SERVER | Host port mapping for MCP server container | 8080 | 18001 | | DOCKER_EXTERNAL_PORT_MCPO_PROXY | Host port mapping for MCPO proxy container | 8000 | 8001 |
Note: AMBARI_CLUSTER_NAME serves as the default target cluster for operations when no specific cluster is specified. All environment variables can be configured via the .env file.
Transport Selection Logic:
Configuration Priority: CLI arguments > Environment variables > Default values
Transport Selection Logic:
- CLI Priority:
--type streamable-http --host 0.0.0.0 --port 18001 - Environment Priority:
FASTMCP_TYPE=streamable-http FASTMCP_HOST=0.0.0.0 FASTMCP_PORT=18001 - Legacy Support:
FASTMCP_PORT=18001(automatically enables streamable-http mode) - Default:
stdiomode when no configuration is provided
Environment Setup
# 1. Clone the repository
git clone https://github.com/call518/MCP-Ambari-API.git
cd MCP-Ambari-API
# 2. Set up environment configuration
cp .env.example .env
# 3. Configure your Ambari connection in .env file
AMBARI_HOST=your-ambari-host
AMBARI_PORT=your-ambari-port
AMBARI_USER=your-username
AMBARI_PASS=your-password
AMBARI_CLUSTER_NAME=your-cluster-name
π Security & Authentication
Bearer Token Authentication
For streamable-http mode, this MCP server supports Bearer token authentication to secure remote access. This is especially important when running the server in production environments.
Configuration
Enable Authentication:
# In .env file
REMOTE_AUTH_ENABLE=true
REMOTE_SECRET_KEY=your-secure-secret-key-here
Or via CLI:
python -m mcp_ambari_api --type streamable-http --auth-enable --secret-key your-secure-secret-key-here
Security Levels
- stdio mode (Default): Local-only access, no authentication needed
- streamable-http + REMOTEAUTHENABLE=false/undefined: Remote access without authentication β οΈ NOT RECOMMENDED for production
- streamable-http + REMOTEAUTHENABLE=true: Remote access with Bearer token authentication β RECOMMENDED for production
> π Default Policy: REMOTE_AUTH_ENABLE defaults to false if undefined, empty, or null. This ensures the server starts even without explicit authentication configuration.
Client Configuration
When authentication is enabled, MCP clients must include the Bearer token in the Authorization header:
{
"mcpServers": {
"mcp-ambari-api": {
"type": "streamable-http",
"url": "http://your-server:8000/mcp",
"headers": {
"Authorization": "Bearer your-secure-secret-key-here"
}
}
}
}
Security Best Practices
- Always enable authentication when using streamable-http mode in production
- Use strong, randomly generated secret keys (32+ characters recommended)
- Use HTTPS when possible (configure reverse proxy with SSL/TLS)
- Restrict network access using firewalls or network policies
- Rotate secret keys regularly for enhanced security
- Monitor access logs for unauthorized access attempts
Error Handling
When authentication fails, the server returns:
- 401 Unauthorized for missing or invalid tokens
- Detailed error messages in JSON format for debugging
Method 1: Local MCP (transport="stdio")
{
"mcpServers": {
"mcp-ambari-api": {
"command": "uvx",
"args": ["--python", "3.12", "mcp-ambari-api"],
"env": {
"AMBARI_HOST": "host.docker.internal",
"AMBARI_PORT": "8080",
"AMBARI_USER": "admin",
"AMBARI_PASS": "admin",
"AMBARI_CLUSTER_NAME": "TEST-AMBARI",
"MCP_LOG_LEVEL": "INFO"
}
}
}
}
Method 2: Remote MCP (transport="streamable-http")
On MCP-Client Host:
{
"mcpServers": {
"mcp-ambari-api": {
"type": "streamable-http",
"url": "http://localhost:18001/mcp"
}
}
}
With Bearer Token Authentication (Recommended for production):
{
"mcpServers": {
"mcp-ambari-api": {
"type": "streamabl
β¦
## Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source β we do not rehost the code.
- **Author:** [call518](https://github.com/call518)
- **Source:** [call518/MCP-Ambari-API](https://github.com/call518/MCP-Ambari-API)
- **License:** MIT
- **Homepage:** https://deepwiki.com/call518/MCP-Ambari-API
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.