Sao Platform

general MCP Server

Zero-egress autonomous incident response for AWS — Knowledge Graph + Bedrock PrivateLink + HITL approval. No AI traffic ever leaves your VPC.

Verified
generalgeneralaws
5 views0 stars0 forksNOASSERTION

Why This Matters

Discovered via github-topic:mcp-server and last synced 4mo ago.

Verified
Source
github-topic:mcp-server
Stars
0
Last synced
4mo ago
Install
Check source

Install

Install instructions not detected yet

Check the source repository for the latest setup steps.

View source instructions
50
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (50)

sao_validate_action

Checks governance + node lock before executing any action

sao_execute_action

Executes approved action via resource plugin, writes precedent

Component

Tokens

Audit

CloudTrail — S3 WORM + KMS

ECSPlugin

scale_desired, force_new_deployment, stop_service

Terraform

>= 1.5

sao_load_context

Loads full Digital Twin context for an incident node

MEDIUM

ECS force-new-deployment, Lambda concurrency

Healthtech

HIPAA

Plugin

Actions

Pending

--- ## Relation to aws-sovereign-ops [aws-sovereign-ops](https://github.com/kratosvil/aws-sovereign-ops) is the v1 demo that validated the concept (4/4 Lambda e2e scenarios passed). SAO Platform is the architectural evolution — the Digital Twin Context Map replaces manual context collection and enables zero-hallucination reasoning at scale. --- ## Prerequisites

Layer

Contents

Phase

Description

IAM

Least-privilege — no IAM write, no billing, no root

IaC

Terraform >= 1.5, S3 remote backend

LambdaPlugin

update_timeout, update_memory, update_concurrency

Python

>= 3.12

GET

`/debug/context/{node_id}`

ecs_restart_service

`cluster`, `service`

Resource

Name

Variable

What to set

Fintech

SOC2 / PCI-DSS

POST

`/debug/prompt`

ecs_update_desired_count

`cluster`, `service`, `desired_count`

ECR

`<account-id>.dkr.ecr.<region>.amazonaws.com/sao-mcp-server`

graph_bucket_name

New unique S3 bucket name (Terraform creates it)

RAG

Amazon Titan Embeddings v1 (1536 dims) + cosine similarity (Python)

Method

Path

lambda_update_reserved_concurrency

`function_name`, `reserved_concurrent_executions`

rds_reboot_instance

`db_instance_identifier`

HIGH

RDS operations, service stop

Docker

latest

tfstate_bucket_name

Existing S3 bucket where your tfstate lives

Industry

Compliance

sao_graph_status

Current Digital Twin summary (nodes, edges, locks, precedent count)

lambda_update_memory

`function_name`, `memory_size`

latest

Configured with credentials for the target account

Symptom

Cause

none

`reason`

Tool

Version

operator_email

Email that receives APPROVE/REJECT HITL links

SOC2

Reduce MTTR without manual on-call toil

Action

Parameters

Examples

Approval

bedrock_model_id

Must be `us.anthropic.claude-sonnet-4-6` — see note below

Manual

**Why this matters:** when Bedrock proposes a fix, it sees the exact network topology, knows which actions are governance-blocked, and retrieves semantically similar past incidents via RAG. Impossible or dangerous proposals are structurally prevented, not prompt-engineered away. --- ## Semantic RAG on Precedents (Phase 8) After each approved and executed fix, the Lambda HITL Executor registers a precedent with a vector embedding: ``` incident query → Titan Embeddings (amazon.titan-embed-text-v1, 1536 dims) ↓ cosine similarity against all stored precedents ↓ top-k most similar past incidents injected into Bedrock context ``` Validated: `similarity_score=0.8484` on same-type incident replay. The system gets smarter with every resolved incident without retraining. --- ## Tech Stack

lambda_update_timeout

`function_name`, `timeout`

LOW

Lambda timeout/memory update

tfstate_kms_key_arn

Only if your tfstate bucket uses SSE-KMS

Government

FedRAMP