InsideOut (Riley)
What this MCP does
Guides cloud architecture design and generates, plans, deploys, inspects, monitors, and destroys AWS or GCP infrastructure through Terraform workflows.
Tools
Input schema
{'type': 'object', 'required': ['session_id', 'service', 'action', 'filters', 'detail', 'raw'], 'properties': {'raw': {'type': 'boolean', 'description': "When true, returns the unprocessed AWS API response. Escape hatch for fields the summarized response doesn't surface."}, 'action': {'type': 'string', 'description': "Operation on the service. Examples: 'describe-instances' (ec2), 'list-buckets' (s3), 'list-keys' (kms), 'get-cost-summary' (cost-explorer), 'list-actions' (discovery), 'list-metrics' / 'get-metrics' (CloudWatch)."}, 'detail': {'type': 'boolean', 'description': 'When true, returns full metadata for a single resource (requires a resource ID in filters). When false (default), returns a summary.'}, 'filters': {'type': 'string', 'description': 'Optional JSON-encoded filter object passed through to the underlying AWS API. Examples: \'{"hours":6}\' for metric windows, \'{"days":7,"granularity":"DAILY"}\' for cost queries.'}, 'service': {'enum': ['account', 'acm', 'alb', 'apigateway', 'apprunner', 'backup', 'bedrock', 'cloudfront', 'cloudwatchlogs', 'cognito', 'cost-explorer', 'dynamodb', 'ebs', 'ec2', 'ecs', 'eks', 'elasticache', 'kms', 'lambda', 'msk', 'opensearch', 'rds', 'route53', 's3', 'sagemaker', 'secretsmanager', 'sqs', 'vpc', 'waf'], 'type': 'string', 'description': "AWS service to query. Examples: 'ec2', 'rds', 'vpc', 's3', 'lambda', 'eks', 'ecs', 'cost-explorer'. Use action='list-actions' to discover the supported actions for a service."}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing. The session must have an AWS deploy attempt before inspect probes will succeed.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id', 'subs'], 'properties': {'subs': {'type': ['null', 'array'], 'items': {'type': 'object', 'required': ['service', 'action'], 'properties': {'action': {'type': 'string', 'description': "Operation on the service (e.g. 'describe-instances', 'list-buckets', 'list-actions' for discovery, 'list-metrics' / 'get-metrics' for time-series)."}, 'filters': {'type': 'string', 'description': 'Optional JSON-encoded filter object passed through to the underlying API. Examples: \'{"hours":6}\' for metric windows, \'{"days":7}\' for cost queries.'}, 'service': {'enum': ['account', 'acm', 'alb', 'apigateway', 'apprunner', 'backup', 'bedrock', 'cloudfront', 'cloudwatchlogs', 'cognito', 'cost-explorer', 'dynamodb', 'ebs', 'ec2', 'ecs', 'eks', 'elasticache', 'kms', 'lambda', 'msk', 'opensearch', 'rds', 'route53', 's3', 'sagemaker', 'secretsmanager', 'sqs', 'vpc', 'waf'], 'type': 'string', 'description': "Cloud service to query (e.g. 'ec2', 'rds', 's3' for AWS; 'compute', 'storage', 'cloudsql' for GCP). Use the singular awsinspect/gcpinspect tool with action='list-actions' to discover supported services."}}, 'additionalProperties': False}, 'maxItems': 32, 'minItems': 1, 'description': 'Up to 32 sub-probes, each with {service, action, filters?, detail?, raw?}. The backend fetches credentials once per batch and fans out probes in parallel (concurrency 8, 30s per-sub timeout, 60s total wall clock). Partial failure is expected â\x80\x94 inspect each result.ok independently.'}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing. The session must have an AWS deploy attempt before inspect probes will succeed.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id'], 'properties': {'timeout': {'type': ['null', 'integer'], 'maximum': 55, 'minimum': 1, 'description': 'Max seconds to wait. Default 50, max 55.'}, 'message_id': {'type': 'string', 'description': 'Optional message ID from a convoreply timeout error. Not required for normal turn-based flow.'}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id'], 'properties': {'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'properties': {'source': {'type': 'string', 'description': "IDE/tool identifier so the connect screen can show the right 'Open {IDE}' button. Use lowercase: 'claude-code', 'codex', 'antigravity', 'kiro', 'cursor', 'vscode', 'windsurf', 'zed', 'aider', 'copilot', 'web', 'mcp'."}, 'github_username': {'type': 'string', 'description': 'GitHub username used for deploy commit attribution; pre-fills the GitHub username field on the connect screen.'}, 'project_context': {'type': 'string', 'description': "Optional tech-stack summary so Riley can skip discovery questions (e.g. 'Next.js 14 + Postgres on AWS, ~50k MAU'). No PII, secrets, file paths, or source code â\x80\x94 only general metadata useful to a cloud architect."}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id', 'text'], 'properties': {'text': {'type': 'string', 'maxLength': 20000, 'minLength': 1, 'description': 'User message to send to Riley. Forward verbatim what the user said â\x80\x94 do not summarize or rewrite.'}, 'retry': {'type': ['null', 'boolean'], 'description': 'When true, re-send the most recent user turn instead of submitting a new one.'}, 'timeout': {'type': ['null', 'integer'], 'maximum': 55, 'minimum': 1, 'description': "Max seconds to wait for Riley's response. Default 50, max 55."}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing.'}, 'project_context': {'type': 'string', 'description': "Only NEW project details revealed after convoopen (e.g. user mentions a new constraint mid-conversation). Don't re-send context already provided in convoopen. No PII or secrets."}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id'], 'properties': {'job_id': {'type': 'string', 'description': 'Optional. Specific job ID to inspect. When omitted, returns the status of the latest job for the session.'}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id'], 'properties': {'cloud': {'enum': ['aws', 'gcp'], 'type': 'string', 'description': "Cloud provider whose credentials are awaited: 'aws' or 'gcp'. Defaults to 'aws'."}, 'timeout': {'type': ['null', 'integer'], 'maximum': 600, 'minimum': 1, 'description': 'Max seconds to wait for the user to complete the browser-based credential connect flow. Default 300, max 600.'}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id', 'service', 'action', 'filters', 'detail', 'raw'], 'properties': {'raw': {'type': 'boolean', 'description': "When true, returns the unprocessed GCP API response. Escape hatch for fields the summarized response doesn't surface."}, 'action': {'type': 'string', 'description': "Operation on the service. Examples: 'list-instances' (compute), 'list-buckets' (storage), 'list-clusters' (gke), 'list-actions' (discovery), 'list-metrics' / 'get-metrics' (Cloud Monitoring)."}, 'detail': {'type': 'boolean', 'description': 'When true, returns full metadata for a single resource. When false (default), returns a summary.'}, 'filters': {'type': 'string', 'description': 'Optional JSON-encoded filter object passed through to the underlying GCP API. Examples: \'{"hours":6}\' for metric windows, \'{"zone":"us-central1-a"}\' for zone-scoped queries.'}, 'service': {'enum': ['apigateway', 'bastion', 'billing', 'certificatemanager', 'cloudarmor', 'cloudbuild', 'cloudcdn', 'clouddeploy', 'clouddns', 'cloudfunctions', 'cloudkms', 'cloudlogging', 'cloudmonitoring', 'cloudrun', 'cloudsql', 'compute', 'firestore', 'gcs', 'gke', 'iam', 'identityplatform', 'loadbalancer', 'memorystore', 'pubsub', 'secretmanager', 'vertexai', 'vpc'], 'type': 'string', 'description': "GCP service to query. Examples: 'compute', 'storage', 'cloudsql', 'gke', 'cloudrun', 'pubsub', 'firestore'. Use action='list-actions' to discover supported actions for a service."}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing. The session must have a GCP deploy attempt before inspect probes will succeed.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id', 'subs'], 'properties': {'subs': {'type': ['null', 'array'], 'items': {'type': 'object', 'required': ['service', 'action'], 'properties': {'action': {'type': 'string', 'description': "Operation on the service (e.g. 'describe-instances', 'list-buckets', 'list-actions' for discovery, 'list-metrics' / 'get-metrics' for time-series)."}, 'filters': {'type': 'string', 'description': 'Optional JSON-encoded filter object passed through to the underlying API. Examples: \'{"hours":6}\' for metric windows, \'{"days":7}\' for cost queries.'}, 'service': {'enum': ['apigateway', 'bastion', 'billing', 'certificatemanager', 'cloudarmor', 'cloudbuild', 'cloudcdn', 'clouddeploy', 'clouddns', 'cloudfunctions', 'cloudkms', 'cloudlogging', 'cloudmonitoring', 'cloudrun', 'cloudsql', 'compute', 'firestore', 'gcs', 'gke', 'iam', 'identityplatform', 'loadbalancer', 'memorystore', 'pubsub', 'secretmanager', 'vertexai', 'vpc'], 'type': 'string', 'description': "Cloud service to query (e.g. 'ec2', 'rds', 's3' for AWS; 'compute', 'storage', 'cloudsql' for GCP). Use the singular awsinspect/gcpinspect tool with action='list-actions' to discover supported services."}}, 'additionalProperties': False}, 'maxItems': 32, 'minItems': 1, 'description': 'Up to 32 sub-probes, each with {service, action, filters?, detail?, raw?}. The backend fetches credentials once per batch and fans out probes in parallel (concurrency 8, 30s per-sub timeout, 60s total wall clock). Partial failure is expected â\x80\x94 inspect each result.ok independently.'}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing. The session must have a GCP deploy attempt before inspect probes will succeed.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'properties': {'section': {'enum': ['workflow', 'tools', 'examples', 'inspect'], 'type': 'string', 'description': "Optional section to focus the response. One of: 'workflow', 'tools', 'examples', 'inspect'. When omitted, returns a compact overview (~500 tokens)."}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id'], 'properties': {'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing.'}, 'to_version': {'type': ['null', 'integer'], 'description': 'Ending stack version number for the diff. Defaults to the current draft.'}, 'from_version': {'type': ['null', 'integer'], 'description': 'Starting stack version number for the diff. Defaults to the latest applied version.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id', 'version'], 'properties': {'version': {'type': 'integer', 'description': 'Target stack version number to roll back to. Use stackversions to list available versions.'}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id'], 'properties': {'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id', 'category', 'message'], 'properties': {'source': {'enum': ['mcp', 'cli', 'web'], 'type': 'string', 'description': "Optional source channel: 'mcp', 'cli', or 'web'."}, 'message': {'type': 'string', 'maxLength': 10000, 'minLength': 1, 'description': 'Feedback content. Free-form text describing the issue, request, or comment.'}, 'category': {'enum': ['bug_report', 'feature_request', 'general_feedback', 'question'], 'type': 'string', 'description': 'Feedback category. One of: bug_report, feature_request, general_feedback, question.'}, 'initiator': {'enum': ['user', 'agent'], 'type': 'string', 'description': "Optional originator: 'user' (human triggered) or 'agent' (automated)."}, 'user_name': {'type': 'string', 'description': 'Optional display name for attribution.'}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing. Identifies the conversation the feedback is about.'}, 'user_email': {'type': 'string', 'format': 'email', 'description': 'Optional email address for follow-up.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id'], 'properties': {'plan_id': {'type': 'string', 'description': 'Apply a previously created plan from tfplan. When set, project_id should also be provided.'}, 'sandbox': {'type': ['null', 'boolean'], 'description': 'When true (default for MCP), deploys a small sandbox stack instead of the real generated Terraform. Set false to deploy the actual user stack.'}, 'version': {'type': ['null', 'integer'], 'description': 'Deploy a specific stack version number. Defaults to the current draft.'}, 'force_new': {'type': ['null', 'boolean'], 'description': 'When true, bypass the session-level single-flight guard and start a new deploy even if another job is in flight. Use only when an existing run is provably wedged.'}, 'project_id': {'type': 'string', 'description': 'Project ID returned by tfplan. Required alongside plan_id.'}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing.'}, 'ignore_drift': {'type': ['null', 'boolean'], 'description': 'When true, proceed with deploy even if drift is detected on the existing stack.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id'], 'properties': {'force_new': {'type': ['null', 'boolean'], 'description': 'When true, bypass the single-flight guard and force a new destroy even if another job is in flight.'}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing. The deployed stack for this session will be torn down.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id'], 'properties': {'force_new': {'type': ['null', 'boolean'], 'description': 'When true, bypass the single-flight guard and force a new drift check even if another job is in flight.'}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id'], 'properties': {'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing. Riley must have signaled [TERRAFORM_READY: true] before calling this tool.'}, 'include_code': {'type': ['null', 'boolean'], 'description': "When true, the response inlines the full generated Terraform source. Use as a fallback when the host can't read the on-disk archive (sandbox or security restrictions)."}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id'], 'properties': {'tail': {'type': ['null', 'integer'], 'maximum': 10000, 'minimum': 0, 'description': 'Return only the last N log entries. Use 0 (or omit) for all available entries.'}, 'job_id': {'type': 'string', 'description': 'Optional. Target a specific job. Use tfruns to discover job IDs. When omitted, streams the latest job for the session.'}, 'timeout': {'type': ['null', 'integer'], 'maximum': 55, 'minimum': 1, 'description': 'Max seconds to collect logs. Default 50, max 55.'}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing.'}, 'last_event_id': {'type': 'string', 'description': 'Resume cursor for pagination. Pass back the last_event_id from a previous tflogs response to fetch only newer entries.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id'], 'properties': {'job_id': {'type': 'string', 'description': 'Optional. Specific job ID to fetch outputs from. When omitted, returns outputs from the latest successful apply.'}, 'lifecycle': {'type': 'string', 'description': "Optional Oracle deploy-step filter for the outputs. Common values are 'provision', 'cloud-provision', 'k8s-provision' â\x80\x94 these correspond to the lifecycle stages of the deployed stack. When omitted, returns outputs from all lifecycle steps."}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id'], 'properties': {'sandbox': {'type': ['null', 'boolean'], 'description': 'When true, plan against the sandbox stack; when false (default), plan the real generated Terraform.'}, 'force_new': {'type': ['null', 'boolean'], 'description': 'When true, bypass the single-flight guard and force a new plan even if one is already running.'}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id'], 'properties': {'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing. Returns the deployment-job history (apply / destroy / plan / drift) for this session.'}}, 'additionalProperties': False}
Input schema
{'type': 'object', 'required': ['session_id'], 'properties': {'job_id': {'type': 'string', 'description': 'Optional. Specific job ID to inspect. When omitted, returns the status of the latest job for the session.'}, 'session_id': {'type': 'string', 'pattern': '^sess_v2_[0-9A-Za-z]+\\?token=[0-9a-f]+$', 'description': 'Session ID from convoopen â\x80\x94 pass back EXACTLY as returned, including the ?token=... suffix (format: sess_v2_*?token=*). The suffix is part of the session credential; never strip it when summarizing.'}}, 'additionalProperties': False}
Recent tool changes
Similar MCP servers
shiply
Publishes and manages web applications with SQL databases, serverless functions, domains, email tests, client intake, contracts, …
Fine Structure
Builds and hosts full-stack applications from prompts and supports agent communication through WhatsApp and email.
mcp
Provisions and manages cloud instances, networks, storage, databases, backups, VPNs, application deployments, and autocoding-agen…
EchoRelay
Manages a hosted API relay runtime, including projects, endpoints, credentials, publishing, keys, delivery logs, and dead-letter …
Supero
Builds, validates, publishes, tests, and deploys multi-tenant applications with schemas, CRUD operations, external data connector…
Replicate
Provides access to Replicate models, versions, collections, hardware, predictions, and deployments for running and managing hoste…
Relin
Configures webhook sources and destinations, monitors delivery health, investigates failures, manages retries, and replays events.
Scalix Cloud
Provides managed databases, SQL tools, container builds, persistent Linux machines, domains, scheduled functions, storage, and pr…