MCP server for managing BOSH deployments, VMs, stemcells, releases, and related infrastructure operations
The BOSH MCP server provides 18 well-structured tools with consistent naming following verb_noun patterns (bosh_list_*, bosh_get_*, bosh_delete_*, etc.). All tools have descriptions and input schemas with typed parameters. However, there are significant gaps in output schema documentation, error handling guidance, and parameter constraints. Most parameter descriptions are minimal (10-30 chars), and many tools lack enum constraints for restricted values. No evidence of confirmation/dry-run patterns for destructive operations beyond a confirmation token parameter. The server lacks error categorization and recovery guidance per the pattern:recovery-guide. Overall, the tools are functional but fall short of production-grade LLM-optimized definitions.
Delete a deployment (requires confirmation token for safety)
Get the current cloud configuration
Get the current CPI configuration
List all runtime configurations
Get details of a specific BOSH task
Get output of a completed BOSH task
List all BOSH deployments
Output schemas not documented. Tool descriptions state what they do but do not specify the structure of returned data (fields, types, pagination). LLMs cannot infer downstream chaining without explicit response documentation.
Parameter descriptions are too minimal (10-30 chars). E.g. 'Named environment to use (optional, uses default if not specified)' is good, but 'Filter by task state' lacks acceptable values. 'Deployment name' does not explain format constraints. LLMs cannot determine valid inputs without richer descriptions.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
List instances with process details in a deployment
List current deployment locks
List all uploaded releases
List all uploaded stemcells
List BOSH tasks with optional filtering
List variables for a deployment
List VMs in a deployment
Recreate VMs for a deployment or specific job (requires confirmation token)
Restart a deployment or specific job
Start a deployment or specific job
Stop a deployment or specific job (requires confirmation token)
State parameter in bosh_list_tasks lacks enum constraint. Description says 'Filter by task state (queued, processing, done, error, etc.)' but does not enforce the allowed set. LLM will guess valid states and pass invalid values.
Type parameter in bosh_get_task_output lacks enum. Description says '(result or event, default: result)' but does not declare enum values. Should have explicit type: enum with ['result', 'event'].
Destructive tools (bosh_delete_deployment, bosh_stop, bosh_restart) rely on a 'confirm' parameter for safety, but no explicit dry-run or preview step is documented. LLMs cannot see consequences before committing. Confirmation token pattern is present but error handling and recovery guidance are absent.
No error handling guidance documented. Tools do not specify what errors they may return, whether errors are retryable, or what the LLM should do next. E.g., what happens if a deployment is not found? If a task times out? If credentials are invalid?
List tools (bosh_list_*) do not document pagination. No limit/offset/page parameters visible in schemas. Description does not state whether results are capped and how to fetch more. Large result sets will blow context windows without pagination guidance.
Timeout parameters (bosh_delete_deployment, bosh_recreate, bosh_stop, bosh_start, bosh_restart) lack min/max constraints in descriptions. 'Task timeout in seconds (default: 600)' does not specify if 0 is allowed, if there is a maximum, or what happens on timeout. LLMs will pass arbitrary values.
No tool annotations visible (readOnlyHint, destructiveHint, idempotentHint). Tools are marked with Risk labels (READ_ONLY, DESTRUCTIVE, etc.) in metadata, but schema likely lacks formal annotation fields for LLM planning.
bosh_list_tasks exposes 'limit' parameter without min/max. LLMs may pass 0, negative, or unreasonably large values. Should enforce (e.g., 1 - 1000) and document default (likely 20 - 50).
Configuration via BOSH_MCP_CONFIG environment variable is mentioned but not documented in tool descriptions. LLMs cannot discover how to configure multiple environments or switch credentials. User-facing documentation is absent.