Auditing and documenting cloud infrastructure
Combining the AWS MCP Server, Cloudflare API MCP Server, and Filesystem MCP: audit resources and configuration across two cloud providers and save the findings as a report.
- Skill Road
- Auditing and documenting cloud infrastructure
Categories
Anyone running infrastructure across more than one cloud provider knows the problem: getting a complete overview of resources, configuration, and potential risks means clicking through several separate consoles. This workflow connects the AWS MCP Server and the Cloudflare API MCP Server with Filesystem MCP, so an agent can query resources and configuration across both providers and save the findings locally as a readable, version-controllable report, instead of only presenting information fleetingly in the chat. The AWS MCP Server gives authenticated access to over 300 AWS services through a single endpoint, the Cloudflare API MCP Server covers DNS, Workers, Zero Trust, and other Cloudflare products through a compact Code Mode approach, and Filesystem MCP writes the collected result as a file into the project directory.
How the three tools work together
The agent first queries relevant resources via the AWS MCP Server, such as running EC2 instances, S3 bucket configurations, or IAM roles with especially broad permissions. In parallel or afterward, it uses the Cloudflare API MCP Server to query DNS records, firewall rules, or Zero Trust policies for the associated domains. Instead of only summarizing the findings in conversation, the agent writes them via Filesystem MCP as a structured Markdown document into a designated folder, such as docs/infrastructure-audit/, where it can be version-controlled with git and compared over time.
A typical step-by-step run
A typical request is: "Create a report of all publicly reachable S3 buckets in my AWS account and all Cloudflare firewall rules for domain X, and save it to docs/infrastructure-audit/2026-09-report.md." The agent queries bucket configurations via the AWS MCP Server, checks the active firewall rules for the named domain via the Cloudflare API MCP Server, and combines both results into a joint report, which Filesystem MCP then saves as a file. Repeating this request regularly builds up a history of audit reports that can be used to track infrastructure changes over time.
Why this combination pays off
Without the AWS MCP Server or the Cloudflare API MCP Server, a human would have to manually gather the relevant information from two separate web consoles, which costs a lot of time for recurring checks. Without Filesystem MCP, every audit run disappears at the end of the chat session, making it hard to compare changes between two points in time. Only the combination of two cloud-provider servers and a local storage location turns a one-off query into a repeatable, documented review process.
Who this workflow fits
This workflow is particularly useful for DevOps and infrastructure teams that regularly run security or cost reviews across multiple cloud providers and have so far had to manually switch between consoles for that. It also suits preparing compliance evidence or internal audits well, since every report remains traceable as a file. For teams that only use one of the two cloud providers, only the matching MCP server together with Filesystem MCP is needed accordingly.
Frequently asked setup questions
Does each of the two cloud servers need its own credentials? Yes, the AWS MCP Server uses IAM credentials via OAuth or SigV4, and the Cloudflare API MCP Server uses its own OAuth or API token — both are configured independently of each other. Should an agent also be allowed write access to the infrastructure for this workflow? For pure audit purposes, a narrowly scoped, read-only access profile is recommended; changes to the infrastructure should always be confirmed by a human. How often should the report be refreshed? That depends on your needs — for security-critical environments, a weekly or monthly cadence is a reasonable starting point.
Building blocks of this workflow
AWS MCP Server
Official, AWS-operated remote MCP server that gives coding agents authenticated access to 300+ AWS services, sandboxed code execution, and AWS documentation.
Cloudflare API MCP Server
Official Cloudflare MCP server that exposes the entire Cloudflare API through just two tools, complemented by a dozen product-specific MCP servers.
Filesystem MCP
Official MCP reference server for controlled local file operations within allowed directories.
Related guides
Guides and background related to this entry.
Set up the Asana plugin for Claude Code
Create your own Asana OAuth app, install the Claude Code plugin, and connect to Asana's V2 MCP server via /asana-setup.
30.09.2026
Setting up the Zernio MCP Server
Connect the Zernio MCP Server via OAuth or an API key, link social accounts, and deliberately safeguard write access to posts, inboxes, and ad campaigns.
28.09.2026
Setting up the Intercom MCP Server
Connect the Intercom MCP Server via OAuth or a bearer token, choose the correct regional endpoint, and deliberately safeguard write access to articles and notes.
23.09.2026
Setting up the PayPal MCP Server
Connect the PayPal MCP Server locally via npx or as a hosted remote server via OAuth, and deliberately safeguard write access.
23.09.2026