Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

BlueArch AWS Steward

Local, MCP-first contextual AWS architecture reviews for Codex, Claude Code, Cursor, and other MCP clients.

Steward reviews one live AWS resource or proposed Terraform/CloudFormation change and the dependencies relevant to that decision. It applies validated AWS Well-Architected knowledge, explains evidence and business impact, and builds a reviewable correction plan. Full-account scans run only when explicitly requested. Reviews are read-only by default.

Beta: use Steward as decision support. Review every recommendation and plan before changing production infrastructure.

Install

Steward requires Python 3.10 or newer. Install it in a virtual environment:

python3 -m venv .venv
source .venv/bin/activate
python -m pip install --upgrade bluearch-aws-steward
bluearch-steward --version
bluearch-steward mcp smoke

Windows activation:

.venv\Scripts\activate

For an isolated command without manually managing a virtual environment:

uv tool install --upgrade bluearch-aws-steward
uv tool update-shell
bluearch-steward mcp smoke

EKS and Kubernetes support is included in the standard package. AWS CLI, kubectl, Terraform/OpenTofu, Helm, Kustomize, Docker, and kind remain external tools used only by workflows that need them.

Connect Your Agent

bluearch-steward mcp install --client codex
bluearch-steward mcp install --client cursor
bluearch-steward mcp install --client claude

Use --dry-run to preview configuration changes. Restart the client after registration. For another stdio MCP client:

bluearch-steward mcp config --runtime installed

Run Your First Review

Authenticate outside the agent conversation. AWS IAM Identity Center users can run:

aws sso login --profile my-sso-profile

Then ask your MCP client about one exact resource:

Review s3://my-application-data before I change its lifecycle policy. Ask only for context that changes which Well-Architected practices apply.

For a proposed change, give the agent a declared workspace root and explicit Terraform or CloudFormation path. Steward never searches arbitrary local files, executes Terraform, or modifies source. If no resource is identified, it asks for one instead of guessing.

Steward returns a bounded architecture neighborhood, WAF practice ledger, contextual recommendations, explicit unknowns, and excluded scope. Results are ephemeral and exportable as JSON, Markdown, HTML, CSV, SARIF, or PDF.

Use an explicit prompt only when you really need breadth:

Run a comprehensive assessment across all supported services. Show only resources caught by rules and report skipped rules and coverage.

Included In This Preview

  • 120 native rules across 17 AWS runtime scopes.
  • Versioned contextual knowledge packs for all 17 scopes and bounded typed relationship collection with a 50-read operation budget.
  • Safe Terraform HCL, Terraform plan JSON, and CloudFormation JSON/YAML review.
  • A 20-rule EKS and Kubernetes assessment and investigation pack.
  • Searchable knowledge for the bundled BlueArch AWS misconfiguration catalog.
  • Native, Security Hub, Compute Optimizer, Cost Optimization Hub, and optional imported Prowler findings in one deduplicated queue.
  • Evidence, risk, confidence, freshness, remediation safety, and cost estimate status on presented findings.
  • Read-only resource investigation and planning-only AWS/IaC change previews.
  • Guarded writes for a small documented set of low-risk operations only.

Steward is standalone. It does not require BlueArch Core, hosted login, hosted telemetry, or a local AWS inventory database. AWS remains the source of truth.

Safety And Scope

  • No assessment applies changes.
  • Most recommendations are planning-only.
  • Guarded writes require a fresh finding, exact short-lived plan, explicit approval, state revalidation, and post-change verification.
  • Missing permissions or unavailable evidence are reported as incomplete, not as passing.
  • The current preview is single-account and single-Region per assessment.

Full documentation:

BlueArch AWS Steward MCP workflow

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

bluearch_aws_steward-0.9.0b1.tar.gz (462.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

bluearch_aws_steward-0.9.0b1-py3-none-any.whl (492.7 kB view details)

Uploaded Python 3

File details

Details for the file bluearch_aws_steward-0.9.0b1.tar.gz.

File metadata

  • Download URL: bluearch_aws_steward-0.9.0b1.tar.gz
  • Upload date:
  • Size: 462.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for bluearch_aws_steward-0.9.0b1.tar.gz
Algorithm Hash digest
SHA256 a5fa447fe44bfcec79c0a0f7deae11631d835f6c813a48ad160f4f0781bd641d
MD5 8ac1ce5697c2c023e6829b1edcea0c9c
BLAKE2b-256 a5ded58a9ef28e875909f096d601d4bca5865ff96615cdb39031b3e21bfa51ff

See more details on using hashes here.

Provenance

The following attestation bundles were made for bluearch_aws_steward-0.9.0b1.tar.gz:

Publisher: publish-pypi.yml on bluearchio/bluearch-aws-steward

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file bluearch_aws_steward-0.9.0b1-py3-none-any.whl.

File metadata

File hashes

Hashes for bluearch_aws_steward-0.9.0b1-py3-none-any.whl
Algorithm Hash digest
SHA256 ba5f3c6ac2034e73ed07f022db64d582cc565d78aa1cabbf7934d00575c05e97
MD5 ee6790d87577a43b404a8a0ef64c7972
BLAKE2b-256 345d92299d13d90be85e56fae4ffd10053702e35842033f5a7151241841b4e2c

See more details on using hashes here.

Provenance

The following attestation bundles were made for bluearch_aws_steward-0.9.0b1-py3-none-any.whl:

Publisher: publish-pypi.yml on bluearchio/bluearch-aws-steward

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.9.0b1 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page