View a markdown version of this page

MCP 服务器集成 - AWS 上的分布式负载测试

本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。

MCP 服务器集成

如果您在解决方案部署期间部署了可选的 MCP 服务器组件,则可以将分布式负载测试解决方案与支持模型上下文协议的 AI 开发工具集成。MCP 服务器提供编程访问权限,可通过 AI 助手检索、管理和分析负载测试。

你可以使用自己选择的客户端(Kiro CLI、Claude 等)连接到 DLT MCP 服务器,每个客户端(Claude 等)的配置说明略有不同。本节提供了 MCP Inspector、Kiro CLI、Cline 和 Amazon Quick 的设置说明。

第 1 步:获取 MCP 端点和访问令牌

在配置任何 MCP 客户端之前,您需要从 DLT Web 控制台检索 MCP 服务器端点和访问令牌。

  1. 导航到分布式负载测试 Web 控制台中的 MCP 服务器页面。

  2. 找到 MCP 服务器端点部分。

  3. 使用复制端点 URL 按钮复制端点 URL。端点 URL 遵循以下格式:https://{gateway-id}.gateway.bedrock-agentcore.{region}.amazonaws.com/mcp

  4. 找到 “访问令牌” 部分。

  5. 使用 “复制访问令牌” 按钮复制访问令牌。

重要

确保您的访问令牌安全。不要公开分享。默认情况下,该令牌通过 MCP 接口提供对分布式负载测试解决方案的只读访问权限。如果 MCP 服务器以 ReadWrite 访问模式部署,则令牌还允许创建、更新和删除操作。有关更多信息,请参阅《开发者指南》中的 MCP 工具规范。

显示端点和访问令牌的 MCP 服务器凭据页面

第 2 步:使用 MCP Inspector 进行测试

模型上下文协议提供了 MCP 检查器,这是一种直接连接到 MCP 服务器和调用工具的工具。这为在配置 AI 客户端之前测试您的 MCP 服务器连接提供了便捷的用户界面和示例网络请求。

注意

MCP Inspector 需要版本 0.17 或更高版本。所有请求也可以直接使用 JSON RPC 提出,但是 MCP Inspector 提供了更友好的界面。

安装并启动 MCP Inspector

  1. 必要时安装 npm。

  2. 运行以下命令启动 MCP 检查器:

    npx @modelcontextprotocol/inspector

配置连接

  1. 在 MCP 检查器界面中,输入您的 MCP 服务器端点 URL。

  2. 使用您的访问令牌添加授权标头。

  3. 选择 “连接” 以建立连接。

MCP 检查器配置屏幕

调用工具

连接后,您可以测试可用的 MCP 工具:

  1. 浏览左侧面板中的可用工具列表。

  2. 选择一个工具(例如,list_scenarios)。

  3. 提供所有必需的参数。

  4. 选择 Invoke 运行该工具并查看响应。

显示可用工具和调用的 MCP 检查器

第 3 步:配置 AI 开发客户端

验证您的 MCP 服务器与 MCP Inspector 的连接后,您可以配置首选的 AI 开发客户端。

Kiro CLI

Kiro CLI(前身为 Amazon Q Developer CLI)通过 MCP 服务器集成提供命令行访问 AI-assisted 开发权限。

配置步骤

  1. 编辑 mcp.json 配置文件。有关配置文件位置的更多信息,请参阅 Kiro CLI 文档中的模型上下文协议 (MCP)。

  2. 添加您的 DLT MCP 服务器配置:

    { "mcpServers": { "dlt-mcp": { "type": "http", "url": "https://<gateway-id>.gateway.bedrock-agentcore.<region>.amazonaws.com/mcp", "headers": { "Authorization": "Bearer <access-token>" } } } }

将<gateway-id>和<region>替换为 MCP 服务器端点 URL 中的值,并<access-token>替换为您在步骤 1 中复制的值。

验证配置

  1. 在终端中,键kiro-cli入启动 Kiro CLI。

  2. 键入/mcp以查看所有可用的 MCP 服务器。

  3. 键入/tools以查看由dlt-mcp和其他已配置的 MCP 服务器提供的可用工具。

  4. 验证是否dlt-mcp成功初始化。

克莱恩

Cline 是一款支持 MCP 服务器集成的人工智能编码助手。

配置步骤

  1. 在 Cline 中,导航到 “管理 MCP 服务器” > “配置” > “配置 MCP 服务器”。

  2. 更新 cline_mcp_settings.json 文件:

    { "mcpServers": { "dlt-mcp": { "type": "streamableHttp", "url": "https://<gateway-id>.gateway.bedrock-agentcore.<region>.amazonaws.com/mcp", "headers": { "Authorization": "Bearer <access-token>" } } } }

    将<gateway-id>和<region>替换为 MCP 服务器端点 URL 中的值,并<access-token>替换为您在步骤 1 中复制的值。

  3. 保存配置文件。

  4. 重新启动 Cline 以应用更改。

Amazon Quick

亚马逊 Quick(前身为亚马逊 Quick Suite)提供全面的人工智能助手平台,支持 MCP 服务器操作。

先决条件

在 Amazon Quick 中配置 MCP 服务器之前,您需要从 DLT 部署的 Cognito 用户池中检索 OAuth 证书:

  1. 导航到 AWS CloudFormation 控制台。

  2. 选择分布式负载测试堆栈。

  3. 在 “输出” 选项卡中,找到并复制与 DLT 部署关联的 Cognito 用户池 ID。

  4. 导航到 Amazon Cognito 控制台。

  5. 使用 CloudFormation 输出中的用户池 ID 选择用户池。

  6. 在左侧导航栏中,选择应用程序集成 > 应用程序客户端。

  7. 找到名称以m2m(机器对机器)结尾的应用程序客户端,然后将其选中。

  8. 在应用程序客户端详细信息页面上,复制客户端 ID 。要显示客户端密钥,请选择 “显示客户端密钥”,然后复制该值。

  9. 返回用户池并从 “域” 选项卡中获取用户池域。

  10. 通过追加/oauth2/token到域末尾来构造令牌端点 URL。

配置步骤

  1. 在 Amazon Quick 中,创建新代理或选择现有代理。

  2. 添加描述如何与 DLT MCP 服务器交互的代理提示。

  3. 添加新操作并选择 MCP 服务器操作。

  4. 配置 MCP 服务器的详细信息:

    • MCP 服务器 URL:您的 DLT MCP 终端节点

    • 身份验证类型: Service-based 身份验证

    • 令牌端点:您的 Cognito 令牌端点 URL

    • 客户端 ID:来自 m2M 应用程序客户端的客户端 ID

    • 客户端密钥:来自 m2M 应用程序客户端的客户端密钥

  5. 保存 MCP 服务器操作配置。

  6. 将新的 MCP 服务器操作添加到您的代理。

启动并测试代理

  1. 在亚马逊 Quick 中启动代理。

  2. 使用自然语言提示开始与代理对话。

  3. 代理将使用 MCP 工具检索和分析您的负载测试数据。

轮换 MCP 服务器客户端密钥

如果您使用基于服务(机器对机器)的身份验证将 MCP 客户端连接到解决方案,则您有责任轮换该客户端使用的客户端密钥。

这适用于哪种凭证

该解决方案会颁发两个不同的 MCP 凭证。其中只有一个需要手动旋转。

凭证 使用者 轮换

用户访问令牌 — 从 Web 控制台的 MCP 服务器页面复制

MCP Inspector、Kiro CLI、Cline 和其他发送标头的客户端 Authorization: Bearer

不需要。这是一个短暂的 Amazon Cognito 访问令牌,在发行后大约一小时过期。要获取新令牌,请返回 MCP 服务器页面并再次复制。

Machine-to-machine 客户端 ID 和客户端密钥 — 从 Amazon Cognito 用户池中检索

Amazon Quick 以及任何其他配置为基于服务的身份验证的客户端

需要手动旋转。客户端密钥是长期存在的,不会自行过期。

本节的其余部分适用于机器对机器的客户端密钥。该解决方案将此凭据创建为 Amazon Cognito 应用程序客户端, <stack-name>-userpool-client-m2m当您在部署时将 “部署可选 MCP 服务器” 设置为时命名。Yes有关检索说明,请参阅 Amazon Quick 中的先决条件。

重要

像对待任何其他长期存在的凭据一样对待客户端密钥:

  • 不要将其提交到源代码管理、将其嵌入到应用程序代码中,也不要将其粘贴到问题跟踪器、聊天或文档中。

  • 不要将其写入日志、构建输出或 CI/CD 任务输出。

  • 将其存储在 A WS Secrets Manager 等密钥管理器中,或存储在使用它的 MCP 客户端的加密凭证存储中。不要将其保存在纯文本文件中。

  • 仅向需要密钥的人授予访问权限,例如您和使用该密钥的服务。

推荐的旋转节奏

至少每 90 天轮换一次机器对计算机的客户端密钥。每当出现以下任何情况时,立即在常规时间表之外进行轮换:

  • 您怀疑或确认机密已泄露。

  • 有权访问密钥的操作员离开团队或更改角色。

  • 您停用了配置了密钥的 MCP 客户端。

轮换密钥

一个 Amazon Cognito 应用程序客户端最多同时支持两个有效的客户端密钥。轮流添加第二个密钥,将 MCP 客户端迁移到该密钥,然后删除原始密钥,不会中断 MCP 访问。

客户端 ID 在轮换期间不会更改,因此您无需更新解决方案的 AWS CloudFormation 堆栈、MCP 服务器终端节点或令牌终端节点。只有存储在 MCP 客户端中的密钥值会发生变化。

  1. 添加第二个客户端密钥。亚马逊 Cognito 生成该值并在响应中返回。

    aws cognito-idp add-user-pool-client-secret \ --user-pool-id <user-pool-id> \ --client-id <m2m-client-id> \ --region <region>
    重要

    复制响应ClientSecretValue中的内容并将其安全存储,然后再继续。亚马逊Cognito仅在此响应中返回生成的密钥值,并且永远不会再透露它——亚马逊Cognito控制台list-user-pool-client-secrets都不会显示它。如果您丢失了该值,请删除该密钥并添加一个新密钥。

    此时,原始密钥仍然有效,因此任何仍使用该密钥配置的 MCP 客户端都可以继续运行。

  2. 更新每个 MCP 客户端以使用新密钥。对于 Amazon Quick,编辑 MCP 服务器操作并替换客户端密钥值,保持 MCP 服务器 URL 、令牌终端节点和客户端 ID 不变。保存动作。

  3. 验证新机密是否发行代币。从您的用户池的令牌端点申请客户端凭证授予。

    curl -X POST https://<user-pool-domain>/oauth2/token \ -H 'Content-Type: application/x-www-form-urlencoded' \ -d 'grant_type=client_credentials' \ -d 'client_id=<m2m-client-id>' \ -d 'client_secret=<new-client-secret>' \ -d 'scope=dlt-mcp-gateway/read'

    成功的响应包含一个access_token字段。然后,通过从您重新配置的客户端调用 MCP 工具来确认端到端访问,例如,要求代理列出您的测试场景。

  4. 列出客户的秘密以识别原始密钥。每个机密都由格式ClientSecretId中的a标识 <client-id>--<epoch-create-time> 。使用该ClientSecretCreateDate字段将原始密钥与您刚刚添加的密钥区分开。

    aws cognito-idp list-user-pool-client-secrets \ --user-pool-id <user-pool-id> \ --client-id <m2m-client-id> \ --region <region>
  5. 使原始机密无效。在这次电话会议之后,Amazon Cognito不再向任何出示旧机密的客户发放代币。

    aws cognito-idp delete-user-pool-client-secret \ --user-pool-id <user-pool-id> \ --client-id <m2m-client-id> \ --client-secret-id <old-client-secret-id> \ --region <region>
注意

旋转时有两个约束条件:

  • 一个应用程序客户端最多可以有两个密钥。如果两个已经存在,请删除不再需要的那个,然后再添加一个。

  • 您无法删除应用程序客户端上最后剩余的密钥。

该add-user-pool-client-secret命令还接受一个可选--client-secret参数来提供您自己的值。如果您提供一个值,Amazon Cognito 不会在响应中返回该值,因此您必须在拨打电话之前将其存储。我们建议让亚马逊 Cognito 生成密钥。

如果秘密被泄露了

使用前面的步骤进行轮换,并尽快完成步骤 5(删除旧密钥),而不是等待维护窗口。然后采取以下额外措施。

  • 记下已经发行的代币。删除密钥会阻止 Amazon Cognito 发行新令牌,但使用暴露的密钥获得的访问令牌在过期前一直有效,最多约一小时。删除机密不会使它们失效。

  • 限制这些代币能做什么。如果您的部署使用ReadWrite访问模式,请在将 MCP 服务器访问模式设置为的情况下执行 AWS CloudFormation 堆栈更新。ReadOnly这会移除写入工具并限制 MCP 服务器 Lambda 函数对GET请求的 IAM 权限,因此未完成的令牌无法创建、修改、删除或启动测试场景。有关每种访问模式的行为,请参阅《开发者指南》中的 MCP 工具规范。

  • 查看该凭证的用途。检查解决方案的测试运行历史记录和 MCP 服务器 Lambda 函数的亚马逊 CloudWatch 日志中是否存在意外活动。如果部署使用ReadWrite访问模式,还要查看您的测试场景和场景存储桶public/test-scenarios/前缀的内容是否存在未经授权的更改。

注意

要立即拒绝所有 MCP 请求,无论令牌有效性如何,请在部署可选 MCP 服务器设置为的情况下执行堆栈更新。No这将删除网 AgentCore 关。

仅在必须保证未付令牌无法到达 MCP 服务器时才使用此选项。将参数设置为No也会删除机器对机器应用程序客户端。将其重新设置为使用新的客户端 ID 和新的密钥Yes创建新的应用程序客户端。然后,您必须使用新的客户端 ID 和新的密钥重新配置每个 MCP 客户端。

提示示例

以下示例演示如何与 AI 助手进行交互以通过 MCP 接口分析负载测试数据。自定义测试 ID、日期范围和标准,以满足您的特定测试需求。

有关可用的 MCP 工具及其参数的详细信息,请参阅《开发者指南》中的 MCP 工具规范。

简单的测试结果查询

与 MCP 服务器的自然语言交互可以很简单,Show me the load tests that have completed in the last 24 hours with their associated completion status也可以更具描述性,例如

Use list_scenarios to find my load tests. Then use get_latest_test_run to show me the basic execution data and performance metrics for the most recent test. If the results look concerning, also get the detailed performance metrics using get_test_run.

采用渐进式披露的交互式绩效分析

I need to analyze my load test performance, but I'm not sure which specific tests to focus on. Please help me by: 1. First, use list_scenarios to show me available test scenarios 2. Ask me which tests I want to analyze based on the list you show me 3. For my selected tests, use list_test_runs to get the test run history 4. Then use get_test_run with the test_run_id to get detailed response times, throughput, and error rates 5. If I want to compare tests, use get_baseline_test_run to compare against the baseline 6. If there are any issues, use get_test_run_artifacts to help me understand what went wrong Please guide me through this step by step, asking for clarification whenever you need more specific information.

生产准备情况验证

Help me validate if my API is ready for production deployment: 1. Use list_scenarios to find recent test scenarios 2. For the most recent test scenario, use get_latest_test_run to get basic execution data 3. Use get_test_run with that test_run_id to get detailed response times, error rates, and throughput 4. Use get_scenario_details with the test_id to show me what load patterns and endpoints were tested 5. If I have a baseline, use get_baseline_test_run to compare current results with the baseline 6. Provide a clear go/no-go recommendation based on the performance data 7. If there are any concerns, use get_test_run_artifacts to help identify potential issues My SLA requirements are: response time under [X]ms, error rate under [Y]%.

性能趋势分析

Analyze the performance trend for my load tests over the past [TIME_PERIOD]: 1. Use list_scenarios to get all test scenarios 2. For each scenario, use list_test_runs with start_date and end_date to get tests from that period 3. Use get_test_run for the key test runs to get detailed metrics 4. Use get_baseline_test_run to compare against the baseline 5. Identify any significant changes in response times, error rates, or throughput 6. If you detect performance degradation, use get_test_run_artifacts on the problematic tests to help identify causes 7. Present the trend analysis in a clear format showing whether performance is improving, stable, or degrading Focus on completed tests and limit results to [N] tests if there are too many.

排除失败的测试故障

Help me troubleshoot my failed load tests: 1. Use list_scenarios to find test scenarios 2. For each scenario, use list_test_runs to find recent test runs 3. Use get_test_run with the test_run_id to get the basic execution data and failure information 4. Use get_test_run_artifacts to get detailed error messages and logs 5. Use get_scenario_details to understand what was being tested when it failed 6. If I have a similar test that passed, use get_baseline_test_run to identify differences 7. Summarize the causes of failure and suggest next steps for resolution Show me the most recent [N] failed tests from the past [TIME_PERIOD].