Skip to content

Project Ramen

Ramen

Multizone, highly available, enterprise-grade MCP server for GCP and AWS Kubernetes.

release ci license MCP

Ramen turns a git repo of tools, resources and prompts into a fleet of MCP workers behind a cloud load balancer. Each worker is a Rust MCP node (JSON-RPC 2.0 over gRPC, auth, IP allow-lists, metrics) paired 1:1 with a Python 3.14 runtime that runs your code. Standard MCP clients (Claude Desktop, Cursor, the mcp SDK) connect through the ramen-mcp-bridge stdio bridge. A single FastAPI console manages groups, environments, zones, secrets, canary deploys, rebalancing, logs and audit, and every action is also available through an API key.

Git → bucket → worker

Push mcp/tools/<name>/<name>.py + <name>.json to a repo. Deploy syncs it to a bucket; workers pip-install and load it. Protos →

gRPC transport (v0.3.1)

One ramen.v1.Mcp/Call per JSON-RPC message: binary framing, HTTP/2 multiplexing, first-class health and deadlines. The LB routes on ramen-group / ramen-zone metadata. Transport →

Canary by default

Every deploy rolls a canary first, smoke-tests tools/list, then rolls the stable track. Failure = canary scaled to 0, stable untouched. Canary →

Enterprise controls

Super admin / group admin / viewer, rmk_ MCP keys, rmn_ API keys, per-zone IP rules (Cloud Armor / WAF), secrets never shown, full audit log. Security →

Quickstart (local, 5 commands)

Needs Docker (compose v2), uv, git. About 3–5 minutes on the first run (image builds).

git clone https://github.com/bkraad47/ramen && cd ramen
make up          # Firestore emulator + console (https://localhost:8443) + one worker (gRPC localhost:8080, h2c)
make demo        # creates group `demo` from the demo repo, mints an rmk_ key, deploys, calls the tool via the bridge
# → demo_calculator_tool({"var1": 2, "var2": 3, "func": "add"}) -> 5
open https://localhost:8443   # self-signed cert; login admin@ramen.local / changeme-ramen
make down        # stop and remove volumes

The console is https://localhost:8443 (accept the self-signed certificate), login admin@ramen.local / changeme-ramen (from deploy/local/.env). The worker is a gRPC endpoint on localhost:8080 that takes a rmk_ MCP key minted on the group page. Point Claude Desktop, Cursor or the mcp SDK at it with the bridge:

ramen-mcp-bridge --target localhost:8080 --insecure --key rmk_… --group demo --zone local

Full walkthrough with a Claude Desktop config, an mcp SDK snippet and a raw grpcurl call: Local quickstart. Coming from 0.3.0? The HTTP /mcp endpoint is gone: migration note.

Ramen console dashboard

Dashboard: load per zone × group (blue = low, green = even, red = high).

Deploy to the cloud

Target Status Guide
GCP (GKE Autopilot, Firestore, GCS, Secret Manager, global HTTPS LB with gRPC header routing, Cloud Armor) verified on a throwaway project in 0.3.0 (89/89 cloud tests); 0.3.1 gRPC routing re-verified locally, cloud re-run pending GCP how-to
AWS (EKS, DynamoDB, S3, Secrets Manager, ALB gRPC target groups, WAF) built and unit-tested only; never applied to a real account AWS how-to
Local (docker compose) CI e2e on every push Local quickstart

Where next