Home

Ramen is a multizone, highly available MCP server for GCP and AWS Kubernetes. Your team keeps a git repo of tools, resources and prompts in plain Python. Ramen turns it into a fleet of MCP workers behind a cloud load balancer, with canary deploys, secrets, a role per group, an OAuth front door for Claude Code and the bridge, and a log line that says who called what. Underneath it is gRPC, JSON-RPC 2.0 and a Rust node. You code in Python.
ramen
The server: console, Rust node, Python runtime, Helm charts and Terraform for GCP and AWS. Releases are tagged and built by CI.
ramen-mcp-bridge
pip install ramen-mcp-bridge. A stdio MCP server for clients that cannot speak HTTP. Carries a group key or
signs you in through the console. On PyPI.
ramen-demo-mcp
The demo group repo every guide deploys: one tool, one resource, one prompt and an env.yaml. Point a group at
it and press Deploy.
Why Ramen
- One deployment per team, not one server per tool. A worker loads every tool of the group. Thirty tools run on one Deployment per zone with a canary, behind one load balancer.
- Built on how organizations work. A group is a team. It owns a repo, a bucket, its secrets and its members. People hold a role per group: Group Admin, Viewer or MCP User.
- Canary by default. Every deploy rolls one canary pod, smoke-tests it, then rolls the stable pods. A failure leaves the old version serving.
- Clients connect as themselves. Claude Code and the bridge sign a person in through the console with OAuth and get a token for one group and zone. Agents and CI use a group key.
- Secrets never show. Values live in Secret Manager, Secrets Manager or the Fernet-encrypted store and reach tool code only as environment variables on deploy.
- The edge is locked. The cloud edges listen on 443 only, IP rules apply per zone at the node and at the cloud edge, Redis throttles by address and by token, and every console action leaves an audit line.
- Multizone from day one. Group, environment, zone, worker. The load balancer routes on two headers, so one client config reaches any zone.
- Rust where it counts. The Rust node owns auth, limits and the transport. Your Python runs in a separate process it can restart at any time.
What is verified. CI proves both transports on real node processes on Linux and Windows, and every release is deployed to a throwaway GKE project and a real AWS account emptied the same day, each with two zones, OAuth, the bridge and a teardown. Microsoft Entra ID and Google Workspace sign-in is untested against a real tenant. What each run covered, hop by hop. Everything in detail is in the wiki.