# Ramen

> Self-hosted, multi-zone MCP server platform that turns a git repo of Python tools into canary-deployed workers on GKE and EKS.

Ramen is an open-source, self-hosted MCP (Model Context Protocol) server platform published by bkraad47 under the BSD-3-Clause license. A team keeps a git repo of tools, resources and prompts in plain Python, and Ramen turns it into a fleet of MCP workers behind a cloud load balancer on GCP or AWS Kubernetes. The latest release listed is v0.7.1.

## What It Is

Ramen is a platform for hosting your own MCP tools rather than a gateway in front of someone else's. Each worker pairs a Rust MCP node, which handles Streamable HTTP and gRPC, bearer auth, IP allow-lists, health and logs, with a Python 3.14 runtime that pip-installs and runs the team's code. A FastAPI console manages groups (tenants), environments, zones, secrets, canary deploys, rebalancing, IP rules, logs, audit and backups, either in the browser or through an API key.

## How the Deploy Workflow Works

A deploy syncs the group's git repo to a bucket, and workers load code by content hash, so pods hold no git credentials. Every deploy rolls a canary, smoke-tests tools/list, diffs tool schemas against stable (breaking changes stop unless flagged), runs the repo's golden test cases, then rolls the stable pods. A failure leaves the stable version serving. A group repo uses mcp/tools/<name>/<name>.py plus a JSON definition, with optional resources, prompts, requirements.txt and env.yaml; secrets are referenced as {{$group.NAME}} and substituted at call time.

## Access, Security and Transport

Workers serve POST /mcp over Streamable HTTP and a gRPC service on the same port, through the same guards. People hold a role per group (Group Admin, Viewer or MCP User), with global super admins. Clients connect with rmk_ MCP keys or per-user OAuth tokens issued by the console, and rmn_ API keys cover console automation. Additional controls include per-zone IP rules, Cloud Armor or WAF at the edge, Redis throttling, secrets that are never displayed, and an audit line for every action. User code runs in a separate Python process from the Rust node that holds keys and does auth. A stdio bridge, ramen-mcp-bridge on PyPI, serves clients that cannot speak HTTP.

## Setup Path and Verification

A local quickstart uses Docker compose, uv, git and make: make up starts the console and a worker, and make demo deploys a demo group. Cloud deployment uses Terraform, Helm and, for AWS, optionally CloudFormation. The docs state that CI proves both transports on Linux and Windows, and that releases are deployed to throwaway GCP and AWS environments; Microsoft Entra ID and Google Workspace sign-in is documented as untested against a real tenant.

## Features
- Git repo of Python tools, resources and prompts deployed as MCP workers
- Canary deploys with smoke tests, schema diffing and golden test cases
- Multi-zone architecture (group, environment, zone, worker) with header-based load balancer routing
- Streamable HTTP and gRPC transport with shared guards
- Rust MCP node paired with Python 3.14 runtime
- Per-group roles, rmk_ MCP keys and rmn_ API keys
- OAuth sign-in via the console for Claude Code and the bridge
- Secrets management via Secret Manager, Secrets Manager or Fernet-encrypted store
- Per-zone IP rules, Cloud Armor/WAF, Redis throttling
- Audit logging and backups
- FastAPI web console and API
- Stdio bridge for stdio-only clients
- Cloud-ops agent skills

## Integrations
GCP, AWS, GKE, EKS, Kubernetes, Terraform, Helm, CloudFormation, Redis, Claude Code, Claude Desktop, Cursor, GitHub Actions, Firestore, DynamoDB, Cloud Armor, AWS WAF

## Platforms
WINDOWS, LINUX, WEB, API, CLI

## Pricing
Open Source

## Version
v0.7.1

## Links
- Website: https://bkraad47.github.io/ramen/
- Documentation: https://bkraad47.github.io/ramen/wiki/
- Repository: https://github.com/bkraad47/ramen
- EveryDev.ai: https://www.everydev.ai/tools/ramen
