Stack · Platform engineering

Release and infrastructure desk

Takes a green branch to a running deployment, and keeps the DNS, the cluster and the access list honest on the way.

Built for: The small team where the person shipping the feature is also the person who owns the DNS record it needs.

Install all 11 parts

The button opens the checkout, where 6 servers and 5 skills are listed one by one with what each does to the bill — free, already yours, monthly or a one-off licence. Nothing is charged until you confirm it there, in Stripe’s own card frame on that page rather than a redirect, and each paid member keeps its own budget cap.

$0/mo
6 servers at their publishers’ prices, with one-off licences spread over 12 months
$0
the free-tier version keeps 6 servers and 1 skill
$0
5 skills with no monthly cost, plus $168 paid once
26.1k
tokens of context the skills add to every session
01 · Outcome

What your agent can do with this

The reason to buy a stack rather than five listings: each line below needs more than one member connected at the same time.

  1. 01

    Create and read deploys on Vercel or Netlify and say which commit is actually live.

  2. 02

    Inspect the cluster — pods, deployments, services — and hold a release when something there is unhealthy.

  3. 03

    Manage the DNS record a launch needs on Cloudflare, and read back what resolves rather than what was intended.

  4. 04

    Walk a pre-launch checklist and produce the runbook and monitoring the launch will be judged by.

02 · Assembly

The assembly, part by part

What each part contributes, and why it was picked over the obvious alternative. Prices and permissions are read from the listings, so nothing here can disagree with the catalogue.

6 servers5 skills
VE01
Vercel MCP server Cloud & DevOps by zueai

Connects to the Vercel API, which is where a front-end release is either live or is not.

read/write split not recordedruns on your machine A v0.0.7 credential not declared · runs locally
Free
$0 of the monthly total
NE02

Netlify's own API and CLI for creating and managing sites and deploys, for the half of the estate that lives there.

read/write split not recordedruns on your machine A v1.15.1 credential not declared · runs locally
Free
$0 of the monthly total
KU03

The cluster check before and after a release: pods, deployments and services, inspected rather than assumed.

read/write split not recordedruns on your machine A v4.1.4 credential not declared · runs locally
Free
$0 of the monthly total
CL04

The DNS record a launch depends on, managed and read back from the zone that actually answers queries.

read/write split not recordedruns on your machine A v1.6.0 credential not declared · runs locally
Free
$0 of the monthly total
GI05

Ties the deploy to the commit and the merge request, so a release note is assembled from the repository rather than from memory.

read/write split not recordedruns on your machine A v1.8.0 credential not declared · runs locally
Free
$0 of the monthly total
DA06

The monitors that tell you whether the release was fine, read from the same desk that shipped it.

read/write split not recordedruns on your machine A v1.8.0 credential not declared · runs locally
Free
$0 of the monthly total
and the instructions that drive them A skill is a prompt file, not a server: it adds context and a procedure, never a tool or a permission of its own.
CI07
CI/CD and Automation Agent skill Guardrail by addyosmani

Sets up the pipeline and its quality gates, so 'it deploys from main' is written down rather than known by one person.

2.8k tokens of context never asks for a write 1 files · MIT needs no server of its own
$49
$4.08 of the monthly total
SH08
Shipping and Launch Agent skill Workflow by addyosmani

The pre-launch checklist — monitoring, rollback, the announcement — which is what separates a launch from a push.

2.5k tokens of context never asks for a write 1 files · MIT needs no server of its own
$35
$2.92 of the monthly total
TE09
Teleport Access Review Agent skill Workflow by gravitational

Recertifies who can reach which resource and whether that access is used, which is the audit nobody schedules until it is demanded.

16k tokens of context never asks for a write 12 files · AGPL-3.0 needs no server of its own
Free
no monthly cost
NE10
Network Config Validation Agent skill Guardrail by affaan-m

Pre-deployment checks for router and switch configuration — dangerous commands, subnet overlaps, stale references — for teams whose stack ends at the hardware.

1.9k tokens of context never asks for a write 1 files · MIT needs no server of its own
$15
$1.25 of the monthly total
AU11
Audit Dependencies Agent skill Workflow by payloadcms

A release is the last moment a known vulnerable dependency is cheap to fix, and this turns the audit output into the upgrade.

2.8k tokens of context never asks for a write 1 files · MIT needs no server of its own
$69
$5.75 of the monthly total
03 · Cost

What it costs, and on what assumption

Every member is a subscription or a licence bought once, so the monthly figure is a price rather than an estimate: what moves it is adding or dropping a member, not how hard the stack is worked. The one assumption is that a one-off licence is spread over a year so it can sit in the same column as a subscription.

PartWhat you are paying forMonthly, as quoted
Vercel Free
Netlify Free
Kubernetes Free
Cloudflare DNS Free
Gitlab Free
Datadog Free
Skills
CI/CD and Automation $49 · $4.08/mo over 12 months $4.08/mo
Shipping and Launch $35 · $2.92/mo over 12 months $2.92/mo
Teleport Access Review Free · context cost only
Network Config Validation $15 · $1.25/mo over 12 months $1.25/mo
Audit Dependencies $69 · $5.75/mo over 12 months $5.75/mo
Everything above $0 of servers plus $14 of skills, the same in a quiet month and a busy one $14/mo

Subscriptions at their monthly plan price; one-off licences spread over 12 months. One-off purchases in this stack total $168 — CI/CD and Automation $49, Shipping and Launch $35, Network Config Validation $15, Audit Dependencies $69 — paid once and spread here so they sit in the same column as a subscription. Everything arrives on one mcprush invoice, taken by Stripe from the card on your account, not one per publisher — mcprush.com is the merchant of record and each publisher is paid out of it.

The free-tier version$0/mo

Install only these and the bill is nothing: 6 servers and 1 skill.

Left out, and what goes with it:

  • CI/CD and Automation · $49Sets up the pipeline and its quality gates, so 'it deploys from main' is written down rather than known by one person.
  • Shipping and Launch · $35The pre-launch checklist — monitoring, rollback, the announcement — which is what separates a launch from a push.
  • Network Config Validation · $15Pre-deployment checks for router and switch configuration — dangerous commands, subnet overlaps, stale references — for teams whose stack ends at the hardware.
  • Audit Dependencies · $69A release is the last moment a known vulnerable dependency is cheap to fix, and this turns the audit output into the upgrade.
What moves the bill
Flat every month$0 · 0 subscriptions
Carries a call allowancenothing
Paid once$168
Traffic assumed5k calls / month

Nothing in this stack carries a call allowance, so nothing here can run out before the month does. The bill is decided when you install it, not when you use it.

Budget caps are set per install and enforced at the gateway, so a retry loop is refused at the cap rather than left to run through an allowance overnight.

04 · Setup

Setting it up, in order

One step per part, in the order they are useful: connect what the work reads before what it writes, and install the skills that decide how the work is done last. Each step is a command you can read before you run it.

1
One token per platform, scoped to a project
Vercel, Netlify and Railway all issue account-wide tokens by default. Narrow each one to the project this desk owns before connecting it.
2
DNS is the dangerous one
The Cloudflare member manages records. Give it the zone you launch into and nothing else — a wrong record on the apex is a full outage with a slow fix.
3
Cluster access by namespace
A kubeconfig limited to the namespaces you deploy to. Read is enough for a release check; write is a separate decision.
4
Run the access review before, not after
The Teleport skill recertifies who can reach what. A launch is the moment that list is smallest and easiest to correct.
One command11 parts
npx mcprush@latest stack add release-infra

Nothing in this stack installs from one command today: 11 members are either paid, run from its own source, or a skill with its own command — the steps above name each one. Nothing is connected until you approve it.

Before you start
  • 6 members have not declared what credential they need — check each one’s own page before you start.
  • What this stack can write is not recorded — 6 members of 6 have no imported tool surface. Section 05 says what is known before you approve anything.
  • 6 members can run on your own machine instead of ours, if you would rather they did.
05 · Permissions

What the whole stack can reach

Installed together, these tool surfaces add up. It is the first thing a security reviewer asks for, so what has been counted — and what nobody has counted yet — is on the page rather than in a PDF.

tools that only read
Which tools read and which write is counted from the surface a publisher imports, and 6 members of 6 have no imported tool surface.
tools that can change something
Not recorded, and not estimated: a total added up from the members that have a surface would be read as the whole stack’s. The table below is what is known, member by member.
0
tools that reach the network
Not recorded: no member of this stack has published a tool surface, so where the calls go is each member’s own page to answer.
Who grants the write accessnot recorded
MemberTool surfaceWrite tools
Cloudflare DNS not imported not recorded
Datadog not imported not recorded
Gitlab not imported not recorded
Kubernetes not imported not recorded
Netlify not imported not recorded
Vercel not imported not recorded
Reading the number

A stack's blast radius is the union of its members, not the worst of them. That union cannot be taken here, because 6 members of 6 have no imported tool surface — so the figure a review asks for is missing rather than low, and a member marked not imported is one nobody has counted rather than one that cannot write.

Tools in total0
Write sharenot recorded
Members that can writenot recorded
Surface imported0 of 6 members
06 · Swaps

Sensible swaps

A stack is a default, not a verdict. These are the substitutions the maintainer would make, and what each one costs or saves.

A service that is a container rather than a set of functions belongs on Railway, and the deploy conversation moves with it.

same money at 5k calls the same 0 tools both grade A

Teams whose workloads are managed services rather than pods get more from talking to the cloud account directly than from a cluster server.

same money at 5k calls the same 0 tools both grade A
07 · Limits

Where this stack stops

Written by the maintainer, kept on the page rather than in a support thread.

  • It cannot approve its own release. Every member here can act, and the order in which they act is a human's plan.

  • The access review it does is Teleport's, not your cloud provider's. IAM roles are out of this stack's reach.

  • It has no opinion about cost. Nothing here reads a bill; a deploy that doubles your spend looks exactly like one that does not.

08 · Maintenance

Who keeps this current

A stack has an owner: whoever keeps it re-checks the combination when a member changes, and the members themselves are published by the people named on each row.

Maintainer
mcprush
Publishes this stack only
Version
null
Set by the curator
Member installs
none yet
Added up across the parts. Nothing counts installs of the set as one thing.
Member rating
No reviews yet
None of the parts has been reviewed, and neither has the stack.
Composition
6 + 5
6 servers, 5 skills
Nearby

Stacks that share parts with this one

All 20 stacks