Part of the ado-aw documentation.
The mcp-servers: field configures MCP (Model Context Protocol) servers that are made available to the agent via the MCP Gateway (MCPG). MCPs can be containerized stdio servers (Docker-based) or HTTP servers (remote endpoints). All MCP traffic flows through the MCP Gateway.
Run containerized MCP servers. MCPG spawns these as sibling Docker containers:
mcp-servers:
azure-devops:
container: "node:20-slim"
entrypoint: "npx"
entrypoint-args: ["-y", "@azure-devops/mcp", "myorg", "-d", "core", "work-items"]
env:
AZURE_DEVOPS_EXT_PAT: ""
allowed:
- core_list_projects
- wit_get_work_item
- wit_create_work_itemConnect to remote MCP servers accessible via HTTP:
mcp-servers:
remote-ado:
url: "https://mcp.dev.azure.com/myorg"
headers:
X-MCP-Toolsets: "repos,wit"
X-MCP-Readonly: "true"
allowed:
- wit_get_work_item
- repo_list_repos_by_projectContainer stdio servers:
container:- Docker image to run (e.g.,"node:20-slim","ghcr.io/org/tool:latest")entrypoint:- Container entrypoint override (equivalent todocker run --entrypoint)entrypoint-args:- Arguments passed to the container entrypointargs:- Additional Docker runtime arguments (inserted before the image indocker run). Security note: dangerous flags like--privileged,--network hostwill trigger compile-time warnings.mounts:- Volume mounts in"source:dest:mode"format (e.g.,["/host/data:/app/data:ro"])env:- Environment variables for the MCP server process. Use""(empty string) for passthrough from the pipeline environment.
HTTP servers:
url:- HTTP endpoint URL for the remote MCP serverheaders:- HTTP headers to include in requests (e.g.,Authorization,X-MCP-Toolsets)
Common (both types):
enabled:- Whether this MCP server is active (default:true). Set tofalseto temporarily disable an entry without removing it from the front matter.allowed:- Array of tool names the agent is permitted to call. Optional — when omitted or empty, all tools from that MCP server are accessible to the agent. Strongly recommended for security: restrict to only the tools the agent needs.
HTTP MCPs ignore env:; use headers: for HTTP authentication instead.
MCP containers may need secrets from the pipeline (e.g., ADO tokens). The env: field supports passthrough:
env:
AZURE_DEVOPS_EXT_PAT: "" # Passthrough from pipeline environment
STATIC_CONFIG: "some-value" # Literal value embedded in configWhen permissions.read is configured, the compiler automatically maps SC_READ_TOKEN → AZURE_DEVOPS_EXT_PAT on the MCPG container, so agents can access ADO APIs without manual wiring.
mcp-servers:
azure-devops:
container: "node:20-slim"
entrypoint: "npx"
entrypoint-args: ["-y", "@azure-devops/mcp", "myorg"]
env:
AZURE_DEVOPS_EXT_PAT: ""
allowed:
- core_list_projects
- wit_get_work_item
permissions:
read: my-read-arm-connection
network:
allowed:
- "dev.azure.com"
- "*.dev.azure.com"- Allow-listing: When
allowed:is set, only the listed tools are accessible to the agent. When omitted or empty, all tools from that server are accessible. Always specify an explicitallowed:list to limit the agent's tool surface. - Containerization: Stdio MCP servers run as isolated Docker containers (per MCPG spec §3.2.1)
- Environment Isolation: MCP containers are spawned by MCPG with only the configured environment variables
- MCPG Gateway: All MCP traffic flows through the MCP Gateway which enforces tool-level filtering
- Trusted egress: MCPG and the stdio/HTTP backends it spawns from
mcp-servers:front matter are trusted infrastructure that runs outside the agent's Squid-enforced allowlist — they have direct network egress and are not subject tonetwork.allowed/network.blocked. Only the Copilot agent process itself is confined to the AWF sandbox and its domain allowlist; seedocs/mcpg.mdanddocs/network.mdfor the topology. - SafeOutputs is further hardened: unlike arbitrary
mcp-servers:entries, the compiler-ownedsafeoutputsMCPG backend is not a user-configurable trusted-egress container — it is a dedicated stdio child spawned by MCPG from the pinned AWFagentimage with--network none,--cap-drop ALL, a read-only rootfs, and the host ADO runner's non-root UID/GID. It has no network access at all, trusted or otherwise; seedocs/mcpg.md.