Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

You can deploy MCP tools on ECS Fargate with AWS CDK, but first decide which Claude architecture you mean. This guide follows the AWS Samples CDK design: a separate agent service calls Claude Sonnet 4 through Amazon Bedrock and communicates with MCP server services on ECS. Claude itself does not run inside the Fargate containers. If instead you want Claude’s hosted clients to connect directly to your custom MCP server, you need a publicly reachable HTTPS endpoint and a different ingress and security design.

Choose how Claude will reach your MCP tools

MCP is a protocol that lets compatible AI applications use tools and data exposed by a server. It does not host the AI model. An ECS task running an MCP server is therefore not, by itself, a Claude deployment.

Design Where the model runs Network path Best fit
Bedrock-backed agent (the CDK sample in this guide) Claude Sonnet 4 is accessed as a hosted model through Amazon Bedrock; the AI agent and MCP servers run as ECS services. The agent and MCP services communicate within the VPC using ECS Service Connect. The sample also includes an Application Load Balancer. An application you operate where the agent, MCP tools, and AWS resources are part of your own AWS deployment.
Claude remote custom connector Claude runs in Anthropic’s hosted client environment and calls your remote MCP server. The MCP endpoint must be reachable from the public internet and Anthropic’s IP ranges. A private-VPC-only endpoint will not work for this connector flow. Users connect a Claude hosted client directly to a custom remote MCP server.
AWS-managed ECS MCP service An assistant such as Claude Code uses AWS’s managed integration to inspect and troubleshoot ECS. Uses AWS IAM permissions and MCP Proxy for AWS to sign requests with SigV4. ECS operations, rather than deploying your own general-purpose MCP server.

The distinction matters for network design: an MCP service that is deliberately private can work for an agent inside the VPC, but it cannot serve as the endpoint for Anthropic’s remote connector. Anthropic’s Help Center explains that “When you add a custom connector, Claude connects to your remote MCP server from Anthropic’s cloud infrastructure, rather than from your local device.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the CDK/Fargate sample deploys

The closest documented match for CDK, Fargate, and Claude is an AWS Samples repository. Its architecture includes an AI service configured to access Claude Sonnet 4 through Bedrock, a custom Python MCP server, and an AWS API MCP server. ECS Service Connect supports service-to-service communication; an Application Load Balancer is also part of the example.

#1 Best Overall
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
  • Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM)
  • Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
  • CanaKit Turbine Black Case for the Raspberry Pi 5
  • CanaKit Low Noise Bearing System Fan
  • Mega Heat Sink - Black Anodized

The sample’s AWS API MCP server is restricted in the example to listing S3 buckets. It also creates an API-key secret and uses an x-api-key header in its load-balancer example. Those are sample implementation details, not universal requirements or a complete production security design. Review the repository’s current code and configuration before adapting it.

Check prerequisites before deploying

The CDK sample README lists these prerequisites:

  • Node.js 20 or later.
  • Docker.
  • A configured AWS CLI.
  • Access to the relevant Bedrock model in the AWS account and Region you plan to use.

The repository instructions also call for installing dependencies, logging in to public Amazon ECR, bootstrapping the AWS environment, and deploying with npm run cdk deploy. Follow the README for the precise setup commands and configuration expected by the version you check out; the available documentation summary does not establish a single repository URL, dependency command, account/Region selection, or configuration file to use.

Rank #2
CanaKit Raspberry Pi 5 16GB Starter Kit PRO - Turbine Black (128GB Edition) (16GB RAM)
  • Includes Raspberry Pi 5 16GB with 2.4Ghz 64-bit quad-core CPU (16GB RAM)
  • Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
  • CanaKit Turbine Black Case for the Raspberry Pi 5
  • CanaKit Low Noise Bearing System Fan
  • Mega Heat Sink - Black Anodized

A separate AWS ECS walkthrough estimates 30–40 minutes for its own CloudFormation and Amazon Nova 2 Lite example. That is not a time estimate for this CDK/Claude sample. The CDK sample README reports 362.32 seconds as example deployment output; AWS Samples does not establish that as a benchmark or promised deployment duration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Deploy the CDK sample

  1. Review the repository and select the target environment. Check the sample’s README and code, then confirm the AWS account and Region, available Bedrock model access, and the AWS permissions required by its stack. Do not assume that sample permissions are appropriate for production.
  2. Install the documented dependencies. Use the dependency installation instructions in the repository. Confirm Node.js 20 or later and Docker are available, and that the AWS CLI is configured for the intended account.
  3. Prepare the container image workflow. Follow the repository’s instructions to log in to public ECR and build or otherwise prepare the required images. Docker is a stated prerequisite; image names, tags, and build commands should come from the checked-out README rather than be guessed.
  4. Bootstrap the CDK environment. Run the bootstrap procedure specified by the sample for the account and Region where you will deploy. CDK bootstrap setup is environment-specific, so verify the target before proceeding.
  5. Deploy the stack. From the location specified by the README, run npm run cdk deploy. Review the CDK changes and outputs, and confirm the stack deployed the expected ECS services, load balancer, and Service Connect configuration.
  6. Verify the service path. Check ECS service and task health, then test the documented application and MCP flow using the sample’s own endpoint and authentication instructions. A healthy task alone does not prove the agent can reach the MCP servers or that Bedrock model access is configured correctly.

The sample README’s summarized instructions do not specify the exact validation request, expected response, or cleanup command. Use the current repository documentation for those actions rather than inventing an endpoint or test payload.

Rank #3
RasTech Raspberry Pi 5 8GB Kit 64GB Edition with Active Cooler,27W GaN 5.1V5A USB-C Power Supply,Pi5 8GB Board,64GB Card Readers Kit,Pi 5 Case,Dual 4K Micro HD Out Cables and User Manual
  • Pi5 8GB Pack: RasTech Pi 5 8GB kit includes 1 x Pi5 8GB board ,1 x 64GB Card, 2 x Card Readers,1 x Active Cooler,1 x Case for Pi5, 2 x 4K Micro HD Out Cable,1 x GaN 27W 5A USB-C Power supply,1 x Screwdriver and 1 x instructions.
  • Pi5 8GB Board: The Pi5 board is equipped with a 64-bit quad-core Arm Cortex-A76 processor running at 2.4GHz and an 800MHz VideoCore VII GPU with support for OpenGL ES 3.1 and Vulkan 1.2, which delivers a significant increase in graphics performance. Dual HD Out 4Kp60 display outputs and a built-in dual 4-channel MIPI camera/display transceiver provide state-of-the-art camera support. The Pi 5 offers a 2-3 times increase in CPU performance compare to Pi4.
  • Important Graphics Features: Equipped with an 800MHz VideoCore VII GPU and providing better graphics performance, suitable for multimedia applications,gaming,and graphics intensive tasks.Provides 1 UART interface,1 card slot that supports high-speed operation, 2 USB. 3 0.5 ports that support synchronous 0Gbps operation,2 USB 2.0 port ports,2 4Kp60 display outputs that support HDR.Built-in dedicated dual 4-channel 1Gbps MIPI DSI/CSI connectors,triple the total bandwidth.
  • Cooling Kit for Pi 5: Compatible with Active Cooler for Raspberry Pi5, It can provide Pi 5 board with better cooling effect in using. The Case can accurately access usb-c power jack,Micro HD Out ports, usb ports, Ethernet jack, card slot, power button, 4-lane MIPI DSI/CSI connectors and so on, and it also supports installation of cooling fan.
  • 64GB Card Kit and GaN 27W USB-C Power Supply: With extra 64GB card to store more files and card readers for multiple medium, keep better performance for Raspberry Pi 5, 27W USB C Power Supply is Compatible with Pi5 8GB, offers a variety of output voltage options, including 5.1V at 5A, 9.0V at 3.0A, 12.0V at 2.25A, and 15.0V at 1.8A, providing for different device requirements.

Adapt the network design for direct Claude connectors

If the requirement is for Claude’s hosted clients to connect to your server, treat the MCP service as an internet-facing service, not as a private-only service behind an internal route. Anthropic says connector requests come from its cloud infrastructure and that the server must be reachable from Anthropic’s IP ranges. Teams that filter ingress should consult Anthropic’s current published ranges and connector documentation when configuring their firewall.

  • Provide a publicly reachable HTTPS endpoint for the MCP server; a private address accessible only within your VPC is incompatible with this connector flow.
  • Configure the authentication method supported by the connector setup, such as an appropriate sign-in flow or fixed request headers, and independently authorize which tools and data each caller may use.
  • Keep downstream AWS permissions on the MCP task role narrowly scoped. Authentication to the MCP endpoint does not constrain what that role can access.
  • For a multi-user or multi-tenant service, design tenant separation and authorization explicitly so one caller cannot use another tenant’s data or permissions.

AWS Prescriptive Guidance treats remote MCP hosting as a way to centrally manage access, authentication and authorization, versioning, and updates. It also emphasizes both sides of the permission boundary: agent-to-server access and the server’s access to downstream resources.

Rank #4
Vilros Raspberry Pi 5 Starter Kit MAX – Official 8GB RAM Pi 5 Board, 128GB Preloaded Micro SD, Case, Power Supply & Cooling – Complete Plug-and-Play Kit for Beginners & Advanced Users
  • 𝗦𝗲𝗮𝗺𝗹𝗲𝘀𝘀 𝗦𝗲𝘁𝘂𝗽 𝘄𝗶𝘁𝗵 𝗣𝗿𝗲-𝗜𝗻𝘀𝘁𝗮𝗹𝗹𝗲𝗱 𝗢𝗦: Start creating right out of the box—our kit arrives with Raspberry Pi OS already on the microSD card, saving you time and effort from day one.
  • 𝗘𝘃𝗲𝗿𝘆𝘁𝗵𝗶𝗻𝗴 𝗬𝗼𝘂 𝗡𝗲𝗲𝗱, 𝗔𝗹𝗹 𝗶𝗻 𝗢𝗻𝗲 𝗕𝗼𝘅: From the case to the power supply and a generous microSD card, we’ve bundled every essential so you can skip the extra shopping and focus on building your dream project.
  • 𝗔𝗱𝘃𝗮𝗻𝗰𝗲𝗱 𝗖𝗼𝗼𝗹𝗶𝗻𝗴 𝗳𝗼𝗿 𝗣𝗲𝗮𝗸 𝗣𝗲𝗿𝗳𝗼𝗿𝗺𝗮𝗻𝗰𝗲: Enjoy smooth, reliable operation as our whisper-quiet fan and heat sinks work together to keep your Pi running cool—even during intensive tasks.
  • 𝗩𝗲𝗿𝘀𝗮𝘁𝗶𝗹𝗶𝘁𝘆 𝗳𝗼𝗿 𝗔𝗻𝘆 𝗣𝗿𝗼𝗷𝗲𝗰𝘁: Whether it’s coding lessons, retro gaming, smart home setups, or robotics experiments, our kit powers unlimited possibilities, letting you tailor your Pi adventure to your passion.
  • 𝗚𝗹𝗼𝗯𝗮𝗹𝗹𝘆 𝗧𝗿𝘂𝘀𝘁𝗲𝗱 𝗯𝘆 𝗘𝗻𝘁𝗵𝘂𝘀𝗶𝗮𝘀𝘁𝘀 & 𝗘𝗱𝘂𝗰𝗮𝘁𝗼𝗿𝘀: Join a worldwide community of hobbyists, teachers, and first-time makers who rely on Vilros for top-tier quality, comprehensive support, and ongoing inspiration.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep permissions narrow across every route

The sample’s bucket-list-only AWS API permissions are a useful illustration of constraining a tool, not a default policy for your own service. Define the minimum downstream AWS actions and resources each server needs, and assign only those permissions to its execution role. Where different tools have different authority, avoid giving every tool the same broad role simply because they share a deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

MCP-specific controls do not necessarily govern every action an AI assistant can take. AWS security guidance warns that an assistant with shell or AWS CLI access may call AWS APIs directly, bypassing MCP controls. Least-privilege IAM and broader AWS account or organization guardrails therefore remain important even when tool calls normally pass through MCP.

Best Value
CanaKit Raspberry Pi 4 4GB Starter PRO Kit - 4GB RAM
  • Includes Raspberry Pi 4 4GB Model B with 1.5GHz 64-bit quad-core CPU (4GB RAM)
  • Includes Pre-Loaded 32GB EVO+ Micro SD Card (Class 10), USB MicroSD Card Reader
  • CanaKit Premium High-Gloss Raspberry Pi 4 Case with Integrated Fan Mount, CanaKit Low Noise Bearing System Fan
  • CanaKit 3.5A USB-C Raspberry Pi 4 Power Supply (US Plug) with Noise Filter, Set of Heat Sinks, Display Cable - 6 foot (Supports up to 4K60p)
  • CanaKit USB-C PiSwitch (On/Off Power Switch for Raspberry Pi 4)

Plan for sessions and horizontal scaling

AWS’s ECS walkthrough uses Streamable HTTP for its MCP server. It notes that stateless Streamable HTTP can support horizontal replication without session affinity, while stateful workflows may use Mcp-Session-Id and require session behavior to be planned. This is an architectural reference, not proof that the CDK/Claude sample uses the same transport or session configuration. Verify the transport and state model in the server you deploy before adding replicas or relying on load-balancer behavior.

Know when a managed ECS MCP service is a better fit

AWS separately documents a managed Amazon ECS MCP server that can integrate with assistants such as Claude Code. It is currently described as preview and subject to change. It uses IAM permissions and MCP Proxy for AWS to sign requests with SigV4, and provides tools for inspecting and troubleshooting ECS workloads. It is an alternative for operating ECS, not a way to deploy your own MCP server to Fargate with CDK.

Quick Recap

Bestseller No. 1
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM); CanaKit Turbine Black Case for the Raspberry Pi 5
$259.95
Bestseller No. 2
CanaKit Raspberry Pi 5 16GB Starter Kit PRO - Turbine Black (128GB Edition) (16GB RAM)
CanaKit Raspberry Pi 5 16GB Starter Kit PRO - Turbine Black (128GB Edition) (16GB RAM)
Includes Raspberry Pi 5 16GB with 2.4Ghz 64-bit quad-core CPU (16GB RAM); CanaKit Turbine Black Case for the Raspberry Pi 5
$419.99
Bestseller No. 5
CanaKit Raspberry Pi 4 4GB Starter PRO Kit - 4GB RAM
CanaKit Raspberry Pi 4 4GB Starter PRO Kit - 4GB RAM
Includes Raspberry Pi 4 4GB Model B with 1.5GHz 64-bit quad-core CPU (4GB RAM); Includes Pre-Loaded 32GB EVO+ Micro SD Card (Class 10), USB MicroSD Card Reader
$159.99

Deployment decision checklist

  • Choose Bedrock-backed Claude when your deployed agent should call Claude through AWS and reach MCP services within your VPC.
  • Choose a remote connector topology when Claude’s hosted clients must call your custom server; design for public HTTPS reachability from Anthropic’s infrastructure.
  • Separate endpoint authentication from downstream AWS authorization, and scope task roles and tool permissions to the minimum required.
  • Use the AWS Samples CDK repository as a starting point, not as a production security blueprint; inspect its current implementation before adopting it.
  • Consider the preview managed ECS MCP service only when the actual need is assistant-driven ECS inspection and troubleshooting.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.