Fabric to Claude Setup with mcp-azure-sql
Budget: $15.0 - $70.0
HOURLY / PART_TIME
⭐ 0.00 (0)
United States
computer-networking, network-administration, network-planning, windows-azure, api, azure-app-services
Qualifications préférées
- Expérience : Intermédiaire
Project in one line: Build and deploy a secure, centrally-hosted MCP (Model Context Protocol) server that connects Claude to our Microsoft Fabric data warehouse's SQL endpoint, so our team can query a governed set of read-only views through Claude.
Current state:
A working Python MCP server already exists (tools for listing views, describing schema, listing metrics, querying views) with a whitelist against our documented "ai schema" context tables — but it's untested against a live Fabric connection, uses stdio transport (single local user only), and auth is a secret embedded in a connection string.
An Azure AD app registration (service principal) exists from an earlier attempt, but its permissions were scoped for a different (abandoned) approach and haven't been confirmed as correct for direct SQL-endpoint access.
No Azure infrastructure has been provisioned yet (no Key Vault entry, no container hosting, no networking).
What needs to be done:
Identity & permissions — Verify/fix the service principal's permissions for Fabric SQL-endpoint access; confirm it has SELECT on the ai schema; move its secret into Azure Key Vault; register a second Azure AD app so individual teammates can authenticate themselves (not a shared credential).
Backend development — Update the Python MCP server to use Azure AD token-based auth (via azure-identity and pyodbc's access-token method) instead of a plain secret; switch transport from stdio to Streamable HTTP so it can serve multiple remote users; write a Dockerfile; test end-to-end against live Fabric data.
Infrastructure/deployment — Provision (or use existing) Azure Container Apps environment; deploy with a managed identity that can read Key Vault; configure HTTPS ingress and networking so the container can reach the Fabric SQL endpoint (handling any IP restrictions/firewall rules).
Claude rollout — Register the deployed server as an org-wide custom connector in the Claude admin settings; each teammate does a one-time sign-in.
Security review — Sign-off on data scope (read-only, ai schema only), secret handling, and logging before wider team rollout, since this touches sales/inventory/financial data.
Ouvrir sur Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Connexion