Skip to main content

Endpoint AIops (preview)

Disclaimer: Community-maintained open-source project. Not affiliated with, endorsed by, or sponsored by any endpoint-management vendor. Product and trademark names belong to their owners. MIT licensed.

Governed AI-ops for managed-endpoint fleets — thin clients, VDI endpoints, and other centrally-managed devices — with a built-in governance harness: unified audit log, policy engine, token/runaway budget guard, undo-token recording, and graduated-autonomy risk tiers. Vendor-neutral: it talks to an endpoint-management server's REST API (Bearer auth). Self-contained: no dependencies beyond httpx and the MCP SDK. Preview — mock-validated only, not yet verified against a live management server.

What it does

Two signature analyses, plus the guarded reads and writes around them:

  • Login-storm analysis — during a "everyone logs in at 9am" incident, detect the storm (bursts of concurrent logins in a sliding window) and rank the endpoints/users dragging login and boot times. Every flag is reported with its number, not a black-box verdict.
  • Patch / config drift — find endpoints that have drifted from the fleet (outdated patch level, stray agent version, divergent OS build or config profile). With no declared baseline it derives one by fleet majority, so it works before a gold image exists.

What works

  • CLI (endpoint-aiops ...): init, overview, endpoint list/get/assign-profile/reboot, session list/storm, drift report/patch, secret set/list/rm/migrate/rotate-password, doctor, mcp.
  • MCP server (endpoint-aiops mcp or endpoint-aiops-mcp): 11 tools (9 read, 2 write), every one wrapped with the bundled @governed_tool harness.
  • Encrypted credentials: the management-server API key lives in an encrypted store ~/.endpoint-aiops/secrets.enc (Fernet + scrypt) — never plaintext on disk. Unlock with a master password from ENDPOINT_AIOPS_MASTER_PASSWORD (MCP/CI) or an interactive prompt (CLI).
  • Reversibility: endpoint_assign_profile (high risk) captures the prior profile and records an inverse "reassign the prior profile" undo descriptor. endpoint_reboot (medium risk) captures the prior online state for the audit record but declares no undo (a reboot has no safe inverse).
  • Safety: state-changing CLI ops (endpoint assign-profile, endpoint reboot) require double confirmation and support --dry-run.

Capability matrix (11 MCP tools)

Category Tools Count R/W
Overview overview 1 read
Inventory endpoint_list, endpoint_get, endpoint_health_score 3 read
Sessions session_list, login_storm_analysis 2 read
Drift drift_report, patch_status, patch_compliance 3 read
Remediation endpoint_assign_profile 1 write (high)
endpoint_reboot 1 write (medium)

The analysis tools (login_storm_analysis, drift_report, patch_status, patch_compliance, endpoint_health_score) accept injected records for pure/offline analysis; endpoint_health_score and patch_compliance are injected-only, the others also pull live from a configured target.

Quick start

uv tool install endpoint-aiops          # or: pipx install endpoint-aiops
endpoint-aiops init                     # wizard: add a target + store its API key (encrypted)
endpoint-aiops doctor                   # verify config, secrets, connectivity
endpoint-aiops overview                 # one-shot fleet health
endpoint-aiops session storm            # detect a login storm + slow contributors
endpoint-aiops drift report             # endpoints drifted from the fleet baseline

Run as an MCP server (stdio):

export ENDPOINT_AIOPS_MASTER_PASSWORD=...   # unlock secrets non-interactively
endpoint-aiops-mcp

Governance

Every MCP tool passes through the bundled @governed_tool harness:

  • Audit — every call (params, result, status, duration, risk tier, approver, rationale) is logged to ~/.endpoint-aiops/audit.db (relocatable via ENDPOINT_AIOPS_HOME).
  • Budget / runaway guard — token and call budgets trip a circuit breaker.
  • Risk tiers — graduated autonomy; high-risk ops can require a named approver (ENDPOINT_AUDIT_APPROVED_BY / ENDPOINT_AUDIT_RATIONALE).
  • Undo recording — reversible writes record an inverse descriptor.

Scope

This is the IT-endpoint member of the AIops-tools family (governed AI-ops with audit + budget + undo + risk tiers). For OT / industrial edge (Modbus, OPC-UA, PROFINET, …) see the separate industrial-aiops line.

Status

Preview — mock-validated only. The endpoint-management REST paths are modelled generically (/endpoints, /sessions, /version) and need live verification against a real server. Missing a capability or a server dialect? Open an issue or PR — contributions welcome.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

endpoint_aiops-0.1.1.tar.gz (127.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

endpoint_aiops-0.1.1-py3-none-any.whl (73.8 kB view details)

Uploaded Python 3

File details

Details for the file endpoint_aiops-0.1.1.tar.gz.

File metadata

  • Download URL: endpoint_aiops-0.1.1.tar.gz
  • Upload date:
  • Size: 127.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.10.0 {"installer":{"name":"uv","version":"0.10.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for endpoint_aiops-0.1.1.tar.gz
Algorithm Hash digest
SHA256 750c7eee4267e36a11190cdcc4888f046aa90ad051de77f7671ebcdfaa02c790
MD5 8e261807f54dcf3b505a3ce79947a476
BLAKE2b-256 11bd9ef72245aa58fafa8cfbb20f8e52c7ebb7e5036d6879e2a0ae4aa3100a9f

See more details on using hashes here.

File details

Details for the file endpoint_aiops-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: endpoint_aiops-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 73.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.10.0 {"installer":{"name":"uv","version":"0.10.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for endpoint_aiops-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 ef686588a2b24fa474317dc62406edce84853c37bd4484247e75628c504ed31f
MD5 1c996732c47fcb32f046ba27659aa46b
BLAKE2b-256 65b983e14cabe7c5704e76c05a23f5abe180dbd75c72a30cd0199b2fd9cc40d8

See more details on using hashes here.

Release history Release notifications | RSS feed

0.9.0

2 files

0.8.0

2 files

0.7.0

2 files

0.6.0

2 files

0.5.0

2 files

0.4.0

2 files

0.3.0

2 files

0.2.1

2 files

0.2.0

2 files

This release

0.1.1 This release

2 files

0.1.0

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page