Skip to main content

Endpoint AIops (preview)

Disclaimer: Community-maintained open-source project. Not affiliated with, endorsed by, or sponsored by any endpoint-management vendor. Product and trademark names belong to their owners. MIT licensed.

Governed AI-ops for managed-endpoint fleets — thin clients, VDI endpoints, and other centrally-managed devices — with a built-in governance harness: unified audit log, policy engine, token/runaway budget guard, undo-token recording, and graduated-autonomy risk tiers. Vendor-neutral: it talks to an endpoint-management server's REST API (Bearer auth). Self-contained: no dependencies beyond httpx and the MCP SDK. Preview — mock-validated only, not yet verified against a live management server.

What it does

Two signature analyses, plus the guarded reads and writes around them:

  • Login-storm analysis — during a "everyone logs in at 9am" incident, detect the storm (bursts of concurrent logins in a sliding window) and rank the endpoints/users dragging login and boot times. Every flag is reported with its number, not a black-box verdict.
  • Patch / config drift — find endpoints that have drifted from the fleet (outdated patch level, stray agent version, divergent OS build or config profile). With no declared baseline it derives one by fleet majority, so it works before a gold image exists.

What works

  • CLI (endpoint-aiops ...): init, overview, endpoint list/get/assign-profile/reboot, session list/storm, drift report/patch, secret set/list/rm/migrate/rotate-password, doctor, mcp.
  • MCP server (endpoint-aiops mcp or endpoint-aiops-mcp): 11 tools (9 read, 2 write), every one wrapped with the bundled @governed_tool harness.
  • Encrypted credentials: the management-server API key lives in an encrypted store ~/.endpoint-aiops/secrets.enc (Fernet + scrypt) — never plaintext on disk. Unlock with a master password from ENDPOINT_AIOPS_MASTER_PASSWORD (MCP/CI) or an interactive prompt (CLI).
  • Reversibility: endpoint_assign_profile (high risk) captures the prior profile and records an inverse "reassign the prior profile" undo descriptor. endpoint_reboot (medium risk) captures the prior online state for the audit record but declares no undo (a reboot has no safe inverse).
  • Safety: state-changing CLI ops (endpoint assign-profile, endpoint reboot) require double confirmation and support --dry-run.

Capability matrix (11 MCP tools)

Category Tools Count R/W
Overview overview 1 read
Inventory endpoint_list, endpoint_get, endpoint_health_score 3 read
Sessions session_list, login_storm_analysis 2 read
Drift drift_report, patch_status, patch_compliance 3 read
Remediation endpoint_assign_profile 1 write (high)
endpoint_reboot 1 write (medium)

The analysis tools (login_storm_analysis, drift_report, patch_status, patch_compliance, endpoint_health_score) accept injected records for pure/offline analysis; endpoint_health_score and patch_compliance are injected-only, the others also pull live from a configured target.

Quick start

uv tool install endpoint-aiops          # or: pipx install endpoint-aiops
endpoint-aiops init                     # wizard: add a target + store its API key (encrypted)
endpoint-aiops doctor                   # verify config, secrets, connectivity
endpoint-aiops overview                 # one-shot fleet health
endpoint-aiops session storm            # detect a login storm + slow contributors
endpoint-aiops drift report             # endpoints drifted from the fleet baseline

Run as an MCP server (stdio):

export ENDPOINT_AIOPS_MASTER_PASSWORD=...   # unlock secrets non-interactively
endpoint-aiops-mcp

Governance

Every MCP tool passes through the bundled @governed_tool harness:

  • Audit — every call (params, result, status, duration, risk tier, approver, rationale) is logged to ~/.endpoint-aiops/audit.db (relocatable via ENDPOINT_AIOPS_HOME).
  • Budget / runaway guard — token and call budgets trip a circuit breaker.
  • Risk tiers — graduated autonomy; high-risk ops can require a named approver (ENDPOINT_AUDIT_APPROVED_BY / ENDPOINT_AUDIT_RATIONALE).
  • Undo recording — reversible writes record an inverse descriptor.

Scope

This is the IT-endpoint member of the AIops-tools family (governed AI-ops with audit + budget + undo + risk tiers). For OT / industrial edge (Modbus, OPC-UA, PROFINET, …) see the separate industrial-aiops line.

Status

Preview — mock-validated only. The endpoint-management REST paths are modelled generically (/endpoints, /sessions, /version) and need live verification against a real server. Missing a capability or a server dialect? Open an issue or PR — contributions welcome.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

endpoint_aiops-0.3.0.tar.gz (152.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

endpoint_aiops-0.3.0-py3-none-any.whl (78.2 kB view details)

Uploaded Python 3

File details

Details for the file endpoint_aiops-0.3.0.tar.gz.

File metadata

  • Download URL: endpoint_aiops-0.3.0.tar.gz
  • Upload date:
  • Size: 152.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.10.0 {"installer":{"name":"uv","version":"0.10.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for endpoint_aiops-0.3.0.tar.gz
Algorithm Hash digest
SHA256 c4f6c9692323b7b5b65133c5af7c97d1137304c449f76949c04d90901e4720c9
MD5 abaab6571b8ba67e9842e1c42266028a
BLAKE2b-256 1a48d9d405770a8a6289efe1fbc49de3598ef0dfc7b61c55fc40340acc19776f

See more details on using hashes here.

File details

Details for the file endpoint_aiops-0.3.0-py3-none-any.whl.

File metadata

  • Download URL: endpoint_aiops-0.3.0-py3-none-any.whl
  • Upload date:
  • Size: 78.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.10.0 {"installer":{"name":"uv","version":"0.10.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for endpoint_aiops-0.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 fcedbefbac45b18766f7a1ed5e739234fb8fb6b7c7a441a94929acdd364245cd
MD5 c1a0adb8a495a2f834ef97c00b316384
BLAKE2b-256 43b629412ef5e3b8c7ef9eebeb09ad00c5247a5998b6d23c788b17fe85284ecc

See more details on using hashes here.

Release history Release notifications | RSS feed

0.9.0

2 files

0.8.0

2 files

0.7.0

2 files

0.6.0

2 files

0.5.0

2 files

0.4.0

2 files

This release

0.3.0 This release

2 files

0.2.1

2 files

0.2.0

2 files

0.1.1

2 files

0.1.0

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page