server-ops-mcp
MCP server for VPS management — SSH commands, Docker containers, service management, GitHub integration, deployments, and monitoring.
Uses lazy category loading — only meta-tools are registered at startup. The agent enables categories on demand.
Quick Start
1. Install
pip install server-ops-mcp
2. Setup your VPS (one-time)
server-ops-mcp setup --host 1.2.3.4
This will:
- Prompt for your sudo password (hidden input, never stored)
- Create a
mcp-agentuser on the VPS - Configure NOPASSWD sudo for service commands
- Generate an Ed25519 SSH keypair
- Save the private key to
~/.ssh/server-ops-<name> - Update
~/.config/devops-mcp/config.json
3. Add to your MCP client
{
"mcpServers": {
"server-ops": {
"command": "server-ops-mcp"
}
}
}
4. Use it
Just talk to your agent:
- "Check disk usage on my server"
- "Restart nginx"
- "Deploy latest code"
The agent discovers and enables tool categories automatically.
Commands
server-ops-mcp # Start MCP server (default)
server-ops-mcp setup --host <ip> # One-time VPS provisioning
server-ops-mcp info # Show setup info and management guide
server-ops-mcp info --name my-vps # Info for a specific host
Configuration
Setup (Recommended)
Use server-ops-mcp setup — handles everything automatically.
Manual Config
Create ~/.config/devops-mcp/config.json:
{
"hosts": {
"my-server": {
"host": "1.2.3.4",
"username": "mcp-agent",
"port": 22,
"key_path": "~/.ssh/server-ops-my-server"
}
},
"default_host": "my-server",
"enabled_categories": ["ssh", "docker", "utility"],
"github": {
"token": "ghp_..."
}
}
Environment Variables
export DEVOPS_MCP_HOST=1.2.3.4
export DEVOPS_MCP_USER=root
export DEVOPS_MCP_KEY=~/.ssh/id_ed25519
export DEVOPS_MCP_GITHUB_TOKEN=ghp_...
MCP Client Setup
opencode
{
"mcpServers": {
"server-ops": {
"command": "server-ops-mcp"
}
}
}
Claude Desktop
{
"mcpServers": {
"server-ops": {
"command": "server-ops-mcp"
}
}
}
Cursor
{
"mcpServers": {
"server-ops": {
"command": "server-ops-mcp"
}
}
}
Security
How it works
server-ops-mcp setupruns once in your terminal (not in the agent)- Creates a dedicated
mcp-agentuser on your VPS - Configures NOPASSWD sudo for service commands only
- Generates SSH keypair — private key stays on your machine
- Password is never stored or passed to the agent
Remove access
# On the VPS
sudo userdel -r mcp-agent
sudo rm /etc/sudoers.d/mcp-agent
Add password to user (if needed later)
# On the VPS
sudo passwd mcp-agent
Rotate SSH key
# On your machine
server-ops-mcp setup --host 1.2.3.4 --name my-vps
Tools (48 total)
Meta-tools (always loaded)
| Tool | Description |
|---|---|
list_categories |
List available tool categories and their status |
enable_category |
Enable a category, registering its tools |
disable_category |
Disable a category, removing its tools |
search_tools |
Search across all categories (including disabled) |
SSH (9 tools)
| Tool | Description |
|---|---|
ssh_exec |
Run a command on the remote host |
ssh_upload |
Upload file content via SFTP |
ssh_download |
Download a file via SFTP |
ssh_file_read |
Read a remote file (with offset/limit) |
ssh_file_write |
Write a remote file (overwrite) |
ssh_file_edit |
Edit a remote file (exact string replacement) |
ssh_provision_user |
Create Linux user + push SSH key |
ssh_unlock_admin |
Unlock sudo session (15-min TTL) |
ssh_lock_admin |
Lock sudo session |
Docker (6 tools)
| Tool | Description |
|---|---|
docker_exec_cmd |
Run command in a container |
docker_logs_cmd |
Get container logs |
docker_ps_cmd |
List containers |
docker_start_cmd |
Start a container |
docker_stop_cmd |
Stop a container |
docker_restart_cmd |
Restart a container |
Services (7 tools)
| Tool | Description |
|---|---|
service_status |
Get systemd service status |
service_start |
Start a systemd service |
service_stop |
Stop a systemd service |
service_restart |
Restart a systemd service |
service_logs |
Get service logs via journalctl |
nginx_test |
Test nginx configuration |
nginx_reload |
Reload nginx (tests config first) |
Monitoring (6 tools)
| Tool | Description |
|---|---|
health_check_http |
HTTP health check from remote host |
health_check_tcp |
TCP connectivity check from remote host |
tail_logs |
Tail logs from journalctl or file |
disk_usage |
Get disk usage (df -h) |
memory_usage |
Get memory usage (free -m) |
process_list |
Get top processes by CPU |
GitHub (7 tools)
| Tool | Description |
|---|---|
github_list_issues |
List issues in a repo |
github_get_issue |
Get issue details with comments |
github_comment_issue |
Comment on an issue |
github_close_issue |
Close an issue |
github_list_pulls |
List pull requests |
github_create_deployment |
Create a GitHub deployment |
github_create_deployment_status |
Create deployment status |
Deploy (5 tools)
| Tool | Description |
|---|---|
deploy_git_pull |
Deploy by pulling latest code |
deploy_docker_compose |
Deploy with docker compose |
deploy_status |
Check current deployed version |
rollback_git |
Rollback to previous git commit |
rollback_docker_compose |
Rollback docker compose deployment |
Utility (4 tools)
| Tool | Description |
|---|---|
server_info |
OS, uptime, kernel info |
list_hosts |
List configured SSH hosts |
add_host |
Add a new SSH host |
remove_host |
Remove an SSH host |
Development
pip install -e ".[dev]"
ruff check src/
pytest
License
MIT
Release files for server-ops-mcp 0.1.9
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| server_ops_mcp-0.1.9.tar.gz | 51.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| server_ops_mcp-0.1.9-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 85.2 kB
Release files / server_ops_mcp-0.1.9.tar.gz
| Download URL | server_ops_mcp-0.1.9.tar.gz |
|---|---|
| Size | 51.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
75e0b17c370521ca4c9f41fad8fc171db7080f39af91be22a689c37cd13e9f7c
|
|
BLAKE2b-256 checksum How to use checksums |
58e2abdbeb5b3d38881f1d6d46bdeb2c53414d7d765874447536c56a9bff8adf
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 8, 2026.
Transparency logRelease files / server_ops_mcp-0.1.9-py3-none-any.whl
| Download URL | server_ops_mcp-0.1.9-py3-none-any.whl |
|---|---|
| Size | 34.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f8a241b6ef4880ea8b798a6e4100d146826ad5c99954b4b60d49f665287d8e90
|
|
BLAKE2b-256 checksum How to use checksums |
cd2bd628ff96f6805b3d1302ab97326cda34d1210f8d841c950a58ee206b2906
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 8, 2026.
Transparency log