VMware workflow orchestration — multi-step state machine with approval gates
Project description
VMware Pilot
Author: Wei Zhou, VMware by Broadcom — wei-wz.zhou@broadcom.com This is a community-driven project by a VMware engineer, not an official VMware product. For official VMware developer tools see developer.broadcom.com.
English | 中文
Multi-step workflow orchestration for VMware MCP skills — state machine, approval gates, audit trail.
Companion skills handle everything else:
Skill Scope Install vmware-aiops VM lifecycle, deployment, guest ops, cluster uv tool install vmware-aiopsvmware-monitor Read-only: inventory, health, alarms, events uv tool install vmware-monitorvmware-storage Datastores, iSCSI, vSAN management uv tool install vmware-storagevmware-vks Tanzu Namespaces, TKC cluster lifecycle uv tool install vmware-vksvmware-nsx NSX networking: segments, gateways, NAT uv tool install vmware-nsx-mgmtvmware-nsx-security DFW firewall rules, security groups uv tool install vmware-nsx-securityvmware-aria Aria Ops: metrics, alerts, capacity uv tool install vmware-ariavmware-avi AVI load balancing, pool management, AKO K8s ops uv tool install vmware-avi
Install
uv tool install vmware-pilot
vmware-pilot mcp # start the MCP server (stdio)
MCP Tools (13 — 4 read, 9 write)
| Tool | Description |
|---|---|
get_skill_catalog |
List all available skills and tools for workflow design |
list_workflows |
List built-in and custom templates |
review_workflow |
Sanity-check a planned workflow before execution |
design_workflow |
Natural language goal → draft workflow |
update_draft |
Edit draft workflow steps |
confirm_draft |
Finalize draft → ready to execute |
plan_workflow |
Generate execution plan from template, returns workflow_id |
create_workflow |
Create custom workflow from step list |
run_workflow |
Execute workflow, pauses at approval gates |
get_workflow_status |
Query state + diff report + audit log |
approve |
Human approval, continue execution |
rollback |
Abort and rollback at any stage |
cancel_workflow |
Cancel a workflow — move it to the terminal CANCELLED state |
- Read-only mode (v1.8.0) — one env var strips all 9 orchestration write tools (design/update/confirm draft, plan/create, run, approve, rollback, cancel) from the MCP registry, leaving the 4 query tools; env vars are the only switch here, pilot has no config file — see Read-Only Mode
MCP Configuration
{
"mcpServers": {
"vmware-pilot": {
"command": "vmware-pilot",
"args": ["mcp"]
}
}
}
Fallback:
{"command": "uvx", "args": ["--from", "vmware-pilot", "vmware-pilot-mcp"]}still works, butuvxre-resolves against PyPI on every start and fails behind a TLS-inspecting corporate proxy (invalid peer certificate: UnknownIssuer). The installed entry point above touches the network zero times; setUV_NATIVE_TLS=trueif you must useuvx.
Read-Only Mode
A prompt instruction is advisory — a model can ignore it. Read-only mode is structural: turn it on and every write tool is removed from the MCP registry at startup, so list_tools() never offers them and the model cannot call what it cannot see. Off by default, and fail-closed: if the mode is requested but cannot be guaranteed, the server refuses to start.
{
"mcpServers": {
"vmware-pilot": {
"command": "vmware-pilot",
"args": ["mcp"],
"env": { "VMWARE_PILOT_READ_ONLY": "true" }
}
}
}
Read this before enabling it here. vmware-pilot is an orchestrator, so orchestration is its write surface. 9 of its 13 tools are writes, and all 9 are withheld:
plan_workflow, run_workflow, approve, rollback, cancel_workflow, create_workflow, design_workflow, update_draft, confirm_draft
Only the 4 read tools survive:
| Tool | Still available for |
|---|---|
list_workflows |
Browsing built-in and custom templates |
get_skill_catalog |
Seeing which skills and tools a workflow could call |
get_workflow_status |
State, diff report and audit log of an existing workflow |
review_workflow |
Static review of a workflow definition before anyone runs it |
A read-only pilot therefore cannot author, plan, run, approve, roll back or cancel anything — it can only inspect workflows that already exist. Note that pilot's writes land in its own workflow database (~/.vmware/workflows.db), not on a VMware estate; it has no vCenter connection of its own. They are classified as writes because run_workflow is where a workflow is dispatched and approve is the gate that releases it — the infrastructure change happens downstream, in the target skill's process, under that skill's own read-only setting.
So if you set the family-wide switch to protect your estate but still want orchestration, keep pilot writable and let the downstream skills enforce the lock — the per-skill variable wins over the family one:
{
"mcpServers": {
"vmware-pilot": {
"command": "vmware-pilot",
"args": ["mcp"],
"env": { "VMWARE_READ_ONLY": "true", "VMWARE_PILOT_READ_ONLY": "false" }
}
}
}
Precedence: per-skill env (VMWARE_PILOT_READ_ONLY) → family env (VMWARE_READ_ONLY) → off. Unlike the other family members, vmware-pilot reads no config file, so the environment variables are the only switch — there is no read_only: config key. Startup logs list exactly which tools were withheld.
License
MIT
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file vmware_pilot-1.8.0.tar.gz.
File metadata
- Download URL: vmware_pilot-1.8.0.tar.gz
- Upload date:
- Size: 166.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: uv/0.10.0 {"installer":{"name":"uv","version":"0.10.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
db9309593c404f6f2e771a9a23c6f5fa9d11983edf5566d21ae6accc47cdbef7
|
|
| MD5 |
13d363f6ad303a69c5015ad02633a762
|
|
| BLAKE2b-256 |
8f9f822f747afceb45730fd1dd3cddda263129b7f3027382988d80c85de339a3
|
File details
Details for the file vmware_pilot-1.8.0-py3-none-any.whl.
File metadata
- Download URL: vmware_pilot-1.8.0-py3-none-any.whl
- Upload date:
- Size: 48.5 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: uv/0.10.0 {"installer":{"name":"uv","version":"0.10.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
2f2d9d3c91555c543a0216239f9113ed791a8ca02179dcd90e57b81c5650b632
|
|
| MD5 |
fa871c572a500aee4d317e46917f4ff1
|
|
| BLAKE2b-256 |
27c703da2a7a395a65c36c1e955789bee9aacdb15988640b9ca7a08052aa29c2
|