Ssh Fleet
БесплатноНе проверенMCP server that provides SSH tools (read-only probes and arbitrary exec) to a fleet of hosts outside Kubernetes, with an inventory-based allowlist and key-based
Описание
MCP server that provides SSH tools (read-only probes and arbitrary exec) to a fleet of hosts outside Kubernetes, with an inventory-based allowlist and key-based authentication.
README
English | Русский
Version MCP Registry Container Build Go Version Go Report Card License: MIT Issues Last Commit
MCP server that gives an agent two tools over SSH to a fleet of hosts outside Kubernetes. The SSH key is a mounted secret (never enters model context); the inventory is a fail-closed allowlist.
Tools
ssh_probe(tags, check)— curated read-only diagnostics on every host carrying the given tags (AND semantics, like GitLab runner tags).checkis one of a built-in set:uptime,disk,mem,failed,logs. Arbitrary commands cannot be passed. Class:read-only.ssh_exec(host, command)— one arbitrary non-interactive command on ONE inventory host (by name or address; hosts outside the inventory are refused). Class:write-external: the server executes the command, while access gating (approval/RBAC) belongs to the MCP client.
Both: output size cap, per-host timeout, TOFU host-key check (fingerprint in logs), output as one section per host.
Configuration (env)
| Variable | Default | Meaning |
|---|---|---|
SSH_FLEET_TRANSPORT |
http |
http (StreamableHTTP, endpoint /mcp) | sse | stdio |
SSH_FLEET_ADDR |
:8080 |
listen address for http/sse |
SSH_FLEET_AUTH_TOKEN |
— | optional X-MCP-AUTH token |
SSH_FLEET_INVENTORY_PATH |
/etc/ssh-fleet/inventory.yaml |
path to the inventory (configmap) |
SSH_FLEET_KEY_PATH |
/etc/ssh-fleet/id_ed25519 |
path to the private key (secret) |
SSH_FLEET_OUTPUT_CAP_BYTES |
8192 |
output cap per section |
SSH_FLEET_CMD_TIMEOUT_SECONDS |
20 |
per-host timeout |
SSH_FLEET_PROBE_CONCURRENCY |
8 |
probe parallelism pool |
SSH_FLEET_PROBE_MAX_HOSTS |
50 |
safety cap on hosts per probe |
Inventory format — see deploy/inventory.example.yaml.
Quickstart (docker, stdio)
docker run -i --rm \
-v /path/to/inventory.yaml:/etc/ssh-fleet/inventory.yaml:ro \
-v /path/to/id_ed25519:/etc/ssh-fleet/id_ed25519:ro \
-e SSH_FLEET_TRANSPORT=stdio \
ghcr.io/inhuman/mcp-ssh-fleet:latest
This is the shape MCP clients use when installing from the
MCP Registry
(io.github.inhuman/mcp-ssh-fleet).
Connecting an MCP client (http/sse)
By default the server speaks StreamableHTTP; register it as a regular HTTP MCP
server with endpoint /mcp (URL like http://<host>:8080/mcp). Both tools
become available to the client.
Client-side security recommendations:
ssh_probeisread-only(curated checks only) and can be granted broadly.ssh_execis arbitrary execution (write-external). Gate its access on the client side (approval / RBAC / user allowlist) — the server merely executes a command on an inventory host; it does not decide access policy.
Development
make test # unit tests + e2e against a real in-process SSH server
make vet
make vulncheck
make build
make docker
Release: tag vX.Y.Z → GitHub Actions builds and publishes a multi-arch image
to ghcr.io/inhuman/mcp-ssh-fleet.
Установка Ssh Fleet
У этого сервера нет опубликованного пакета — он собирается из исходников. Открой репозиторий и следуй инструкции в README.
▸ github.com/inhuman/mcp-ssh-fleetFAQ
Ssh Fleet MCP бесплатный?
Да, Ssh Fleet MCP бесплатный — установка в пару кликов через Unyly без оплаты.
Нужен ли API-ключ для Ssh Fleet?
Нет, Ssh Fleet работает без API-ключей и переменных окружения.
Ssh Fleet — hosted или self-hosted?
Доступен hosted-вариант: Unyly запускает сервер в облаке, локальная установка не обязательна.
Как установить Ssh Fleet в Claude Desktop, Claude Code или Cursor?
Открой Ssh Fleet на unyly.org, выбери вкладку своего клиента (Claude Desktop, Claude Code, Cursor) и нажми Install — конфиг сгенерируется автоматически, без правки JSON.
Похожие MCP
GitHub
PRs, issues, code search, CI status
автор: GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
автор: mcpdotdirectCompare Ssh Fleet with
Не уверен что выбрать?
Найди свой стек за 60 секунд
Автор?
Embed-бейдж для README
Похожее
Все в категории development
