Skip to main content
Glama
elmuz

Remote Server MCP

by elmuz

Remote Server MCP

Python 3.11+ License: MIT

A security-first MCP server that gives AI assistants controlled, safe access to manage remote servers via SSH.

Design principle: Whitelist operations, don't blacklist commands. No generic command execution — only 13 validated tools.

┌───────────────┐    ┌──────────────────────────────┐    ┌──────────────┐
│  AI Assistant │───▶│        MCP Server            │───▶│  SSH to      │
│  (Qwen Code)  │◀───│      (Secure Tools Only)     │◀───│  Remote      │
└───────────────┘    │                              │    │  Server      │
                     │  Safe Tools:                 │    └──────────────┘
                     │  • list_services()           │
                     │  • get_service_logs()        │
                     │  • get_service_status()      │
                     │  • restart/start/stop        │
                     │  • get_service_file()        │
                     │  • list_service_files()      │
                     │  • search_service_logs()     │
                     │  • get_server_health()       │
                     │  • query_influxdb()          │
                     │  • query_prometheus()        │
                     │  • get_prometheus_targets()  │
                     └──────────────────────────────┘
                                │
                     All commands validated
                     against security policy
                     before execution

Quick Start

uv pip install -e . --python .venv
cp config.example.yaml config.yaml   # edit with your SSH details
uv run pytest tests/ -v

See Getting Started for full setup instructions and Qwen Code integration.

Related MCP server: Simple SSH MCP Server

Architecture

This project is a thin MCP server layer built on top of server-management-lib, which provides the core security validation, SSH management, and HTTP clients:

remote-server-mcp/          # This project — MCP server layer
├── src/remote_server_mcp/
│   ├── __init__.py         # Entry point
│   └── server.py           # MCP tool definitions (13 tools)
└── tests/

server-management-lib/      # Shared library (separate repo)
├── security.py             # Security validator
├── ssh_manager.py          # SSH connection handler
├── http_clients.py         # InfluxDB + Prometheus clients
└── config.py               # Configuration loader

Security Model 🛡️

  • ❌ No arbitrary command execution

  • ❌ No file access outside /srv/{service}/

  • ❌ No sensitive files (.env, .git/, *.key, secrets)

  • ✅ Only specific, validated Docker operations

  • ✅ All inputs sanitized against injection, traversal, and encoding bypasses

See Security Model for the full threat model and controls.

Available Tools

Tool

Purpose

list_services

List services in /srv/

get_service_logs

Docker container logs

get_service_status

Status + resource usage

restart_service

Restart container

start_service

Start container

stop_service

Stop container

get_service_file

Read files in /srv/{service}/

list_service_files

List service directory

search_service_logs

Search logs (plain text)

get_server_health

CPU / memory / disk metrics

query_influxdb

Query InfluxDB v3 via SQL (read-only)

query_prometheus

Query Prometheus via PromQL

get_prometheus_targets

List Prometheus scrape targets

See Tools for detailed descriptions.

Development

uv run ruff check . && uv run ruff format . && uv run ty check && uv run pytest tests/ -v

See Development for project structure, pre-commit hooks, and how to add new tools safely.

License

This tool is licensed under the terms of MIT license.

See LICENSE for more information.

A
license - permissive license
-
quality - not tested
D
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    D
    maintenance
    An MCP server that enables remote SSH command execution and bidirectional file transfers through a standardized interface. It allows AI assistants to securely manage remote servers while keeping credentials isolated and applying command-level security controls.
    Last updated
    ISC
  • A
    license
    -
    quality
    C
    maintenance
    An MCP server that gives AI agents SSH access to remote machines through your local OpenSSH client, enabling remote command execution, file transfer, persistent shell sessions, and port forwarding.
    Last updated
    4
    MIT
  • A
    license
    -
    quality
    C
    maintenance
    A secure SSH-based MCP server for diagnosing remote servers. It allows AI agents to execute read-only commands and read files automatically, while requiring user confirmation for write operations.
    Last updated
    MIT

View all related MCP servers

Related MCP Connectors

  • Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step.

  • An MCP server for Arcjet - the runtime security platform that ships with your AI code.

  • Operate your Linux servers from your LLM. Every action runs through an auditable allowlist.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/elmuz/remote-server-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server