Secure MCP server that gives AI agents structured, audited access to Linux VPS: monitoring, Docker and Compose management, config changes, security checks, and safe recovery over SSH.
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
claude mcp add vps-guardian-mcp -- npx -y @murzirius/vps-guardian-mcp{
"mcpServers": {
"vps-guardian-mcp": {
"command": "npx",
"args": ["-y", "@murzirius/vps-guardian-mcp"]
}
}
}Resumen de MCP Servers
# VPS Guardian MCP
[](https://github.com/murzirius/VPS-Guardian-MCP/actions/workflows/ci.yml)
[](https://www.npmjs.com/package/@murzirius/vps-guardian-mcp)
[](https://pypi.org/project/vps-guardian-mcp/)
[](LICENSE)
VPS Guardian is a secure [Model Context Protocol](https://modelcontextprotocol.io/) server for AI agents that work with Linux VPSs. It replaces an unrestricted “run this command and paste the result” loop with named, structured and safety-checked operations.
An agent can inspect a workload, collect bounded diagnostics, preview the impact of a change, and request an exact confirmation for a mutation. The server never exposes a general-purpose shell tool.
**Explore the project:** [capabilities](https://thomas-studios.com/projects/vps-guardian-mcp#capabilities) · [agent workflows](https://thomas-studios.com/projects/vps-guardian-mcp#agent-workflows) · [security model](https://thomas-studios.com/projects/vps-guardian-mcp#security) · [tool catalogue](https://thomas-studios.com/projects/vps-guardian-mcp#tools) · [release notes](UPDATES.md)
<!-- mcp-name: io.github.murzirius/vps-guardian-mcp -->
## Quick start
VPS Guardian has two parts:
- The Python MCP server runs on the VPS.
- The small npm launcher runs on the computer where Codex, Claude, Cursor or another AI client is installed. It opens an SSH stdio connection and never uploads the private key.
### What you need
- A Linux VPS reachable via SSH.
- An SSH key for that VPS.
- Python 3.10+ on the VPS and Node.js 16+ on the AI client's computer.
- A verified SSH host key. Password-based SSH is intentionally unsupported by the launcher.
### 1. Install the server on the VPS
Run once on the VPS. This installs the published, pinned release:
```bash
sudo mkdir -p /opt/vps-guardian-mcp
sudo chown "$USER" /opt/vps-guardian-mcp
python3 -m venv /opt/vps-guardian-mcp/.venv
/opt/vps-guardian-mcp/.venv/bin/pip install --upgrade pip
/opt/vps-guardian-mcp/.venv/bin/pip install vps-guardian-mcp==0.19.1
```
For development from source instead:
```bash
git clone --branch v0.19.1 https://github.com/murzirius/VPS-Guardian-MCP.git /opt/vps-guardian-mcp
cd /opt/vps-guardian-mcp
python3 -m venv .venv
.venv/bin/pip install -e .
```
If the server runs as a non-root user, grant only the required read access. Docker and journal features gracefully report as unavailable when that access is absent.
```bash
sudo usermod -aG docker <MCP_USER>
sudo usermod -aG systemd-journal <MCP_USER>
```
Log out and back in after changing groups.
### 2. Choose a safety mode
| Mode | Use it when | Result |
| --- | --- | --- |
| `read-only` | Inspecting or diagnosing | Default. Every mutation is blocked. |
| `controlled` | Assisted administration | Recommended. Each exact change needs a short-lived, single-use confirmation token. |
| `unrestricted` | A separately protected automation environment | Changes run immediately. Avoid on a general-purpose agent. |
Start with `read-only`; use `controlled` once the connection is verified.
### 3. Connect an AI client over SSH
First verify the VPS fingerprint independently and make a normal SSH connection once. That stores the host key in `~/.ssh/known_hosts` (or `%USERPROFILE%\.ssh\known_hosts` on Windows). The launcher requires host-key verification by default.
Use this configuration for JSON-based MCP clients:
```json
{
"mcpServers": {
"vps-guardian": {
"command": "npx",
"args": [
"-y",
"@murzirius/vps-guardian-mcp@0.19.1",
"--host", "<VPS_IP_OR_HOSTNAME>",
"--user", "root",
"--key", "~/.ssh/id_ed25519",
"--mode", "controlled"
]
}
}
}
```
Every item in `args` is a separate argument. Do not join `--host` with its value or paste the entire command into one form field.
### 4. Codex / ChatGPT Desktop
Open **Settings → MCP servers → Add server**, choose **STDIO**, then enter:
| Field | Value |
| --- | --- |
| Name | `vps-guardian` |
| Command | `npx` |
| Environment variables | Leave empty |
| Working directory | Leave empty/default |
Add these arguments as separate rows, in order:
```text
-y
@murzirius/vps-guardian-mcp@0.19.1
--host
<VPS_IP_OR_HOSTNAME>
--user
root
--key
C:\Users\<WindowsUser>\.ssh\id_ed25519
--mode
controlled
```
Save, restart the client, then use `/mcp` to confirm that `vps-guardian` is connected.
### 5. Common situations
**Claude Code**
```bash
claude mcp add vps-guardian -- npx -y @murzirius/vps-guardian-mcp@0.19.1 --host <VPS_IP_OR_HOSTNAME> --user root --key ~/.ssh/id_ed25519 --mode controlled
```
**A non-root SSH user** — replace `root` after `--user`. Do not add passwordless `sudo` just for the MCP; grant the minimum group permissions needed.
**A non-standard port** — add separate arguments:
```text
--port
2222
```
**A different server location** — add:
```text
--remote-path
/srv/vps-guardian/.venv/bin/vps-guardian-mcp
```
**Host key verification failed** — do not disable verification. Check the VPS fingerprint through a trusted channel and correct `known_hosts`. Use `--known-hosts <path>` for a dedicated file. `--accept-new-host-key` is only for an intentional first-time bootstrap.
### 6. Verify and upgrade
Ask the agent: **“Check CPU and RAM load on my server.”** A correct setup returns structured VPS data rather than a shell command for you to run.
To upgrade the VPS server, install the matching version and restart the client connection:
```bash
/opt/vps-guardian-mcp/.venv/bin/pip install --upgrade vps-guardian-mcp==X.Y.Z
```
Then replace `@0.19.1` with `@X.Y.Z` in the client configuration. For source installations, fetch the tag, inspect local changes, check out the tag, and reinstall with `.venv/bin/pip install -e .`.
## What it can do
VPS Guardian is built around a few workflows instead of a long, unstructured command list:
- **Observe:** system pressure, processes, services, Docker, databases, ports, TLS, logs and updates.
- **Understand a workload:** discover a site or Compose project, map its dependencies and health, then collect focused diagnostic evidence.
- **Coordinate agents:** secret-redacted sessions, handoffs, short-lived workload locks and resumable server-event watches.
- **Change safely:** preview impact, stage configuration changes, validate, back up, health-check and roll back when a deployment fails.
- **Recover deliberately:** create baselines, compare drift, produce repair plans and require exact confirmation for changes.
Examples of native MCP tools:
| Request | Example tool | Result |
| --- | --- | --- |
| “Why is the API slow?” | `diagnose_workload` | Bounded health, logs, OOM and kernel evidence. |
| “What will a restart affect?” | `get_change_impact` | A read-only dependency and impact report. |
| “Hand this incident to another agent.” | `handoff_agent_session` | Secret-redacted context and outcome tracking. |
| “Deploy this Nginx change safely.” | `plan_config_deployment` | Validated diff, backup, confirmation and rollback path. |
See the [complete capability guide](https://thomas-studios.com/projects/vps-guardian-mcp#capabilities) and [full tool catalogue](https://thomas-studios.com/projects/vps-guardian-mcp#tools) on the project site.
## Security model
- No arbitrary command-execution MCP tool.
- Server-side allow-lists for files, paths, services and mutation types.
- `controlled` mode uses parameter-bound, single-use confirmation tokens.
- Secret values are redacted from file reads, sessions, audit data and diagnostic output.
- Reads, logs, directory scans and stored state are bounded for small VPSs.
Details: [security model](https://thomas-studios.com/projects/vps-guardian-mcp#security) · [agent operating guide](https://thomas-studios.com/projects/vps-guardian-mcp#agent-workflows)
## Packages and releases
- npm: [`@murzirius/vps-guardian-mcp`](https://www.npmjs.com/package/@murzirius/vps-guardian-mcp)
- PyPI: [`vps-guardian-mcp`](https://pypi.org/project/vps-guardian-mcp/)
- MCP Registry: [`io.github.murzirius/vps-guardian-mcp`](https://registry.modelcontextprotocol.io/)
- GitHub Packages mirrors each npm release; npmjs is recommended for normal installation.
## Development
```bash
python -m unittest discover -s tests -v
npm test
```
Please report security issues privately rather than publishing exploit details in a public issue.
## License
[MIT](LICENSE) © 2026 murzirius.
Lo que la gente pregunta sobre VPS-Guardian-MCP
¿Qué es murzirius/VPS-Guardian-MCP?
+
murzirius/VPS-Guardian-MCP es mcp servers para el ecosistema de Claude AI. Secure MCP server that gives AI agents structured, audited access to Linux VPS: monitoring, Docker and Compose management, config changes, security checks, and safe recovery over SSH. Tiene 0 estrellas en GitHub y su última actualización registrada es del 2026-09-16.
¿Cómo se instala VPS-Guardian-MCP?
+
Puedes instalar VPS-Guardian-MCP clonando el repositorio (https://github.com/murzirius/VPS-Guardian-MCP) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar murzirius/VPS-Guardian-MCP?
+
Nuestro agente de seguridad ha analizado murzirius/VPS-Guardian-MCP y le ha asignado un Trust Score de 95/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene murzirius/VPS-Guardian-MCP?
+
murzirius/VPS-Guardian-MCP es mantenido por murzirius. La última actividad registrada en GitHub es del 2026-09-16, con 0 issues abiertos.
¿Hay alternativas a VPS-Guardian-MCP?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega VPS-Guardian-MCP en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/murzirius-vps-guardian-mcp)<a href="https://claudewave.com/repo/murzirius-vps-guardian-mcp"><img src="https://claudewave.com/api/badge/murzirius-vps-guardian-mcp" alt="Featured on ClaudeWave: murzirius/VPS-Guardian-MCP" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ
The fastest path to AI-powered full stack observability, even for lean teams.