Server ops MCP: logs, monitoring, code edit, Nginx & certs. Local + SSH, confirmations & redaction.
English | 简体中文
A general-purpose server-ops MCP Server. Let AI tools like Claude Code / Cursor / Codex manage multiple projects or servers through .mcp.json — log troubleshooting, system resource inspection, code read/write, and Nginx / certificate management.
Supports local and remote (SSH) modes, with built-in two-step confirmation, command whitelisting, path-traversal protection, and automatic secret redaction.
Requires Node.js 18+. No clone or build needed — npx fetches and runs the published npm package on first use (see the config below).
To build from source instead (e.g. for development):
git clone https://github.com/GT-dinuo/server-ops-mcp.git
cd server-ops-mcp
npm install
npm run build
Build output goes to dist/; the entry point is dist/index.js.
In each project where you want to use this tool, create (or append to) .mcp.json and declare an MCP Server per environment. Local mode only needs OPS_PROJECT_ROOT; remote mode adds the SSH variables.
{
"mcpServers": {
"myproject-server": {
"command": "npx",
"args": ["-y", "server-ops-mcp"],
"env": {
"OPS_PROJECT_ROOT": "/www/wwwroot/your-project",
"OPS_SSH_HOST": "<server-ip-or-domain>",
"OPS_SSH_PORT": "22",
"OPS_SSH_USER": "ubuntu",
"OPS_SSH_KEY": "~/.ssh/id_rsa"
}
}
}
}
If you built from source, point the command at the local build instead: "command": "node", "args": ["/absolute/path/to/server-ops-mcp/dist/index.js"].
| Variable | Required | Description |
|---|---|---|
OPS_PROJECT_ROOT | Yes | Project root path; all file operations are sandboxed here |
OPS_SSH_HOST | No | Remote server IP / domain; leave empty to run locally |
OPS_SSH_PORT | No | SSH port, default 22 |
OPS_SSH_USER | No | SSH username |
OPS_SSH_KEY | No | Path to SSH private key (choose either key or password) |
OPS_SSH_PASSWORD | No | SSH password (choose either key or password) |
OPS_SSH_PASSPHRASE | No | Private key passphrase |
OPS_CONFIG_PATH | No | Path to an extra config file — see "Custom Configuration" |
Once configured, just give ops instructions in natural language in your AI tool. The AI picks and calls the right tool automatically.
Check the server's CPU, memory, and disk usage
Search for error-level logs from the last hour
List the project's log files
Read the Nginx config and check for problems
Find every place in the code that calls sendSms
For writes, deletes, command execution, Nginx reload, certificate install, and similar, the tool first returns a confirmationId. The AI shows you exactly what will run, and it only executes after you confirm:
You: Reload nginx
AI: (calls nginx_reload, returns the pending action + confirmationId)
About to run: nginx -s reload. Confirm?
You: Confirm
AI: (calls confirm_execute to run it)
file_write, file_patch, file_delete, command_exec, and similar all follow the same confirmation flow.
memory_analysis + log_search working togetherdisk_analysisconfig_audit (output is auto-redacted)| Tool | Description |
|---|---|
system_info | CPU / memory / disk / load / processes |
memory_analysis | Memory usage analysis |
disk_analysis | Disk usage analysis |
service_status | Service status |
log_search_system | Search system logs |
nginx_config_test | Test Nginx config |
nginx_config_read | Read Nginx config |
nginx_reload | Reload Nginx (requires confirmation) |
certbot_install | Install certificate (requires confirmation) |
certbot_renew | Renew certificate (requires confirmation) |
| Tool | Description |
|---|---|
log_list | List project logs |
log_read | Read a log |
log_search | Search logs |
file_read | Read a file |
file_list | List a directory |
file_search | Search code |
file_write | Write a file (requires confirmation) |
file_patch | Patch a file (requires confirmation) |
file_delete | Delete a file (requires confirmation) |
command_exec | Run whitelisted commands |
project_overview | Project overview |
config_audit | Audit config (auto-redacted) |
confirm_execute | Confirm and run a pending action |
confirm_execute).rm -rf, sudo, and piping into a shell are rejected.OPS_PROJECT_ROOT; path traversal is blocked..env files and logs are automatically redacted.Download config.example.json as config.json, then point OPS_CONFIG_PATH at it to customize log channels, the command whitelist, read limits, and more.
curl -o config.json https://raw.githubusercontent.com/GT-dinuo/server-ops-mcp/main/config.example.json
# (if you cloned the repo: cp config.example.json config.json)
# After editing config.json, set in the .mcp.json env:
# "OPS_CONFIG_PATH": "/absolute/path/to/config.json"
Main fields of config.example.json:
logChannels: channel name → log directory path (relative to project root)maxReadLines / maxReadBytes: per-read line / byte limitscommandWhitelist.direct: commands that run directlycommandWhitelist.confirm: commands that require confirmationnpm run dev # watch mode, recompiles on change
npm run build # build to dist/
npm run clean # remove dist/
npm start # run the built Server
600 (chmod 600 ~/.ssh/id_rsa)..mcp.json or config.json containing passwords to a repository.MIT © 2026 server-ops-mcp
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y server-ops-mcpMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-gt-dinuo-server-ops-mcp": {
"command": "npx",
"args": [
"-y",
"server-ops-mcp"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referenceserver-ops-mcpnpmServer Ops MCP works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.