中文日本語

Features

Want AI to watch or run your machine?

What the assistant can do

The MCP server offers nine tools: host information, list VMs, show one VM, start, stop, force off, create, delete, and read the last lines of a VM's serial console. Tools that change nothing are marked read-only, and delete is marked destructive.

A skill in the Agent Skills format comes with it. It tells the assistant what is different on keelOS (a hypervisor under the host, guest memory kept in a pool, storage on ZFS), how to do a health check and write the report, where to look when a VM does not boot, and when to ask first: before stopping a router or NAS VM, since the assistant may lose its own way to the host.

How it connects

The MCP tools are clients of the same HTTPS API as the web interface and the command line. Each call goes through the same permission check and lands in the same audit log. For an assistant on your own computer there is keel-mcp, a small standalone program that passes MCP messages to the host over HTTPS and checks the host's certificate by its fingerprint. keel-mcp --check tells a connection problem apart from a token that is not allowed enough.

What a token allows

  • Which operations: read, power, console, write, delete, and so on.
  • Which VMs: all of them, a list, or those with a tag. VMs outside the token look as if they did not exist.
  • From which addresses, and until when.
  • Deleting is a separate permission and is not part of vm:*. A delete also needs the VM's name as confirmation.
  • A token cannot hand out more than it has itself.

In testing, an assistant created a VM, started it, waited for the login prompt on the console, stopped it and deleted it. A wrong confirmation name was refused, and VMs outside its token were not visible.

Not done yet

The MCP tools do not yet cover snapshots, suspend, typing into a console, ISO images, network, storage, tokens, or restarting and upgrading the host. The API has most of these; they can become tools later. The skill says so, so the assistant does not try to piece them together. The skill and keel-mcp are not yet in the release repository.

← All features