Skip to main content
Glama

Reconfigure a Virtual Machine

reconfigure_virtual_machine
DestructiveIdempotent

Change an existing Cycle virtual machine: its config (hostname, public network mode, ports, egress, CPU, RAM), its guest root password, its assigned SSH keys, or its metadata (name, identifier, annotations, lock, deprecate). Volumes are NOT handled here — VM volume changes exist on Cycle but have no MCP tool yet; surface that gap rather than improvising. The boot image is fixed at create; there is no VM equivalent of a container reimage. The container equivalent is reconfigure_container.

Each group reaches Cycle through a different mechanism and differs in disruption; every change in the preview diff is tagged with an 'impact':

  • 'restart' — config. Cycle's reconfigure REPLACES the VM's entire config, so this tool fetches the current config, applies only the fields you pass, and submits the whole result; everything you don't pass keeps its value (including deployment constraints, startup/shutdown policies, telemetry, and runtime attachments). Applying RESTARTS the VM — a hard interruption of a running guest OS.

  • 'root-password' — the guest's root password, changed by a Cycle job inside the VM. Neither the preview nor the result echoes it; whoever sets it must record it themselves, since Cycle only makes a VM's root password readable for ~10 minutes after creation.

  • 'none' — metadata and SSH key assignment. Applies immediately: no job, no restart. Cycle stores one flat list of assigned keys; add_ssh_keys/remove_ssh_keys read it, apply your changes, and write it back. Keys are written into the guest at provision time, so a running guest may not honor an added key until it restarts, and removing a key does NOT reliably revoke access for a running guest — to be certain, restart the VM (cycle_control_virtual_machine) and verify from inside the guest.

Always call with preview:true first — it fetches the current state and returns a field-by-field from/to diff with each change's impact, making NO changes. The diff is computed by this tool, not validated by Cycle; use it to confirm the change matches the user's intent. Get explicit confirmation, then call again without preview.

Changes from several groups are applied in order — metadata and SSH keys, then config, then root password — and each step is reported in 'steps'. The run stops at the first failed step, so a partial result is possible; read 'steps' rather than assuming all-or-nothing.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
ramNoNew RAM limit, e.g. '4G'. At least 512M, less than 65G.
lockNotrue blocks delete_virtual_machine until unlocked; false lifts the lock.
nameNoNew display name.
coresNoNew core count (1-32), placed by Cycle. Mutually exclusive with cpu_pin; clears any pinning.
portsNoComplete replacement port list, e.g. ['443:443'] — pass every port wanted.
publicNoNew public network access mode.
contextNoWhy are you calling this tool? Briefly describe the user's goal.
cpu_pinNoPin to specific host cores, e.g. '0-3' ('x' = the host's max core). Mutually exclusive with cores; clears the core count.
previewNoReturn the from/to diff with each change's impact and make NO changes. Always run this first.
hostnameNoNew private-network hostname.
deprecateNoMark the VM deprecated (true) or undo it (false).
identifierNoNew identifier slug.
annotationsNoReplacement annotation map (user metadata); replaces every existing annotation.
environmentYesEnvironment the VM lives in.
add_ssh_keysNoExisting environment-scoped SSH keys to assign, by name or 24-char ID.
allocate_ramNoPreallocate the RAM limit rather than letting the guest grow into it.
wait_secondsNoMax seconds to wait, across every step this call performs. 0 returns as soon as the jobs are accepted.
root_passwordNoNew guest root password, at least 10 characters. Confirm with the user and have them record it before applying.
allocate_coresNoReserve the cores exclusively so no other VM can use them.
conversation_idNoConversation tracking id. Omit on your first tool call; every result then includes a conversation_id line — pass that exact value on all later calls in this conversation.
remove_ssh_keysNoAssigned SSH keys to unassign, by name or 24-char ID.
virtual_machineYesVM to reconfigure.
egress_via_gatewayNoRoute outbound traffic through the Cycle gateway instead of the host.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations (destructive=true, idempotent=true, openWorld=true) only set the safety profile; the description adds far more: per-group 'impact' tags, the fact that config changes restart the guest, that root password is never echoed and only readable ~10 min post-create, that SSH key removal does not reliably revoke access, and that multi-group runs are ordered and can partially fail. This is exactly the behavioral context annotations cannot carry.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Long but well organized with grouped bullets and impact labels; each sentence carries distinct operational information. Slightly dense and could trim a few clauses, but nothing is filler given 23 parameters and multi-step behavior.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description compensates fully by explaining the preview diff, the 'steps' reporting, and the partial-failure model. An agent has everything needed to call this correctly and safely for a 23-parameter mutation tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds real meaning beyond the schema: it explains the preview-diff mechanism, the config-replacement-with-preserve semantics, and how SSH-key and root-password parameters behave at runtime. It goes beyond restating field-level docs.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (Change/reconfigure) and resource (an existing Cycle VM), then enumerates the changeable groups (config, root password, SSH keys, metadata) and explicitly excludes what it does not cover (volumes, boot image). It names the sibling reconfigure_container and contrasts with the container reimage, so an agent can distinguish it without opening a schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives an explicit workflow ('Always call with preview:true first... Get explicit confirmation, then call again without preview'), names alternatives for adjacent needs (reconfigure_container, cycle_control_virtual_machine for restart), and flags the volume gap rather than improvising. When-to-use and when-not-to-use are both covered.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources