nodel-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@nodel-mcplist all nodes in the runtime"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Nodel AI MCP Sidecar
Model Context Protocol sidecar for a local Nodel runtime. This release is an
independent unsupported preview (v0.1.x), is not affiliated with Museum Victoria,
and does not imply upstream endorsement.
The source and release repository is mcartmel/nodel-mcp.
For compatibility, the v0.1 runtime, package, service, state paths, and release
artifacts remain named nodel-ai.
Clone the repository for development:
git clone https://github.com/mcartmel/nodel-mcp.gitReleased archives and checksums are published on the GitHub Releases page.
Preview and Support Posture
Supported shape: Linux + Node.js 22, with
systemdas the supported service manager.Support status: unsupported public preview, no SLA, and no commitment to review issues or pull requests.
Security posture: single-operator deployment patterns only (not multi-user, multi-tenant).
Compatibility stance: pre-1.0 MCP/HTTP interface; patch releases should avoid intentional breaking changes, while minor releases may break with notes.
Nodel baseline: 2.2.1.542 is the validated baseline compatibility target; other versions are best effort until listed in the compatibility matrix.
Related MCP server: argocd-mcp
Quick Start (Read-Only by Default)
The v0.1 release path is a versioned GitHub Release archive. Extract it and run the precompiled application without a build. Before starting, choose the Nodel runtime to connect to and whether this sidecar should expose write tools.
Extract
nodel-ai-v<version>.tar.gzand enter its directory.Install production dependencies:
npm ci --omit=devCopy the example environment:
cp .env.example .envSet the primary Nodel runtime in
.env.If Nodel and this sidecar run on the same host, keep the default:
NODEL_BASE_URL=http://127.0.0.1:8085If Nodel runs on another trusted host, replace it with that host's reachable REST base URL, for example:
NODEL_BASE_URL=http://nodel-host.example.internal:8085127.0.0.1always means the sidecar's own network namespace. When running the sidecar in a container or on another machine, use an address it can actually reach. Do not pointNODEL_BASE_URLat an untrusted service or expose Nodel's REST port directly to an untrusted network.Choose an access mode in
.env.No changes are required for read-only operation. To enable parameter, binding, recipe/file, and action writes while retaining short-lived operator approvals, set:
NODEL_ENABLE_WRITES=true NODEL_REQUIRE_WRITE_APPROVAL=trueCreate and restart operations require one additional gate:
NODEL_ENABLE_NODE_LIFECYCLE=trueDeletion is a separate, cumulative opt-in and requires all three gates:
NODEL_ENABLE_WRITES=true NODEL_ENABLE_NODE_LIFECYCLE=true NODEL_ENABLE_DELETES=true NODEL_REQUIRE_WRITE_APPROVAL=trueKeep
NODEL_REQUIRE_WRITE_APPROVAL=truefor normal operation. Approval IDs are workflow controls, not authentication; keep the MCP listener loopback-only or configure the token and reverse-proxy protections described below.Start the service:
node dist/index.jsConfirm sidecar liveness and connectivity to the configured Nodel runtime:
curl -s http://127.0.0.1:8765/healthz curl -s http://127.0.0.1:8765/readyz/healthzconfirms that the sidecar is running./readyzconfirms that it can reachNODEL_BASE_URL. Add the configured bearer token whenNODEL_MCP_TOKENis set.
For non-loopback access, use the tested Caddy renderer documented in
docs/operations.md. Caddy is never bundled or
auto-installed; keep the out-of-band token in a 0600 .env.
Host warning: this host currently exposes plaintext/basic-auth 8080 and
unauthenticated 8085. The host is not secure until those listeners are
firewalled or rebound; the renderer only warns.
The service is read-only by default. Write, lifecycle, and delete capabilities are enabled independently and cumulatively through the gates above.
Release downloads also include SHA256SUMS, SBOM.cdx.json,
dependency-licenses.json, and ARTIFACT-MANIFEST.json. These files are both
inside the archive and attached as separate draft-release assets; checksums cover
all of them except SHA256SUMS itself.
Required and Optional Environment
Variable | Default | Purpose |
|
| Primary trusted Nodel REST base URL; defaults to Nodel in the sidecar's host/network namespace |
|
| Listener bind address |
|
| Listener port |
| unset | Inbound bearer token for |
| unset | Exact allowed browser Origins for HTTP requests |
| unset | Exact allowed runtime origins for explicit |
|
| Persistent approval/audit/backup state |
|
| Enable maintenance writes/actions |
|
| Enable |
|
| Enable |
|
| Require workflow approval ids for writes |
Set additional request/retention limits as needed:
MCP_REQUEST_BODY_LIMIT_BYTES(default: 1048576)NODEL_AUDIT_MAX_BYTES(default: 10485760)NODEL_AUDIT_RETENTION_FILES(default: 5)NODEL_BACKUP_RETENTION_DAYS(default: 30)NODEL_BACKUP_RETENTION_PER_NODE_KIND(default: 50)
Access Modes Reference
Read-only
NODEL_ENABLE_WRITES=false
NODEL_ENABLE_NODE_LIFECYCLE=false
NODEL_ENABLE_DELETES=false
NODEL_REQUIRE_WRITE_APPROVAL=trueWrites and actions
NODEL_ENABLE_WRITES=true
NODEL_ENABLE_NODE_LIFECYCLE=false
NODEL_ENABLE_DELETES=false
NODEL_REQUIRE_WRITE_APPROVAL=trueWrites plus create/restart
NODEL_ENABLE_WRITES=true
NODEL_ENABLE_NODE_LIFECYCLE=true
NODEL_ENABLE_DELETES=false
NODEL_REQUIRE_WRITE_APPROVAL=trueDelete mode
# Writes + lifecycle + deletes + approval must all be enabled for delete mode
NODEL_ENABLE_WRITES=true
NODEL_ENABLE_NODE_LIFECYCLE=true
NODEL_ENABLE_DELETES=true
NODEL_REQUIRE_WRITE_APPROVAL=trueWrites remain experimental and require operator workflow discipline.
Trusted Network Access Model
Loopback use (
127.0.0.1) is the direct mode. For any non-loopback bind, configure a high-entropyNODEL_MCP_TOKENand set a strictMCP_ALLOWED_ORIGINSallowlist.The sidecar rejects arbitrary caller-supplied hostnames and only contacts configured/local-discovered endpoints.
Use a reverse proxy for transport hardening where needed; this component does not provide TLS termination.
If NODEL_MCP_TOKEN is present, send this header on MCP requests:
Authorization: Bearer <NODEL_MCP_TOKEN>MCP endpoint behavior
GET /healthz: unauthenticated liveness with minimal fields (ok,version).GET /readyz: protected Nodel readiness probe.POST /mcp: MCP Streamable HTTP endpoint behind token/origin policies.
When a token is configured, unauthenticated /mcp and /readyz requests must
return 401; /healthz is the unauthenticated 200 preflight.
Approval and Write Flow
This project treats write approval as a human workflow control, not a security boundary. Operational flow is:
read/proposeordryRunOperator review and confirmation
nodel.approve_writeas a fallback when MCP elicitation is unavailableApply tool with
approvalIdRead-back / readiness verification based on tool capability
nodel.request_write_approval is the MCP-native path when supported by the
client and falls back to manual confirmation guidance when unsupported.
Operations and Service Deployment
A release may be run directly (node dist/index.js) or under systemd.
Recommended service layout
The system installer supports configurable paths:
App directory: configurable (example
/opt/nodel-ai)Env file: configurable (example
/etc/nodel-ai.env)State directory: configurable (example
/var/lib/nodel-ai)
The user and system installers render units with configurable paths and service
account. User defaults use the extracted directory, .env, and .state; system
defaults use /opt/nodel-ai, /etc/nodel-ai.env, and /var/lib/nodel-ai.
scripts/install-systemd-user.shscripts/install-systemd-system.sh
For service guidance and recovery steps (backups, log interpretation, upgrade,
rollback, health/readiness, and turning writes back off), see
docs/operations.md.
Tools
The README no longer maintains a manual tool list. Use the generated reference to avoid drift:
The list is generated from canonical tool definitions and includes capability, stability, and gate information.
MCP Client Configuration
Point MCP clients at http://127.0.0.1:8765/mcp for local testing.
Minimal JSON config example
{
"mcp": {
"nodel": {
"type": "remote",
"url": "http://127.0.0.1:8765/mcp"
}
}
}Add bearer auth in the MCP client only when NODEL_MCP_TOKEN is configured.
Codex clients should use bearer_token_env_var = "NODEL_MCP_TOKEN", never a
literal token in client configuration.
Documentation
docs/architecture.md: trust boundaries and contract modeldocs/security-model.md: security assumptions and failure modeldocs/operations.md: operational runbooksdocs/operations.md#trusted-reverse-proxy-tls-example-caddy: tested Caddy renderer and rollout workflowdocs/migration-v0.1.md: migration from an earlier local build tov0.1.xdocs/releasing.md: maintainer release procedureSUPPORT.md,SECURITY.md,CHANGELOG.md,THIRD_PARTY_NOTICES.md
Compatibility and Compatibility Notes
Before 1.0.0, patch releases should avoid intentional breaking changes.
Before enabling writes, complete the migration checklist in
docs/migration-v0.1.md.
This server cannot be deployed
Maintenance
Related MCP Connectors
Model Context Protocol server for the Apideck Unified API. Connect any MCP-compatible agent framework to 100+ accounting systems, HRIS platforms, file storage providers, and more through one integration. More information https://www.apideck.com/mcp-server
Guarded MCP server for agent-readable business truth, provenance, readiness, and discovery.
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
The official MCP Server from Mia-Platform to interact with Mia-Platform Console
Related MCP Servers
AlicenseNot gradedqualityCmaintenanceModel Context Protocol (MCP) server for OpsLevel12MIT
argocd-mcpofficial
AlicenseCqualityCmaintenanceAn implementation of Model Context Protocol (MCP) server for Argo CD.1413,169566Apache 2.0- FlicenseNot gradedqualityDmaintenanceA server implementation of the Model Context Protocol (MCP) that provides REST API endpoints for managing and interacting with MCP resources.-
- AlicenseBqualityCmaintenanceModel Context Protocol (MCP) server for the Rancher ecosystem: multi-cluster Kubernetes, Harvester HCI (VMs, storage, networks), and Fleet GitOps.1012Apache 2.0