CesSpace ARC
Provides tools for interacting with Git repositories, including branch protection, diff inspection, and commit operations, with policy enforcement and audit logging.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@CesSpace ARCshow me the git diff and recent commits"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
CesSpace ARC — Secure Agent-to-Machine Control Plane
CesSpace ARC (Agent Remote Control) is a secure, vendor-neutral control plane that provides policy-enforced, audited access to development machines, repositories, terminals, and processes for authorized AI clients and coding agents.
Overview
Modern MCP-compatible AI clients need controlled access to host environments for tasks such as reading files, inspecting diffs, running tests, and managing processes. Direct ambient access creates material security risks, including destructive filesystem actions, credential exposure, prompt-driven command execution, and repository tampering.
CesSpace ARC places an explicit security boundary between the client and the host. Every privileged operation is mediated through authentication, policy evaluation, approval where required, and audit before the relevant subsystem can execute.
Related MCP server: MCP SSH Orchestrator
Architecture
AI Client / Coding Agent
|
v
MCP Interface
|
v
ARC Gateway & Authentication
|
v
Policy Engine
|
v
Approval + Audit
|
v
Authorized Workspace
| | | |
Files Git Terminal ProcessesThe core invariant is simple:
No filesystem, Git, terminal, or process operation may execute without traversing the ARC security pipeline.
Key capabilities
Default-deny policy enforcement with explicit
DENY > REQUIRE_APPROVAL > ALLOWprecedence.Human approval for sensitive or mutating operations.
Workspace containment with canonical path checks and strict filesystem boundaries.
Controlled Git operations with protected-branch safeguards.
Bounded terminal and process execution without shell interpolation.
Durable audit evidence with redaction, integrity checks, and fail-closed behavior.
Vendor-neutral MCP interoperability for standards-conformant clients.
Local operation without requiring a CesSpace account or hosted service.
Release and platform support
The current stable release is CesSpace ARC Core 1.0.0.
Supported: Linux x86-64
Development-compatible: WSL Linux userspace
Validation-only: Linux arm64 and macOS
Unsupported: native Windows host execution
Canonical release and publisher information are maintained in PUBLISHER.md.
Security
ARC is designed around zero implicit trust, least privilege, fail-closed behavior, mandatory policy mediation, explicit approval for sensitive actions, and append-only audit evidence.
See:
Installation and operation
Start with the operator documentation:
Example configuration and policy templates are available under examples/.
Documentation
Architecture and implementation references:
Historical release-candidate acceptance documents remain in the repository because current source, verification scripts, and tests reference them. They are engineering evidence, not the primary product documentation surface.
Development
CesSpace ARC uses:
Node.js:
^24.0.0Package manager:
pnpm@12.4.2Workspace protocol:
workspace:*
Common checks:
pnpm install --frozen-lockfile
pnpm run check:format
pnpm run lint
pnpm run typecheck
pnpm run test
pnpm run buildSee CONTRIBUTING.md before proposing changes.
Public repository policy
The public repository contains ARC Core source, stable release information, operator documentation, security/privacy material, contribution guidance, and technical verification evidence.
Private CesSpace strategy, commercial planning, internal delivery sequencing, and private infrastructure details do not belong on the public branch.
Security reporting
Do not open a public issue for a suspected vulnerability.
Follow the private reporting process in SECURITY.md.
Publisher and identity
Official publisher, release provenance, and distribution identity are documented in PUBLISHER.md.
Trademark and branding rules are documented in TRADEMARKS.md.
Contributing
Contributions are welcome subject to the security and review requirements in CONTRIBUTING.md and the Code of Conduct.
Project stewardship and support boundaries are documented in GOVERNANCE.md, MAINTAINERS.md, and SUPPORT.md.
License
CesSpace ARC Core is licensed under the Apache License, Version 2.0.
This server cannot be deployed
Maintenance
Related MCP Connectors
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Fail-closed policy guardrails for AI agents running kubectl, terraform, helm, and argocd.
Context and control for any AI. Agent identity, scoped access, and proof across tools.
Governance layer for AI coding agents: knowledge-graph grounding, session audit, policy controls.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables secure remote access operations through SSH, SFTP, rsync, VPN, and tunneling with enterprise-grade policy enforcement and audit logging. Provides AI assistants with secure, policy-driven access to remote systems while maintaining comprehensive audit trails and zero-trust security.1Apache 2.0
- AlicenseBqualityAmaintenanceProvides policy-driven, auditable SSH access to server fleets for AI assistants with zero-trust security controls, command whitelisting, and comprehensive audit logging to safely manage infrastructure.1328Apache 2.0
- FlicenseNot gradedqualityAmaintenanceGive AI agents Zero-Trust access to production infrastructure without the risks of granting them shell access. Actions are bounded by policy and an on-host runner.337-
- AlicenseCqualityAmaintenanceSecure agent coding runtime for local Git repos with policy enforcement, RBAC, sessions, approval workflow, and sandboxed writes, optionally connectable to ChatGPT via Secure MCP Tunnel.86MIT