Skip to main content
Glama

CesSpace ARC — Secure Agent-to-Machine Control Plane

License Stage Security Policy Node pnpm

CesSpace ARC (Agent Remote Control) is a secure, vendor-neutral control plane that provides policy-enforced, audited access to development machines, repositories, terminals, and processes for authorized AI clients and coding agents.

Overview

Modern MCP-compatible AI clients need controlled access to host environments for tasks such as reading files, inspecting diffs, running tests, and managing processes. Direct ambient access creates material security risks, including destructive filesystem actions, credential exposure, prompt-driven command execution, and repository tampering.

CesSpace ARC places an explicit security boundary between the client and the host. Every privileged operation is mediated through authentication, policy evaluation, approval where required, and audit before the relevant subsystem can execute.

Related MCP server: MCP SSH Orchestrator

Architecture

AI Client / Coding Agent
          |
          v
MCP Interface
          |
          v
ARC Gateway & Authentication
          |
          v
Policy Engine
          |
          v
Approval + Audit
          |
          v
Authorized Workspace
   |        |        |        |
 Files    Git    Terminal  Processes

The core invariant is simple:

No filesystem, Git, terminal, or process operation may execute without traversing the ARC security pipeline.

Key capabilities

  • Default-deny policy enforcement with explicit DENY > REQUIRE_APPROVAL > ALLOW precedence.

  • Human approval for sensitive or mutating operations.

  • Workspace containment with canonical path checks and strict filesystem boundaries.

  • Controlled Git operations with protected-branch safeguards.

  • Bounded terminal and process execution without shell interpolation.

  • Durable audit evidence with redaction, integrity checks, and fail-closed behavior.

  • Vendor-neutral MCP interoperability for standards-conformant clients.

  • Local operation without requiring a CesSpace account or hosted service.

Release and platform support

The current stable release is CesSpace ARC Core 1.0.0.

  • Supported: Linux x86-64

  • Development-compatible: WSL Linux userspace

  • Validation-only: Linux arm64 and macOS

  • Unsupported: native Windows host execution

Canonical release and publisher information are maintained in PUBLISHER.md.

Security

ARC is designed around zero implicit trust, least privilege, fail-closed behavior, mandatory policy mediation, explicit approval for sensitive actions, and append-only audit evidence.

See:

Installation and operation

Start with the operator documentation:

Example configuration and policy templates are available under examples/.

Documentation

Architecture and implementation references:

Historical release-candidate acceptance documents remain in the repository because current source, verification scripts, and tests reference them. They are engineering evidence, not the primary product documentation surface.

Development

CesSpace ARC uses:

  • Node.js: ^24.0.0

  • Package manager: pnpm@12.4.2

  • Workspace protocol: workspace:*

Common checks:

pnpm install --frozen-lockfile
pnpm run check:format
pnpm run lint
pnpm run typecheck
pnpm run test
pnpm run build

See CONTRIBUTING.md before proposing changes.

Public repository policy

The public repository contains ARC Core source, stable release information, operator documentation, security/privacy material, contribution guidance, and technical verification evidence.

Private CesSpace strategy, commercial planning, internal delivery sequencing, and private infrastructure details do not belong on the public branch.

See Public Repository Policy.

Security reporting

Do not open a public issue for a suspected vulnerability.

Follow the private reporting process in SECURITY.md.

Publisher and identity

Official publisher, release provenance, and distribution identity are documented in PUBLISHER.md.

Trademark and branding rules are documented in TRADEMARKS.md.

Contributing

Contributions are welcome subject to the security and review requirements in CONTRIBUTING.md and the Code of Conduct.

Project stewardship and support boundaries are documented in GOVERNANCE.md, MAINTAINERS.md, and SUPPORT.md.

License

CesSpace ARC Core is licensed under the Apache License, Version 2.0.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables secure remote access operations through SSH, SFTP, rsync, VPN, and tunneling with enterprise-grade policy enforcement and audit logging. Provides AI assistants with secure, policy-driven access to remote systems while maintaining comprehensive audit trails and zero-trust security.
    1
    Apache 2.0
  • A
    license
    B
    quality
    A
    maintenance
    Provides policy-driven, auditable SSH access to server fleets for AI assistants with zero-trust security controls, command whitelisting, and comprehensive audit logging to safely manage infrastructure.
    13
    28
    Apache 2.0
  • F
    license
    Not graded
    quality
    A
    maintenance
    Give AI agents Zero-Trust access to production infrastructure without the risks of granting them shell access. Actions are bounded by policy and an on-host runner.
    337
    -
  • A
    license
    C
    quality
    A
    maintenance
    Secure agent coding runtime for local Git repos with policy enforcement, RBAC, sessions, approval workflow, and sandboxed writes, optionally connectable to ChatGPT via Secure MCP Tunnel.
    8
    6
    MIT