homelab-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| HOMELAB_AUDIT_LOG | No | Optional path to append-only JSONL audit log. Empty or malformed value disables it. | |
| HOMELAB_ADVISORY_DB | No | Path to local/offline advisory database JSON used for vulnerability incident reports. | |
| HOMELAB_ALLOWED_LOGS | Yes | Comma-separated list of exact canonical allowlisted log paths, e.g. '/var/log/syslog'. | |
| HOMELAB_ALLOWED_DISKS | Yes | Comma-separated list of allowlisted disk paths, e.g. '/,/home'. | |
| HOMELAB_ALLOWED_SERVICES | Yes | Comma-separated list of allowlisted systemd units, e.g. 'ssh.service,nginx.service'. | |
| HOMELAB_MAX_OUTPUT_BYTES | No | Optional maximum output bytes for bounded subprocess output. | |
| HOMELAB_DEPLOYMENT_MANIFEST | No | Path to trusted deployment manifest JSON file (max 64 KiB) used for deployment incident reports. | |
| HOMELAB_COMMAND_TIMEOUT_SECONDS | No | Optional timeout in seconds for subprocesses. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| healthA | Return server health and the configured read-only capability count. |
| uptimeA | Return host uptime using the standard uptime command. |
| disk_usageB | Report disk usage for an exactly allowlisted mount path. |
| memoryB | Return Linux memory usage. |
| service_statusB | Show selected systemd properties for an allowlisted service only. |
| docker_containersA | List Docker containers. Returns a normal error result when Docker is absent. |
| tail_logsB | Read final lines of one exactly allowlisted log file; traversal is rejected. |
| evidence_snapshotC | Return bounded raw evidence only for a fixed incident category. |
| incident_reportC | Turn read-only evidence into hypotheses; this tool never remediates. |
| propose_remediationC | Propose text-only actions. No proposed command is ever executed here. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 10 tools
Each tool targets a distinct homelab diagnostic or incident-response action, with no true duplicates. The incident workflow tools (evidence_snapshot, incident_report, propose_remediation) are separated by clear read-only, hypothesis, and proposal boundaries.
All names use snake_case, which keeps the set readable and predictable. However, the pattern is not uniformly verb_noun; many tools are noun-only or noun_phrase, so it is mostly consistent with minor deviations.
Ten tools is well-scoped for a homelab read-only diagnostic and incident-response server. Each tool earns its place without obvious redundancy or missing core actions.
The surface covers disk, memory, services, Docker, logs, uptime, health, evidence capture, incident reporting, and remediation proposals. Minor gaps remain, such as CPU/load, network, or process-level diagnostics, but the core read-only incident workflow is complete.