Skip to main content
Glama

ansible-flow-mcp

Give agents Ansible. Not the keys.

MCP server that exposes real Ansible modules and playbooks to AI agents — and a SSH hub/spoke fabric so multi-host automation is enrolled, bastion-scoped, and check-first by default.

Hero: agent hub session and enrolled inventory rail

Track

What you get

Agent loop

search → schema → check → execute on allowlisted collections

Fleet fabric

One hub · join tokens · SSH ForceCommand spokes · fixed inventory

OpenFlow dual-track · Marketing site · Campaign storyboard · Hub/spoke ops · Apache-2.0

Not affiliated with Red Hat or the Ansible project beyond using the public Ansible CLI and docs.

New here? Marketing site (story + Schema Lab) · full step-by-step docs/QUICKSTART.md — local MCP · compose lab · bare-metal hub/spoke · editor wiring.

./scripts/site_preview.sh   # http://127.0.0.1:8765/  (gallery + live schemas)

Visual tour

Why it exists

Agent loop

Why: god-mode control node vs enrolled bastion

Agent ritual: search → schema → check → execute

Hub / spoke fabric

Operators

SSH hub/spoke topology and enrollment

Operator TUI, hub MCP tools, lab demo

Screenshots live in docs/images/campaign-*.png. Re-shoot from docs/campaign/ with ./capture.sh.


Related MCP server: AAP MCP Server

Why this exists

Agents on a god-mode control node invent inventory, reach for shell, and treat every worker as an entrypoint. That is not a security model.

Without a fabric vs ansible-flow-mcp controls

You need this when:

  • You want Cursor / Claude / OpenCode to run Ansible like an operator, not freestyle root across the fleet

  • Multi-host must mean bastion ops you already understand (SSH, inventory, enrollment) — not a mesh hop plane

  • Prompt injection will still ask for bad ops — policy and topology must refuse


Two tracks

1. Agent loop — search → schema → check → execute

Curated module gallery. Slim argSpec before any run. Check mode default. Free-form modules denied. Playbooks path-jailed.

Agent ritual and MCP tools

Tool

Purpose

search_modules

Gallery search

get_module_schema

Slim argSpec for FQCN

run_module

Ad-hoc Ansible (check_mode default true)

run_playbook

ansible-playbook on a path-jailed .yml

list_collections

Collections in gallery

Ritual (modules): search_modulesget_module_schemarun_module(..., check_mode=true) → apply only if appropriate.

Ritual (playbooks): confirm path under allowlisted roots → check → apply.

2. Hub/spoke — nothing is a target until enrolled

Secure multi-host mode: agent attaches to the hub only. Hub reaches spokes over SSH only. Spokes execute localhost and cannot lateral-move via this fabric.

SSH hub/spoke topology and enrollment

Full mesh (withdrawn)

Hub/spoke (shipped)

Worker compromise

Could MCP-hop fleet-wide

No lateral MCP

Inventory

Gossip / replicas

Hub is source of truth

Agent attach

Any node

Hub only

Ops model

Mesh OS

Classic Ansible bastion

Enrollment: hub initissue-token (TTL, one-time jti) → spoke join (token + SSH identity) → hub inventory. Runtime: ForceCommand MCP session — no shell on the hub→spoke path.

Hub tools: list_nodes / hub_status, issue_token, revoke_node, groups (create_group, set_group_members, …), spoke_call, plus catalog run_* against enrolled hosts or groups only. Client-supplied -i is rejected in hub mode.

Deep ops: docs/HUB.md.


Operators

Day-2 surface matches the agent: enroll, group, hand the hub to OpenCode.

Operator TUI, hub MCP tools, lab demo

ansible-flow-mcp hub init --name ctrl-01
ansible-flow-mcp hub issue-token --name web-03 --ttl 15m
ansible-flow-mcp spoke join --token "$TOKEN" --hub user@hub:22 --public-addr web-03.example.com
ansible-flow-mcp hub session          # MCP stdio for the agent
ansible-flow-mcp tui                  # servers · groups · invite · OpenCode
ansible-flow-mcp hub spoke-call --node web-03 --tool list_collections

Lab one-shot

cd lab && ./scripts/demo.sh
# then: ./scripts/tui.sh  |  ./scripts/opencode-host.sh

See lab/README.md.


Quick start

Full guide (all paths, verify, troubleshooting): docs/QUICKSTART.md

Path

Guide section

Local MCP + Cursor/Claude

Path A

Compose lab (hub + 3 spokes)

Path B

Bare-metal hub/spoke

Path C

Single-node / dev (short form)

Requirements: Python ≥ 3.11 · collection ansible.posix (JSON callback) · collections you will run.
pip install pulls ansible-core (provides ansible / ansible-playbook).

cd ansible-flow-mcp
python -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"
ansible-galaxy collection install ansible.posix
pytest -q
ansible-flow-mcp

Or install via pypi.org

pip install ansible-flow-mcp
ansible-galaxy collection install ansible.posix
ansible-flow-mcp

Editor snippets: examples/cursor-mcp.json, examples/claude-desktop.json.
Hub + OpenCode: examples/opencode-hub.jsonc · ansible-flow-mcp hub write-opencode-config.

{
  "mcpServers": {
    "ansible-flow": {
      "command": "/path/to/ansible-flow-mcp/.venv/bin/ansible-flow-mcp"
    }
  }
}

Security (honest)

Control

Behavior

Collection allowlist

Only configured collections

Module deny list

command / shell / raw / script denied by default

Check mode

Default true on run_module

Playbook jail

Allowlisted roots · size limit · .yml/.yaml only

No shell interpolation

argv-only subprocess

Hub inventory

Enrolled hosts only · no client -i · host key checking on

Spoke path

SSH ForceCommand · localhost exec · no peer fabric

Residual: hub compromise = fleet (same class as any Ansible control node). Harden the bastion — see docs/SECURITY.md and docs/HUB.md.


Catalog & OpenFlow

  • catalog/collections-allowlist.yml — allowlist + deny free-form modules

  • catalog/gallery.json + catalog/schemas/ — searchable gallery

  • Regenerate: python scripts/generate_catalog.py

  • Galaxy factory TUI: scripts/factory/README.md

Dual-tracked with OpenFlow Ansible canvas gallery
(plan · umbrella).

OpenFlow

This MCP server

Palette Ansible gallery

search_modules

Form | JSON module options

get_module_schema + run_module

Playbook resource

run_playbook

Control-node SSH / become

Inventory + Ansible config · hub→spoke SSH in hub mode


Env (common)

Variable

Meaning

ANSIBLE_FLOW_CATALOG_DIR

Override catalog path

ANSIBLE_FLOW_COLLECTIONS

Comma-separated allowlist override

ANSIBLE_FLOW_INVENTORY

Default -i (non-hub / dev)

ANSIBLE_FLOW_TIMEOUT

Seconds (default 120 module / 300 playbook)

ANSIBLE_FLOW_PLAYBOOK_ROOTS

Extra playbook roots (:-separated)

ANSIBLE_FLOW_HUB_DIR

Hub state (default: /var/lib/… if writable, else ~/.local/share/ansible-flow/hub)

ANSIBLE_FLOW_SPOKE_DIR

Spoke state (same pattern under …/spoke)


License & publish

Apache-2.0

pip install build twine && python -m build
# twine upload dist/*
uvx --from ansible-flow-mcp ansible-flow-mcp
A
license - permissive license
A
quality
A
maintenance

Maintenance

Maintainers
<1hResponse time
0dRelease cycle
4Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    C
    quality
    F
    maintenance
    This Model Context Protocol server enables AI assistants to interact directly with Ansible, allowing them to execute playbooks, manage inventory, check syntax, and perform other Ansible operations.
    18
    26
    MIT
  • A
    license
    B
    quality
    B
    maintenance
    Enterprise-grade MCP server exposing Ansible Automation Platform 2.x as a complete AI interface for LLMs, enabling natural language management of automation resources.
    86
    1
    Apache 2.0
  • F
    license
    Not graded
    quality
    D
    maintenance
    Industry-standard MCP server for AWX/AAP/Ansible Tower automation, enabling AI agents to manage job templates, launch and monitor jobs, and handle inventories and projects through natural language.
    11

View all related MCP servers

Related MCP Connectors

  • MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.

  • MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.

  • Personal assistant MCP server with search, execute, packages, jobs, secrets, and integrations.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/real-limitless/ansible-flow-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server