Skip to main content
Glama
toddbartholow

irq-freeipa-mcp

README.md
# irq-freeipa-mcp

MCP server for FreeIPA identity management. Provides 36 tools for managing users, groups, sudo rules, HBAC rules, certificates, hosts, and SSSD cache.

## Setup

```bash
npm install
npm run build
```

Configure credentials:

```bash
cp config.yaml.example config.yaml   # non-sensitive settings
cp .env.example .env                  # passwords (required)
```

Passwords **must** be set via environment variables in `.env` — they are ignored if placed in `config.yaml`.

## MCP Configuration

```json
{
  "mcpServers": {
    "irq-freeipa": {
      "command": "node",
      "args": ["/path/to/irq-freeipa-mcp/build/index.js"]
    }
  }
}
```

## Tools

| Category | Tools | Examples |
|----------|-------|---------|
| **User Management** | `freeipa_user_find`, `freeipa_user_show`, `freeipa_user_add`, `freeipa_check_user_groups` | Search, create, inspect users |
| **Group Management** | `freeipa_group_find`, `freeipa_group_add_member`, `freeipa_group_remove_member` | Manage group membership |
| **Sudo Rules** | `freeipa_sudorule_find`, `_show`, `_add`, `_enable`, `_disable`, `_add_user`, `_add_host`, `_add_command`, `freeipa_sudocmdgroup_add`, `_add_member` | Create and configure sudo policies |
| **HBAC Rules** | `freeipa_hbacrule_find`, `_show`, `_add`, `_enable`, `_disable`, `_add_user`, `_add_host`, `_add_service` | Host-based access control |
| **Certificates** | `freeipa_service_add`, `freeipa_cert_request` | Service principals and TLS certs |
| **Hosts** | `freeipa_host_find`, `freeipa_host_add` | Manage FreeIPA hosts |
| **SSSD Cache** | `freeipa_clear_sssd_cache`, `_update_sssd_timeout`, `_check_sssd_status`, `_invalidate_user_cache`, `_test_ssh_connectivity` | Remote cache management via SSH |
| **Utility** | `freeipa_ping`, `freeipa_get_server_info` | Connection testing |

All tools include descriptive `inputSchema` definitions — your MCP client will display parameter docs automatically.

## Configuration Reference

**config.yaml** — non-sensitive settings (server hostnames, timeouts, SSSD domain/timeouts).

**`.env`** — credentials only:

```env
FREEIPA_PASSWORD=your-freeipa-password
SSH_PASSWORD=your-ssh-password
```

Environment variables override config.yaml. See `config.yaml.example` and `.env.example` for all options.

## License

MIT

TDQS

B3.4/5.0

Scored across 36 tools

Disambiguation5/5

Each tool targets a distinct area (users, groups, sudo rules, HBAC rules, hosts, etc.) with clear action verbs. There is minimal overlap; e.g., freeipa_sudorule_enable and freeipa_hbacrule_enable operate on different resource types.

Naming Consistency5/5

All tools follow a consistent 'freeipa_<domain>_<action>' pattern using snake_case. The naming is predictable and makes it easy to infer the purpose of each tool from its name.

Tool Count4/5

With 36 tools, the count is slightly high for the typical range, but it is justified by the comprehensive coverage of FreeIPA's various subdomains (users, groups, sudo rules, HBAC rules, hosts, services, certificates, SSSD cache).

Completeness3/5

The tool set covers many operations but lacks update and delete actions for key resources such as users, groups, sudo rules, HBAC rules, and hosts. This leaves noticeable gaps for full lifecycle management.

Maintenance

ActivityInactive
ResponsivenessNo issues