rsync-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@rsync-mcppull the projects/rsync-mcp directory from the remote"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
rsync-mcp
The /home/toxic rsync connection as a first-class MCP server.
Bun/TypeScript, zero npm dependencies, stdio JSON-RPC — the same house
pattern as sovereign/tools/tmux-mcp/server.ts.
Lineage
Fork lineage: jasonlinjc/mcp-ssh-remote
(MIT) — the system-rsync + system-ssh wrapping pattern, with ~/.ssh/config
inheritance (so host aliases like pc resolve). Rewritten rsync-first for
the estate: the connection is parameterized, both ends are sandboxed, and
destructive operations are gated. Full upstream history is preserved in this
repo; the Bun rewrite lands on top.
Related MCP server: remotessh-mcp
The connection
The estate's established rsync route, as found in shell history
(sovereign-recon-20260928):
rsync -avzP -e 'ssh -o ServerAliveInterval=30 -o ConnectTimeout=10' pc:/home/toxic/<path>/ <dest>All knobs are env config (non-secret — host alias + existing SSH keys only, never credential values):
Env | Default | Meaning |
|
| SSH host alias of the box holding the tree |
|
| Remote tree root; all remote paths are relative to it |
|
| Extra ssh options |
|
| Local sandbox root — local paths cannot escape it |
|
| Default rsync flags |
Tools
Tool | Safety |
| Read-only. Describes the route (no secrets). |
| Read-only. |
| Copies remote → local sandbox. Non-destructive to remote. |
| Preview a push/pull with |
| Copies local sandbox → remote. |
Path rules: remote .. segments are refused; local paths must resolve
inside RSYNC_LOCAL_ROOT. Output capped at 24KB per call; per-call ceiling
4.5 min (under Gatehouse's 5-min tool timeout).
Run
bun src/server.tsGatehouse
Registered as the rsync stdio server in
ranch/barn/gatehouse/mcp_config.json (+ durable mcp_config.json.dist):
{
"name": "rsync",
"command": "/home/toxic/.bun/bin/bun",
"args": ["run", "/home/toxic/projects/rsync-mcp/src/server.ts"],
"env": {
"RSYNC_HOST": "pc",
"RSYNC_REMOTE_ROOT": "/home/toxic",
"RSYNC_LOCAL_ROOT": "/home/toxic"
},
"protocol": "stdio",
"enabled": true,
"health_check_interval": "15s",
"tool_discovery_interval": "2m0s",
"isolation": { "enabled": false, "mode": "none" },
"quarantined": false
}Restart Gatehouse through its owned path after config changes:
cd /home/toxic/sovereign && sovereign/bin/pitchfork-restart # gatehouse daemon onlyThis server cannot be deployed
Maintenance
Related MCP Connectors
Securely control computers you explicitly pair through files, terminals, processes, screenshots, desktop UI/input, clipboard, browser automation, diagnostics, and document tools.
Scoped, audited SSH exec, sessions, and SFTP on your saved servers without exposing credentials
Secure tunneling, reverse proxy and remote access for local applications.
Run commands and read/write files on your servers over Termalin's keyless tunnels (hosted MCP).
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceA deliberately narrow, approval-gated workspace server that safely reads and writes files and runs allowlisted commands only inside one configured workspace, requiring visible approval for every write, process execution, and file read, with stale-overwrite protection and symlink-escape rejection.1MIT
- AlicenseNot gradedqualityBmaintenanceProvides local command execution, remote SSH, interactive terminals, file read/write, and source search for AI CLI through stdio, with large output pagination and safety confirmations.19 npm2Apache 2.0
- FlicenseBqualityBmaintenanceEnables safe VPS diagnostics and Docker/Docker Compose management over SSH, providing predefined read-only and mutating tools for system monitoring, container inspection, and Compose orchestration without exposing arbitrary shell execution.26-
- FlicenseNot gradedqualityCmaintenanceProvides an AI agent with authenticated shell and file access to a sandbox host, plus a restricted gateway for safe deploys on a production host via forced SSH commands.-