vmware-vdi
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| VMWARE_VDI_CONFIG | No | Path to the vmware-vdi configuration file. If not set, defaults to ~/.vmware-vdi/config.yaml. | ~/.vmware-vdi/config.yaml |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| app_pool_listA | [READ] List published application pools: id, name, farm, enabled, executable path. Paginated. |
| image_listA | [READ] List instant-clone base VMs and snapshots (the golden-image catalog for pool_push_image). |
| ad_user_searchA | [READ] Resolve AD users/groups by name to their SIDs — needed to entitle a pool (entitlement_add). |
| entitlement_listA | [READ] List the AD users/groups entitled to a desktop pool (who can access it). Paginated. A wrong pool id returns a teaching 404. Use pool_list for pool ids. |
| entitlement_addA | [WRITE] Grant desktop-pool access to AD user/group SID(s). Get SIDs from ad_user_search. A bare call returns blast_radius (pool identity, which principals are already entitled and which are new) and grants nothing; confirm=True grants. Refused when the pool's current entitlements cannot be read. Show blast_radius to the user and wait for their decision. Do not set confirm=True on your own because the user asked for this earlier: they have not seen the blast radius yet. Audited. |
| entitlement_removeA | [WRITE] Revoke desktop-pool access from AD user/group SID(s). Get SIDs from entitlement_list. A bare call returns blast_radius (pool identity, which principals lose access and which were not entitled) and revokes nothing; confirm=True revokes. Refused when the pool's current entitlements cannot be read. Show blast_radius to the user and wait for their decision. Do not set confirm=True on your own because the user asked for this earlier: they have not seen the blast radius yet. Audited. |
| farm_listA | [READ] List Horizon RDS farms: id, name, type, enabled, RDS server count. Paginated. |
| machine_listA | [READ] List Horizon desktop machines, filtered by pool id / state. Paginated. Each item: id, name, pool_id, state (AVAILABLE/CONNECTED/AGENT_UNREACHABLE/PROVISIONING/ ERROR/MAINTENANCE/…), assigned user, agent_version, base_image. Verify pair for the machine write tools. |
| machine_getA | [READ] One Horizon desktop machine by id (teaching 404 on a wrong id). Same projection as one machine_list row — id, name, pool_id, state, assigned user, agent_version, base_image — fetched with a single GET instead of scanning the estate. Use it to re-check one machine after a write, or when you already hold an id. |
| machine_resetA | [WRITE] Hard-reset desktop machine(s) — the user loses unsaved state. A bare call returns blast_radius (machine ids, names, states, assigned users) and resets nothing; confirm=True resets. A machine whose state cannot be read is refused. Show blast_radius to the user and wait for their decision. Do not set confirm=True on your own because the user asked for this earlier: they have not seen the blast radius yet. For a graceful in-guest reboot use vmware-aiops (the vCenter VM). Audited. |
| machine_maintenanceA | [WRITE] Enter (enabled=True) or exit (False) maintenance mode for machine(s). Maintenance drains the machine (no new sessions). A bare call returns blast_radius (machine ids, states, assigned users) and changes nothing; confirm=True applies. A machine whose state cannot be read is refused. Show blast_radius to the user and wait for their decision. Do not set confirm=True on your own because the user asked for this earlier: they have not seen the blast radius yet. Audited. |
| machine_removeA | [WRITE] Remove machine(s) from their pool — for instant clones this DELETES the backing VM. A bare call returns blast_radius (machine ids, names, states, assigned users) and removes nothing; confirm=True removes. A machine whose state cannot be read is refused. Show blast_radius to the user and wait for their decision. Do not set confirm=True on your own because the user asked for this earlier: they have not seen the blast radius yet. Audited. |
| health_summaryA | [READ] One-glance Horizon VDI health: session totals by state, problem machines, pool availability. The first thing to call for "how is VDI right now?". Aggregates sessions, machines, and pools into a compact status. Drill into problems with machine_list --state or session_list. |
| session_statsA | [READ] Session statistics: concurrency by state / protocol, current concurrent, busiest pools. The reporting counterpart to session_list — aggregate numbers, not per-session rows. |
| pool_utilizationA | [READ] Per-pool capacity: total / available / in-use / error machines and utilization %. The "am I running out of desktops?" view, sorted by utilization. Drill in with machine_list --pool. |
| event_listA | [READ] List Horizon audit events (newest first), optionally filtered by severity. Paginated. Each item: time, severity, type, module, user, machine, message. Use for "what went wrong recently". |
| pool_listA | [READ] List Horizon desktop pools: id, name, type (AUTOMATED/MANUAL/RDS), enabled, assignment. The verify pair for pool_set_enabled and pool_push_image. Paginated envelope. |
| pool_getA | [READ] One desktop pool by id (teaching 404 on a wrong id). Same projection as one pool_list row — id, name, type, enabled, provisioning_enabled, assignment — fetched with a single GET instead of listing every pool. Use it to re-check one pool after a write, or when you already hold an id. |
| pool_set_enabledA | [WRITE] Enable or disable a desktop pool — disabling stops NEW sessions (existing keep running). Idempotent (matching state returns a noop). A bare call returns blast_radius (pool identity, current and new enabled state) and changes nothing; confirm=True applies. A pool whose current enabled state cannot be read is refused. Show blast_radius to the user and wait for their decision. Do not set confirm=True on your own because the user asked for this earlier: they have not seen the blast radius yet. Audited. |
| pool_push_imageA | [WRITE] Apply the pending image to an instant-clone pool — RECREATES EVERY DESKTOP in it. Highest blast radius in the family: the preview states affected-desktop and in-session counts before you confirm, plus blast_radius.occupancy — "determined" when those counts can be believed, "unknown" when sessions exist that cannot be attributed to any pool or farm. confirm=True schedules the apply. Show blast_radius to the user and wait for their decision. Do not set confirm=True on your own because the user asked for this earlier: they have not seen the blast radius yet. Audited. |
| session_listA | [READ] List Horizon VDI sessions, filtered by user / pool id / state. Paginated. Returns a {items, returned, limit, total, truncated, hint} envelope; each item has id, user, type (DESKTOP/APPLICATION), state (CONNECTED/DISCONNECTED/PENDING), protocol (BLAST/PCOIP/RDP), pool_id, machine_id, start_time. This is the verify pair for logoff/disconnect — get a session id or confirm a user's sessions here first. |
| session_getA | [READ] Full detail for one Horizon session by id. A wrong id returns a teaching error ("run session_list for current ids"), not a traceback. Use session_list to discover ids. |
| session_logoffA | [WRITE] Force-logoff Horizon session(s) — kicks the user, triggers profile write-back. Identify targets by explicit session_ids OR by user (all of that user's sessions). A bare call returns blast_radius — session ids, count and affected users — and logs off nothing; confirm=True logs off. A session whose user cannot be read is refused. Show blast_radius to the user and wait for their decision. Do not set confirm=True on your own because the user asked for this earlier: they have not seen the blast radius yet. Audited. |
| session_disconnectA | [WRITE] Disconnect Horizon session(s) — state preserved, the user can reconnect. Less disruptive than logoff. Identify by session_ids OR user. A bare call returns blast_radius (session ids, count, affected users) and changes nothing; confirm=True disconnects. A session whose user cannot be read is refused. Show blast_radius to the user and wait for their decision. Do not set confirm=True on your own because the user asked for this earlier: they have not seen the blast radius yet. Audited. |
| session_send_messageA | [WRITE] Send a message to Horizon session(s) — e.g. "save your work, maintenance in 10 min". Low blast radius (informational only, no session disruption), so no confirm gate. Identify by session_ids OR user. Audited. |
| task_statusA | [READ] Status of a pool's long task (image push / provisioning), or all tasks for the pool. Horizon tasks are pool-scoped. Give task_id (from pool_push_image or a prior task_status) for one task; omit it to list all tasks for the pool. |
| task_cancelA | [WRITE] Cancel a running pool task (e.g. an in-progress image push). A bare call reads the task and returns blast_radius (task type, state, progress) and cancels nothing; confirm=True cancels. A task whose type or state cannot be read is refused. Work already applied is not rolled back. Show blast_radius to the user and wait for their decision. Do not set confirm=True on your own because the user asked for this earlier: they have not seen the blast radius yet. Audited. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 27 tools
Each tool maps to a unique resource+action; same-resource operations are clearly separated (session_get/list vs session_logoff/disconnect/send_message, machine_list/get vs reset/maintenance/remove). The aggregate read tools also have distinct outputs, so there is no real risk of picking the wrong tool for a task.
The set is mostly consistent and all snake_case, with resource-first names and predictable _get/_list suffixes. Some names break the pattern: machine_maintenance is not an imperative, and health_summary/session_stats/pool_utilization are noun phrases rather than action verbs.
27 tools is on the high side of the ideal range, but the VDI domain is broad and each tool covers a distinct operation or read view across sessions, machines, pools, entitlements, tasks, farms, and apps. There is little redundancy, so the count feels justified rather than bloated.
Core operational workflows are well covered: read/list for every resource, high-risk write actions with confirm gates, task status/cancel, entitlements, and health reporting. Gaps exist at the lifecycle level (no pool create/update/delete, no app-pool or farm management beyond listing), but these are not fatal for the apparent operational purpose.