Proxmox SSH MCP Server
Enables execution of commands on a Proxmox host via SSH, allowing for the management and monitoring of virtual machines and containers while implementing security filters to prevent destructive system actions.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Proxmox SSH MCP Serverlist all virtual machines and their current status"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Proxmox SSH MCP Server
A Model Context Protocol (MCP) server that enables AI assistants to execute commands on a Proxmox host via SSH.
Features
SSH key-based authentication (no passwords in code)
Built-in security: dangerous commands are blocked
Single tool:
proxmox_run_host_command
Related MCP server: SSH MCP Server
Prerequisites
Node.js 18+
SSH key pair (
~/.ssh/id_ed25519)Public key added to Proxmox server's
~/.ssh/authorized_keys
Installation
git clone https://github.com/Zaptimist/mcp-proxmox.git
cd mcp-proxmox
npm installConfiguration
Set your Proxmox host via environment variables or edit index.js:
Option 1: Environment variables (recommended)
export PROXMOX_HOST=192.168.1.100
export PROXMOX_USER=root
export PROXMOX_PORT=22
export PROXMOX_KEY_PATH=~/.ssh/id_ed25519Option 2: Edit index.js directly
const sshConfig = {
host: process.env.PROXMOX_HOST || '192.168.1.100', // Your Proxmox IP
username: process.env.PROXMOX_USER || 'root',
port: parseInt(process.env.PROXMOX_PORT) || 22,
privateKeyPath: process.env.PROXMOX_KEY_PATH || path.join(os.homedir(), '.ssh', 'id_ed25519')
};SSH Key Setup
The MCP server will automatically detect if SSH keys are missing or not configured and provide setup instructions. But here's the manual process:
Generate a key (if you don't have one):
ssh-keygen -t ed25519Copy public key to Proxmox:
Windows (PowerShell):
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh root@YOUR_PROXMOX_IP "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"Linux/Mac:
ssh-copy-id root@YOUR_PROXMOX_IPTest the connection:
ssh root@YOUR_PROXMOX_IP "echo 'SSH key auth works!'"
If you haven't set up SSH keys yet, the MCP server will return helpful instructions when you try to use it.
MCP Client Configuration
Add to your MCP client config (e.g., ~/.kiro/settings/mcp.json):
{
"mcpServers": {
"proxmox": {
"command": "node",
"args": ["/path/to/mcp-proxmox/index.js"],
"env": {
"PROXMOX_HOST": "192.168.1.100"
},
"disabled": false,
"autoApprove": ["proxmox_run_host_command"]
}
}
}Usage
The server exposes one tool:
proxmox_run_host_command
Execute a command on the Proxmox host.
Input:
command(string, required): The command to execute
Example:
{
"command": "qm list"
}Response:
{
"success": true,
"command": "qm list",
"host": "192.168.1.100",
"exitCode": 0,
"stdout": "VMID NAME STATUS MEM(MB) ...",
"stderr": ""
}Security
The following commands are blocked for safety:
VM/Container deletion (
qm destroy,pct destroy)File operations (
rm,rmdir,dd)System operations (
shutdown,reboot,halt)Package removal (
apt remove,apt purge)Service management (
systemctl stop)Storage deletion (
zfs destroy,lvremove)
Destructive actions must be performed manually via the Proxmox web interface.
License
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Tools
Related MCP Servers
- AlicenseAqualityCmaintenanceEnables AI assistants to securely execute remote SSH commands, perform file transfers, and monitor system status through a standardized interface. It features robust security controls including command whitelisting, blacklisting, and credential isolation to prevent unauthorized operations.Last updated1044MIT
- Alicense-qualityDmaintenanceEnables AI coding agents to securely execute shell commands on remote SSH servers with granular per-host permission controls. Automatically discovers hosts from ~/.ssh/config and exposes dedicated tools for each allowed host to ensure proper authorization before remote execution.Last updated1,198Apache 2.0
- Alicense-qualityFmaintenanceEnables AI assistants to execute commands and transfer files on remote servers over SSH connections.Last updated1MIT
- Alicense-qualityBmaintenanceEnables AI assistants to securely execute commands, transfer files, and manage port forwarding on remote servers via SSH.Last updated13536Apache 2.0
Related MCP Connectors
Operate your own Linux servers from your LLM. Requires the SentinelX agent installed per host.
Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Zaptimist/mcp-proxmox'
If you have feedback or need assistance with the MCP directory API, please join our Discord server