mechub sovereign network-security automation ← all projects
mcp server v0.10.0 MIT

rustproxmoxmcp

MCP server for Proxmox VE

MCP server for Proxmox VE: one endpoint across many clusters, with destructive work held behind plan, approve and apply.

About

rustproxmoxmcp is an MCP server for Proxmox VE, the virtualisation platform under network-security lab rigs. It serves one endpoint across many clusters and resolves a guest's node on every call, because guests migrate.

Destructive work goes through plan, approve and apply: the approval binds the plan digest and the stored preview, and the apply re-checks the guest's fingerprint.

Features

  • 50 callable tools: 31 read, 18 low-risk and apply_proxmox_change_set as the single destructive entry point
  • Destructive scopes such as delete_vm are reached only through plan_proxmox_destroy
  • Per-cluster CA pinning, with no insecure-skip-verify at any layer
  • Structured audit logging with optional HMAC-keyed redaction
  • Time-boxed operator waivers; there is deliberately no grant_waiver tool and no force argument

Quick start

Full instructions in the README ↗