mechub sovereign network-security automation ← all projects
mcp server v0.0.5 MIT

rustsdcmcp

MCP server for HPE Juniper Security Director Cloud

Async Rust MCP server for HPE Juniper Security Director Cloud: bounded read tools and a prepare, approve, apply path for policy deployment.

About

rustsdcmcp exposes HPE Juniper Security Director Cloud (SDC) to MCP clients as a bounded, auditable tool surface. SDC is the portal for an SRX estate, so this server talks HTTPS REST to the management plane rather than to any single firewall.

One SDC action can affect many managed SRX devices, so strict approval, credential-safe attribution and bounded I/O protect the management plane.

Features

  • Bounded read tools for discovery and change-control tools
  • Every mutation goes through prepare, independent approval, then apply; there is no direct deploy tool
  • A wildcard token scope grants no write tool
  • A full prepare, approve, apply policy deploy has run against a lab tenant and reached a managed vSRX
  • Debian 13 package, LXC installer and a linux/amd64 container image

Quick start

Download the release

gh release download v0.0.5 \
  --repo mechubsec/rustsdcmcp \
  --pattern 'rustsdcmcp_0.0.5.*_amd64.tar.gz*'
sha256sum -c rustsdcmcp_0.0.5.*_amd64.tar.gz.sha256

Or build from the release tag

approved_commit=$(git rev-parse v0.0.5^{commit})
git checkout --detach "$approved_commit"
cargo build --release --locked

Full instructions in the README ↗