Agent♥︎Age
Catalog

emisar

OfficialLive

by AndrewDryga · Elixir

Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step.

emisar (MCP Server)

emisar is an MCP-capable server that provides a catalog of declared infrastructure actions so AI agents can operate servers without SSH. Actions are governed by policy, with approval gates for risky changes, and auditing of each step. A small outbound-only runner re-checks the action on the host before execution.

🛠️ Key Features

  • Catalog-based declared infrastructure actions (no shell/SSH)
  • Policy decides what runs, what waits for a person, and what is denied
  • Approval for risky changes and audit of every step
  • Outbound-only runner that verifies actions again on the host
  • Supports a “public pack catalog” and host-matched pack suggestions
  • Add own actions without adding another MCP server to every client

🚀 Use Cases

  • Controlled remote execution of infrastructure actions
  • DevOps/DevSecOps workflows requiring policy-as-code style governance
  • Self-hosted infrastructure automation with bounded production authority

⚡ Developer Benefits

  • Clear separation between action suggestions and what is allowed to execute
  • Host-level re-checking before any action runs
  • Central action catalog shared across clients (via packs)

⚠️ Limitations

  • Requires an emisar account
  • Works with Linux hosts (as stated in setup notes)

Topics

aidevopselixirgosecurityinfrastructuremcpai-agentsdevsecopsinfosecinframcp-serverpolicy-as-coderemote-executionself-hosted

Related servers

More in Security