Monitor MCP, CI, and HTTP targets with health history, TLS expiry, assertions, and diagnostics
io.github.oaslananka/health-monitor-mcp — Model Context Protocol (MCP) Server
This MCP server monitors MCP, CI, and HTTP targets. It provides health history, TLS expiry tracking, assertions, and diagnostics, along with operational reports. The project is implemented as a CI workflow and generic HTTP endpoint monitoring setup, covering uptime-style observation across supported targets.
🛠️ Key Features
Health history tracking for monitored targets
TLS expiry monitoring
Assertions for expected conditions
Diagnostics and operational reports
Supports MCP, CI, and HTTP target monitoring
🚀 Use Cases
Monitor MCP endpoints and related services
Track TLS certificate expiry for HTTP targets
Apply assertions to validate health expectations
Produce diagnostics and operational reports from monitoring runs
⚡ Developer Benefits
Consolidates monitoring for MCP, CI, and HTTP targets
Provides diagnostics and operational reporting outputs
Aligns with automation/DevOps workflows (TypeScript/Node.js)
⚠️ Limitations
Source material indicates MCP, CI, and HTTP coverage only; other target types are not described
health-monitor-mcp keeps local registries of MCP servers, GitHub Actions workflows, GitLab pipelines, and generic HTTP endpoints. It performs live checks, records bounded evidence in SQLite, evaluates MCP alert thresholds, and returns JSON or Markdown diagnostics suitable for agents and operators.
Supported target transports:
Streamable HTTP for current remote MCP servers.
SSE for legacy MCP servers.
stdio for trusted local executables after explicit opt-in.
GitHub Actions workflow runs, failed jobs, and failed steps for public or private repositories.
GitLab CI/CD pipelines, failed jobs, stages, refs, commits, URLs, and bounded trace excerpts for GitLab.com or allowlisted self-hosted instances.
Generic HTTP/HTTPS endpoints with status, header, body-substring, JSON-value, redirect, latency, and TLS-expiry checks.
Azure DevOps monitoring was retired in v1.1.0. GitHub Actions shipped in v1.2.0 and GitLab CI/CD in v1.3.0; generic HTTP/TLS monitoring completes the current multi-provider feature line.
Quick Start
Run the published package noninteractively with Node.js 24:
Only the environment-variable name in token_env is stored. The token value is read at check time and is never written to SQLite, logs, reports, or tool responses.
Register GitLab Pipelines
Public GitLab.com projects can be checked without authentication. Private projects require a token exposed only through the runtime environment:
Only token_env is persisted. Token values, response bodies, and full traces are never stored or returned. Failed-job trace excerpts are range-requested, sanitized, and bounded.
Register HTTP Targets
Public HTTP and HTTPS endpoints are allowed by default. The provider sends GET requests only and supports bounded status, header, body-substring, JSON scalar, and TLS-expiry assertions:
Private, loopback, link-local, and other non-public addresses are blocked. A trusted private origin is available only in the full runtime profile and must be explicitly listed:
Every DNS answer and every redirect destination is revalidated. Responses are capped at 262144 bytes; full response bodies and certificate chains are never stored or returned.
HEALTH_MONITOR_MAX_CONCURRENCY limits MCP, GitHub Actions, GitLab, and HTTP checks through one shared scheduled and interactive queue. Results preserve MCP-then-GitHub-then-GitLab-then-HTTP registration order even when checks complete out of order.
The repository pins Node.js 24.18.0 and pnpm 11.14.0 through .mise.toml.
bash
mise trust
mise install
pnpm install --frozen-lockfile
pnpm run ci
Useful gates:
bash
pnpm run build
pnpm run typecheck
pnpm run lint
pnpm run lint:test
pnpm run test:coverage
pnpm run test:integration
pnpm run docs:api:check
pnpm run security:supply-chain
pnpm run check:metadata
pnpm run check:package
Coverage and Test Analytics
Jest remains the blocking coverage gate with repository-local thresholds. The CI validation job runs
all unit and integration tests once, writes coverage/lcov.info and
reports/junit/junit.xml, and uploads both reports to Codecov. Codecov project and patch statuses
start as informational with target: auto and a 1% tolerance, adding pull-request diff coverage,
file-level visibility, and failed-test analytics without duplicating the local merge gate.
Codecov Bundle Analysis is intentionally not enabled. This package ships Node.js entrypoints compiled
with tsc; it does not currently produce a Rollup, Vite, or Webpack application bundle whose download
size is a product metric.
This repository owns its product-specific MCP configuration, plugin manifest, and skills:
File
Purpose
.claude-plugin/plugin.json
Claude Code plugin manifest
.mcp.json
Project-local MCP configuration
.codex/config.example.toml
Codex CLI example
.vscode/mcp.example.json
VS Code / Copilot example
opencode.example.jsonc
OpenCode example
skills/
Product-specific monitoring workflows
docs/agent-runtime-config.md
Runtime setup and validation
Security and Contributing
Report vulnerabilities through GitHub Private Vulnerability Reporting. See SECURITY.md and docs/security.md.
Contribution setup and standards are documented in docs/contributing.md. Usage questions belong in GitHub Discussions; actionable work belongs in issues.
License
MIT
Install
Configuration
Environment variables
HEALTH_MONITOR_DB
Custom path for the SQLite database
HEALTH_MONITOR_AUTO_CHECK
Set to '1' to enable background scheduled checks
HEALTH_MONITOR_RETENTION_DAYS
Number of days to retain health check history
HEALTH_MONITOR_MAX_CONCURRENCY
Maximum concurrent scheduled and interactive server checks
GITHUB_TOKENsecret
Optional GitHub token with Actions read access for private repositories and higher API rate limits
GITLAB_TOKENsecret
Optional GitLab token with read access to private projects, pipelines, jobs, and traces
HEALTH_MONITOR_GITLAB_BASE_URL_ALLOWLIST
Comma-separated self-hosted GitLab HTTPS origins allowed for monitoring
HEALTH_MONITOR_HTTP_TARGET_ALLOWLIST
Comma-separated private HTTP(S) origins allowed only in the full runtime profile