Back to Discover

synapse-rmcp

connector

jmagar

Rust MCP and CLI server for Docker, host inspection, SSH, logs, ZFS, and safe file operations.

View on GitHub
0 starsSynced Aug 2, 2026

Install to Claude Code

/plugin marketplace add jmagar/synapse-rmcp

README

synapse-rmcp

MCP server and CLI for host and container operations: Docker and Compose control, SSH, host inspection, logs, ZFS, and safe file transfer.

Synapse is a full-parity Rust port of synapse-mcp, built with the rmcp framework.

The server exposes two MCP tools (flux and scout) plus equivalent CLI commands, covering all 59 production actions from the original TypeScript server.

Contents

Naming

The repository is synapse-rmcp, the Rust crate is synapse, the MCP server identity is synapse, and the installed binary is synapse. The npm launcher package is synapse-rmcp.

Across most of the RMCP family, naming follows repo=<service>-rmcp, npm=<service>-rmcp, and CLI=r<service>. Synapse is an exception because it is a Rust port of the older TypeScript synapse-mcp project and keeps the operator-facing synapse binary.

Capabilities And Boundaries

Synapse provides local Docker, Compose, host, SSH, log, ZFS, and file-operation workflows through two MCP tools and the equivalent CLI:

  • flux manages Docker infrastructure, containers, Compose projects, and host inspection.
  • scout handles SSH/local host inspection, safe file reads, allowlisted command execution, bounded descriptor-confined file transfer, ZFS introspection, and log retrieval.
  • REST exists only as a compatibility shim for a subset of actions.
  • The web surface is a lightweight static admin shell, not a full dashboard.

Not for: arbitrary shell access, unaudited remote mutation, or bypassing host SSH trust. Destructive Docker/Compose/exec/file-transfer actions require explicit host targets and confirmation policy.

MCP callers never provide credentials, tokens, keys, or secrets as action arguments. Tokens, OAuth settings, host topology, SSH trust, and allowlists live in server-side configuration or the local SSH environment.

Install

Use the npm launcher for stdio MCP or CLI access without a manual binary install:

npx -y @dinglebear/synapse --help
npx -y @dinglebear/synapse mcp

For a permanent command:

npm i -g @dinglebear/synapse
synapse --version

The npm package downloads the synapse binary from GitHub Releases during postinstall, keeping the release tag aligned with packages/synapse-rmcp/package.json.

From source:

cargo build --release

The production image includes Python 3 plus the official Docker CLI/Compose plugin because Scout's remote descriptor wrappers and Flux Compose operations invoke those runtime tools. The image does not contain a Docker daemon; Flux uses the mounted socket or SSH-forwarded remote socket. Persistent appdata lives at ~/.synapse on the host and /data in the container.

Quickstart

The first-screen 30-second path is:

npx -y @dinglebear/synapse mcp

Then configure an MCP client with stdio:

{
  "mcpServers": {
    "synapse": {
      "command": "npx",
      "args": ["-y", "synapse-rmcp", "mcp"]
    }
  }
}

Start with a read-only call:

{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "scout",
    "arguments": {
      "action": "nodes"
    }
  }
}

Client Configuration

stdio is preferred for local MCP clients:

{
  "mcpServers": {
    "synapse": {
      "command": "synapse",
      "args": ["mcp"]
    }
  }
}

Streamable HTTP uses /mcp on the configured host and port:

{
  "mcpServers": {
    "synapse": {
      "url": "http://127.0.0.1:40080/mcp",
      "headers": {
        "Authorization": "Bearer ${SYNAPSE_MCP_TOKEN}"
      }
    }
  }
}

Plugin Packages

plugins/synapse/ ships Claude Code, Codex, and Gemini CLI manifests that all point at the same HTTP MCP endpoint and the same shared skill.

These packages contain no lifecycle hooks. Connecting to a server that is already running needs no setup — the manifests substitute your server_url and api_token directly. If this machine also runs the server, bootstrap it once by hand:

synapse setup install                  # put/refresh the binary on PATH
synapse setup plugin-hook              # check, then repair on blocking failures
synapse setup plugin-hook --no-repair  # audit only; never mutates appdata

Export the relevant SYNAPSE_* variables (or write them to ~/.synapse/.env) first; plugins/README.md maps each plugin option to its variable. Re-run synapse setup install after a plugin update.

Runtime Surfaces

SurfaceStatusPurpose
MCPRequiredAgent-facing flux and scout tools
CLIRequiredScriptable parity surface for operators
RESTCompatibilityThin local action endpoint for 14 of 59 actions
WebPresentLightweight static admin shell

MCP Tool Reference

Synapse exposes two MCP tools:

  • flux: Docker daemon, container, host, and Compose operations.
  • scout: SSH/local host inspection, filesystem reads, allowlisted exec, multi-host emit, file beam, ZFS, and logs.

Both tools use an action-dispatched JSON shape:

{"name":"flux","arguments":{"action":"docker","subaction":"info"}}
{"name":"scout","arguments":{"action":"nodes"}}

The detailed action tables below are curated README reference material. The generated runtime MCP schema and the Rust action definitions are the source of truth for the live tool contract.

CLI Reference

Common commands:

synapse flux docker info
synapse flux container list
synapse flux compose list --host myhost
synapse scout nodes
synapse scout exec --host myhost --command hostname
synapse scout zfs pools --host myhost
synapse scout logs journal --host myhost --unit docker

Authentication

Mounted HTTP supports bearer and Google OAuth modes. Loopback stdio/local dev can run without mounted HTTP auth. Important variables:

SYNAPSE_MCP_HOST=127.0.0.1
SYNAPSE_MCP_PORT=40080
SYNAPSE_MCP_TOKEN=change-me
SYNAPSE_MCP_AUTH_MODE=bearer

See Configuration and docs/CONFIG.md for the full auth matrix.

Safety And Trust Model

Synapse separates read and write scopes (synapse:read, synapse:write) and uses confirmation gates for destructive operations. SYNAPSE_MCP_ALLOW_DESTRUCTIVE can skip prompts only in loopback-safe contexts. Host protocol is authoritative and defaults to SSH when omitted; local execution requires the explicit built-in local host or protocol: "local". SSH host trust is delegated to OpenSSH known-hosts behavior, and command execution uses execvp/argv semantics without shell interpolation. scout beam enforces both endpoints' configured read roots, blocks sensitive and symlinked paths, and caps each transfer at 64 MiB.

scout exec and scout emit accept only these 18 typed commands (ALLOWED_READ_COMMANDS in src/synapse/command_policy.rs):

cat, head, tail, grep, rg, ls, tree, wc, uniq, diff, stat, file, du, df, pwd, hostname, uptime, whoami

git is deliberately excluded, as are shells, interpreters, network clients, and mutating tools (EXEC_DENYLIST). There is no find or sort in the allowlist — use the dedicated scout find action for filesystem search. Per-host custom commands may be enabled via execAllowlist, but receive a zero-argument policy until a typed argument policy is registered.

Distribution Contract

The source of truth for release identity is the version shared by Cargo.toml, .release-please-manifest.json, packages/synapse-rmcp/package.json, release artifacts, and server.json.

Distribution/version invariants:

  • The npm package downloads the matching GitHub Release binary.
  • The installed binary remains synapse.
  • server.json must point at ghcr.io/dinglebear-ai/synapse:<version>.
  • Plugin manifests stay versionless where marketplaces derive identity from git state.
  • Generated docs and schemas must come from source-controlled generation inputs; curated README/docs should point at source-of-truth files for details.

Verification

just validate-plugin          # plugin manifests, MCP config, monitors, skills
npm --prefix packages/synapse-rmcp run check
cargo fmt --check
cargo check
cargo test
git diff --check

Deployment

For a persistent mounted HTTP server:

SYNAPSE_MCP_HOST=0.0.0.0 \
SYNAPSE_MCP_PORT=40080 \
SYNAPSE_MCP_TOKEN=change-me \
synapse serve

Use bearer or OAuth before exposing the endpoint beyond loopback. Production Docker/Compose notes live in docs/DEPLOYMENT.md and docs/DOCKER.md when present; local operator usage can stay on stdio.

Troubleshooting

  • 401 or 403 from /mcp: check bearer/OAuth settings and gateway headers.
  • no hosts appear: check SYNAPSE_HOSTS_CONFIG, SYNAPSE_CONFIG_FILE, and ~/.ssh/config.
  • destructive actions are refused: confirm the host target and confirmation policy.
  • SSH errors: verify OpenSSH known_hosts, mux/socket availability, and host reachability outside Synapse first.

Tools and Actions

flux — Docker infrastructure management

flux docker — Docker daemon operations (9 actions)

SubactionScopeDescription
infosynapse:readDocker daemon information
dfsynapse:readDocker disk usage
imagessynapse:readList Docker images; dangling_only to filter untagged
networkssynapse:readList Docker networks
volumessynapse:readList Docker volumes
pullsynapse:writePull a Docker image; requires host, image
buildsynapse:writeBuild a Docker image; requires host, context, tag; optional dockerfile, no_cache
rmisynapse:writeRemove a Docker image; requires host, image, force=true
prunesynapse:writeRemove unused resources; requires host, prune_target, force=true

flux container — Container lifecycle + inspection (14 actions)

SubactionScopeDescription
listsynapse:readList containers; optional state, name_filter, image_filter, label_filter
inspectsynapse:readDetailed container info; requires container_id; optional summary
logssynapse:readContainer logs; requires container_id; optional lines, since, until, grep, stream
statssynapse:readResource usage stats; optional container_id
topsynapse:readShow running processes; requires container_id
searchsynapse:readFull-text search by name/image/labels; requires query
startsynapse:writeStart a stopped container; requires host, container_id
stopsynapse:writeStop a running container (destructive); requires host, container_id
restartsynapse:writeRestart a container; requires host, container_id
pausesynapse:writePause a running container; requires host, container_id
resumesynapse:writeResume a paused container; requires host, container_id
pullsynapse:writePull latest image for a container; requires host, container_id
recreatesynapse:writeRecreate container with image pull (destructive); requires host, container_id; optional pull (default true)
execsynapse:writeExecute command inside container (destructive, execvp); requires host, container_id, command array

flux host — Host inspection (9 actions)

SubactionScopeDescription
statussynapse:readCheck Docker connectivity on a host
infosynapse:readOS, kernel, architecture
uptimesynapse:readSystem uptime
resourcessynapse:readCPU, memory, disk usage
servicessynapse:readSystemd service status; requires host; optional state, service
networksynapse:readNetwork interfaces
mountssynapse:readMounted filesystems; requires host
portssynapse:readPort mappings; requires host; optional protocol, limit, offset
doctorsynapse:readDiagnostic checks; requires host; optional checks (comma-separated)

flux compose — Docker Compose project management (10 actions)

SubactionScopeDescription
listsynapse:readList all Docker Compose projects; requires host
statussynapse:readGet project service status; requires host, project; optional service
upsynapse:writeStart a compose project; requires host, project
downsynapse:writeStop a compose project (destructive); requires host, project; optional remove_volumes, force
restartsynapse:writeRestart a compose project (destructive); requires host, project
recreatesynapse:writeRecreate compose containers (destructive); requires host, project
logssynapse:readGet project logs; requires host, project; optional service, lines, since
buildsynapse:writeBuild compose project images; requires host, project; optional service
pullsynapse:writePull compose project images; requires host, project; optional service
refreshsynapse:readRefresh compose project cache; requires host

flux help — Auto-generated flux docs

ActionScopeDescription
helppublicReturn flux action reference; optional topic (e.g. "container:list"), format (markdown|json)

scout — SSH/local host inspection

Scout simple actions (9 actions)

ActionScopeDescription
nodessynapse:readList all configured SSH hosts
peeksynapse:readRead a file or directory listing; requires host, path; optional tree, depth
findsynapse:readFind files by glob; requires host, path, pattern; optional depth, limit
pssynapse:readList processes; requires host; optional sort (cpu|mem|pid|time), grep, user, limit
dfsynapse:readDisk usage; requires host; optional path
deltasynapse:readCompare files or content; requires source_host, source_path; then either target_host+target_path or content
execsynapse:writeExecute allowlisted command (destructive, execvp); requires host, command; optional path, args, timeout_secs
emitsynapse:writeMulti-host execution (destructive); requires targets array, command; optional args, timeout_secs
beamsynapse:writeBounded root-confined file transfer (destructive); requires source_host, source_path, dest_host, dest_path; both paths must be under configured Scout/Compose roots

scout zfs — ZFS introspection (3 subactions)

SubactionScopeDescription
poolssynapse:readList ZFS pools; requires host; optional pool name filter
datasetssynapse:readList ZFS datasets; requires host; optional pool, dataset_type, recursive
snapshotssynapse:readList ZFS snapshots; requires host; optional pool, dataset, limit

scout logs — Log retrieval (4 subactions)

SubactionScopeDescription
syslogsynapse:readRead /var/log/syslog (falls back to /var/log/messages); requires host; optional lines, grep
journalsynapse:readRead systemd journal; requires host; optional lines, unit, priority, since, until, grep
dmesgsynapse:readRead kernel ring buffer; requires host; optional lines, grep
authsynapse:readRead /var/log/auth.log (falls back to /var/log/secure); requires host; optional lines, grep

scout help — Auto-generated scout docs

ActionScopeDescription
helppublicReturn scout action reference; optional topic (e.g. "zfs:pools"), format (markdown|json)

Known Parity Gaps

synapse achieves action-level parity with synapse-mcp — all 59 production actions from synapse-mcp/docs/INVENTORY.md are implemented. However, the following features from the original TypeScript server are not yet ported:

Not ported

FeatureDescription
claude/channel notificationsOriginal forwards Docker events and log tails as notifications/claude/channel MCP notifications. No equivalent exists in Rust.
Templated MCP resourcesOriginal exposes synapse://hosts/{host}, synapse://hosts/{host}/stacks, synapse://stacks, synapse://stacks/{host}/{stack}, synapse://stacks/{host}/{stack}/env, synapse://containers/{host}, synapse://containers/{host}/{id}. Rust exposes tool-specific schema and help resources plus read-scoped synapse://hosts, synapse://compose/projects, synapse://status, and synapse://activity.
Root SSH login gateOriginal gates sshUser=root through elicitation unless SYNAPSE_ALLOW_ROOT_LOGIN=true. Rust has destructive-operation elicitation but no root-login gate.
TOFU fingerprint storeOriginal persists fingerprints to ~/.config/synapse/known_hosts.json and rejects changed fingerprints. Rust uses strict OpenSSH known_hosts with wildcard warnings — different operator behavior.
SYNAPSE_EXCLUDE_HOSTSOriginal env var to exclude hosts from fleet discovery is absent in Rust.
SYNAPSE_MCP_ALLOW_YOLOOriginal "skip all confirmation gates" mode. Rust has SYNAPSE_MCP_ALLOW_DESTRUCTIVE (per-restart override, loopback-only), which is not identical.
SYNAPSE_DEBUG_ERRORSOriginal opt-in mode that returns full internal error detail. Rust always sanitizes internal tool errors.
git in exec allowlistOriginal includes git in ALLOWED_READ_COMMANDS with flag guards. Rust deliberately excludes git.

Configuration

SYNAPSE_MCP_HOST=127.0.0.1
SYNAPSE_MCP_PORT=40080
SYNAPSE_MCP_TOKEN=change-me

Key environment variables:

VariableDefaultDescription
SYNAPSE_MCP_HOST127.0.0.1Bind host for HTTP transport.
SYNAPSE_MCP_PORT40080Bind port for HTTP transport.
SYNAPSE_MCP_TOKENunsetStatic bearer token for auth.
SYNAPSE_MCP_NO_AUTHfalseDisable auth for loopback development only.
SYNAPSE_NOAUTHfalseDelegate auth/authz to an isolated trusted upstream gateway.
SYNAPSE_MCP_ALLOW_DESTRUCTIVEfalseSkip destructive-operation confirmation prompts (loopback only).
SYNAPSE_MCP_MAX_CONCURRENCY50Maximum simultaneous in-flight operational requests. Excess requests receive HTTP 429 with Retry-After. Set to 0 to disable. Public probes, OAuth discovery, and static assets are exempt from concurrency shedding.
SYNAPSE_MCP_PUBLIC_URLunsetOAuth public URL; HTTPS required except loopback development.
SYNAPSE_HOSTS_CONFIGunsetInline host topology. Omitted host protocols default to SSH; local execution requires protocol: "local".

See .env.example for the full list of variables, docs/CONFIG.md for configuration details, and docs/SECURITY.md for transport, path, transfer, container, and CI runner trust boundaries.

Run

# Start MCP server (stdio transport)
cargo run -- mcp

# Start HTTP server
cargo run -- serve

# CLI examples
cargo run -- flux docker info
cargo run -- flux container list
cargo run -- flux compose list --host myhost
cargo run -- scout nodes
cargo run -- scout exec --host myhost --command hostname
cargo run -- scout zfs pools --host myhost
cargo run -- scout logs journal --host myhost --unit docker

MCP examples:

{"name":"flux","arguments":{"action":"docker","subaction":"info"}}
{"name":"flux","arguments":{"action":"container","subaction":"list","state":"running"}}
{"name":"flux","arguments":{"action":"compose","subaction":"status","host":"myhost","project":"mystack"}}
{"name":"scout","arguments":{"action":"nodes"}}
{"name":"scout","arguments":{"action":"exec","host":"myhost","command":"hostname"}}
{"name":"scout","arguments":{"action":"zfs","subaction":"pools","host":"myhost"}}
{"name":"scout","arguments":{"action":"logs","subaction":"journal","host":"myhost","unit":"docker"}}

Architecture

FluxService   (src/flux_service/)  Docker/container/compose/host ops
ScoutService  (src/scout_service/) SSH/exec/fs/zfs/logs ops
      ↓ via SynapseService facade (src/app.rs)
MCP shims     (src/mcp/tools.rs)  tool args → service → Value
CLI shim      (src/cli.rs)        argv → service → stdout
REST layer    (src/api.rs)        POST /v1/synapse → service → JSON

Development

cargo fmt --check
cargo test
cargo clippy -- -D warnings
cargo build --release

just dev     # serve with no auth (loopback, dev mode)
just test    # cargo test
just lint    # clippy
just fmt     # cargo fmt

Useful docs:

  • docs/API.md for full tool contracts
  • docs/CONFIG.md for environment and auth
  • docs/QUICKSTART.md for local smoke tests
  • plugins/synapse/skills/synapse/SKILL.md for agent usage guidance
  • tests/parity.rs for automated parity verification against synapse-mcp INVENTORY

Documentation

This README is curated for first-run orientation and high-level action discovery. Source-of-truth docs and code are split as follows:

  • docs/API.md for the curated action contract reference.
  • docs/MCP_SCHEMA.md for MCP schema shape and drift expectations.
  • docs/CONFIG.md for environment and auth policy.
  • docs/QUICKSTART.md for local smoke tests.
  • docs/PLUGINS.md and plugins/synapse/skills/synapse/SKILL.md for agent and marketplace usage.
  • docs/generated/openapi.json for generated OpenAPI output.
  • src/flux_service/, src/scout_service/, and src/mcp/ for runtime source of truth.

Related Servers

  • runifi - UniFi controller REST API bridge.
  • rtailscale - Tailscale API bridge for devices, users, and tailnet operations.
  • unraid / runraid - Unraid GraphQL bridge for NAS and server management.
  • rapprise - Apprise notification fan-out bridge for many delivery backends.
  • rgotify - Gotify push notification bridge for sends, messages, apps, and clients.
  • rarcane - Arcane Docker management bridge for containers and related resources.
  • yarr - Media-stack bridge for Sonarr, Radarr, Prowlarr, Plex, and related services.
  • rytdl - Media download and metadata workflow server.
  • cortex - Syslog and homelab log aggregation MCP server.
  • axon - RAG, crawl, scrape, extract, and semantic search project.
  • labby - Homelab control plane and Labby gateway project.
  • lumen - Local semantic code search MCP server.
  • nugs - Project/package management helper for local agent workflows.
  • agentcast - Agent transcript and activity publishing project.
  • soma - RMCP scaffold/runtime template for new provider-backed servers.

License

MIT

Rendered live from jmagar/synapse-rmcp's GitHub README — not stored, always reflects the source repo.

1 Install Method

NameDescriptionCategorySource
npm packageInstall via npm (stdio transport)mcp-serversynapse-rmcp

0 Comments

Login required
Log in to post a comment or update on this repo.

No comments yet — be the first to share an update.