The 5 management tools (get_service_status, tail_log, list_lxcs, get_lxc_state, ping_service) were registered with sse but all SSH calls went to per-host targets via a 'mcp-reader' user that didn't exist anywhere. New design routes every management call through ONE channel: LXC 105 -> hubris (SSH key + restricted authorized_keys command), then hubris pct-execs into the right LXC where needed. Adds mcp/mcp-reader-shell — a strict allowlist wrapper read from $SSH_ORIGINAL_COMMAND. Rejects shell metacharacters up front and then matches against a fixed set of read-only patterns (systemctl is-active/ is-enabled, journalctl -u, pct list/status/config, pct exec for the same subset). Logged to syslog tag mcp-reader. Authorized_keys line on hubris: command="/usr/local/bin/mcp-reader-shell",restrict ssh-ed25519 ... mcp-reader@homelab-mcp Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2.1 KiB
Executable File
2.1 KiB
Executable File