Skip to content

Releases: IBM/storage-protect-mcp-server

v1.1.0 - IBM Storage Protect MCP Server

Choose a tag to compare

@SandeepNagamalli SandeepNagamalli released this 25 Sep 07:39
c3a0695

This release delivers a comprehensive security hardening initiative across the IBM Storage Protect MCP Server. Every change in this release traces to a named security control and is covered by an automated regression test.

**✨ Highlights**  

• Least-privilege credential management — per-module service accounts (mcp-svc-readonly, mcp-svc-operator, mcp-svc-storage, mcp-svc-policy, mcp-svc-system) with narrowest-privilege selection at execution
time
• OS keyring integration — passwords resolved from the OS keyring before falling back to environment variables, removing plain-text secrets from the process environment
• Dynamic user authentication — interactive challenge-response session flow (authenticate_session / logout_session tools) with sliding-window TTL, absolute max-TTL enforcement, and cross-server session r
euse prevention
• Credential lifecycle protection — SessionLease.password is zeroed in every removal path (explicit revocation, expiry, bulk cleanup, and server shutdown)
• Secure startup guards — secure_startup() atomically enforces .env permission checks (chmod 600) before loading secrets; missing or insecure .env files abort the process before any credential is read
• TLS enforcement — HTTP transport requires SP_TLS_CERT + SP_TLS_KEY at startup; plaintext operation requires an explicit opt-in override and is blocked in production environments
• Password policy validation — REGISTER ADMIN, REGISTER NODE, and UPDATE commands with passwords invoke execute_silent() so credentials never appear in process arguments or logs; server-side MINPWLENGTH
is queried and enforced before submission
• Audit trail correlation — every write-class tool call emits a DEFINE SCRATCHPADENTRY record carrying user=, tool=, priv=, and corr= fields before execution; SP_MCP_STRICT_AUDIT=1 blocks tool execution
when the audit write fails
• Command-approval workflow support — SP_MCP_AUTH_MODE=dynamic issues structured AUTHENTICATION_REQUIRED / AUTHORIZATION_DENIED challenges for unauthenticated or under-privileged calls, enabling approval
-gate patterns in AI client workflows
• Production guard — SP_MCP_SKIP_SECURITY_CHECKS=1 is blocked when SP_MCP_ENV=production, preventing bypass of startup security validation in live environments
• dsm.sys configuration template — config/dsm.sys.template with SSLREQUIRED=Yes and PASSWORDACCESS=GENERATE for stash-based credential management that eliminates -PA= exposure on the command line
• Service account provisioning script — scripts/provision-sp-service-accounts.sh idempotently registers all five MCP service accounts with SESSIONSECURITY=STRICT and 30-day password expiration
• Security regression test suite — 60+ automated tests across five new test modules covering every named security control

🔐 Security Controls Implemented
CRED-1 — Per-module credential selection — narrowest available tier used per tool call
CRED-2 — Password stash mode (SP_MCP_USE_PASSWORD_STASH=1) eliminates -PA= from subprocess args
CRED-3 — .env file permission guard — aborts startup if file is group- or world-readable
INT-4 — OS keyring-first password resolution with environment variable fallback
NET-1 — Startup validation rejects service accounts without SESSIONSECURITY=STRICT
NET-3 — dsm.sys stanza support via SP_SERVER_NAME for TLS-enforced server connections
ACC-2 — Privilege-filtered tool registration — tool set narrowed to account's privilege class
ACC-4 — dsmserv and servermon invoked via sudo -u -- for safe user switching
POL-3 — Startup warning when INVALIDPWLIMIT=0 (lockout policy not configured)
POL-4 — DEFINE SCRATCHPADENTRY audit record emitted before every write-class tool call
NR-1 — Audit entries carry user identity, tool name, privilege tier, and correlation ID
NR-4 — SP_MCP_STRICT_AUDIT=1 fail-closed mode blocks tool execution on audit write failure
RG-1 — SP_MCP_SKIP_SECURITY_CHECKS blocked when SP_MCP_ENV=production
RG-2 — secure_startup() combines permission check + dotenv load atomically
RG-3 — Password-bearing commands (REGISTER ADMIN, REGISTER NODE, UPDATE ) use execute_silent()
RG-4 — Audit write failures logged at ERROR level (not WARNING)
RG-5 — HTTP transport startup aborts without TLS cert + key unless explicitly overridden
INT-2 — OIDC bearer middleware validates RS256/ES256 tokens and maps mcp:
scopes to privilege tiers
INT-3 — execute_silent() suppresses command-string logging for credential-bearing operations
AUD-05 — Automated inventory test asserts every main*.py entry point calls secure_startup()
AUD-08 — SessionLease.password zeroed in all removal paths: revoke, expiry, cleanup, clear
DAUTH-7 — Cross-server session reuse prevention — session target_server validated against active config

⬆️ Upgrade Notes

1. Fix .env permissions before starting the upgraded server

chmod 600 .env

2. Provision per-module service accounts (recommended)

export SP_ADMIN_ID=
export SP_ADMIN_PASSWORD=
export MCP_PWD_SYSTEM=$(openssl rand -base64 20)

... (see scripts/provision-sp-service-accounts.sh for all five accounts)

bash scripts/provision-sp-service-accounts.sh

3. Update .env to use per-module credentials

echo "SP_ADMIN_ID_SYSTEM=mcp-svc-system" >> .env
echo "SP_ADMIN_PASSWORD_SYSTEM=" >> .env

... repeat for operator, storage, policy, readonly

4. Deploy dsm.sys from the template (enables TLS + stash mode)

cp config/dsm.sys.template /opt/sp-mcp-server/config/dsm.sys
sed -i "s/your-sp-server/${SP_SERVER_ADDRESS}/" /opt/sp-mcp-server/config/dsm.sys
chmod 600 /opt/sp-mcp-server/config/dsm.sys
echo "DSM_CONFIG=/opt/sp-mcp-server/config/dsm.sys" >> .env
echo "SP_MCP_USE_PASSWORD_STASH=1" >> .env

v1.0.0 - IBM Storage Protect MCP Server

Choose a tag to compare

@SandeepNagamalli SandeepNagamalli released this 16 Jul 09:33

Initial public release of the IBM Storage Protect MCP Server, providing Model Context Protocol (MCP) integration for IBM Storage Protect administration and automation.
✨ Highlights

  • Natural-language administration for IBM Storage Protect through MCP-compatible clients
  • Modular server groups for system, operations, clients, policy, and storage workflows
    Command wrappers for dsmadmc, dsmserv, and servermon
  • Environment-based configuration for server connectivity and credentials
  • Wheel-based packaging for simplified installation and distribution

Management Capabilities
The IBM Storage Protect MCP Server provides AI-assisted management capabilities across core administrative domains of an IBM Storage Protect environment. Through MCP-compatible clients, administrators can use natural language to query status, review configuration, investigate issues, and perform guided operational tasks.

Key management capabilities include:

  • System administration: Query server status, review configuration, inspect administrative settings, and support day-to-day platform management tasks.
  • Operations management: Assist with operational workflows such as protection monitoring, maintenance activities, rule-related tasks, and general server operations.
  • Client management: Review and manage client-related configuration and core client administration workflows. - Policy management: Support lifecycle and policy management activities, including policy-related review and administrative actions.
  • Storage management: Query and manage storage pools, storage hardware, storage devices, volumes, and related storage configuration areas.
  • Server diagnostics integration: Use dsmadmc, dsmserv, and servermon backed workflows to support command execution, diagnostics collection, and operational visibility.
  • Flexible deployment and control: Run in different modes and enable only selected server groups, allowing more controlled exposure of management functions based on operational needs.

These capabilities help simplify IBM Storage Protect administration by translating complex command-driven workflows into structured, MCP-enabled interactions suitable for automation and AI-assisted operations.