Skip to content

Releases: tphakala/solidserver-mcp

Release list

v1.1.0

Choose a tag to compare

@github-actions github-actions released this 25 Aug 10:55

Highlights

This is a big step up from the first release. v1.1.0 roughly doubles the tool set, teaches the server to hand your MCP client ready-made inventory and guided workflows, and wraps the whole thing in safety rails so an LLM driving it cannot wander into a destructive change or be steered by untrusted text coming back from the appliance.

If you skim one thing: there are now create/update/delete tools across IPAM, DNS, VLAN and DHCP, read-only resources and guided prompts for everyday DDI tasks, a read-only mode and protected object lists to fence off production, and a solidserver_doctor preflight that tells you in one call whether the connection, TLS and API token are actually working.

New tools and transports

  • Expanded tool coverage across every area: ip_update, space_create / space_delete, dns_record_update, dns_zone_create / dns_zone_delete, vlan_domain_create / vlan_domain_delete, dhcp_scope_create, and dhcp_range_create join the existing list/create/delete tools. The README Features list has the full set. By @tphakala in #48
  • New Unix socket transport (SOLIDSERVER_TRANSPORT=unix) for local clients that prefer a filesystem socket over a TCP port, alongside the existing stdio and HTTP transports. By @tphakala in #48

Resources and prompts

  • Read-only MCP resources so a client can pull inventory without spending a tool call: solidserver://spaces, solidserver://dns/zones, solidserver://vlan/domains and solidserver://dhcp/servers, plus templated resources for a single subnet, the records in a zone, and the VLANs in a domain. By @tphakala in #47
  • Guided prompts for common DDI workflows: provision a host, decommission a host, audit a subnet, and plan a VLAN and subnet. Each walks the model through the multi-step sequence with the right arguments. By @tphakala in #47

Safety and hardening

  • Guardrails on every mutating tool: a global read-only mode (SOLIDSERVER_READ_ONLY) that rejects all writes, and per-object protection lists (SOLIDSERVER_PROTECTED_SPACES, SOLIDSERVER_PROTECTED_ZONES, SOLIDSERVER_PROTECTED_SUBNETS) that refuse changes to named production objects. By @tphakala in #42
  • solidserver_doctor preflight: one call runs DNS resolution, network reachability, TLS handshake and API-token checks and points at the exact step that fails. Also runnable from the CLI as solidserver-mcp doctor. By @tphakala in #42
  • File-based secrets: point SOLIDSERVER_TOKEN_ID_FILE / SOLIDSERVER_TOKEN_SECRET_FILE at a file (a Docker or Kubernetes secret mount) instead of putting the token in an environment variable. By @tphakala in #42
  • Untrusted-data fencing: appliance free-text (record comments, object names, error messages) is writable by anyone who can edit an object, so it is a prompt-injection surface. Tool output the model reads as text is now wrapped in an explicit <untrusted-data> envelope that tells the model to treat it as data, not instructions. By @tphakala in #45 and #41
  • Structured outputs and errors: list tools return typed structured content with has_more / next_offset pagination signals and always serialize data as an array (never null); failures come back as structured error objects (message, status, errno, hint) a client can branch on instead of parsing prose. By @tphakala in #45 and #41
  • Query hardening: WHERE-clause values sent to the appliance are escaped and inputs are validated client-side, closing an injection path. By @tphakala in #40

Maintenance

  • Toolchain bumped to Go 1.27 and golangci-lint pinned to v2.13.1 (Dockerfile and CI build on Go 1.27). By @tphakala
  • CI: added a govulncheck workflow (push, PR, and a weekly schedule) and a CodeQL badge. By @tphakala
  • Dependency bumps: github.com/modelcontextprotocol/go-sdk, and the GitHub Actions checkout, setup-go, upload-artifact and codeql-action. By @tphakala

Upgrading

Drop-in from v1.0.0. Every new guardrail defaults to off (read-only disabled, no protected lists), so existing setups keep working unchanged; turn read-only mode or the protection lists on when you want them.

One note if you are copying config from an older README: every variable uses the SOLIDSERVER_ prefix (for example SOLIDSERVER_TRANSPORT, SOLIDSERVER_HTTP_HOST, SOLIDSERVER_LOG_LEVEL). Earlier README drafts showed MCP_* / LOG_LEVEL names the server never actually read; the README is now corrected.

Full Changelog: v1.0.0...v1.1.0