Repository navigation
Releases: tphakala/solidserver-mcp
Release list
v1.1.0
Highlights
This is a big step up from the first release. v1.1.0 roughly doubles the tool set, teaches the server to hand your MCP client ready-made inventory and guided workflows, and wraps the whole thing in safety rails so an LLM driving it cannot wander into a destructive change or be steered by untrusted text coming back from the appliance.
If you skim one thing: there are now create/update/delete tools across IPAM, DNS, VLAN and DHCP, read-only resources and guided prompts for everyday DDI tasks, a read-only mode and protected object lists to fence off production, and a solidserver_doctor preflight that tells you in one call whether the connection, TLS and API token are actually working.
New tools and transports
- Expanded tool coverage across every area:
ip_update,space_create/space_delete,dns_record_update,dns_zone_create/dns_zone_delete,vlan_domain_create/vlan_domain_delete,dhcp_scope_create, anddhcp_range_createjoin the existing list/create/delete tools. The README Features list has the full set. By @tphakala in #48 - New Unix socket transport (
SOLIDSERVER_TRANSPORT=unix) for local clients that prefer a filesystem socket over a TCP port, alongside the existing stdio and HTTP transports. By @tphakala in #48
Resources and prompts
- Read-only MCP resources so a client can pull inventory without spending a tool call:
solidserver://spaces,solidserver://dns/zones,solidserver://vlan/domainsandsolidserver://dhcp/servers, plus templated resources for a single subnet, the records in a zone, and the VLANs in a domain. By @tphakala in #47 - Guided prompts for common DDI workflows: provision a host, decommission a host, audit a subnet, and plan a VLAN and subnet. Each walks the model through the multi-step sequence with the right arguments. By @tphakala in #47
Safety and hardening
- Guardrails on every mutating tool: a global read-only mode (
SOLIDSERVER_READ_ONLY) that rejects all writes, and per-object protection lists (SOLIDSERVER_PROTECTED_SPACES,SOLIDSERVER_PROTECTED_ZONES,SOLIDSERVER_PROTECTED_SUBNETS) that refuse changes to named production objects. By @tphakala in #42 solidserver_doctorpreflight: one call runs DNS resolution, network reachability, TLS handshake and API-token checks and points at the exact step that fails. Also runnable from the CLI assolidserver-mcp doctor. By @tphakala in #42- File-based secrets: point
SOLIDSERVER_TOKEN_ID_FILE/SOLIDSERVER_TOKEN_SECRET_FILEat a file (a Docker or Kubernetes secret mount) instead of putting the token in an environment variable. By @tphakala in #42 - Untrusted-data fencing: appliance free-text (record comments, object names, error messages) is writable by anyone who can edit an object, so it is a prompt-injection surface. Tool output the model reads as text is now wrapped in an explicit
<untrusted-data>envelope that tells the model to treat it as data, not instructions. By @tphakala in #45 and #41 - Structured outputs and errors: list tools return typed structured content with
has_more/next_offsetpagination signals and always serializedataas an array (nevernull); failures come back as structured error objects (message,status,errno,hint) a client can branch on instead of parsing prose. By @tphakala in #45 and #41 - Query hardening: WHERE-clause values sent to the appliance are escaped and inputs are validated client-side, closing an injection path. By @tphakala in #40
Maintenance
- Toolchain bumped to Go 1.27 and golangci-lint pinned to v2.13.1 (Dockerfile and CI build on Go 1.27). By @tphakala
- CI: added a govulncheck workflow (push, PR, and a weekly schedule) and a CodeQL badge. By @tphakala
- Dependency bumps:
github.com/modelcontextprotocol/go-sdk, and the GitHub Actionscheckout,setup-go,upload-artifactandcodeql-action. By @tphakala
Upgrading
Drop-in from v1.0.0. Every new guardrail defaults to off (read-only disabled, no protected lists), so existing setups keep working unchanged; turn read-only mode or the protection lists on when you want them.
One note if you are copying config from an older README: every variable uses the SOLIDSERVER_ prefix (for example SOLIDSERVER_TRANSPORT, SOLIDSERVER_HTTP_HOST, SOLIDSERVER_LOG_LEVEL). Earlier README drafts showed MCP_* / LOG_LEVEL names the server never actually read; the README is now corrected.
Full Changelog: v1.0.0...v1.1.0