Emisar
About
Give your AI agents access to production without the risks of sharing SSH keys.
Details
- Author
- andrewdryga
- Categories
- Developer Tools, Other, Security, Infrastructure
Jump to
Setup
Install Emisar in your MCP client (Claude Desktop, Cursor, Windsurf, and others).
Repository: https://github.com/andrewdryga/emisar
Follow the installation instructions in the repository README, then restart your MCP client.
Leave the agent working. Keep production authority bounded.
emisar gives MCP-capable agents a catalog of declared infrastructure actions instead of a shell. Policy decides what runs, what waits for a person, and what is denied. A small outbound-only runner checks the action again on the host before it executes anything.
Start with the public pack catalog, let emisar suggest the packs that match a host, and add your own actions without adding another MCP server to every client.
In the dashboard, chooseConnect a runner. Copy the generated command; it contains a fresh, single-use enrollment key.
curl -fsSL https://emisar.dev/install.sh \ | sudo EMISAR_ENROLLMENT_KEY=emkey-enroll-... EMISAR_URL=https://emisar.dev bash
The installer verifies the release checksum, creates the service, installs host-matched starter packs, and starts the runner.
Confirm the runner is online in the dashboard, then dispatchlinux.uptimewith a reason. You are done when the output appears and the run is present in the audit trail.
OpenLLM agentsand connect your client. Remote MCP clients use OAuth; local stdio clients can use theemisar-mcpbridge and its browser approval flow.
The complete walkthrough, including expected output and troubleshooting, is atemisar.dev/docs/quickstart. An agent can perform and certify the setup with the publicinstall-emisarskill.
AI client | MCP: discover actions, request one with typed arguments v emisar control plane | authenticate, scope, apply policy, wait for approval when required v outbound-only runner | verify pack hash, validate arguments, enforce local limits v declared host command stream redacted output, journal the attempt, update fleet audit
The action pack is the contract. It fixes the executable, argv shape, argument schema, risk, timeout, output limits, redaction, and side-effect description. The model selects from that contract; it does not invent a command line for the runner to execute.
Adding a pack adds capabilities behind the same MCP surface. Operators do not need to deploy another tool server or reconfigure every agent when the catalog changes.
- No inbound runner listener.The runner opens an outbound TLS WebSocket and exposes no inbound listener; commands return through that established connection.
- Declared actions only.Cloud input is limited to typed, schema-bounded arguments. The runner rejects unknown actions and arguments.
- Content-addressed packs.The control plane pins the trusted pack hash; the runner recomputes it from disk before execution. New or changed custom packs wait for trust.
- Policy before side effects.Runner scope, risk policy, action overrides, standing grants, and conditional approval are evaluated before dispatch.
- Host-side enforcement.The runner clamps execution options to the pack's limits and runs the declared binary and argv. Runner output is redacted before leaving the host; Emisar retains the resulting redacted output in audit log.
- Two records.The control-plane audit includes denied and pending requests; every runner also writes its execution attempts and local refusals to a hash-chained JSONL journal.
- Optional bridge-attested dispatch.A runner can require an Ed25519 intent signed by the customer-authorized MCP bridge, so the control plane cannot originate or widen a permitted call.
Read the exact guarantees, limitations, and threat model in.agent/kb/specs/security-model.md.
- It is not a sandbox or process isolator. We recommend using one, such ascoop.
- It is not a genericexecute(command)tool or a replacement for SSH.
- It does not replace OS least privilege, change management, or configuration management.
- It does not make a permitted destructive action harmless. The safety boundary is only as strong as the actions, pack trust, policy, runner configuration, and host permissions in use.
The staging-onlyshellpack is the explicit break-glass exception to the declared-action model. It is critical-risk, default-denied, never suggested, and should not be installed on production runners.
portal/ Elixir/Phoenix control plane, operator console, website, and MCP API runner/ Go host runner and operator CLI mcp/ Go stdio-to-HTTP MCP bridge packs/ Versioned action-pack catalog skills/ Standalone customer skills for coding agents infra/ Production Terraform for emisar on Google Cloud run Root contributor command for development, tests, gates, and operations dev/ Development Compose topologies, images, configs, and fixtures tools/ Go implementations behind the contributor command and CI dist/ Tracked distribution packages plus ignored generated build output .agent/kb/ Repository architecture, specifications, runbooks, and rules
Each top-level project has its ownAGENTS.mdwith its architecture, security rules, and verification gate. Run./run helpfor the complete contributor command surface.
The recommended path needs onlyCoopand Docker on the host. It installs every repository pin in the isolated project image:
./run bootstrap # works before Go is installed coop build # build the pinned project image once coop run -- ./run setup # sidecars, deps, migrations, browser tooling coop shell # enter the development box
./run seed # explicit, idempotent demo data ./run serve # live reload at the URL printed by Coop # or: ./run serve --iex
For native development, install the exact versions in.tool-versionswith asdf, plus Git, Coop, Docker, the PostgreSQL client, ShellCheck, Chrome/Chromium, and ImageMagick../run setupvalidates all prerequisites before starting services;./run doctorreports every detected version and an actionable mismatch. On macOS, run./run certs trustonce for this workspace after setup.
The fast loop runs Phoenix in the current environment and keeps only PostgreSQL and Keycloak in the workspace-isolated Coop dependency stack.
./run urlsprints this workspace's distinct Portal, metrics, Postgres, and Keycloak URLs. Coop forks inherit the same setup but receive different ports and volumes. Seeds are never applied by setup, serve, or reset unless explicitly requested.
Use./run statusfor a read-only view of the current workspace,./run logs [db|keycloak]for its exact sidecar logs, and./run psqlfor its development database. Every canonical gate prints its current phase and elapsed time; a failure names the phase that stopped it.
The rootdocker-compose.ymlremains the slower packaged topology with the release Portal image, seeded demo data, three runners, MCP, and signing. Start it with./run smoke; it serveshttp://localhost:4010. Seeportal/README.mdanddev/README.md.
- runner/,mcp/, andpacks/are open source under theApache License 2.0. You can inspect, build, package, and operate the on-host components independently.
- Everything else, includingportal/, is source-available under theBusiness Source License 1.1. Non-production use is free. Production use is permitted only as needed to operate the Apache-licensed components or the hosted service under the Additional Use Grant; other production use requires a commercial license. Each version converts to Apache 2.0 on its Change Date.
Seecontributing,security, andthe CLA. For commercial licensing, contactlicensing@emisar.dev.
This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.
Secure Zero-Trust SSH Gateway for AI Agents. A Go-based Model Context Protocol (MCP) server featuring runtime Regex Command Firewalls and multi-host isolation.
awaBerry Agentic allows for secure remote access to any terminal based device for workflows allowing any Agent and Large Language Model based routine to execute commands on your devices for getting access to required data - and to also write genrated data back.
DevOps MCP — Secure MCP Server for Linux Server Automation
A three-tier access control MCP server that allows AI assistants (Claude Code, Cursor, Windsurf) to safely scan, plan, and operate Linux servers via SSH without full write access. Includes an out-of-band human consent token gate, automated port-conflict scanning, and a completely read-only default safe mode to eliminate accidental destructive commands on production environments.
A security-focused MCP server for performing safe operations on an Ubuntu system, featuring robust security controls and audit logging.
Network reconnaissance and security scanning with port scanning, DNS analysis, and vulnerability assessment
A comprehensive MCP server for managing OPNsense firewalls, offering over 300 tools for configuration and monitoring.
Manage OPNsense firewalls using Infrastructure as Code (IaC) principles.
An MCP server that provides SSH-based remote management tools, acting as proxy
Create secure tunnels to expose local servers to the internet using untun.
A MCP server to allow your AI agent to manage your SikkerKey secrets vault.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.





