{"repo":"samerfarida/mcp-ssh-orchestrator","free":true,"listed":false,"github":"https://github.com/samerfarida/mcp-ssh-orchestrator","clone":"git clone https://github.com/samerfarida/mcp-ssh-orchestrator.git","description":"Secure SSH access for AI agents via MCP. Execute commands across your server fleet with policy enforcement, network controls, and comprehensive audit logging.","language":"Python","stars":27,"topics":["ai-agents","automation","claude","cursor","docker","mcp","mcp-server","network-control","python","security-policy"],"license":"Apache-2.0","category":"mcp-servers","readme_excerpt":"MCP SSH Orchestrator Zero-Trust SSH Orchestration for AI Assistants Enforce declarative policy-as-code and audited access for Claude Desktop, Cursor, and any MCP-aware client. Launch in minutes with Docker + MCP tooling, deny-by-default controls, and hardened SSH key management. --- What Problem Does This Solve? Imagine this: Your AI assistant (Claude, ChatGPT, etc.) can access your servers, but you're terrified of what it might do. rm -rf / ? Delete your databases? Change firewall rules? Now imagine this: Your AI has governed, auditable access to your infrastructure. It can check logs, restart services, and manage your fleet, but only if your security policies allow it. That's exactly what MCP SSH Orchestrator provides: the power of AI-driven server management with deny-by-default access control, IP allowlists, host key verification, and comprehensive audit logging backed by declarative YAML policy-as-code ( config/servers.yml , config/credentials.yml , config/policy.yml ) . Why This Matters Zero-Trust Security Model - Deny-by-default : Nothing runs unless explicitly allowed - Network controls : IP allowlists prevent lateral movement - Command whitelisting : Only approved commands can execute - Declarative policy-as-code : Versioned YAML files define hosts, credentials, and allowed commands - Comprehensive audit trails : Every action is logged in JSON Prevents Common Attack Vectors - Dangerous commands blocked : rm -rf , dd , file deletions - Network isolation : Servers can'","default_branch":null,"files":null,"tree":[],"storefront":"/r/samerfarida","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/samerfarida/mcp-ssh-orchestrator/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}