homelab-mcp
Model Context Protocol (MCP) servers for managing homelab infrastructure through Claude Desktop. Monitor Docker/Podman containers, Ollama AI models, Pi-hole DNS, Unifi networks, and Ansible inventory. Includes security checks, templates, and automated pre-push validation. Production-ready for homelabs.
Documentation
Homelab MCP Servers
Model Context Protocol (MCP) servers for managing homelab infrastructure through Claude Desktop.
A collection of Model Context Protocol (MCP) servers for managing and monitoring your homelab infrastructure through Claude Desktop.
๐ Security Notice
**โ ๏ธ IMPORTANT: Please read SECURITY.md before deploying this project.**
This project interacts with critical infrastructure (Docker APIs, DNS, network devices). Improper configuration can expose your homelab to security risks.
Key Security Requirements:
- NEVER expose Docker/Podman APIs to the internet - Use firewall rules to restrict access
- Keep `.env` file secure - Contains API keys and should never be committed
- Use unique API keys - Generate separate keys for each service
- Review network security - Ensure proper VLAN segmentation and firewall rules
See SECURITY.md for comprehensive security guidance.
๏ฟฝ Documentation Overview
This project includes several documentation files for different audiences:
- **README.md** (this file) - Installation, setup, and usage guide
- **MIGRATION_V3.md** - Migration guide for v2.0 unified server
- **PROJECT_INSTRUCTIONS.md** - Copy into Claude project instructions for AI context
- **CLAUDE.md** - Developer guide for AI assistants and contributors
- **SECURITY.md** - Security policies and best practices
- **CONTRIBUTING.md** - How to contribute to this project
- **CHANGELOG.md** - Version history and changes
๐ฅ For End Users: Follow this README + copy PROJECT_INSTRUCTIONS.md to Claude
๐ Migrating from v1.x? See MIGRATION_V3.md for unified server migration
๐ค For AI Assistants: Read CLAUDE.md for complete development context
๐ง For Contributors: Start with CONTRIBUTING.md and CLAUDE.md
๏ฟฝ๐ Important: Configure Claude Project Instructions
After setting up the MCP servers, create your personalized project instructions:
1. Copy the example template:
# Windows
copy PROJECT_INSTRUCTIONS.example.md PROJECT_INSTRUCTIONS.md
# Linux/Mac
cp PROJECT_INSTRUCTIONS.example.md PROJECT_INSTRUCTIONS.md2. Edit the file with your actual infrastructure details:
PROJECT_INSTRUCTIONS.md (for Claude Desktop project instructions):
CLAUDE_CUSTOM.md (for AI development work - contributors only):
3. Add to Claude Desktop:
What's included:
- Detailed MCP server capabilities and usage patterns
- Infrastructure overview and monitoring capabilities
- Specific commands and tools available for each service
- Troubleshooting and development guidance
This README covers installation and basic setup. The project instructions provide Claude with comprehensive usage context.
๐ฏ Deployment Options
Version 3.0.0 offers flexible deployment with two modes and two methods:
Deployment Modes
Choose how your MCP servers are organized:
1. Unified Server (Recommended)
Run all MCP servers in a single process with namespaced tools. This is the recommended approach for new installations and required for Docker deployments.
{
"mcpServers": {
"homelab-unified": {
"command": "python",
"args": ["C:\\Path\\To\\Homelab-MCP\\homelab_unified_mcp.py"]
}
}
}Advantages:
- โ Single configuration entry
- โ One Python process for all servers
- โ Cleaner logs (no duplicate warnings)
- โ All tools namespaced (e.g., `docker_get_containers`, `ping_ping_host`)
- โ Required for Docker deployments
- โ Built-in health checks
- โ Production-ready containerization
2. Individual Servers (Legacy, Fully Supported)
Run each MCP server as a separate process. This mode remains fully supported for backward compatibility and only available with native Python installation.
{
"mcpServers": {
"docker": {
"command": "python",
"args": ["C:\\Path\\To\\Homelab-MCP\\docker_mcp_podman.py"]
},
"ollama": {
"command": "python",
"args": ["C:\\Path\\To\\Homelab-MCP\\ollama_mcp.py"]
}
}
}Advantages:
- โ Granular control over each server
- โ Can enable/disable servers individually
- โ Original tool names (e.g., `get_docker_containers`, `ping_host`)
- โ Backward compatible with v1.x
Note: Tool names differ between modes. See MIGRATION_V3.md for detailed migration instructions and tool name changes.
Deployment Methods
Choose how to install and run the servers:
1. Docker Container (Recommended for Production)
Pre-built images available on Docker Hub for immediate deployment. See ๐ณ Docker Deployment for full setup instructions.
Quick Start:
docker pull bjeans/homelab-mcp:latest
docker-compose up -dAdvantages:
- โ No Python environment setup required
- โ Pre-built, tested images
- โ Automatic updates with image pulls
- โ Multi-platform support (amd64, arm64)
- โ Simplified configuration
- โ Production-grade containerization
Limitations:
- Unified server mode only
- mcp-registry-inspector not available (deprecated)
2. Native Python Installation (Development & Legacy)
Install Python dependencies directly and run servers from source. See ๐ฆ Installation for full setup instructions.
Quick Start:
pip install -r requirements.txt
python homelab_unified_mcp.pyAdvantages:
- โ Full access to source code
- โ Easy debugging and development
- โ Supports both unified and individual server modes
- โ Can run on any Python-compatible platform
Requirements:
- Python 3.10+ with pip
- Manual dependency management
- Environment configuration via .env file
Migration Guide: See MIGRATION_V3.md for detailed instructions on switching between modes or methods.
โก FastMCP Framework (v3.0.0)
Version 3.0.0 uses FastMCP: A modern MCP framework that simplifies server architecture while adding support for multiple transport mechanisms and tool annotations.
What is FastMCP?
FastMCP is a lightweight framework that:
- โ Reduces server code by 38% (1,754 lines eliminated)
- โ Uses simple decorator pattern (`@mcp.tool()`) for tool definitions
- โ Includes comprehensive tool annotations for behavioral hints
- โ Adds support for HTTP and SSE transports (in addition to stdio)
- โ Auto-generates schemas from Python type hints
- โ Improves code maintainability and makes adding new servers easier
All 39 tools now include MCP annotations (`readOnlyHint`, `idempotentHint`, etc.) to help Claude make informed decisions about tool usage.
Transport Options
FastMCP servers can operate using different transport mechanisms:
1. Standard Input/Output (stdio) - Default
The traditional MCP transport used by Claude Desktop. This is the default and recommended option for most users.
# Run with stdio (default)
python homelab_unified_mcp.py
# Or explicitly specify stdio transport
python homelab_unified_mcp.py --transport stdioWhen to use:
- Claude Desktop integration (default mode)
- Most common use case
- No additional configuration needed
2. HTTP Transport
Run MCP servers as HTTP services for remote or flexible deployment scenarios.
# Start server with HTTP transport
python homelab_unified_mcp.py --transport http --host 0.0.0.0 --port 8000
# Test the HTTP endpoint
curl http://localhost:8000/toolsWhen to use:
- Deploying servers remotely
- Web-based integrations
- Multi-client scenarios
- Load balancing requirements
3. Server-Sent Events (SSE) Transport
Stream-based protocol for real-time bidirectional communication.
# Start server with SSE transport
python homelab_unified_mcp.py --transport sse --host 0.0.0.0 --port 8000
# Connect via SSE client
curl http://localhost:8000/sseWhen to use:
- Real-time monitoring applications
- Browser-based integrations
- Event-driven architectures
- Streaming responses
Configuring Claude Desktop with FastMCP
Claude Desktop continues to use stdio transport by default. No configuration changes are required:
{
"mcpServers": {
"homelab-unified": {
"command": "python",
"args": ["C:\\Path\\To\\Homelab-MCP\\homelab_unified_mcp.py"]
}
}
}Migration from v2.2.0
If you're upgrading from v2.2.0:
- โ No breaking changes - Your existing configuration continues to work unchanged
- โ Same functionality - All 7 servers and all tools remain identical
- โ Cleaner code - Internal refactoring produces the same results
- โ New options - Optional HTTP/SSE transports available if needed
No action required - just update and restart Claude Desktop.
๐ Quick Start
1. Clone the repository
git clone https://github.com/bjeans/homelab-mcp
cd homelab-mcp2. Install security checks (recommended)
# Install pre-push git hook for automatic security validation
python helpers/install_git_hook.py3. Set up configuration files
Environment variables:
# Windows
copy .env.example .env
# Linux/Mac
cp .env.example .envEdit `.env` with your actual values:
# Windows
notepad .env
# Linux/Mac
nano .envAnsible inventory (if using):
# Windows
copy ansible_hosts.example.yml ansible_hosts.yml
# Linux/Mac
cp ansible_hosts.example.yml ansible_hosts.ymlEdit with your infrastructure details.
Project instructions:
# Windows
copy PROJECT_INSTRUCTIONS.example.md PROJECT_INSTRUCTIONS.md
# Linux/Mac
cp PROJECT_INSTRUCTIONS.example.md PROJECT_INSTRUCTIONS.mdCustomize with your network topology and servers.
AI development guide customizations (optional):
# Windows
copy CLAUDE_CUSTOM.example.md CLAUDE_CUSTOM.md
# Linux/Mac
cp CLAUDE_CUSTOM.example.md CLAUDE_CUSTOM.mdCustomize with your actual server names and infrastructure details. This file is gitignored and allows Claude to understand your specific homelab setup. See `CLAUDE.md` for more information about local customizations.
4. Install Python dependencies
pip install -r requirements.txt5. Add to Claude Desktop config
Config file location:
- Windows: `%APPDATA%\Claude\claude_desktop_config.json`
- macOS: `~/Library/Application Support/Claude/claude_desktop_config.json`
- Linux: `~/.config/Claude/claude_desktop_config.json`
Option A: Unified Server (Recommended)
Single entry for all homelab servers:
{
"mcpServers": {
"homelab-unified": {
"command": "python",
"args": ["C:\\Path\\To\\Homelab-MCP\\homelab_unified_mcp.py"],
"env": {
"ANSIBLE_INVENTORY_PATH": "C:\\Path\\To\\ansible_hosts.yml"
}
}
}
}Note: The unified server includes 7 MCP servers: Ansible, Docker/Podman, Ollama, Pi-hole, Unifi, UPS, and Ping. The deprecated mcp-registry-inspector is not included.
Option B: Individual Servers (Legacy)
Separate entry for each server:
{
"mcpServers": {
"docker": {
"command": "python",
"args": ["C:\\Path\\To\\Homelab-MCP\\docker_mcp_podman.py"],
"env": {
"ANSIBLE_INVENTORY_PATH": "C:\\Path\\To\\ansible_hosts.yml"
}
},
"ollama": {
"command": "python",
"args": ["C:\\Path\\To\\Homelab-MCP\\ollama_mcp.py"],
"env": {
"ANSIBLE_INVENTORY_PATH": "C:\\Path\\To\\ansible_hosts.yml"
}
},
"pihole": {
"command": "python",
"args": ["C:\\Path\\To\\Homelab-MCP\\pihole_mcp.py"],
"env": {
"ANSIBLE_INVENTORY_PATH": "C:\\Path\\To\\ansible_hosts.yml"
}
},
"unifi": {
"command": "python",
"args": ["C:\\Path\\To\\Homelab-MCP\\unifi_mcp_optimized.py"],
"env": {
"ANSIBLE_INVENTORY_PATH": "C:\\Path\\To\\ansible_hosts.yml"
}
},
"ping": {
"command": "python",
"args": ["C:\\Path\\To\\Homelab-MCP\\ping_mcp_server.py"],
"env": {
"ANSIBLE_INVENTORY_PATH": "C:\\Path\\To\\ansible_hosts.yml"
}
},
"ups-monitor": {
"command": "python",
"args": ["C:\\Path\\To\\Homelab-MCP\\ups_mcp_server.py"],
"env": {
"ANSIBLE_INVENTORY_PATH": "C:\\Path\\To\\ansible_hosts.yml"
}
}
}
}Note: Tool names differ between modes. See MIGRATION_V3.md for details. The deprecated mcp-registry-inspector has been removed from this example. Ansible MCP server integration is tracked in #39.
6. Restart Claude Desktop
7. Add project instructions to Claude
- Copy the contents of your customized `PROJECT_INSTRUCTIONS.md`
- Paste into your Claude project's "Project instructions" field
- This gives Claude comprehensive context about your MCP capabilities
๐ณ Docker Deployment (Alternative)
Run the MCP servers in Docker containers for easier distribution, isolation, and production deployment.
Docker Hub: bjeans/homelab-mcp
Quick Start with Docker Hub (Easiest)
Pre-built images are automatically published to Docker Hub with multi-platform support (amd64/arm64):
# Pull the latest image
docker pull bjeans/homelab-mcp:latest
# Run with your Ansible inventory
docker run -d \
--name homelab-mcp \
--network host \
-v $(pwd)/ansible_hosts.yml:/config/ansible_hosts.yml:ro \
bjeans/homelab-mcp:latest
# Or use a specific commit
docker pull bjeans/homelab-mcp:main-17bae01Available on Docker Hub: https://hub.docker.com/r/bjeans/homelab-mcp/tags
Currently available tags:
- `latest` - Latest stable release from main branch (recommended)
- `edge` - Latest development build from main branch
- `main-` - Specific commit builds for traceability (e.g., `main-17bae01`)
Semantic version tags (available after release):
- Version tags like `2.2.0`, `2.2`, `2` will be created when the `v2.2.0` Git release is published
- Until then, use `latest` for the most recent stable build
Multi-platform support:
- `linux/amd64` - x86_64 servers and workstations
- `linux/arm64` - Raspberry Pi, ARM-based systems
Build from Source (Advanced)
Build the image locally if you need to customize:
# Pull the pre-built image from Docker Hub (recommended)
docker pull bjeans/homelab-mcp:latest
# Run with Docker Compose (recommended for production)
docker-compose up -d
# Or run unified server directly
docker run -d \
--name homelab-mcp \
--network host \
-v $(pwd)/ansible_hosts.yml:/config/ansible_hosts.yml:ro \
bjeans/homelab-mcp:latestBuilding from source (optional):
# Clone and navigate to repository
git clone https://github.com/bjeans/homelab-mcp
cd homelab-mcp
# Build the image locally
docker build -t homelab-mcp:latest .Docker Features
2.0.0 Docker Improvements:
- โ Unified MCP server as default entrypoint (all 7 servers in one container)
- โ Automatic unified mode detection (no ENABLED_SERVERS needed)
- โ Built-in health checks (HEALTHCHECK configured)
- โ Non-root user security (mcpuser UID 1000)
- โ Proper signal handling and clean shutdown
- โ Optimized layer caching for faster rebuilds
- โ System dependencies included (iputils-ping for cross-platform support)
Configuration Methods
Method 1: Ansible Inventory (Recommended)
# Create your ansible_hosts.yml with infrastructure details
# Then mount as volume:
docker run -d \
--name homelab-mcp \
--network host \
-v $(pwd)/ansible_hosts.yml:/config/ansible_hosts.yml:ro \
bjeans/homelab-mcp:latestMethod 2: Environment Variables (Marketplace Ready)
docker run -d \
--name homelab-mcp \
--network host \
-e DOCKER_SERVER1_ENDPOINT=192.168.1.100:2375 \
-e DOCKER_SERVER1_NAME=Local-Docker \
-e OLLAMA_SERVER1_ENDPOINT=192.168.1.100:11434 \
bjeans/homelab-mcp:latestLegacy Mode: Individual Servers (Docker)
For backward compatibility, you can still run individual servers by setting `ENABLED_SERVERS`:
docker run -d \
--name homelab-mcp-docker \
--network host \
-e ENABLED_SERVERS=docker \
-v $(pwd)/ansible_hosts.yml:/config/ansible_hosts.yml:ro \
bjeans/homelab-mcp:latestAvailable Servers
Unified Mode (Default):
- โ All 7 servers in one process: Ansible, Docker, Ping, Ollama, Pi-hole, Unifi, UPS
- โ Namespaced tools (e.g., `ansible_get_all_hosts`, `docker_get_containers`, `ups_get_ups_status`)
- โ Single configuration entry
- โ Built-in health checks
Legacy Mode (Set `ENABLED_SERVERS`):
- โ `ansible` - Ansible inventory queries
- โ `docker` - Docker/Podman container management
- โ `ping` - Network ping utilities
- โ `ollama` - Ollama AI model management
- โ `pihole` - Pi-hole DNS statistics
- โ `unifi` - Unifi network device monitoring
- โ `ups` - UPS/NUT power monitoring
Docker Configuration
Two configuration methods supported:
1. Ansible Inventory (Recommended) - Mount as volume
2. Environment Variables - Pass via Docker `-e` flags
See DOCKER.md for comprehensive Docker deployment guide including:
- Detailed setup instructions
- Network configuration options
- Security best practices
- Claude Desktop integration
- Troubleshooting common issues
Integration with Claude Desktop
Unified Mode (Recommended):
{
"mcpServers": {
"homelab-unified": {
"command": "docker",
"args": ["exec", "-i", "homelab-mcp", "python", "homelab_unified_mcp.py"]
}
}
}Legacy Mode (Individual Servers):
{
"mcpServers": {
"homelab-docker": {
"command": "docker",
"args": ["exec", "-i", "homelab-mcp-docker", "python", "docker_mcp_podman.py"]
},
"homelab-ping": {
"command": "docker",
"args": ["exec", "-i", "homelab-mcp", "python", "ping_mcp_server.py"]
}
}
}Important: Use `docker exec -i` (not `-it`) for proper MCP stdio communication.
Testing Docker Containers
Quick verification test (using environment variables - marketplace ready):
# Test Unified Server
docker run --rm --network host \
-e DOCKER_SERVER1_ENDPOINT=localhost:2375 \
-e OLLAMA_SERVER1_ENDPOINT=localhost:11434 \
bjeans/homelab-mcp:latest
# Test Individual Server (legacy)
docker run --rm --network host \
-e ENABLED_SERVERS=ping \
bjeans/homelab-mcp:latestDocker Compose testing:
docker-compose up -d
docker-compose logs -fFor comprehensive Docker deployment guide, see DOCKER.md.
๐ฆ Available MCP Servers
โจ Dynamic Tool Parameter Enums (New in v2.1.0)
When you configure Ansible inventory, Claude Desktop will automatically show your infrastructure options in dropdown menus. No more guessing hostnames or group names!
What gets auto-populated:
- Ping tools - Your Ansible groups appear in dropdown menus
- Docker tools - Your Docker/Podman hosts shown in dropdowns
- Ollama tools - Your Ollama server hostnames available for selection
- UPS tools - Your NUT server hostnames shown in dropdowns
How it works:
1. Set `ANSIBLE_INVENTORY_PATH` in your `.env` file
2. Restart Claude Desktop (required - enums load at startup)
3. When using tools, Claude shows your actual infrastructure in dropdown menus instead of requiring manual entry
Important Notes:
- Restart Required: Changes to Ansible inventory require restarting Claude Desktop to update dropdown options
- Performance: Enums generate once at startup - minimal impact even with large inventories (100+ hosts)
- Graceful Degradation: If no Ansible inventory is configured, tools still work - you just won't see dropdown suggestions
Example before/after:
*Before:* "Which group should I ping?" โ User manually types "webservers" (or guesses)
*After:* "Which group should I ping?" โ User selects from dropdown: `all`, `docker_hosts`, `webservers`, `databases`, etc.
Troubleshooting:
- Dropdowns not showing? Verify `ANSIBLE_INVENTORY_PATH` is set and restart Claude Desktop
- Wrong options showing? Check that your Ansible inventory is up-to-date and restart Claude Desktop
- Performance issues? Enum generation happens once at startup - if slow, check inventory file size and Ansible installation
MCP Registry Inspector (โ ๏ธ DEPRECATED)
> Deprecation Notice (v2.3.0): This tool is deprecated. Claude Desktop now has native file system access, making this MCP server unnecessary. You can simply ask Claude to read your MCP server files or configuration directly.
Replacement: Use Claude's built-in file access:
- "Read my claude_desktop_config.json file"
- "Show me the source code for docker_mcp_podman.py"
- "List all .py files in this directory"
For users with existing configurations: This server will continue to work but will not receive updates. It will be removed from documentation in v3.0.0. Consider removing it from your `claude_desktop_config.json`.
Legacy Configuration (for reference only)
Tools:
- `get_claude_config` - View Claude Desktop MCP configuration
- `list_mcp_servers` - List all registered MCP servers
- `list_mcp_directory` - Browse MCP development directory
- `read_mcp_file` - Read MCP server source code
- `write_mcp_file` - Write/update MCP server files
- `search_mcp_files` - Search for files by name
Configuration:
MCP_DIRECTORY=/path/to/your/Homelab-MCP
CLAUDE_CONFIG_PATH=/path/to/claude_desktop_config.json # OptionalDocker/Podman Container Manager
Manage Docker and Podman containers across multiple hosts.
๐ Security Warning: Docker/Podman APIs typically use unencrypted HTTP without authentication. See SECURITY.md for required firewall configuration.
Tools:
Individual server mode:
- `get_docker_containers` - Get containers on a specific host
- `get_all_containers` - Get all containers across all hosts
- `get_container_stats` - Get CPU and memory stats
- `check_container` - Check if a specific container is running
- `find_containers_by_label` - Find containers by label
- `get_container_labels` - Get all labels for a container
Unified server mode (namespaced):
- `docker_get_containers` - Get containers on a specific host
- `docker_get_all_containers` - Get all containers across all hosts
- `docker_get_container_stats` - Get CPU and memory stats
- `docker_check_container` - Check if a specific container is running
- `docker_find_containers_by_label` - Find containers by label
- `docker_get_container_labels` - Get all labels for a container
Configuration Options:
Option 1: Using Ansible Inventory (Recommended)
ANSIBLE_INVENTORY_PATH=/path/to/ansible_hosts.yml
# Ansible inventory group names (default: docker_hosts, podman_hosts)
# Change these if you use different group names in your ansible_hosts.yml
DOCKER_ANSIBLE_GROUP=docker_hosts
PODMAN_ANSIBLE_GROUP=podman_hostsOption 2: Using Environment Variables
DOCKER_SERVER1_ENDPOINT=192.168.1.100:2375
DOCKER_SERVER2_ENDPOINT=192.168.1.101:2375
PODMAN_SERVER1_ENDPOINT=192.168.1.102:8080Ollama AI Model Manager
Monitor and manage Ollama AI model instances across your homelab, plus check your LiteLLM proxy for unified API access.
What's Included
Ollama Monitoring:
- Track multiple Ollama instances across different hosts
- View available models and their sizes
- Check instance health and availability
LiteLLM Proxy Integration:
- LiteLLM provides a unified OpenAI-compatible API across all your Ollama instances
- Enables load balancing and failover between multiple Ollama servers
- Allows you to use OpenAI client libraries with your local models
- The MCP server can verify your LiteLLM proxy is online and responding
Why use LiteLLM?
- Load Balancing: Automatically distributes requests across multiple Ollama instances
- Failover: If one Ollama server is down, requests route to healthy servers
- OpenAI Compatibility: Use any OpenAI SDK/library with your local models
- Centralized Access: Single endpoint (e.g., `http://192.0.2.10:4000`) for all models
- Usage Tracking: Monitor which models are being used most
Tools:
- `get_ollama_status` - Check status of all Ollama instances and model counts
- `get_ollama_models` - Get detailed model list for a specific host
- `get_litellm_status` - Verify LiteLLM proxy is online and responding
Configuration Options:
Option 1: Using Ansible Inventory (Recommended)
ANSIBLE_INVENTORY_PATH=/path/to/ansible_hosts.yml
OLLAMA_PORT=11434 # Default Ollama port
# Ansible inventory group name (default: ollama_servers)
# Change this if you use a different group name in your ansible_hosts.yml
OLLAMA_INVENTORY_GROUP=ollama_servers
# LiteLLM Configuration
LITELLM_HOST=192.168.1.100 # Host running LiteLLM proxy
LITELLM_PORT=4000 # LiteLLM proxy port (default: 4000)Option 2: Using Environment Variables
# Ollama Instances
OLLAMA_SERVER1=192.168.1.100
OLLAMA_SERVER2=192.168.1.101
OLLAMA_WORKSTATION=192.168.1.150
# LiteLLM Proxy
LITELLM_HOST=192.168.1.100
LITELLM_PORT=4000Setting Up LiteLLM (Optional):
If you want to use LiteLLM for unified access to your Ollama instances:
1. Install LiteLLM on one of your servers:
pip install litellm[proxy]2. Create configuration (`litellm_config.yaml`):
model_list:
- model_name: llama3.2
litellm_params:
model: ollama/llama3.2
api_base: http://server1:11434
- model_name: llama3.2
litellm_params:
model: ollama/llama3.2
api_base: http://server2:11434
router_settings:
routing_strategy: usage-based-routing3. Start LiteLLM proxy:
litellm --config litellm_config.yaml --port 40004. Use the MCP tool to verify it's running:
Example Usage:
- "What Ollama instances do I have running?"
- "Show me all models on my Dell-Server"
- "Is my LiteLLM proxy online?"
- "How many models are available across all servers?"
Pi-hole DNS Manager
Monitor Pi-hole DNS statistics and status.
๐ Security Note: Store Pi-hole API keys securely in `.env` file. Generate unique keys per instance.
Tools:
- `get_pihole_stats` - Get DNS statistics from all Pi-hole instances
- `get_pihole_status` - Check which Pi-hole instances are online
Configuration Options:
Option 1: Using Ansible Inventory (Recommended)
ANSIBLE_INVENTORY_PATH=/path/to/ansible_hosts.yml
# Ansible inventory group name (default: PiHole)
# Change this if you use a different group name in your ansible_hosts.yml
PIHOLE_ANSIBLE_GROUP=PiHole
# API keys still required in .env:
PIHOLE_API_KEY_SERVER1=your-api-key-here
PIHOLE_API_KEY_SERVER2=your-api-key-hereOption 2: Using Environment Variables
PIHOLE_API_KEY_SERVER1=your-api-key
PIHOLE_API_KEY_SERVER2=your-api-key
PIHOLE_SERVER1_HOST=pihole1.local
PIHOLE_SERVER1_PORT=80
PIHOLE_SERVER2_HOST=pihole2.local
PIHOLE_SERVER2_PORT=8053Getting Pi-hole API Keys:
- Web UI: Settings โ API โ Show API Token
- Or generate new: `pihole -a -p` on Pi-hole server
Unifi Network Monitor
Monitor Unifi network infrastructure and clients with caching for performance.
๐ Security Note: Use a dedicated API key with minimal required permissions.
Tools:
- `get_network_devices` - Get all network devices (switches, APs, gateways)
- `get_network_clients` - Get all active network clients
- `get_network_summary` - Get network overview
- `refresh_network_data` - Force refresh from controller (bypasses cache)
Configuration:
UNIFI_API_KEY=your-unifi-api-key
UNIFI_HOST=192.168.1.1Note: Data is cached for 5 minutes to improve performance. Use `refresh_network_data` to force update.
Ansible Inventory Inspector
Query Ansible inventory information (read-only). Available in both unified and standalone modes.
Unified Mode Tools (with `ansible_` prefix):
- `ansible_get_all_hosts` - Get all hosts in inventory
- `ansible_get_all_groups` - Get all groups
- `ansible_get_host_details` - Get detailed host information
- `ansible_get_group_details` - Get detailed group information
- `ansible_get_hosts_by_group` - Get hosts in specific group
- `ansible_search_hosts` - Search hosts by pattern or variable
- `ansible_get_inventory_summary` - High-level inventory overview
- `ansible_reload_inventory` - Reload inventory from disk
Standalone Mode Tools (without prefix):
- `get_all_hosts` - Get all hosts in inventory
- `get_all_groups` - Get all groups
- `get_host_details` - Get detailed host information
- `get_group_details` - Get detailed group information
- `get_hosts_by_group` - Get hosts in specific group
- `search_hosts` - Search hosts by pattern or variable
- `get_inventory_summary` - High-level inventory overview
- `reload_inventory` - Reload inventory from disk
Configuration:
ANSIBLE_INVENTORY_PATH=/path/to/ansible_hosts.ymlDeployment:
- โ Available in unified server mode
- โ Available in Docker deployments
- โ Available in standalone mode: `python ansible_mcp_server.py`
Ping Network Connectivity Monitor
Test network connectivity and host availability using ICMP ping across your infrastructure.
Why use this?
- Quick health checks during outages or after power events
- Verify which hosts are reachable before querying service-specific MCPs
- Simple troubleshooting tool to identify network issues
- Baseline connectivity testing for your infrastructure
Tools:
- `ping_host` - Ping a single host by name (resolved from Ansible inventory)
- `ping_group` - Ping all hosts in an Ansible group concurrently
- `ping_all` - Ping all infrastructure hosts concurrently
- `list_groups` - List available Ansible groups for ping operations
Features:
- โ Cross-platform support - Works on Windows, Linux, and macOS
- โ Ansible integration - Automatically resolves hostnames/IPs from inventory
- โ Concurrent pings - Test multiple hosts simultaneously for faster results
- โ Detailed statistics - RTT min/avg/max, packet loss percentage
- โ Customizable - Configure timeout and packet count
- โ No dependencies - Uses system `ping` command (no extra libraries needed)
Configuration:
ANSIBLE_INVENTORY_PATH=/path/to/ansible_hosts.yml
# No additional API keys required!Example Usage:
- "Ping server1.example.local"
- "Check connectivity to all Pi-hole servers"
- "Ping all Ubuntu_Server hosts"
- "Test connectivity to entire infrastructure"
- "What groups can I ping?"
When to use:
- After power outages - Quickly identify which hosts came back online
- Before service checks - Verify host is reachable before checking specific services
- Network troubleshooting - Isolate connectivity issues from service issues
- Health monitoring - Regular checks to ensure infrastructure availability
UPS Monitoring (Network UPS Tools)
Monitor UPS (Uninterruptible Power Supply) devices across your infrastructure using Network UPS Tools (NUT) protocol.
Why use this?
- Real-time visibility into power infrastructure status
- Proactive alerts before battery depletion during outages
- Monitor multiple UPS devices across different hosts
- Track battery health and runtime estimates
- Essential for critical infrastructure planning
Tools:
- `get_ups_status` - Check status of all UPS devices across all NUT servers
- `get_ups_details` - Get detailed information for a specific UPS device
- `get_battery_runtime` - Get battery runtime estimates for all UPS devices
- `get_power_events` - Check for recent power events (on battery, low battery)
- `list_ups_devices` - List all UPS devices configured in inventory
- `reload_inventory` - Reload Ansible inventory after changes
Features:
- โ NUT protocol support - Uses Network UPS Tools standard protocol (port 3493)
- โ Ansible integration - Automatically discovers UPS from inventory
- โ Multiple UPS per host - Support for servers with multiple UPS devices
- โ Battery monitoring - Track charge level, runtime remaining, load percentage
- โ Power event detection - Identify when UPS switches to battery or low battery
- โ Cross-platform - Works with any NUT-compatible UPS (TrippLite, APC, CyberPower, etc.)
- โ Flexible auth - Optional username/password authentication
Configuration:
Option 1: Using Ansible Inventory (Recommended)
ANSIBLE_INVENTORY_PATH=/path/to/ansible_hosts.yml
# Default NUT port (optional, defaults to 3493)
NUT_PORT=3493
# NUT authentication (optional - only if your NUT server requires it)
NUT_USERNAME=monuser
NUT_PASSWORD=secretAnsible inventory example:
nut_servers:
hosts:
dell-server.example.local:
ansible_host: 192.168.1.100
nut_port: 3493
ups_devices:
- name: tripplite
description: "TrippLite SMART1500LCDXL"Option 2: Using Environment Variables
NUT_PORT=3493
NUT_USERNAME=monuser
NUT_PASSWORD=secretPrerequisites:
1. Install NUT on servers with UPS devices:
# Debian/Ubuntu
sudo apt install nut nut-client nut-server
# RHEL/Rocky/CentOS
sudo dnf install nut nut-client2. Configure NUT daemon (`/etc/nut/ups.conf`):
[tripplite]
driver = usbhid-ups
port = auto
desc = "TrippLite SMART1500LCDXL"3. Enable network monitoring (`/etc/nut/upsd.conf`):
LISTEN 0.0.0.0 34934. Configure access (`/etc/nut/upsd.users`):
[monuser]
password = secret
upsmon master5. Start NUT services:
sudo systemctl enable nut-server nut-client
sudo systemctl start nut-server nut-clientExample Usage:
- "What's the status of all my UPS devices?"
- "Show me battery runtime for the Dell server UPS"
- "Check for any power events"
- "Get detailed info about the TrippLite UPS"
- "List all configured UPS devices"
When to use:
- After power flickers - Verify UPS devices handled the event properly
- Before maintenance - Check battery levels and estimated runtime
- Regular monitoring - Track UPS health and battery condition
- Capacity planning - Understand how long systems can run on battery
Common UPS Status Codes:
- `OL` - Online (normal operation, AC power present)
- `OB` - On Battery (power outage, running on battery)
- `LB` - Low Battery (critically low battery, shutdown imminent)
- `CHRG` - Charging (battery is charging)
- `RB` - Replace Battery (battery needs replacement)
๐ Security
Automated Security Checks
This project includes automated security validation to prevent accidental exposure of sensitive data:
Install the pre-push git hook (recommended):
# From project root
python helpers/install_git_hook.pyWhat it does:
- Automatically runs `helpers/pre_publish_check.py` before every git push
- Blocks pushes that contain potential secrets or sensitive data
- Protects against accidentally committing API keys, passwords, or personal information
Manual security check:
# Run security validation manually
python helpers/pre_publish_check.pyBypass security check (use with extreme caution):
# Only when absolutely necessary
git push --no-verifyCritical Security Practices
Configuration Files:
- โ DO use `.env.example` as a template
- โ DO keep `.env` file permissions restrictive (`chmod 600` on Linux/Mac)
- โ NEVER commit `.env` to version control
- โ NEVER commit `ansible_hosts.yml` with real infrastructure
- โ NEVER commit `PROJECT_INSTRUCTIONS.md` with real network topology
API Security:
- โ DO use unique API keys for each service
- โ DO rotate API keys regularly (every 90 days recommended)
- โ DO use strong, randomly-generated keys (32+ characters)
- โ NEVER expose Docker/Podman APIs to the internet
- โ NEVER reuse API keys between environments
Network Security:
- โ DO use firewall rules to restrict API access
- โ DO implement VLAN segmentation
- โ DO enable TLS/HTTPS where possible
- โ NEVER expose management interfaces publicly
**For detailed security guidance, see SECURITY.md**
๐ Requirements
System Requirements
- Python: 3.10 or higher
- Claude Desktop: Latest version recommended
- Network Access: Connectivity to homelab services
Python Dependencies
Install via `requirements.txt`:
pip install -r requirements.txtCore dependencies:
- `mcp` - Model Context Protocol SDK
- `aiohttp` - Async HTTP client
- `pyyaml` - YAML parsing for Ansible inventory
Service Requirements
- Docker/Podman: API enabled on monitored hosts
- Pi-hole: v6+ with API enabled
- Unifi Controller: API access enabled
- Ollama: Running instances with API accessible
- NUT (Network UPS Tools): Installed and configured on hosts with UPS devices
- Ansible: Inventory file (optional but recommended)
๐ป Compatibility
Tested Platforms
Developed and tested on:
- OS: Windows 11
- Claude Desktop: Version 0.13.64
- Python: Version 3.13.8
Cross-Platform Notes
Windows: Fully tested and supported โ
macOS: Should work but untested โ ๏ธ
Linux: Should work but untested โ ๏ธ
Known platform differences:
- File paths in documentation are Windows-style
- Path separators may need adjustment for Unix systems
- `.env` file permissions should be set on Unix (`chmod 600 .env`)
Contributions for other platforms welcome!
๐ ๏ธ Development
๐ First time contributing? Read CLAUDE.md for complete development guidance including architecture patterns, security requirements, and AI assistant workflows.
Getting Started
1. Install security git hook (required for contributors):
python helpers/install_git_hook.py2. Set up development environment:
pip install -r requirements.txt
cp .env.example .env
# Edit .env with your test valuesTesting MCP Servers Locally
Before submitting a PR, test your MCP server changes locally using the MCP Inspector tool.
Quick start:
# MCP Inspector is an optional Node.js tool for interactive testing
# Option 1: Use npx (no installation needed - recommended)
npx @modelcontextprotocol/inspector uv --directory . run _mcp.py
# Option 2: Install globally first (one-time setup)
npm install -g @modelcontextprotocol/inspector
# Then run: mcp-inspector uv --directory . run _mcp.pyThis opens a web-based debugger at `http://localhost:5173` where you can:
- See all available tools for the MCP server
- Test each tool with sample arguments
- Verify responses are properly formatted
- Debug issues before submitting PRs
For detailed testing instructions, see the Testing MCP Servers Locally section in CONTRIBUTING.md.
Helper Scripts
The `helpers/` directory contains utility scripts for development and deployment:
- `install_git_hook.py` - Installs git pre-push hook for automatic security checks
- `pre_publish_check.py` - Security validation script (runs automatically via git hook)
Usage:
# Install security git hook
python helpers/install_git_hook.py
# Run security check manually
python helpers/pre_publish_check.pyProject Structure
Homelab-MCP/
โโโ MCP Servers (7 production servers)
โ โโโ ansible_mcp_server.py # Ansible inventory queries (integration in progress)
โ โโโ docker_mcp_podman.py # Docker/Podman container monitoring
โ โโโ ollama_mcp.py # Ollama AI model management
โ โโโ pihole_mcp.py # Pi-hole DNS monitoring
โ โโโ ping_mcp_server.py # Network connectivity testing
โ โโโ unifi_mcp_optimized.py # Unifi network device monitoring
โ โโโ ups_mcp_server.py # UPS/NUT monitoring
โ
โโโ Unified Server & Core Modules
โ โโโ homelab_unified_mcp.py # Combines all servers (Docker entrypoint)
โ โโโ mcp_config_loader.py # Secure environment variable loading
โ โโโ mcp_error_handler.py # Centralized error handling
โ โโโ ansible_config_manager.py # Ansible inventory + enum generation
โ
โโโ Utilities & Deprecated Tools
โ โโโ unifi_exporter.py # Unifi data export utility
โ โโโ mcp_registry_inspector.py # MCP file management (โ ๏ธ DEPRECATED v2.3.0)
โ
โโโ Configuration & Examples
โ โโโ .env.example # Configuration template (gitignored)
โ โโโ ansible_hosts.example.yml # Ansible inventory example (gitignored)
โ โโโ PROJECT_INSTRUCTIONS.example.md # AI assistant guide template
โ โโโ CLAUDE_CUSTOM.example.md # Local customization template (gitignored)
โ
โโโ Documentation
โ โโโ README.md # This file - user documentation
โ โโโ CLAUDE.md # AI assistant development guide
โ โโโ SECURITY.md # Security guidelines
โ โโโ CONTRIBUTING.md # Contribution guide
โ โโโ CHANGELOG.md # Version history
โ โโโ MIGRATION_V3.md # Version migration guide
โ โโโ CONTEXT_AWARE_SECURITY.md # Security scanning docs
โ โโโ CI_CD_CHECKS.md # CI/CD automation docs
โ โโโ LICENSE # MIT License
โ
โโโ Docker Deployment
โ โโโ Dockerfile # Container build configuration
โ โโโ docker-compose.yml # Container orchestration (uses bjeans/homelab-mcp:latest)
โ โโโ docker-entrypoint.sh # Container startup script
โ
โโโ Development Tools
โ โโโ helpers/
โ โ โโโ install_git_hook.py # Git pre-push hook installer
โ โ โโโ pre_publish_check.py # Security validation
โ โ โโโ run_checks.py # CI/CD check runner
โ โ โโโ requirements-dev.txt # Development dependencies
โ โโโ requirements.txt # Production Python dependencies
โ โโโ .gitignore # Git ignore rulesAdding a New MCP Server
1. Create the server file
#!/usr/bin/env python3
"""
My Service MCP Server
Description of what it does
"""
import asyncio
from mcp.server import Server
# ... implement tools ...2. Add configuration to `.env.example`
# My Service Configuration
MY_SERVICE_HOST=192.168.1.100
MY_SERVICE_API_KEY=your-api-key3. Update documentation
4. Test thoroughly
Environment Variables
All MCP servers support two configuration methods:
1. Environment Variables (`.env` file)
- Simple key=value pairs
- Loaded automatically by each MCP server
- Good for simple setups or testing
2. Ansible Inventory (recommended for production)
- Centralized infrastructure definition
- Supports complex host groupings
- Better for multi-host environments
- Set `ANSIBLE_INVENTORY_PATH` in `.env`
Coding Standards
- Python 3.10+ syntax and features
- Async/await for all I/O operations
- Type hints where beneficial
- Error handling for network operations
- Logging to stderr for debugging
- Security: Validate inputs, sanitize outputs
Testing Checklist
Before committing changes:
- [ ] Security git hook installed (`python helpers/install_git_hook.py`)
- [ ] Manual security check passes (`python helpers/pre_publish_check.py`)
- [ ] No sensitive data in code or commits
- [ ] Environment variables for all configuration
- [ ] Error handling for network failures
- [ ] Logging doesn't expose secrets
- [ ] Documentation updated
- [ ] Security implications reviewed
- [ ] `.gitignore` updated if needed
๐ Troubleshooting
MCP Servers Not Appearing in Claude
1. Check Claude Desktop config:
# Windows
type %APPDATA%\Claude\claude_desktop_config.json
# Mac/Linux
cat ~/.config/Claude/claude_desktop_config.json2. Verify Python path is correct in config
3. Restart Claude Desktop completely
4. Check logs - MCP servers log to stderr
Connection Errors
Docker/Podman API:
# Test connectivity
curl http://your-host:2375/containers/json
# Check firewall
netstat -an | grep 2375Pi-hole API:
# Test API key
curl "http://your-pihole/api/stats/summary?sid=YOUR_API_KEY"Ollama:
# Test Ollama endpoint
curl http://your-host:11434/api/tagsUnderstanding Error Messages
Error Message Format (v2.2.0+):
All MCP servers now provide detailed, actionable error messages in this format:
โ [Service] [Error Type] (HTTP Status)
[Specific problem description]
Host: [hostname:port]
โ [Actionable remediation steps]
Technical details: [error details] (timestamp)Common Error Types:
1. Authentication Failed (401)
Example:
โ Pi-hole Authentication Failed (401)
Invalid API key for pi-hole-1
Host: 192.168.1.5:80
โ Verify PIHOLE_API_KEY_PI_HOLE_1 in .env matches your Pi-hole admin password.
โ You can find/reset this in Pi-hole Settings > API.How to Fix:
1. Check your `.env` file for the correct API key variable
2. Verify the API key matches the service's admin panel
3. For Pi-hole: Settings > API > Show API token
4. For Unifi: Settings > Admins > API > Generate key
2. Connection Failed
Example:
โ Unifi Connection Failed
Unable to connect to unifi-controller:443
Host: unifi-controller:443
โ Ensure Unifi controller is running and accessible at unifi-controller:443.
โ Test connectivity: nc -zv unifi-controller 443
โ Check firewall: sudo iptables -L | grep 443How to Fix:
1. Verify the service is running: `systemctl status [service-name]`
2. Test network connectivity with `nc` or `telnet`
3. Check firewall rules allow access to the port
4. Verify the hostname/IP is correct in your configuration
3. Timeout Errors
Example:
โ Ollama Timeout
Connection to ollama-1:11434 timed out (after 5s)
Host: ollama-1:11434
โ The service is not responding. Check if Ollama is running and not overloaded.
โ Check service status and logs for performance issues.How to Fix:
1. Check if the service is running: `systemctl status ollama`
2. Look for performance issues in service logs
3. Verify network latency: `ping [hostname]`
4. Consider increasing timeout values if service is legitimately slow
4. Invalid/Expired Credentials (403)
Example:
โ Service Authorization Failed (403)
Valid credentials but insufficient permissions
โ Ensure the API key/account has the required permissions for this operation.How to Fix:
1. Check account permissions in the service admin panel
2. Ensure the API key has admin/full access rights
3. Regenerate API key if permissions were recently changed
5. Unifi Exporter Errors
Before (v2.1.0):
Error: Exporter failed with code 1After (v2.2.0):
โ Unifi Authentication Failed
Invalid Unifi API key for unifi-controller
Host: unifi-controller
โ Verify UNIFI_API_KEY in .env matches the API key from Unifi Settings > Admins > API.
โ Ensure the key has not expired.
Technical details: 401 Unauthorized (at 2025-11-20T10:30:45Z)How to Fix:
1. Log into Unifi controller
2. Navigate to Settings > Admins > API
3. Verify or regenerate API key
4. Update `UNIFI_API_KEY` in `.env` file
5. Restart Claude Desktop to reload configuration
6. Service Unavailable (503)
How to Fix:
1. Check if the service is running
2. Look for service startup errors in logs
3. Verify all dependencies are available
4. Consider restarting the service
Debugging Tips
Enable Detailed Logging:
All errors are logged to stderr with full context. Check Claude Desktop logs:
- Windows: `%APPDATA%\Claude\logs\`
- Mac: `~/Library/Logs/Claude/`
- Linux: `~/.config/Claude/logs/`
Test API Endpoints Directly:
Use `curl` or `httpie` to test API endpoints outside of MCP:
# Pi-hole
curl "http://pi-hole:80/api/stats/summary?sid=YOUR_API_KEY"
# Docker
curl http://docker-host:2375/containers/json
# Unifi (requires SSL and API key)
curl -k -H "X-API-KEY: YOUR_KEY" https://unifi:443/api/stat/sta
# Ollama
curl http://ollama:11434/api/tags
# NUT (Network UPS Tools)
telnet nut-server 3493
> LIST UPSCheck Configuration:
# Verify .env file exists and is readable
ls -la .env
# Check for syntax errors in .env
cat .env | grep -v '^#' | grep -v '^$'
# Verify Ansible inventory
ansible-inventory -i ansible_hosts.yml --listImport Errors
If you get Python import errors:
# Reinstall dependencies
pip install --upgrade -r requirements.txt
# Verify MCP installation
pip show mcpPermission Errors
On Linux/Mac:
# Fix .env permissions
chmod 600 .env
# Make scripts executable
chmod +x *.py๐ Additional Resources
MCP Protocol
Related Projects
๐ License
MIT License - See LICENSE file for details
Copyright (c) 2025 Barnaby Jeans
๐ค Contributing
Contributions are welcome! Please see CONTRIBUTING.md for detailed guidelines.
For AI Assistants & Developers
**๐ Read CLAUDE.md first** - This file contains:
- Complete project architecture and development patterns
- Security requirements and common pitfalls to avoid
- Specific workflows for adding features and fixing bugs
- AI assistant-specific guidance for working with this codebase
Quick Start for Contributors
1. Install security git hook (`python helpers/install_git_hook.py`)
2. Review security guidelines in SECURITY.md
3. No sensitive data in commits (hook will block automatically)
4. All configuration uses environment variables or Ansible
5. Update documentation for any changes
6. Test thoroughly with real infrastructure
Pull Request Process
1. Fork the repository
2. Create a feature branch (`git checkout -b feature/amazing-feature`)
3. Make your changes
4. Test with your homelab setup
5. Update README and other docs as needed
6. Commit with clear messages (`git commit -m 'Add amazing feature'`)
7. Push to your fork (`git push origin feature/amazing-feature`)
8. Open a Pull Request
Code Review Criteria
- Security best practices followed
- No hardcoded credentials or IPs
- Proper error handling
- Code follows existing patterns
- Documentation is clear and complete
- Changes are tested
๐ Acknowledgments
- Anthropic for Claude and MCP
- The homelab community for inspiration
- Contributors and testers
๐ Support
- Issues: GitHub Issues
- Discussions: GitHub Discussions
- Security: See SECURITY.md for reporting vulnerabilities
Remember: This project handles critical infrastructure. Always prioritize security and test changes in a safe environment first!
Frequently asked questions
What is homelab-mcp?
homelab-mcp is Model Context Protocol (MCP) servers for managing homelab infrastructure through Claude Desktop. Monitor Docker/Podman containers, Ollama AI models, Pi-hole DNS, Unifi networks, and Ansible inventory. Includes security checks, templates, and automated pre-push validation. Production-ready for homelabs.
How do I install homelab-mcp?
Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.
Is homelab-mcp open source?
Yes โ it is hosted on GitHub at https://github.com/bjeans/homelab-mcp and has 40 stars.
Related MCP tools
Control Gmail, Google Calendar, Docs, Sheets, Slides, Chat, Forms, Tasks, Search & Drive with AI - Comprehensive Google Workspace MCP Server & CLI Tool
Cut AI token costs 95%+ on code exploration. The leading MCP server for precise, symbol-level GitHub code retrieval via tree-sitter AST. Works with Claude Code, Cursor & any MCP client. 313B+ tokens saved.
AI-powered OSINT agent with interactive REPL, MCP server, and CLI. 19 tools. Works with Claude, GPT-4, or local models. For authorized security research only.
Decision audit trail + persistent memory for AI trading agents. Outcome-weighted recall, tamper-evident SHA-256 chain with RFC 3161 anchoring, 20 MCP tools.
Natural voice conversations with Claude Code
On-premises conversational RAG with configurable containers for the Model Context Protocol. Enhance AI assistants with powerful integrations.
Run your own MCP server? See who uses it and what to fix.
Measure it with TrackMCP