SSH Orchestrator
Provides secure SSH fleet orchestration with policy-enforced command execution across multiple servers, featuring deny-by-default
A secure SSH fleet orchestrator built by Samer Farida that provides policy-enforced command execution across multiple servers through MCP tools. The implementation features a deny-by-default security model with IP allowlisting, command pattern matching, host key verification, and audit logging, while supporting both key-based and password authentication with Docker secrets integration. It includes tools for host discovery, command planning with dry-run capabilities, single-host and tag-based batch execution, real-time streaming output with cancellation support, and hot-reloadable configuration, making it useful for infrastructure automation, compliance-aware server management, and AI-assisted DevOps workflows where security and auditability are paramount.
Source
Repository: https://github.com/samerfarida/mcp-ssh-orchestrator
Maintain SSH Orchestrator?
Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.
[SSH Orchestrator on getagentictools](https://getagentictools.com/mcp/samerfarida-mcp-ssh-orchestrator?ref=badge)