mcp-systemctl
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-systemctlshow status of nginx"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
mcp-systemctl
An MCP (Model Context Protocol) server that reports on and manages systemd services via systemctl and journalctl. Works with any MCP client — Claude Desktop, AI coding agents, or custom tooling.
Quick Start
npm install && npm run build
node dist/index.jsThe server speaks JSON-RPC over stdio (the standard MCP transport). Connect it to your MCP client — see MCP_SYSTEMCTL_USAGE.md for client configuration and all available tools.
Related MCP server: journald-mcp-server
Tools
Tool | Description |
| List systemd units with state/pattern/type filters |
| Detailed status of a specific service (PID, memory, CPU, uptime, etc.) |
| All services in a failed/error state |
| Recent journald log entries for a service |
| Start, stop, restart, reload, enable, or disable a service |
Full parameter details in MCP_SYSTEMCTL_USAGE.md.
Architecture
The project follows a clean three-layer separation:
src/index.ts — Server setup, tool registration
src/tools/*.ts — Zod input schemas + handler functions (thin glue)
src/systemctl.ts — Core logic: systemctl/journalctl exec, parsing, formatting┌──────────────┐ stdio (JSON-RPC) ┌──────────────────────┐
│ MCP Client │ ◄──────────────────────► │ mcp-systemctl │
│ │ │ (Node.js process) │
│ │ │ │
│ │ │ tools/*.ts │
│ │ │ → systemctl.ts │
│ │ │ → systemd │
└──────────────┘ └──────────────────────┘Layer Responsibilities
src/index.ts — Entry point. Creates the McpServer instance, calls server.registerTool() for each tool, then connects to the StdioServerTransport. Adding a new tool means importing its schema and handler and adding one more registerTool call here.
src/tools/ — One file per tool. Each exports:
A schema object (Zod-defined input parameters with
describe()for documentation)A handler function conforming to
ToolCallback<T>— receives validated args, calls intosystemctl.ts, formats the response as MCPcontentblocks
src/systemctl.ts — The engine. All systemctl and journalctl interactions live here:
Shell execution via
execFile(no shell injection risk)Structured result type
SystemctlResult<T>— every function returns{ ok: true, data }or{ ok: false, error, code, stderr }Parsers for the systemctl table and key=value output formats
Human-readable formatters for bytes, nanoseconds, etc.
Extending the Server
Adding a new tool takes four steps. This example adds a get_service_unit_file tool that returns a service's unit file contents.
1. Add the core logic in src/systemctl.ts
export async function getUnitFile(name: string): Promise<SystemctlResult<string>> {
const unitName = name.includes(".") ? name : `${name}.service`;
// Run: systemctl cat <unit>
const args = ["cat", unitName, "--no-pager", "-l"];
return await runSystemctl(args);
}Use the existing helpers — runSystemctl() and runJournalctl() handle timeouts, permission errors, and missing commands consistently. If you need to parse new output formats, add a parser alongside the existing ones.
2. Create the tool file src/tools/getUnitFile.ts
import * as z from "zod";
import type { ToolCallback } from "@modelcontextprotocol/sdk/server/mcp.js";
import { getUnitFile as getUnitFileCore } from "../systemctl.js";
export const getUnitFileSchema = {
name: z
.string()
.min(1)
.describe("Service name (e.g. 'sshd', 'cron.service')"),
};
export const getUnitFileHandler: ToolCallback<typeof getUnitFileSchema> = async (args) => {
try {
const result = await getUnitFileCore(args.name);
if (!result.ok) {
return {
content: [{ type: "text", text: `Error: ${result.error}` }],
isError: true,
};
}
return {
content: [{ type: "text", text: result.data }],
};
} catch (err) {
return {
content: [{ type: "text", text: `Internal error: ${err instanceof Error ? err.message : String(err)}` }],
isError: true,
};
}
};The pattern is always: import the core function → call it → check result.ok → format the response. Every handler returns { content: [...], isError?: boolean }.
3. Register the tool in src/index.ts
Add the imports:
import { getUnitFileSchema, getUnitFileHandler } from "./tools/getUnitFile.js";Add the registration (alongside the existing ones):
server.registerTool(
"get_unit_file",
{
description: "Print the unit file contents of a systemd service.",
inputSchema: getUnitFileSchema,
},
getUnitFileHandler,
);4. Build and test
npm run build
node dist/index.jsYour MCP client will now discover the new get_unit_file tool automatically — no client-side config changes needed.
Design conventions to follow
Convention | Why |
Every core function returns | Caller always handles errors explicitly; no thrown exceptions |
Use | Prevents shell injection through service names or patterns |
Schema parameters use | MCP clients use this description to document the parameter to the LLM |
Handlers wrap core calls in try/catch | Last-resort safety net for unexpected errors (not for expected failures) |
Permission errors handled in | Consistent messaging across all tools |
Source files use | Required by NodeNext module resolution with ESM |
What not to do
Don't put shell execution logic in tool handlers — keep it in
systemctl.tsDon't throw exceptions for expected failures (missing service, permission denied) — return error responses
Don't skip error handling on
result.ok— everySystemctlResultmust be checkedDon't use
anytypes — the Zod schema provides full type inferenceDon't add new dependencies without evaluating whether the existing patterns suffice
Project Structure
mcp-systemctl/
├── src/
│ ├── index.ts # Server entry point, tool registration
│ ├── systemctl.ts # Core systemctl/journalctl logic
│ └── tools/
│ ├── listServices.ts
│ ├── getServiceStatus.ts
│ ├── listFailedServices.ts
│ ├── getServiceLogs.ts
│ └── serviceControl.ts
├── dist/ # Build output (gitignored)
├── node_modules/ # Dependencies (gitignored)
├── MCP_SYSTEMCTL_USAGE.md
├── package.json
├── tsconfig.json
└── .gitignoreLicense
MIT
Available Tools
5 toolsget_service_logsA
Retrieve recent journald log entries for a specific systemd service. Supports configurable line count (up to 5000) and optional priority filtering (emerg, alert, crit, err, warning, notice, info, debug).
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Service name (e.g. 'sshd', 'cron', 'nginx.service') | |
| lines | No | Number of recent log lines to retrieve (default: 50, max: 5000) | |
| priority | No | Filter logs by minimum priority level |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries full burden. It mentions retrieval and configurable parameters but lacks detail on side effects, permissions, or output format, though it adequately describes the basic behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences with no wasted words; every part adds value.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple retrieval tool without output schema, the description covers purpose and key parameters, but could hint at return format or journald specifics for full completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so baseline 3. The description restates line count and priority filtering without adding significant new meaning beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it retrieves journald log entries for a systemd service with a specific verb and resource, distinguishing it from sibling tools like get_service_status or service_control.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage for retrieving logs but does not explicitly state when not to use this tool or compare to alternatives; however, sibling tools are sufficiently different, making context clear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_service_statusA
Get detailed status of a specific systemd service. Returns load state, active state, main PID, memory, CPU, tasks, documentation, and uptime. Accepts service names with or without the .service suffix.
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Service name (e.g. 'sshd', 'cron', 'nginx.service') |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must disclose behavioral traits. It correctly indicates a read operation ('Get') and adds a helpful behavioral detail: 'Accepts service names with or without the .service suffix.' This goes beyond the schema. It also lists the return fields, providing transparency on what the output contains. The description does not contradict any annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences: first sentence states purpose and output contents; second adds a usage tip about suffix. Every sentence provides unique value. No fluff or repetition. Front-loaded with key information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity (one required parameter, no output schema, no nested objects), the description covers the core functionality, parameter behavior, and return fields. It does not mention potential errors or permissions, but for a read-only status check this is acceptable. The description is sufficiently complete for effective use.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with one parameter 'name' described. The description adds meaning beyond the schema by specifying 'Accepts service names with or without the .service suffix,' which is not in the schema description. This helps the agent understand acceptable input formats. Since schema already covers the parameter, the description enriches it.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Get detailed status of a specific systemd service.' It lists the specific fields returned (load state, active state, PID, memory, CPU, tasks, documentation, uptime), which distinguishes it from sibling tools like get_service_logs (logs), list_services (listing), or service_control (actions). The verb 'Get' and resource 'systemd service' are specific.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage for retrieving status of one service, but does not explicitly state when to use this tool versus siblings (e.g., 'Use this to check a single service's status; for logs use get_service_logs'). No exclusions or prerequisites are provided. The context is clear but guidance is minimal.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_failed_servicesA
List all systemd services that are currently in a failed/error state. Returns unit name, load state, active state, sub state, and description for each failed service.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries full burden. It describes the return fields, but does not explicitly state that it is a read-only operation or disclose any side effects, permissions, or behavioral nuances beyond the basic listing.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two concise sentences that front-load the purpose and include specific return fields. No wasted words.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no parameters and no output schema, the description is fairly complete. It specifies the input (none) and the output fields. Could mention ordering or limitations, but not necessary for basic usage.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Tool has no parameters, so schema coverage is 100%. The description does not need to add parameter info. Baseline 4 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states it lists systemd services in a failed/error state and specifies the returned fields (unit name, load state, etc.). It distinguishes from siblings like list_services (all services) and get_service_status (specific service).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No explicit guidance on when to use this tool versus alternatives. It is implied that this tool is for filtering to failed services, but no when-not conditions or comparisons are provided.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_servicesB
List all systemd services. Optionally filter by state (running, exited, failed, inactive, all) and by name glob pattern (e.g. 'ssh*', 'cron*'). Defaults to listing all service units.
| Name | Required | Description | Default |
|---|---|---|---|
| state | No | Filter by service state (default: all) | all |
| pattern | No | Optional glob pattern to filter service names (e.g. 'ssh*', 'cron*') | |
| type | No | Systemd unit type to list (default: service) | service |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations exist, so the description carries the full burden. It describes listing and filtering, which implies a read operation with no side effects. However, it lacks disclosure of output format, pagination, or ordering.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is concise, with two sentences that front-load the purpose. However, it could be more precise by acknowledging the type parameter, which slightly reduces efficiency.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with three parameters and no output schema, the description covers filtering basics but fails to mention the type parameter's existence. Sibling tools are not referenced, and the discrepancy between 'services' and the broader unit types may confuse the agent.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, giving a baseline of 3. The description adds examples for pattern ('ssh*', 'cron*') and enumerates state options, but it omits the 'type' parameter entirely, which controls which unit types are listed. This omission reduces clarity for agents.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states the tool lists systemd services and mentions filtering options, but it inaccurately limits to 'services' while the schema includes other unit types (timer, socket, etc.). This is a minor misrepresentation.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides context for filtering by state and pattern, but does not differentiate when to use this tool versus siblings (e.g., list_failed_services, get_service_status), nor does it mention that the type parameter allows listing non-service units.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
service_controlA
Control a systemd service: start, stop, restart, reload, enable, or disable. NOTE: Most actions require root/sudo privileges and will return a permission error if unavailable.
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Service name (e.g. 'sshd', 'cron', 'nginx.service') | |
| action | Yes | Action to perform on the service |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description discloses that most actions require root/sudo and may return permission errors. However, with no annotations provided, it does not cover other behavioral traits such as side effects on dependent services, action idempotency, or response format. This is adequate but not exhaustive.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is very concise: two sentences with no extraneous words. The first sentence states purpose and actions; the second adds crucial permission context. Every sentence earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the simple nature of the tool (2 params, no output schema, no annotations), the description covers the main actions and a critical permission note. It does not explain success/failure output or naming conventions, but it is nearly complete for a systemd control tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with both parameters described in the schema. The description does not add new semantic information beyond restating the action enum and the service name concept. Baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb 'control' and the resource 'systemd service', listing the exact actions (start, stop, restart, etc.). This distinguishes it from sibling monitoring tools like get_service_logs and get_service_status.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description includes a note about root/sudo privileges and permission errors, providing clear context on when the tool can be used. However, it does not explicitly mention when to use this tool versus alternatives like list_services or get_service_status.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
5 tool updates
v1.0.0- First observed
get_service_logs - First observed
get_service_status - First observed
list_failed_services - First observed
list_services - First observed
service_control
TDQS
Each tool targets a distinct aspect of systemd service management: listing all services, listing failed ones, getting detailed status, retrieving logs, and performing control actions. No overlap in purpose.
All tool names follow a consistent verb_noun pattern using snake_case (e.g., get_service_logs, list_services, service_control). The naming is predictable and clear.
5 tools is an appropriate number for managing systemd services. It covers the essential operations without being overly granular or sparse.
The set covers all common tasks: listing with filters, checking status, retrieving logs, controlling services (start/stop/enable/disable), and listing failed services. No obvious gaps for typical systemctl usage.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
An MCP server that let you interact with Cycloid.io Internal Development Portal and Platform
A MCP server built for developers enabling Git based project management with project and personal…
An MCP server that provides congressional transcripts
The MCP server for Azure DevOps, bringing the power of Azure DevOps directly to your agents.
Related MCP Servers
- AlicenseAqualityAmaintenanceAn MCP server for read-only Linux system administration and diagnostics on RHEL-based systems via SSH. It enables users to troubleshoot remote hosts by accessing system information, services, logs, and network configurations through natural language.19292Apache 2.0
- FlicenseNot gradedqualityDmaintenanceAn MCP server for accessing systemd journal logs.1-
- FlicenseNot gradedqualityDmaintenanceAn MCP server for managing Ubuntu/Linux systems, enabling AI assistants to execute commands, manage services, files, logs, and packages via local or SSH connection.-
- FlicenseNot gradedqualityDmaintenanceMCP server for infrastructure discovery and remote management, enabling SSH command execution, file transfer, log tailing, and machine/service inventory with a companion web dashboard.2-
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/rileylsmith1997/sample-mcp-systemctl'
If you have feedback or need assistance with the MCP directory API, please join our Discord server