Skip to main content
Glama
rileylsmith1997

mcp-systemctl

mcp-systemctl

An MCP (Model Context Protocol) server that reports on and manages systemd services via systemctl and journalctl. Works with any MCP client — Claude Desktop, AI coding agents, or custom tooling.

Quick Start

npm install && npm run build
node dist/index.js

The server speaks JSON-RPC over stdio (the standard MCP transport). Connect it to your MCP client — see MCP_SYSTEMCTL_USAGE.md for client configuration and all available tools.

Related MCP server: journald-mcp-server

Tools

Tool

Description

list_services

List systemd units with state/pattern/type filters

get_service_status

Detailed status of a specific service (PID, memory, CPU, uptime, etc.)

list_failed_services

All services in a failed/error state

get_service_logs

Recent journald log entries for a service

service_control

Start, stop, restart, reload, enable, or disable a service

Full parameter details in MCP_SYSTEMCTL_USAGE.md.


Architecture

The project follows a clean three-layer separation:

src/index.ts          — Server setup, tool registration
src/tools/*.ts        — Zod input schemas + handler functions (thin glue)
src/systemctl.ts      — Core logic: systemctl/journalctl exec, parsing, formatting
┌──────────────┐     stdio (JSON-RPC)     ┌──────────────────────┐
│  MCP Client  │ ◄──────────────────────► │  mcp-systemctl       │
│              │                          │  (Node.js process)   │
│              │                          │                      │
│              │                          │  tools/*.ts          │
│              │                          │    → systemctl.ts    │
│              │                          │    → systemd         │
└──────────────┘                          └──────────────────────┘

Layer Responsibilities

src/index.ts — Entry point. Creates the McpServer instance, calls server.registerTool() for each tool, then connects to the StdioServerTransport. Adding a new tool means importing its schema and handler and adding one more registerTool call here.

src/tools/ — One file per tool. Each exports:

  • A schema object (Zod-defined input parameters with describe() for documentation)

  • A handler function conforming to ToolCallback<T> — receives validated args, calls into systemctl.ts, formats the response as MCP content blocks

src/systemctl.ts — The engine. All systemctl and journalctl interactions live here:

  • Shell execution via execFile (no shell injection risk)

  • Structured result type SystemctlResult<T> — every function returns { ok: true, data } or { ok: false, error, code, stderr }

  • Parsers for the systemctl table and key=value output formats

  • Human-readable formatters for bytes, nanoseconds, etc.


Extending the Server

Adding a new tool takes four steps. This example adds a get_service_unit_file tool that returns a service's unit file contents.

1. Add the core logic in src/systemctl.ts

export async function getUnitFile(name: string): Promise<SystemctlResult<string>> {
  const unitName = name.includes(".") ? name : `${name}.service`;
  // Run: systemctl cat <unit>
  const args = ["cat", unitName, "--no-pager", "-l"];
  return await runSystemctl(args);
}

Use the existing helpers — runSystemctl() and runJournalctl() handle timeouts, permission errors, and missing commands consistently. If you need to parse new output formats, add a parser alongside the existing ones.

2. Create the tool file src/tools/getUnitFile.ts

import * as z from "zod";
import type { ToolCallback } from "@modelcontextprotocol/sdk/server/mcp.js";
import { getUnitFile as getUnitFileCore } from "../systemctl.js";

export const getUnitFileSchema = {
  name: z
    .string()
    .min(1)
    .describe("Service name (e.g. 'sshd', 'cron.service')"),
};

export const getUnitFileHandler: ToolCallback<typeof getUnitFileSchema> = async (args) => {
  try {
    const result = await getUnitFileCore(args.name);
    if (!result.ok) {
      return {
        content: [{ type: "text", text: `Error: ${result.error}` }],
        isError: true,
      };
    }
    return {
      content: [{ type: "text", text: result.data }],
    };
  } catch (err) {
    return {
      content: [{ type: "text", text: `Internal error: ${err instanceof Error ? err.message : String(err)}` }],
      isError: true,
    };
  }
};

The pattern is always: import the core function → call it → check result.ok → format the response. Every handler returns { content: [...], isError?: boolean }.

3. Register the tool in src/index.ts

Add the imports:

import { getUnitFileSchema, getUnitFileHandler } from "./tools/getUnitFile.js";

Add the registration (alongside the existing ones):

server.registerTool(
  "get_unit_file",
  {
    description: "Print the unit file contents of a systemd service.",
    inputSchema: getUnitFileSchema,
  },
  getUnitFileHandler,
);

4. Build and test

npm run build
node dist/index.js

Your MCP client will now discover the new get_unit_file tool automatically — no client-side config changes needed.

Design conventions to follow

Convention

Why

Every core function returns SystemctlResult<T>

Caller always handles errors explicitly; no thrown exceptions

Use execFile, never exec or shell commands

Prevents shell injection through service names or patterns

Schema parameters use .describe()

MCP clients use this description to document the parameter to the LLM

Handlers wrap core calls in try/catch

Last-resort safety net for unexpected errors (not for expected failures)

Permission errors handled in systemctl.ts

Consistent messaging across all tools

Source files use .js extensions in imports

Required by NodeNext module resolution with ESM

What not to do

  • Don't put shell execution logic in tool handlers — keep it in systemctl.ts

  • Don't throw exceptions for expected failures (missing service, permission denied) — return error responses

  • Don't skip error handling on result.ok — every SystemctlResult must be checked

  • Don't use any types — the Zod schema provides full type inference

  • Don't add new dependencies without evaluating whether the existing patterns suffice


Project Structure

mcp-systemctl/
├── src/
│   ├── index.ts          # Server entry point, tool registration
│   ├── systemctl.ts      # Core systemctl/journalctl logic
│   └── tools/
│       ├── listServices.ts
│       ├── getServiceStatus.ts
│       ├── listFailedServices.ts
│       ├── getServiceLogs.ts
│       └── serviceControl.ts
├── dist/                 # Build output (gitignored)
├── node_modules/         # Dependencies (gitignored)
├── MCP_SYSTEMCTL_USAGE.md
├── package.json
├── tsconfig.json
└── .gitignore

License

MIT

Available Tools

5 tools
get_service_logsA

Retrieve recent journald log entries for a specific systemd service. Supports configurable line count (up to 5000) and optional priority filtering (emerg, alert, crit, err, warning, notice, info, debug).

ParametersJSON Schema
NameRequiredDescriptionDefault
nameYesService name (e.g. 'sshd', 'cron', 'nginx.service')
linesNoNumber of recent log lines to retrieve (default: 50, max: 5000)
priorityNoFilter logs by minimum priority level

TDQS

A4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries full burden. It mentions retrieval and configurable parameters but lacks detail on side effects, permissions, or output format, though it adequately describes the basic behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences with no wasted words; every part adds value.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple retrieval tool without output schema, the description covers purpose and key parameters, but could hint at return format or journald specifics for full completeness.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so baseline 3. The description restates line count and priority filtering without adding significant new meaning beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states it retrieves journald log entries for a systemd service with a specific verb and resource, distinguishing it from sibling tools like get_service_status or service_control.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage for retrieving logs but does not explicitly state when not to use this tool or compare to alternatives; however, sibling tools are sufficiently different, making context clear.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

get_service_statusA

Get detailed status of a specific systemd service. Returns load state, active state, main PID, memory, CPU, tasks, documentation, and uptime. Accepts service names with or without the .service suffix.

ParametersJSON Schema
NameRequiredDescriptionDefault
nameYesService name (e.g. 'sshd', 'cron', 'nginx.service')

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description must disclose behavioral traits. It correctly indicates a read operation ('Get') and adds a helpful behavioral detail: 'Accepts service names with or without the .service suffix.' This goes beyond the schema. It also lists the return fields, providing transparency on what the output contains. The description does not contradict any annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences: first sentence states purpose and output contents; second adds a usage tip about suffix. Every sentence provides unique value. No fluff or repetition. Front-loaded with key information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's simplicity (one required parameter, no output schema, no nested objects), the description covers the core functionality, parameter behavior, and return fields. It does not mention potential errors or permissions, but for a read-only status check this is acceptable. The description is sufficiently complete for effective use.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with one parameter 'name' described. The description adds meaning beyond the schema by specifying 'Accepts service names with or without the .service suffix,' which is not in the schema description. This helps the agent understand acceptable input formats. Since schema already covers the parameter, the description enriches it.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose: 'Get detailed status of a specific systemd service.' It lists the specific fields returned (load state, active state, PID, memory, CPU, tasks, documentation, uptime), which distinguishes it from sibling tools like get_service_logs (logs), list_services (listing), or service_control (actions). The verb 'Get' and resource 'systemd service' are specific.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage for retrieving status of one service, but does not explicitly state when to use this tool versus siblings (e.g., 'Use this to check a single service's status; for logs use get_service_logs'). No exclusions or prerequisites are provided. The context is clear but guidance is minimal.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

list_failed_servicesA

List all systemd services that are currently in a failed/error state. Returns unit name, load state, active state, sub state, and description for each failed service.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

A4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries full burden. It describes the return fields, but does not explicitly state that it is a read-only operation or disclose any side effects, permissions, or behavioral nuances beyond the basic listing.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two concise sentences that front-load the purpose and include specific return fields. No wasted words.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no parameters and no output schema, the description is fairly complete. It specifies the input (none) and the output fields. Could mention ordering or limitations, but not necessary for basic usage.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Tool has no parameters, so schema coverage is 100%. The description does not need to add parameter info. Baseline 4 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Description clearly states it lists systemd services in a failed/error state and specifies the returned fields (unit name, load state, etc.). It distinguishes from siblings like list_services (all services) and get_service_status (specific service).

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No explicit guidance on when to use this tool versus alternatives. It is implied that this tool is for filtering to failed services, but no when-not conditions or comparisons are provided.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

list_servicesB

List all systemd services. Optionally filter by state (running, exited, failed, inactive, all) and by name glob pattern (e.g. 'ssh*', 'cron*'). Defaults to listing all service units.

ParametersJSON Schema
NameRequiredDescriptionDefault
stateNoFilter by service state (default: all)all
patternNoOptional glob pattern to filter service names (e.g. 'ssh*', 'cron*')
typeNoSystemd unit type to list (default: service)service

TDQS

B3.2/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations exist, so the description carries the full burden. It describes listing and filtering, which implies a read operation with no side effects. However, it lacks disclosure of output format, pagination, or ordering.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is concise, with two sentences that front-load the purpose. However, it could be more precise by acknowledging the type parameter, which slightly reduces efficiency.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a tool with three parameters and no output schema, the description covers filtering basics but fails to mention the type parameter's existence. Sibling tools are not referenced, and the discrepancy between 'services' and the broader unit types may confuse the agent.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, giving a baseline of 3. The description adds examples for pattern ('ssh*', 'cron*') and enumerates state options, but it omits the 'type' parameter entirely, which controls which unit types are listed. This omission reduces clarity for agents.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states the tool lists systemd services and mentions filtering options, but it inaccurately limits to 'services' while the schema includes other unit types (timer, socket, etc.). This is a minor misrepresentation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides context for filtering by state and pattern, but does not differentiate when to use this tool versus siblings (e.g., list_failed_services, get_service_status), nor does it mention that the type parameter allows listing non-service units.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

service_controlA

Control a systemd service: start, stop, restart, reload, enable, or disable. NOTE: Most actions require root/sudo privileges and will return a permission error if unavailable.

ParametersJSON Schema
NameRequiredDescriptionDefault
nameYesService name (e.g. 'sshd', 'cron', 'nginx.service')
actionYesAction to perform on the service

TDQS

A4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description discloses that most actions require root/sudo and may return permission errors. However, with no annotations provided, it does not cover other behavioral traits such as side effects on dependent services, action idempotency, or response format. This is adequate but not exhaustive.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is very concise: two sentences with no extraneous words. The first sentence states purpose and actions; the second adds crucial permission context. Every sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the simple nature of the tool (2 params, no output schema, no annotations), the description covers the main actions and a critical permission note. It does not explain success/failure output or naming conventions, but it is nearly complete for a systemd control tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with both parameters described in the schema. The description does not add new semantic information beyond restating the action enum and the service name concept. Baseline score of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb 'control' and the resource 'systemd service', listing the exact actions (start, stop, restart, etc.). This distinguishes it from sibling monitoring tools like get_service_logs and get_service_status.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description includes a note about root/sudo privileges and permission errors, providing clear context on when the tool can be used. However, it does not explicitly mention when to use this tool versus alternatives like list_services or get_service_status.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 5 tool updatesv1.0.0
    • First observedget_service_logs
    • First observedget_service_status
    • First observedlist_failed_services
    • First observedlist_services
    • First observedservice_control

TDQS

A4/5.0
Disambiguation5/5

Each tool targets a distinct aspect of systemd service management: listing all services, listing failed ones, getting detailed status, retrieving logs, and performing control actions. No overlap in purpose.

Naming Consistency5/5

All tool names follow a consistent verb_noun pattern using snake_case (e.g., get_service_logs, list_services, service_control). The naming is predictable and clear.

Tool Count5/5

5 tools is an appropriate number for managing systemd services. It covers the essential operations without being overly granular or sparse.

Completeness5/5

The set covers all common tasks: listing with filters, checking status, retrieving logs, controlling services (start/stop/enable/disable), and listing failed services. No obvious gaps for typical systemctl usage.

Maintenance

ActivityStale
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    An MCP server for read-only Linux system administration and diagnostics on RHEL-based systems via SSH. It enables users to troubleshoot remote hosts by accessing system information, services, logs, and network configurations through natural language.
    19
    292
    Apache 2.0
  • F
    license
    Not graded
    quality
    D
    maintenance
    An MCP server for managing Ubuntu/Linux systems, enabling AI assistants to execute commands, manage services, files, logs, and packages via local or SSH connection.
    -
  • F
    license
    Not graded
    quality
    D
    maintenance
    MCP server for infrastructure discovery and remote management, enabling SSH command execution, file transfer, log tailing, and machine/service inventory with a companion web dashboard.
    2
    -

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/rileylsmith1997/sample-mcp-systemctl'

If you have feedback or need assistance with the MCP directory API, please join our Discord server