{"_id":"@dinglebear/unraid","_rev":"2-8ae49ee886d4312f6bc493f2c04f4aeb","name":"@dinglebear/unraid","dist-tags":{"latest":"0.3.0"},"versions":{"0.2.5":{"name":"@dinglebear/unraid","version":"0.2.5","keywords":["mcp","mcp-server","model-context-protocol","rmcp","rust","unraid","nas","graphql","storage","docker","virtualization","homelab","cli","claude-code","codex","gemini","automation","oauth"],"author":{"url":"https://dinglebear.ai","name":"dinglebear.ai"},"license":"MIT","_id":"@dinglebear/unraid@0.2.5","maintainers":[{"name":"dinglebear","email":"jmagar@gmail.com"}],"homepage":"https://github.com/dinglebear-ai/unraid#readme","bugs":{"url":"https://github.com/dinglebear-ai/unraid/issues"},"bin":{"runraid":"bin/runraid.js","unraid-rmcp":"bin/runraid.js"},"dist":{"shasum":"ea82cc757b503a5c71b3c5ed39716cf17849bd4a","tarball":"https://registry.npmjs.org/@dinglebear/unraid/-/unraid-0.2.5.tgz","fileCount":8,"integrity":"sha512-CVTTHGDmgSqbpWJr2zIFZwKuT28MHTadoAO2A+d2jnwMQv5rccuDwhi7MnIm99P6ZTpf/JIa2HfRY5tIL/Q9VA==","signatures":[{"sig":"MEUCICGbG82bzIcHC2Jp9tZuZPJVoILmyhOVAPKJkk5uNFDZAiEA1jQmTBrAIzcJZ1wAz9oNIWmpoHyarj5KEL9zXyNpTmU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":48326},"engines":{"node":">=18"},"mcpName":"ai.dinglebear/unraid","scripts":{"test":"node --test","check":"node --check bin/runraid.js && node --check scripts/install.js && node --check lib/platform.js && node --check scripts/sync-readme.js && node --check scripts/check-package.js && node scripts/check-package.js","prepack":"node scripts/sync-readme.js","postinstall":"node scripts/install.js","prepublishOnly":"node scripts/check-package.js --release"},"_npmUser":{"name":"dinglebear","email":"jmagar@gmail.com"},"repository":{"url":"git+https://github.com/dinglebear-ai/unraid.git","type":"git","directory":"unraid-rs/packages/unraid-rmcp"},"_npmVersion":"10.9.8","description":"Rust MCP server and CLI for Unraid GraphQL operations across NAS, Docker, VM, and storage workflows.","directories":{},"_nodeVersion":"22.23.1","binaryVersion":"0.2.5","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/unraid_0.2.5_1785625010385_0.2176031833833072","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@dinglebear/unraid","version":"0.3.0","description":"Rust MCP server and CLI for Unraid GraphQL operations across NAS, Docker, VM, and storage workflows.","license":"MIT","homepage":"https://github.com/dinglebear-ai/unraid#readme","repository":{"type":"git","url":"git+https://github.com/dinglebear-ai/unraid.git","directory":"unraid-rs/packages/unraid-rmcp"},"bugs":{"url":"https://github.com/dinglebear-ai/unraid/issues"},"bin":{"unraid-rmcp":"bin/runraid.js","runraid":"bin/runraid.js"},"scripts":{"prepack":"node scripts/sync-readme.js","postinstall":"node scripts/install.js","test":"node --test","check":"node --check bin/runraid.js && node --check scripts/install.js && node --check lib/platform.js && node --check scripts/sync-readme.js && node --check scripts/check-package.js && node scripts/check-package.js","prepublishOnly":"node scripts/check-package.js --release"},"engines":{"node":">=18"},"keywords":["mcp","mcp-server","model-context-protocol","rmcp","rust","unraid","nas","graphql","storage","docker","virtualization","homelab","cli","claude-code","codex","gemini","automation","oauth"],"mcpName":"ai.dinglebear/unraid","binaryVersion":"0.3.0","author":{"name":"dinglebear.ai","url":"https://dinglebear.ai"},"publishConfig":{"access":"public"},"_id":"@dinglebear/unraid@0.3.0","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-4ZGTZuD0zffydSGNXIU2LaM4HtkAzI9g4m38cXXkNG56ieOW0LAK7T4tx6Q+hE6YXytp4YVt2hxmO5Y6POh0CQ==","shasum":"9d60e85f3ec30fdb13e376c0edf14582f6f09df7","tarball":"https://registry.npmjs.org/@dinglebear/unraid/-/unraid-0.3.0.tgz","fileCount":8,"unpackedSize":48953,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIE9dZsG47LZnyfRUdieR1PJa5BZcYYZE7UsfEzEdS7T2AiEA0bJLlJrWF+kWM6/91uHUnub6Rb7ImLE8Nk3pRLk9ju4="}]},"_npmUser":{"name":"dinglebear","email":"jmagar@gmail.com"},"directories":{},"maintainers":[{"name":"dinglebear","email":"jmagar@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/unraid_0.3.0_1785652446289_0.11694172358159771"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-01T22:56:50.239Z","modified":"2026-08-02T06:34:06.568Z","0.2.5":"2026-08-01T22:56:50.524Z","0.3.0":"2026-08-02T06:34:06.439Z"},"bugs":{"url":"https://github.com/dinglebear-ai/unraid/issues"},"author":{"name":"dinglebear.ai","url":"https://dinglebear.ai"},"license":"MIT","homepage":"https://github.com/dinglebear-ai/unraid#readme","keywords":["mcp","mcp-server","model-context-protocol","rmcp","rust","unraid","nas","graphql","storage","docker","virtualization","homelab","cli","claude-code","codex","gemini","automation","oauth"],"repository":{"type":"git","url":"git+https://github.com/dinglebear-ai/unraid.git","directory":"unraid-rs/packages/unraid-rmcp"},"description":"Rust MCP server and CLI for Unraid GraphQL operations across NAS, Docker, VM, and storage workflows.","maintainers":[{"name":"dinglebear","email":"jmagar@gmail.com"}],"readme":"# unraid-rmcp\n\nRust MCP server and CLI for Unraid GraphQL operations across NAS, Docker, VM, and storage workflows.\n\nIt exposes one MCP tool, `unraid`, plus the `runraid` CLI. Agents can inspect\narray health, disks, Docker containers and logs, VMs, shares, notifications,\nsystem metrics, UPS, logs, network settings, plugins, parity history, rclone,\nremote access, and Unraid Connect through stdio MCP, Streamable HTTP MCP, or\ndirect shell commands.\n\n**30-second path:** install CRGX, set `UNRAID_API_URL` and `UNRAID_API_KEY`,\nthen run `crgx unraid-rmcp -- server --json` -> start loopback HTTP with\n`UNRAID_RMCP_HOST=127.0.0.1 crgx unraid-rmcp -- serve mcp` -> call\n`tools/call` with `{\"action\":\"server\"}`.\n\n**Status:** operational RMCP upstream-client server with the full Unraid GraphQL\nquery and mutation surface. Read actions require `unraid:read`; writes require\n`unraid:admin`. Destructive operations use MCP form elicitation and fail closed\nwhen the client cannot obtain user approval. HTTP MCP supports loopback dev mode,\nstatic bearer tokens, and Google OAuth through `lab-auth`. Release binaries and\nDocker images target linux/amd64 only.\n\n**Not for:** replacing the Unraid web UI, running arbitrary shell commands,\nstoring API keys for callers, multi-tenant isolation, or passing Unraid API keys\nthrough MCP tool arguments.\n\n## Contents\n\n- [Naming](#naming)\n- [Capabilities And Boundaries](#capabilities-and-boundaries)\n- [Install](#install)\n- [Quickstart](#quickstart)\n- [Client Configuration](#client-configuration)\n- [Runtime Surfaces](#runtime-surfaces)\n- [MCP Tool Reference](#mcp-tool-reference)\n- [CLI Reference](#cli-reference)\n- [Configuration](#configuration)\n- [Authentication](#authentication)\n- [Safety And Trust Model](#safety-and-trust-model)\n- [Architecture](#architecture)\n- [Distribution Contract](#distribution-contract)\n- [Development](#development)\n- [Verification](#verification)\n- [Deployment](#deployment)\n- [Troubleshooting](#troubleshooting)\n- [Related Servers](#related-servers)\n- [Documentation](#documentation)\n- [License](#license)\n\n## Naming\n\n| Surface | This repo |\n|---|---|\n| Repository | `unraid` monorepo (`unraid-rs/` component) |\n| Rust crate | `unraid-rmcp` |\n| Binary / CLI | `runraid` |\n| crates.io package | `unraid-rmcp` |\n| CRGX command | `crgx unraid-rmcp -- <runraid args>` |\n| Legacy npm package | `unraid-rmcp` |\n| MCP tool | `unraid` |\n| Config home | `~/.unraid` on hosts, `/data` in containers |\n| Env prefixes | `UNRAID_*`, `UNRAID_RMCP_*` |\n\nThis repo is a small naming exception in the RMCP family: MCP/server variables\nuse `UNRAID_RMCP_*` rather than `UNRAID_MCP_*` for compatibility with the\nexisting deployment config.\n\n## Capabilities And Boundaries\n\n- Read Unraid array state, parity status, disk health, SMART summaries, and\n  capacity.\n- Manage array, Docker, VM, notification, plugin, API-key, rclone, onboarding,\n  settings, remote-access, and Unraid Connect state through GraphQL mutations.\n- Require MCP form elicitation for destructive operations while allowing ordinary\n  writes to proceed after scope authorization.\n- Provide pagination/filtering for MCP list actions and output truncation for\n  large MCP responses.\n- Expose the `server_summary` prompt and `unraid://schema/mcp-tool` schema\n  resource.\n- Provide setup and doctor commands for local plugin/runtime checks.\n\n| This repo owns | Unraid owns | Explicitly out of scope |\n|---|---|---|\n| MCP/CLI projection, GraphQL operation selection, response shaping, pagination, auth policy, elicitation policy, setup checks, and prompt/resource metadata. | NAS state, array/docker/VM behavior, GraphQL schema, Unraid API key issuance, remote access, and Connect state. | Arbitrary shell execution, controller UI replacement, credential brokerage, background monitoring, multi-tenant sandboxing, and direct local filesystem writes. |\n\n## Install\n\n| Path | Command | Best for | Notes |\n|---|---|---|---|\n| CRGX | `crgx unraid-rmcp -- --help` | Local MCP clients and quick trials. | Resolves the crate from crates.io and downloads the matching GitHub Release binary. |\n| Cargo install | `cargo install unraid-rmcp --locked` | Persistent CLI installation. | Builds `runraid` from the crates.io source package. |\n| Release installer | `curl -fsSL https://raw.githubusercontent.com/dinglebear-ai/unraid/main/unraid-rs/scripts/install.sh \\| bash` | Host installs without CRGX. | Installs `runraid` for linux/amd64. |\n| Docker / Compose | `docker compose up -d` | Shared HTTP MCP deployments. | Reads `.env` and exposes container port `40010`. |\n| Build from source | `cargo build --release` | Development and audits. | Produces `target/release/runraid`. |\n| Plugin | `claude plugin install agents/unraid-rs` | Claude Code local plugin setup from this checkout. | Ships the skill and local runtime metadata. No hooks — run `runraid setup plugin-hook` once to provision credentials. |\n\n### CRGX / crates.io\n\nRun the stdio MCP server or CLI without installing Node or compiling Rust:\n\n```bash\ncrgx unraid-rmcp -- --help\ncrgx unraid-rmcp -- mcp\ncrgx unraid-rmcp -- server --json\n```\n\nCRGX resolves `unraid-rmcp` from crates.io, reads its cargo-binstall metadata,\nand downloads the matching `runraid` archive from the component-prefixed GitHub\nRelease. Exact crate versions can be pinned with `unraid-rmcp@<version>`.\n\nThe npm launcher remains available only as a compatibility path for existing\ninstallations; new MCP configurations should use CRGX.\n\n### Build From Source\n\n```bash\ngit clone https://github.com/dinglebear-ai/unraid\ncd unraid-mcp/unraid-rs\ncargo build --release\n./target/release/runraid --help\n```\n\nMinimum supported Rust version: 1.90.\n\n## Quickstart\n\n### 1. Configure Unraid\n\nCreate an Unraid API key in Settings -> API Management, then set:\n\n```bash\nexport UNRAID_API_URL=\"https://10-1-0-2.<hash>.myunraid.net:31337/graphql\"\nexport UNRAID_API_KEY=\"your-api-key-here\"\n```\n\nSet `UNRAID_API_SKIP_TLS_VERIFY=true` only when your Unraid GraphQL endpoint uses\na certificate your host does not trust.\n\n### 2. Run A Safe CLI Call\n\n```bash\ncrgx unraid-rmcp -- server --json\n```\n\n### 3. Start Loopback HTTP MCP\n\n```bash\nUNRAID_RMCP_HOST=127.0.0.1 crgx unraid-rmcp -- serve mcp\n```\n\nIn another shell:\n\n```bash\ncurl -sf http://127.0.0.1:40010/health\n```\n\n### 4. Make A First MCP Call\n\n```bash\ncurl -s -X POST http://127.0.0.1:40010/mcp \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Accept: application/json, text/event-stream\" \\\n  -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"tools/call\",\"params\":{\"name\":\"unraid\",\"arguments\":{\"action\":\"server\"}}}'\n```\n\n## Client Configuration\n\n### Claude Code Stdio\n\n```json\n{\n  \"mcpServers\": {\n    \"unraid\": {\n      \"command\": \"crgx\",\n      \"args\": [\"unraid-rmcp\", \"--\", \"mcp\"],\n      \"env\": {\n        \"UNRAID_API_URL\": \"https://10-1-0-2.<hash>.myunraid.net:31337/graphql\",\n        \"UNRAID_API_KEY\": \"your-api-key-here\"\n      }\n    }\n  }\n}\n```\n\n### Claude Code HTTP\n\n```json\n{\n  \"mcpServers\": {\n    \"unraid\": {\n      \"type\": \"http\",\n      \"url\": \"http://127.0.0.1:40010/mcp\",\n      \"headers\": {\n        \"Authorization\": \"Bearer ${UNRAID_RMCP_TOKEN}\"\n      }\n    }\n  }\n}\n```\n\n### Codex / Labby Gateway\n\nRegister Unraid through Labby as an HTTP upstream when sharing one long-running\nserver, or run it directly as stdio for local-only use.\n\n```toml\n[mcp_servers.unraid]\ncommand = \"crgx\"\nargs = [\"unraid-rmcp\", \"--\", \"mcp\"]\n```\n\n### Generic MCP JSON\n\n```json\n{\n  \"command\": \"runraid\",\n  \"args\": [\"mcp\"],\n  \"env\": {\n    \"UNRAID_API_URL\": \"https://10-1-0-2.<hash>.myunraid.net:31337/graphql\",\n    \"UNRAID_API_KEY\": \"your-api-key-here\"\n  }\n}\n```\n\nDo not put `UNRAID_API_KEY`, OAuth secrets, passwords, SSH keys, or upstream\nbearer tokens in MCP tool arguments. Use env, config files, or the MCP client's\nsecret storage. MCP callers never provide credentials, tokens, keys, or secrets\nas action arguments.\n\n## Runtime Surfaces\n\n| Surface | Status | Entry point | Purpose |\n|---|---:|---|---|\n| MCP stdio | Supported | `runraid mcp`, `crgx unraid-rmcp -- mcp` | Local child-process MCP clients. |\n| MCP HTTP | Supported | `runraid serve mcp`, `POST /mcp` | Streamable HTTP MCP for local or shared server deployments. |\n| CLI | Supported | `runraid <command>` | Scriptable parity and debugging. |\n| Prompt | Supported | `server_summary` | Guides a model to call `info` and summarize server state. |\n| Resource | Supported | `unraid://schema/mcp-tool` | JSON schema for the `unraid` tool. |\n| Health endpoint | Supported | `GET /health` | Unauthenticated liveness check. |\n| REST API | Not shipped | N/A | Unraid owns the GraphQL API. |\n| Web UI | Not shipped | N/A | Unraid owns the web UI. |\n\n## MCP Tool Reference\n\nOne MCP tool is exposed: `unraid`. Pass the required `action` argument to select\nthe operation.\n\n### Core Actions\n\n| Action | Description | Required params | Optional params |\n|---|---|---|---|\n| `array` | Array state, disk health, parity check status, and capacity. | none | none |\n| `disks` | Physical disks with SMART status, temperature, size, interface, and partitions. | none | `limit`, `offset`, `name` |\n| `docker` | Docker containers with state, status, ports, and update availability. | none | `limit`, `offset`, `state`, `name` |\n| `docker_logs` | Container log lines. | `id` | `tail` |\n| `vms` | Virtual machines and state. | none | `limit`, `offset`, `state`, `name` |\n| `server` | Server identity, LAN/WAN IP, local/remote URLs, GUID, and online status. | none | none |\n| `info` | OS, CPU, memory layout, Unraid version, and kernel version. | none | none |\n| `shares` | User shares with size, cache settings, and encryption state. | none | `limit`, `offset`, `name` |\n| `notifications` | Active warnings and alerts with overview counts. | none | none |\n\n### System Actions\n\n| Action | Description |\n|---|---|\n| `services` | Running system services with uptime. |\n| `network` | Network access URLs and addresses. |\n| `metrics` | Live CPU, memory, and temperature sensor data. |\n| `vars` | System configuration variables. |\n| `registration` | License type, state, and expiry. |\n| `flash` | USB flash drive details. |\n\n### Log And Storage Actions\n\n| Action | Description | Required params | Optional params |\n|---|---|---|---|\n| `log_files` | Available log files with sizes and modified times. | none | none |\n| `log_file` | Read a log file. | `path` | `lines`, `start_line` |\n| `parity_history` | Past parity check results. | none | none |\n| `rclone` | Backup remote configurations and drive names. | none | none |\n\n### UPS, Remote, Plugin, And Meta Actions\n\n| Action | Description |\n|---|---|\n| `ups` | UPS devices, charge, runtime, and load. |\n| `ups_config` | UPS monitoring configuration. |\n| `remote_access` | WAN access and port forwarding configuration. |\n| `connect` | Unraid Connect dynamic remote access state. |\n| `plugins` | Installed community plugins with versions. |\n| `status` | Server observability: version, PID, uptime, and counters. |\n| `help` | Markdown reference for all actions. |\n\nPagination and filtering are MCP-only. List actions return a paginated envelope\nwith `items`, `total`, `limit`, `offset`, `has_more`, and `next_offset`.\n\n## CLI Reference\n\nAll CLI commands accept `--json` for machine-readable output.\n\n```bash\nrunraid array [--json]\nrunraid disks [--json]\nrunraid docker [--json]\nrunraid docker logs <id> [--tail N] [--json]\nrunraid vms [--json]\nrunraid server [--json]\nrunraid info [--json]\nrunraid shares [--json]\nrunraid notifications [--json]\nrunraid services [--json]\nrunraid network [--json]\nrunraid metrics [--json]\nrunraid vars [--json]\nrunraid registration [--json]\nrunraid flash [--json]\nrunraid log-files [--json]\nrunraid log <path> [--lines N] [--start-line N] [--json]\nrunraid parity-history [--json]\nrunraid rclone [--json]\nrunraid ups [--json]\nrunraid ups-config [--json]\nrunraid remote-access [--json]\nrunraid connect [--json]\nrunraid plugins [--json]\nrunraid doctor [--json]\nrunraid setup check [--json]\nrunraid setup repair [--json]\n```\n\n`status` is MCP-only; `setup` and `doctor` are CLI-only.\n\n## Configuration\n\nHost installs read `~/.unraid/.env` before loading config. Containers read\n`/data/.env`. Process environment overrides both.\n\n| Variable | Default | Purpose |\n|---|---|---|\n| `UNRAID_API_URL` | unset | Full Unraid GraphQL endpoint URL. |\n| `UNRAID_API_KEY` | unset | API key for the `x-api-key` header. |\n| `UNRAID_API_SKIP_TLS_VERIFY` | `false` | Skip TLS certificate verification for self-signed endpoints. |\n| `UNRAID_RMCP_HOST` | `0.0.0.0` | HTTP bind host. |\n| `UNRAID_RMCP_PORT` | `40010` | HTTP bind port. |\n| `UNRAID_RMCP_SERVER_NAME` | `unraid-rmcp` | Advertised MCP server name. |\n| `UNRAID_RMCP_TOKEN` | unset | Static bearer token for HTTP MCP. |\n| `UNRAID_RMCP_NO_AUTH` | `false` | Disable auth only for loopback development. |\n| `UNRAID_RMCP_DISABLE_HTTP_AUTH` | `false` | Compatibility alias for disabling auth. |\n| `UNRAID_NOAUTH` | `false` | Trust an upstream gateway to enforce auth. |\n| `UNRAID_RMCP_ALLOWED_HOSTS` | unset | Extra accepted Host header values. |\n| `UNRAID_RMCP_ALLOWED_ORIGINS` | unset | Extra accepted CORS origins. |\n| `UNRAID_RMCP_PUBLIC_URL` | unset | Public URL for OAuth metadata. |\n| `UNRAID_RMCP_AUTH_MODE` | `bearer` | `bearer` or `oauth`. |\n| `UNRAID_RMCP_GOOGLE_CLIENT_ID` | unset | Google OAuth client ID. |\n| `UNRAID_RMCP_GOOGLE_CLIENT_SECRET` | unset | Google OAuth client secret. |\n| `UNRAID_RMCP_AUTH_ADMIN_EMAIL` | unset | Admin email for OAuth bootstrap. |\n\n## Authentication\n\nStdio MCP runs as a local trusted child process and does not use HTTP auth.\n\nHTTP MCP auth policy:\n\n| State | Condition | Behavior |\n|---|---|---|\n| Loopback dev | `UNRAID_RMCP_HOST` starts with `127.` or auth is explicitly disabled on loopback | Local unauthenticated development is allowed. |\n| Mounted bearer | Non-loopback with `UNRAID_RMCP_TOKEN` | Requires `Authorization: Bearer <token>` and action scopes. |\n| Mounted OAuth | `UNRAID_RMCP_AUTH_MODE=oauth` | Uses Google OAuth/JWT through `lab-auth`. |\n| Trusted gateway | `UNRAID_NOAUTH=true` | Assumes a reverse proxy or gateway already enforced auth. |\n\nRead actions require `unraid:read`; mutating actions require `unraid:admin`.\nConfigured static bearer tokens are operator credentials and receive admin scope.\nOAuth clients receive the scopes granted by the authorization flow.\n\n## Safety And Trust Model\n\n- Unraid API keys are loaded from config/env only.\n- MCP callers select actions and arguments, not upstream credentials.\n- Destructive actions issue an MCP form-elicitation request before dispatch. A\n  decline, cancellation, malformed response, or client without elicitation support\n  stops the operation before the GraphQL request is sent.\n- Ordinary mutations remain directly available after `unraid:admin` authorization;\n  the server does not add a second confirmation parameter or disable writes.\n- `log_file` reads through the Unraid GraphQL API, not arbitrary local files.\n- Non-loopback HTTP deployments must use bearer auth, OAuth, or a trusted\n  authenticated gateway.\n- This bridge does not sandbox Unraid itself. Unraid remains responsible for API\n  permissions and GraphQL response semantics.\n\n## Architecture\n\n```text\nGraphQL operations (src/graphql.rs)  queries + mutations\n        |\nUnraidService (src/app.rs)           action behavior and response shaping\n        |\nMCP scope + elicitation              authorization and destructive approval\n        |\nMCP shim      (src/mcp/tools.rs)     JSON args -> service -> Value\nCLI shim      (src/cli.rs)           argv -> service -> stdout\n```\n\n## Distribution Contract\n\n- `Cargo.toml`, `Cargo.lock`, both `version` and `binaryVersion` in\n  `packages/unraid-rmcp/package.json`, `.release-please-manifest.json`, agent\n  manifests, and `server.json` must agree on the released version.\n- crates.io publishes `lab-auth` first and `unraid-rmcp` second through\n  `.github/workflows/crates-publish.yml`; automatic publication stays disabled\n  until `CRATES_IO_PUBLISHING_ENABLED=true` and the `crates-io` environment holds\n  `CARGO_REGISTRY_TOKEN`.\n- GitHub Releases publish the linux/amd64 `runraid` archive consumed by CRGX and\n  cargo-binstall through the manifest metadata in `Cargo.toml`.\n- The npm package remains a compatibility surface only. Automatic npm publishing\n  is enabled only when `NPM_TRUSTED_PUBLISHING_ENABLED=true`.\n- Docker/OCI metadata uses `ghcr.io/dinglebear-ai/unraid-rmcp:<version>`.\n- `agents/unraid-rs/.mcp.json` must launch `crgx unraid-rmcp -- mcp` so stdio\n  clients resolve the crates.io package without requiring Node.\n- The root README is curated. `docs/INVENTORY.md` is the curated inventory for\n  actions, CLI commands, env vars, HTTP endpoints, and dependencies.\n\n## Development\n\n```bash\ncargo fmt --check\ncargo test\ncargo clippy -- -D warnings\ncargo build --release\nnpm --prefix packages/unraid-rmcp run check\n```\n\n## Verification\n\n```bash\npython3 /home/jmagar/workspace/soma/scripts/check-readme-guide.py README.md\nnpm --prefix packages/unraid-rmcp run check\ncargo check\ncargo test\ngit diff --check\n```\n\nRuntime smoke:\n\n```bash\nUNRAID_API_URL=https://10-1-0-2.<hash>.myunraid.net:31337/graphql \\\nUNRAID_API_KEY=... \\\nrunraid server --json\n```\n\nHTTP smoke:\n\n```bash\nUNRAID_RMCP_HOST=127.0.0.1 runraid serve mcp\ncurl -sf http://127.0.0.1:40010/health\n```\n\n## Deployment\n\nUse loopback for local development:\n\n```bash\nUNRAID_RMCP_HOST=127.0.0.1 runraid serve mcp\n```\n\nUse Docker Compose for shared HTTP deployment:\n\n```bash\ncp .env.example .env\ndocker compose up -d\n```\n\nWhen binding to a non-loopback address, configure `UNRAID_RMCP_TOKEN`,\n`UNRAID_RMCP_AUTH_MODE=oauth`, or `UNRAID_NOAUTH=true` behind an authenticated\ngateway.\n\n## Troubleshooting\n\n| Symptom | Check |\n|---|---|\n| `UNRAID_API_URL` or `UNRAID_API_KEY` is missing | Set it in env or `~/.unraid/.env`. |\n| TLS errors against Unraid | Set `UNRAID_API_SKIP_TLS_VERIFY=true` only for self-signed endpoints. |\n| HTTP `/mcp` returns unauthorized | Set `UNRAID_RMCP_TOKEN` and send `Authorization: Bearer <token>`. |\n| Stdio client hangs or logs JSON errors | Ensure client config runs `unraid-rmcp mcp`, not the default HTTP server mode. |\n| Large list response is truncated | Use `limit`, `offset`, `name`, or `state` filters on MCP list actions. |\n| `docker_logs` fails | Pass a valid container `id` and optional `tail`. |\n\n## Related Servers\n\n- [soma](https://github.com/jmagar/soma) - RMCP runtime for provider-backed MCP servers.\n- [unifi-rmcp](https://github.com/jmagar/runifi) - UniFi controller REST API bridge.\n- [tailscale-rmcp](https://github.com/jmagar/rtailscale) - Tailscale API bridge for devices, users, and tailnet operations.\n- [apprise-rmcp](https://github.com/jmagar/rapprise) - Apprise notification fan-out bridge for many delivery backends.\n- [gotify-rmcp](https://github.com/jmagar/rgotify) - Gotify push notification bridge for sends, messages, apps, and clients.\n- [arcane-rmcp](https://github.com/jmagar/rarcane) - Arcane Docker management bridge for containers and related resources.\n- [yarr](https://github.com/jmagar/yarr) - Media-stack bridge for Sonarr, Radarr, Prowlarr, Plex, and related services.\n- [ytdl-rmcp](https://github.com/jmagar/rytdl) - Media download and metadata workflow server.\n- [synapse-rmcp](https://github.com/jmagar/synapse) - Local Synapse workflow server for scout and flux actions.\n- [cortex](https://github.com/jmagar/cortex) - Syslog and homelab log aggregation MCP server.\n- [axon](https://github.com/jmagar/axon) - RAG, crawl, scrape, extract, and semantic search project.\n- [labby](https://github.com/jmagar/labby) - Homelab control plane and MCP gateway project.\n- [lumen](https://github.com/jmagar/lumen) - Local semantic code search MCP server.\n\n## Documentation\n\n- `CLAUDE.md` is the curated local operating guide for contributors and agents.\n- `docs/INVENTORY.md` is the curated/generated inventory for actions, CLI\n  commands, env vars, HTTP endpoints, and dependencies.\n- `docs/stack/ARCH.md` is the curated architecture guide.\n- `agents/unraid-rs/skills/unraid/SKILL.md` is the agent usage guide.\n- `src/` is the source of truth for current GraphQL queries, config defaults,\n  auth behavior, and CLI parsing.\n\n## License\n\nMIT. See [LICENSE](LICENSE).\n","readmeFilename":"README.md"}