
Seristack
io.github.TechXploreLabsv0.4.6Updated Oct 1, 2026
Run YAML-defined shell command stacks as MCP tools
Installation
In SourceWeft
- Open Seristack in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
Seristack
[Go Reference] [Go Version] [License] [Release]
One YAML configuration. CLI commands, HTTP endpoints, and MCP tools.
Seristack is a lightweight automation engine for DevOps, Platform, SRE, and Cloud teams.
Define shell-based workflows in YAML, manage dependencies and variables, execute them locally or through HTTP, and expose selected stacks as MCP tools for AI agents and IDE integrations.
Why Seristack?
Operational workflows often live as shell scripts, runbooks, CI jobs, and undocumented procedures.
Seristack provides a single configuration layer for turning those workflows into reusable execution stacks that can be:
- Run from the CLI
- Exposed as HTTP endpoints
- Exposed as MCP tools
- Protected with per-stack authorization
- Audited with structured JSON logs
- Composed using dependencies and shared results
Documentation
Features
- π Run multiple command stacks from a single YAML configuration
- π Execute stacks sequentially or concurrently
- π’ Repeat stack execution with configurable counts
- π Define dependencies between stacks
- π§© Variable substitution with validation rules
- π¦ Share output and results between dependent stacks
- π Expose stacks as HTTP endpoints
- π Per-stack authorization using identity headers
- π Structured JSON audit logging
- π§ Run as an MCP server for AI agents and IDE integrations
- π Support for mvdan shell, Bash, sh, and PowerShell
- β± Per-stack execution timeouts
- π Configurable working directories
- π‘ Allow and deny rules for stack variables
Installation
Homebrew β macOS and Linux
Linux β installer
Linux β release archive
- Go to Seristack Releases.
- Download the latest:
For example:
- Extract the archive:
- Install the binary:
- Verify:
Windows β installer
Run PowerShell as a user with permission to install the binary:
Windows β release archive
- Go to Seristack Releases.
- Download the Windows release archive:
For example:
-
Extract the archive with a tool that supports
.tar.gz. -
Place
seristack.exein a directory included in your%PATH%. -
Verify:
Configuration
Seristack uses YAML to define execution stacks.
For a complete description of all configuration fields, see the Configuration Reference.
Example
Running stacks
Trigger all stacks
Trigger a specific stack
Start the HTTP server
Start the MCP server
HTTP server
The HTTP server exposes configured stacks as HTTP endpoints.
For example:
Start the server:
A reverse proxy such as nginx or Caddy can expose the service externally while Seristack remains bound to localhost.
Production deployment
Seristack executes shell commands and should not be exposed directly to the public internet.
A recommended architecture is:
Start Seristack on localhost:
For a remote MCP deployment, the same pattern can be used:
Authentication should be handled by the identity-aware proxy or gateway, while Seristack performs authorization at the individual stack level.
Per-stack authorization
Seristack can restrict individual stacks using identity headers forwarded by an authenticated reverse proxy.
For example:
Access matching
matchAccess controls how multiple access rules are evaluated.
ANY
Access is granted when at least one access rule matches.
This is OR logic.
ALL
Access is granted only when every access rule matches.
This is AND logic.
No access rules
If a stack does not define an access block, there is no stack-level access restriction.
The authentication layer should still protect the service itself in production.
Identity headers
The actual headers depend on the authentication provider and reverse proxy.
The headers must be configured and trusted only when they originate from your authenticated proxy.
Do not allow untrusted external clients to directly supply authorization headers.
Audit logging
Seristack can write a structured JSON audit log for stack executions.
Enable audit logging:
Audit entries include information such as:
- Timestamp
- Event
- Stack name
- HTTP path and method
- Source IP when available
- Identity headers
- Variables
- Success/failure
- Execution duration
- Output
- Error information
Example:
Use logrotate or an equivalent logging system to manage log rotation.
Do not put secrets in stack variables
Variables may be included in audit records.
Avoid passing passwords, tokens, API keys, or other secrets as stack variables.
Prefer:
- Environment variables
- Secret managers
- Workload identity
- External credential providers
MCP server
Seristack can expose configured stacks as MCP tools.
Start a Streamable HTTP MCP server:
Stacks with a description can be exposed as MCP tools.
AI agents and MCP-compatible IDEs can then discover and invoke the available stacks.
A production deployment should place the MCP server behind HTTPS and an authentication layer:
Variable validation
Variables can define validation and authorization rules.
Only variables declared in vars can be overridden by HTTP requests or MCP arguments.
Undeclared variables supplied through external inputs are ignored.
Validation rules can include:
requiredallowed_valuedenied_valueallowed_regexdenied_regex
Dependencies
Stacks can depend on other stacks:
Seristack resolves the dependency order before execution.
This allows larger workflows to be composed from smaller reusable stacks.
Execution modes
Stacks can be configured to execute sequentially or concurrently.
Sequential
Commands or repeated executions run in sequence.
Parallel
Independent executions can run concurrently.
Example:
Command execution
Seristack supports shell-based execution using the configured shell execution mechanisms.
Examples include:
Multi-line commands:
The configured execution environment determines which shell syntax is available.
Testing
Run the complete test suite:
To force tests to execute without using Go's test cache:
For verbose output and individual test execution times:
Run tests for a specific package:
Run the race detector:
The race detector requires a working C compiler/toolchain on supported platforms.
seristack run command reference
Run:
for the current command and flag reference.
Security considerations
Seristack executes commands on the host where it runs.
Before deploying it in a production environment:
- Keep Seristack bound to localhost or a private network.
- Put an authenticated reverse proxy or gateway in front of externally accessible endpoints.
- Use HTTPS/TLS for remote access.
- Do not trust identity headers supplied directly by clients.
- Restrict which users or groups can execute sensitive stacks.
- Avoid putting secrets into stack variables.
- Review and rotate audit logs.
- Run Seristack with the minimum operating-system privileges required.
- Restrict filesystem and network permissions where possible.
- Review shell commands carefully before exposing them through HTTP or MCP.
MCP access should be treated with the same security considerations as an HTTP API because MCP clients can invoke the tools exposed by the server.
Support the project
If Seristack helps your team turn shell scripts or operational runbooks into reusable CLI commands, HTTP APIs, or MCP tools, consider:
- β Starring the repository
- π Opening issues
- π‘ Sharing feedback
- π§ͺ Adding examples and tests
- π§ Contributing improvements
License
Apache License 2.0
Source: README.md at commit 95009dd
Tools
0Version history
1- v0.4.6LatestOct 1, 2026


