
Opencode Workbench
io.github.simonmak-ascentv2.0.0Updated Oct 2, 2026
Provision an OpenCode workbench and MCP stack on any Linux box, local or over SSH.
Overview
An MCP server that inspects a Linux machine and clones a preconfigured OpenCode development workbench onto it, locally or over SSH.
- What it does
- It provisions a full OpenCode workstation profile onto a Linux box, either the local machine or a remote host reached over SSH. The workflow runs in stages: inspect_target, plan_clone, apply_clone and verify_clone. apply_clone is consent-gated, so without confirm:true it only returns a plan listing components and a preview of privileged commands. A list_required_credentials tool reports which keys the target still needs, and the clone is key-resilient: with no model key it still boots on a free tier, and MCP servers whose credentials are missing are disabled and reported.
- When to use it
- Use it when you want to reproduce a documented OpenCode development environment on another Linux machine, or rebuild one after losing a build box, without repeating manual setup. It suits users who already keep this workbench repository as their configuration source of truth and want the runtime to match it.
- Requirements
- A Linux target, local or reachable over SSH with a user and host. The server runs as a local stdio process via npx from the npm package, or as a remote endpoint. No authentication is declared. Credentials for the cloned stack are supplied separately by the user; the connector writes an empty environment template rather than reading or transmitting secret values.
Installation
In SourceWeft
- Open Opencode Workbench in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"opencode-workbench": {
"type": "http",
"url": "https://opencode-workbench.simonmak.com/mcp"
}
}
}README
OpenCode Workbench
[Secret Scan] [License: MIT] [MCP Server] [Validate Documentation] [MCP Tool Definition Quality]
A reproducible, self-documenting, and recoverable OpenCode development workstation — configuration, agent skills, MCP stack, and an MCP server that clones the entire setup onto any Linux machine (locally or over SSH).
Purpose
This repository is the single source of truth for a complete cloud development workstation. Everything needed to rebuild from scratch is versioned here:
- Workstation configuration and automation
- OpenCode configuration (model, providers, MCP servers)
- Agent skills (45 reusable AI instructions across research, dev, data, science and ops)
- Operational prompts (disaster recovery, backup, security)
- Recovery procedures (playbook, checklist, gap analysis)
- Security governance (secret management, threat model)
opencode-workbench— an MCP server that installs this profile on any Linux box
No important knowledge exists only in human memory.
Clone This Workbench to Another Linux Machine
Register the MCP server with OpenCode:
Then ask the agent to run inspect_target → plan_clone → apply_clone { confirm: true } → verify_clone, for { "mode": "local" } or { "mode": "ssh", "host": "<your-box>", "user": "<your-user>" }. apply_clone is consent-gated: without confirm:true it returns a plan (components + privileged-command preview) and changes nothing. Run list_required_credentials to see which keys the box still needs and how to acquire them, and bash scripts/selftest/run-selftest.sh to verify it works. See mcp-server/README.md and docs/architecture/clone-mcp.md.
The clone is key-resilient: with no model key it still boots on the OpenCode Zen free floor, and MCP servers whose credentials are absent are disabled and reported (not left to fail at runtime).
The connector never reads or transmits secret values; it writes an empty ~/.env.workbench template for you to fill in.
Quick Start
Architecture
What's Inside
Workstation Governance
This workstation operates under a formal charter. Key principles:
- Single Source of Truth: Runtime must match repository. Drift is a bug.
- Secrets Never Touch Disk: All secrets flow through the build box Secrets.
- Immutable History: Changelog is append-only. Every change is traceable.
- Documentation Lives With Code: Docs describe the system as it is, not as imagined.
Read the full charter: docs/WORKBENCH_CHARTER.md
Backup Workflow
Or use OpenCode prompts:
docs/prompts/RUN_MASTER_BACKUP.md— execute backup via AIdocs/prompts/QUICK_BACKUP.md— rapid state preservation
Recovery Workflow
Assume the build box is deleted. Only Git repo + build box Secrets survive.
Full details: docs/recovery/RECOVERY_PLAYBOOK.md
MCP Architecture
Totals: 35 configured (33 enabled, 2 disabled: google-search, google-workspace).
See: docs/architecture/mcp-inventory.md
Secrets Management
All secrets stored in the build box Secrets. Never in repository files.
Additional keys for opt-in servers (EXA_API_KEY, CLOUDFLARE_API_TOKEN,
STRIPE_SECRET_KEY, SURREAL_*, ALIBABA_CLOUD_*, AZURE_*, FIRECRAWL_API_KEY,
FRED_API_KEY, COMPANIES_HOUSE_API_KEY) are catalogued in
docs/architecture/secrets.md — never by value.
See: docs/architecture/secrets.md
Documentation Index
Adding to the Workbench
- MCP Server: Add npm package to
.devcontainer/setup.sh, add toopencode.json, document indocs/architecture/mcp-inventory.md - Agent Skill: Create
.opencode/skills/<name>/SKILL.md, follow naming convention - Tool: Add to
scripts/bootstrap-tools.sh - Prompt: Create in
docs/prompts/, updateprompt-index.md - After any change: Update
CHANGELOG_WORKBENCH.md, run master backup
Recovery Score: 94/100
Validated disaster recovery within < 10 minutes using repository + build box Secrets alone.
Use with Context7
Up-to-date OpenCode Workbench documentation is indexed on Context7, so coding agents can pull it into context on demand. With the Context7 MCP server or ctx7 CLI installed, name the library in your prompt:
License
MIT — see LICENSE.
A tool by Simon Mak.
If this saves you time, a ⭐ on GitHub helps others find it.
Source: README.md at commit 091e373
Tools
0Version history
1- v2.0.0LatestOct 2, 2026

