
kapaweb deploy
io.github.kapawebv0.7.0更新于 Oct 9, 2026
Deploy websites, PHP apps and WordPress to kapaweb DirectAdmin hosting without sharing your password
概览
让助手把网站、PHP 应用和 WordPress 部署到 kapaweb DirectAdmin 主机,并管理其文件、数据库和设置。
- 功能
- 这是一个本地连接器,与用户自己的 kapaweb DirectAdmin 主机面板通信。工具涵盖部署(会先自动备份)、回滚、列出文件、读取和写入文件、创建、导入和导出数据库、PHP 版本与设置、SSL 状态、定时任务、子域名、网址检查、日志、用量和账户信息。connect 工具会在本机打开登录页面,让主机密码在用户电脑上输入而不是在对话中,并换取受限的 DirectAdmin 登录密钥。
- 适用场景
- 适合在 kapaweb DirectAdmin 上托管网站或 PHP 应用的人,希望助手通过对话完成推送改动、查看文件、执行数据库导入导出,或调整 PHP、SSL 和定时任务设置,而不必进入控制面板。
- 运行要求
- 一个位于 DirectAdmin 服务器上的 kapaweb 主机账户。同一台电脑上需安装 Node.js 18.17 或更高版本。需要能启动本地 MCP 服务器的 Claude 环境,例如 Claude Code 或在本机运行的 Cowork 会话;网页版 Claude 对话无法启动,需改用桌面扩展。需要能访问用户自己的面板以及 kapaweb.gr 和 firewall.kapaweb.gr。
安装
在 SourceWeft 中
- 打开 控制台中的 kapaweb deploy,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
kapaweb deploy
Deploy websites, PHP apps and WordPress to kapaweb DirectAdmin hosting from a conversation with Claude, without your hosting password ever entering the chat. The plugin bundles the kapaweb connector, a local MCP server that runs on your computer, and a skill that tells Claude how to use it safely.
Requirements
- A hosting account at kapaweb (https://kapaweb.gr) on a DirectAdmin server.
- Node.js 18.17 or newer on the computer that runs Claude. The connector has no dependencies and nothing to build.
- A Claude surface that starts local MCP servers: Claude Code, or Cowork sessions that run on your computer. Claude chat on the web does not start local servers, so use the Claude Desktop extension from https://kapaweb.gr/deploy-with-ai/ there.
Use it
Ask Claude to deploy a project to kapaweb. The skill makes Claude read the public playbook (https://kapaweb.gr/deploy-with-ai/playbook.md), check that the connector is current, and call connect. connect opens a sign-in page on your own computer (http://127.0.0.1, random port and token): you type your DirectAdmin address, username and password there, never in the chat. The connector exchanges the password for a restricted DirectAdmin login key, forgets the password, and keeps only the key in your computer's protected storage (Windows DPAPI, macOS Keychain, Linux secret-tool).
Tools: deploy (always makes a backup first), rollback, list_files, read_file, write_file, db_create, db_import, db_export (streamed, any size, saved on your computer), php_versions, set_php_version, php_settings, ssl_status, cron_*, subdomain_*, check_url, logs, usage, account_info, playbook, connect, disconnect. Read-only tools are annotated readOnlyHint, destructive ones destructiveHint.
What it runs, stores and sends
- Runs
node server/index.jsfrom this plugin, on your computer, over stdio. On macOS it callssecurity(Keychain), on Linuxsecret-tool, on Windows PowerShell DPAPI, to store and read its own login key; it opens your browser on the local sign-in page. - Sends requests only to: your own kapaweb DirectAdmin panel (the address you typed; it is checked against kapaweb's own server list before every connection);
https://firewall.kapaweb.gr/servers.txt(that list of kapaweb server addresses);https://kapaweb.gr/deploy-with-ai/playbook.md(the playbook);https://kapaweb.gr/downloads/kapaweb-connector.version.json(a version check at most once a day, nothing is sent but the User-Agentkapaweb-connector/<version>;KAPAWEB_CONNECTOR_NO_UPDATE_CHECK=1turns it off); and, only when you ask for it withcheck_url, the domains of your own hosting account (plus a short fixed list of sites that kapaweb itself maintains). - Stores on your computer: the saved connection (panel address, user name, key id; no password), the login key and generated database passwords in the protected storage, and database exports you ask for in the connector's settings folder. Nothing is sent to kapaweb for analytics, and nothing about you is collected by this plugin.
- Never shows Claude your password, the login key or generated database passwords.
Privacy policy
Kapaweb (https://kapaweb.gr, [email protected]) provides this plugin.
- What we collect: nothing. The plugin has no accounts, no analytics and no telemetry on our side.
- What stays on your computer: the address, user name and key id of your hosting panel; a restricted DirectAdmin login key and generated database passwords (in your operating system's protected storage); and the database exports you ask for. Your hosting password is used once, to create the key, and is then forgotten. All of this stays until you delete it:
disconnect, or remove the key in DirectAdmin under Login Keys. The key expires (30 days by default; you can choose 90 days, a year, or never) and can be revoked at any time. - Where data goes: to your own hosting panel (the files, databases, settings and logs of your account, as far as you ask Claude to work on them). The requests to kapaweb.gr and firewall.kapaweb.gr listed above carry no personal data except the usual network data (your IP address, the time, the file requested and the User-Agent
kapaweb-connector/<version>), which kapaweb's web server records in its normal access log. What the tools return (file listings, logs, command results) is given to Claude, the AI app you use, and is covered by that app's own terms and privacy policy. - Third parties: we share nothing with anyone. No advertising, no sale of data.
- Retention: local data stays until you remove it (see above); kapaweb's web server logs follow kapaweb's normal log retention.
- Children: this is a business tool and is not intended for people under 18.
- Contact: [email protected].
Notes for reviewers
The directory scan holds this plugin for review because its heuristics see "a credential" near "a remote host". What each finding points at (all checked in the source):
server/da.js:ssd5.kdns.grappears only in a code comment (the example shape of a panel address). The panel address the user typed is checked against kapaweb's own server list (verifyPanelHost) and the connection is pinned to the verified IP address before the login key is ever sent.server/setup.js:${h}is a JavaScript template literal in the Origin check of the local sign-in page (http://127.0.0.1:<random port>); it is not a host and no secret is sent to it.server/tools.js:kapaweb.gris a comment and the public playbook URL. That request carries only the headerUser-Agent: kapaweb-connector(no key, no password).server/clients.js: this file builds help text for the user and mentions the path~/.claude.jsoninside that text. It reads no file and sends nothing.
The only credential the plugin handles is the restricted DirectAdmin login key of the user's own hosting account. It is created from a password typed once on the local sign-in page, kept in the operating system's protected storage, and sent only to that user's own verified kapaweb panel. The plugin does not read any other credential, environment token or file from the user's computer.
License
MIT. See the LICENSE file.
来源:README.md,提交 e67cd67
工具
0版本历史
1- v0.7.0最新Oct 9, 2026

