
Opencode Workbench
io.github.simonmak-ascentv2.0.0更新于 Oct 2, 2026
Provision an OpenCode workbench and MCP stack on any Linux box, local or over SSH.
概览
一个 MCP 服务器,可检查 Linux 机器并在本地或通过 SSH 将预配置的 OpenCode 开发工作台克隆到该机器上。
- 功能
- 它把完整的 OpenCode 工作站配置部署到 Linux 机器上,目标可以是本机,也可以是通过 SSH 访问的远程主机。流程分阶段进行:inspect_target、plan_clone、apply_clone 和 verify_clone。apply_clone 需要确认,未提供 confirm:true 时只返回计划,列出组件和特权命令预览。list_required_credentials 工具会报告目标机器还缺哪些密钥;克隆对密钥缺失有容错:没有模型密钥时仍可在免费层启动,凭据缺失的 MCP 服务器会被禁用并报告。
- 适用场景
- 当你需要在另一台 Linux 机器上复现一套有文档记录的 OpenCode 开发环境,或在构建机丢失后重建环境、又不想重复手工配置时使用。它适合已将该工作台仓库作为配置唯一来源、并希望运行时与之一致的用户。
- 运行要求
- 需要一个 Linux 目标机,可以是本机,或可通过 SSH 访问的主机(需提供主机与用户)。服务器以本地 stdio 进程方式通过 npx 运行该 npm 包,也可作为远程端点使用。未声明身份验证。克隆出的环境所需凭据由用户另行提供;连接器只写入一个空的环境变量模板,不读取也不传输密钥值。
安装
在 SourceWeft 中
- 打开 控制台中的 Opencode Workbench,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"opencode-workbench": {
"type": "http",
"url": "https://opencode-workbench.simonmak.com/mcp"
}
}
}README
OpenCode Workbench
[Secret Scan] [License: MIT] [MCP Server] [Validate Documentation] [MCP Tool Definition Quality]
A reproducible, self-documenting, and recoverable OpenCode development workstation — configuration, agent skills, MCP stack, and an MCP server that clones the entire setup onto any Linux machine (locally or over SSH).
Purpose
This repository is the single source of truth for a complete cloud development workstation. Everything needed to rebuild from scratch is versioned here:
- Workstation configuration and automation
- OpenCode configuration (model, providers, MCP servers)
- Agent skills (45 reusable AI instructions across research, dev, data, science and ops)
- Operational prompts (disaster recovery, backup, security)
- Recovery procedures (playbook, checklist, gap analysis)
- Security governance (secret management, threat model)
opencode-workbench— an MCP server that installs this profile on any Linux box
No important knowledge exists only in human memory.
Clone This Workbench to Another Linux Machine
Register the MCP server with OpenCode:
Then ask the agent to run inspect_target → plan_clone → apply_clone { confirm: true } → verify_clone, for { "mode": "local" } or { "mode": "ssh", "host": "<your-box>", "user": "<your-user>" }. apply_clone is consent-gated: without confirm:true it returns a plan (components + privileged-command preview) and changes nothing. Run list_required_credentials to see which keys the box still needs and how to acquire them, and bash scripts/selftest/run-selftest.sh to verify it works. See mcp-server/README.md and docs/architecture/clone-mcp.md.
The clone is key-resilient: with no model key it still boots on the OpenCode Zen free floor, and MCP servers whose credentials are absent are disabled and reported (not left to fail at runtime).
The connector never reads or transmits secret values; it writes an empty ~/.env.workbench template for you to fill in.
Quick Start
Architecture
What's Inside
Workstation Governance
This workstation operates under a formal charter. Key principles:
- Single Source of Truth: Runtime must match repository. Drift is a bug.
- Secrets Never Touch Disk: All secrets flow through the build box Secrets.
- Immutable History: Changelog is append-only. Every change is traceable.
- Documentation Lives With Code: Docs describe the system as it is, not as imagined.
Read the full charter: docs/WORKBENCH_CHARTER.md
Backup Workflow
Or use OpenCode prompts:
docs/prompts/RUN_MASTER_BACKUP.md— execute backup via AIdocs/prompts/QUICK_BACKUP.md— rapid state preservation
Recovery Workflow
Assume the build box is deleted. Only Git repo + build box Secrets survive.
Full details: docs/recovery/RECOVERY_PLAYBOOK.md
MCP Architecture
Totals: 35 configured (33 enabled, 2 disabled: google-search, google-workspace).
See: docs/architecture/mcp-inventory.md
Secrets Management
All secrets stored in the build box Secrets. Never in repository files.
Additional keys for opt-in servers (EXA_API_KEY, CLOUDFLARE_API_TOKEN,
STRIPE_SECRET_KEY, SURREAL_*, ALIBABA_CLOUD_*, AZURE_*, FIRECRAWL_API_KEY,
FRED_API_KEY, COMPANIES_HOUSE_API_KEY) are catalogued in
docs/architecture/secrets.md — never by value.
See: docs/architecture/secrets.md
Documentation Index
Adding to the Workbench
- MCP Server: Add npm package to
.devcontainer/setup.sh, add toopencode.json, document indocs/architecture/mcp-inventory.md - Agent Skill: Create
.opencode/skills/<name>/SKILL.md, follow naming convention - Tool: Add to
scripts/bootstrap-tools.sh - Prompt: Create in
docs/prompts/, updateprompt-index.md - After any change: Update
CHANGELOG_WORKBENCH.md, run master backup
Recovery Score: 94/100
Validated disaster recovery within < 10 minutes using repository + build box Secrets alone.
Use with Context7
Up-to-date OpenCode Workbench documentation is indexed on Context7, so coding agents can pull it into context on demand. With the Context7 MCP server or ctx7 CLI installed, name the library in your prompt:
License
MIT — see LICENSE.
A tool by Simon Mak.
If this saves you time, a ⭐ on GitHub helps others find it.
来源:README.md,提交 091e373
工具
0版本历史
1- v2.0.0最新Oct 2, 2026


