kapaweb deploy

io.github.kapawebv0.7.0更新於 Oct 9, 2026

Deploy websites, PHP apps and WordPress to kapaweb DirectAdmin hosting without sharing your password

概覽

AI 產生的概覽

讓助理把網站、PHP 應用程式和 WordPress 部署到 kapaweb DirectAdmin 主機,並管理其檔案、資料庫與設定。

功能
這是一個本機連接器,與使用者自己的 kapaweb DirectAdmin 主機面板通訊。工具涵蓋部署(會先自動備份)、回復、列出檔案、讀取與寫入檔案、建立、匯入與匯出資料庫、PHP 版本與設定、SSL 狀態、排程工作、子網域、網址檢查、日誌、用量與帳戶資訊。connect 工具會在本機開啟登入頁面,讓主機密碼在使用者電腦上輸入而非在對話中,並換取受限的 DirectAdmin 登入金鑰。
適用情境
適合在 kapaweb DirectAdmin 上代管網站或 PHP 應用程式的人,希望助理透過對話完成推送變更、檢視檔案、執行資料庫匯入匯出,或調整 PHP、SSL 與排程工作設定,而不必進入控制面板。
執行需求
一個位於 DirectAdmin 伺服器上的 kapaweb 主機帳戶。同一台電腦需安裝 Node.js 18.17 或更新版本。需要能啟動本機 MCP 伺服器的 Claude 環境,例如 Claude Code 或在本機執行的 Cowork 工作階段;網頁版 Claude 對話無法啟動,需改用桌面擴充功能。需要能連線到使用者自己的面板以及 kapaweb.gr 和 firewall.kapaweb.gr。
安裝前請注意
連接器會處理該主機帳戶的受限 DirectAdmin 登入金鑰,儲存在作業系統的受保護儲存區中,也會處理產生的資料庫密碼;主機密碼只在本機登入頁面輸入一次,之後即被丟棄。寫入、部署、回復、資料庫與排程工作類工具會變更或刪除線上主機帳戶中的資料,因此備份與破壞性標註很重要。檔案清單、日誌等工具輸出會交給所使用的 AI 應用程式。金鑰預設 30 天後過期,可在 DirectAdmin 中撤銷。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 kapaweb deploy,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

kapaweb deploy

Deploy websites, PHP apps and WordPress to kapaweb DirectAdmin hosting from a conversation with Claude, without your hosting password ever entering the chat. The plugin bundles the kapaweb connector, a local MCP server that runs on your computer, and a skill that tells Claude how to use it safely.

Requirements

  • A hosting account at kapaweb (https://kapaweb.gr) on a DirectAdmin server.
  • Node.js 18.17 or newer on the computer that runs Claude. The connector has no dependencies and nothing to build.
  • A Claude surface that starts local MCP servers: Claude Code, or Cowork sessions that run on your computer. Claude chat on the web does not start local servers, so use the Claude Desktop extension from https://kapaweb.gr/deploy-with-ai/ there.

Use it

Ask Claude to deploy a project to kapaweb. The skill makes Claude read the public playbook (https://kapaweb.gr/deploy-with-ai/playbook.md), check that the connector is current, and call connect. connect opens a sign-in page on your own computer (http://127.0.0.1, random port and token): you type your DirectAdmin address, username and password there, never in the chat. The connector exchanges the password for a restricted DirectAdmin login key, forgets the password, and keeps only the key in your computer's protected storage (Windows DPAPI, macOS Keychain, Linux secret-tool).

Tools: deploy (always makes a backup first), rollback, list_files, read_file, write_file, db_create, db_import, db_export (streamed, any size, saved on your computer), php_versions, set_php_version, php_settings, ssl_status, cron_*, subdomain_*, check_url, logs, usage, account_info, playbook, connect, disconnect. Read-only tools are annotated readOnlyHint, destructive ones destructiveHint.

What it runs, stores and sends

  • Runs node server/index.js from this plugin, on your computer, over stdio. On macOS it calls security (Keychain), on Linux secret-tool, on Windows PowerShell DPAPI, to store and read its own login key; it opens your browser on the local sign-in page.
  • Sends requests only to: your own kapaweb DirectAdmin panel (the address you typed; it is checked against kapaweb's own server list before every connection); https://firewall.kapaweb.gr/servers.txt (that list of kapaweb server addresses); https://kapaweb.gr/deploy-with-ai/playbook.md (the playbook); https://kapaweb.gr/downloads/kapaweb-connector.version.json (a version check at most once a day, nothing is sent but the User-Agent kapaweb-connector/<version>; KAPAWEB_CONNECTOR_NO_UPDATE_CHECK=1 turns it off); and, only when you ask for it with check_url, the domains of your own hosting account (plus a short fixed list of sites that kapaweb itself maintains).
  • Stores on your computer: the saved connection (panel address, user name, key id; no password), the login key and generated database passwords in the protected storage, and database exports you ask for in the connector's settings folder. Nothing is sent to kapaweb for analytics, and nothing about you is collected by this plugin.
  • Never shows Claude your password, the login key or generated database passwords.

Privacy policy

Kapaweb (https://kapaweb.gr, [email protected]) provides this plugin.

  • What we collect: nothing. The plugin has no accounts, no analytics and no telemetry on our side.
  • What stays on your computer: the address, user name and key id of your hosting panel; a restricted DirectAdmin login key and generated database passwords (in your operating system's protected storage); and the database exports you ask for. Your hosting password is used once, to create the key, and is then forgotten. All of this stays until you delete it: disconnect, or remove the key in DirectAdmin under Login Keys. The key expires (30 days by default; you can choose 90 days, a year, or never) and can be revoked at any time.
  • Where data goes: to your own hosting panel (the files, databases, settings and logs of your account, as far as you ask Claude to work on them). The requests to kapaweb.gr and firewall.kapaweb.gr listed above carry no personal data except the usual network data (your IP address, the time, the file requested and the User-Agent kapaweb-connector/<version>), which kapaweb's web server records in its normal access log. What the tools return (file listings, logs, command results) is given to Claude, the AI app you use, and is covered by that app's own terms and privacy policy.
  • Third parties: we share nothing with anyone. No advertising, no sale of data.
  • Retention: local data stays until you remove it (see above); kapaweb's web server logs follow kapaweb's normal log retention.
  • Children: this is a business tool and is not intended for people under 18.
  • Contact: [email protected].

Notes for reviewers

The directory scan holds this plugin for review because its heuristics see "a credential" near "a remote host". What each finding points at (all checked in the source):

  • server/da.js: ssd5.kdns.gr appears only in a code comment (the example shape of a panel address). The panel address the user typed is checked against kapaweb's own server list (verifyPanelHost) and the connection is pinned to the verified IP address before the login key is ever sent.
  • server/setup.js: ${h} is a JavaScript template literal in the Origin check of the local sign-in page (http://127.0.0.1:<random port>); it is not a host and no secret is sent to it.
  • server/tools.js: kapaweb.gr is a comment and the public playbook URL. That request carries only the header User-Agent: kapaweb-connector (no key, no password).
  • server/clients.js: this file builds help text for the user and mentions the path ~/.claude.json inside that text. It reads no file and sends nothing.

The only credential the plugin handles is the restricted DirectAdmin login key of the user's own hosting account. It is created from a password typed once on the local sign-in page, kept in the operating system's protected storage, and sent only to that user's own verified kapaweb panel. The plugin does not read any other credential, environment token or file from the user's computer.

License

MIT. See the LICENSE file.

來源:README.md,提交 e67cd67

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.7.0最新Oct 9, 2026