
Opencode Workbench
io.github.simonmak-ascentv2.0.0更新於 Oct 2, 2026
Provision an OpenCode workbench and MCP stack on any Linux box, local or over SSH.
概覽
一個 MCP 伺服器,可檢查 Linux 機器,並在本地或透過 SSH 把預先設定好的 OpenCode 開發工作台複製到該機器上。
- 功能
- 它會把完整的 OpenCode 工作站設定部署到 Linux 機器上,目標可以是本機,也可以是透過 SSH 存取的遠端主機。流程分階段進行:inspect_target、plan_clone、apply_clone 與 verify_clone。apply_clone 需要確認,未提供 confirm:true 時只會回傳計畫,列出元件與特權命令預覽。list_required_credentials 工具會回報目標機器還缺哪些金鑰;複製流程對金鑰缺失有容錯:沒有模型金鑰時仍可在免費層啟動,憑證缺失的 MCP 伺服器會被停用並回報。
- 適用情境
- 當你需要在另一台 Linux 機器上重現一套有文件記錄的 OpenCode 開發環境,或在建置機遺失後重建環境、又不想重複手動設定時使用。它適合已將此工作台儲存庫視為設定唯一來源、並希望執行環境與之一致的使用者。
- 執行需求
- 需要一台 Linux 目標機,可以是本機,或是可透過 SSH 存取的主機(需提供主機與使用者)。伺服器以本地 stdio 程序方式透過 npx 執行該 npm 套件,也可作為遠端端點使用。未宣告身分驗證。複製出的環境所需憑證由使用者另行提供;連接器只會寫入一個空的环境變數範本,不讀取也不傳輸金鑰值。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Opencode Workbench,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。
其他 MCP 客戶端
把它新增到你客戶端的 mcpServers 設定中。
{
"mcpServers": {
"opencode-workbench": {
"type": "http",
"url": "https://opencode-workbench.simonmak.com/mcp"
}
}
}README
OpenCode Workbench
[Secret Scan] [License: MIT] [MCP Server] [Validate Documentation] [MCP Tool Definition Quality]
A reproducible, self-documenting, and recoverable OpenCode development workstation — configuration, agent skills, MCP stack, and an MCP server that clones the entire setup onto any Linux machine (locally or over SSH).
Purpose
This repository is the single source of truth for a complete cloud development workstation. Everything needed to rebuild from scratch is versioned here:
- Workstation configuration and automation
- OpenCode configuration (model, providers, MCP servers)
- Agent skills (45 reusable AI instructions across research, dev, data, science and ops)
- Operational prompts (disaster recovery, backup, security)
- Recovery procedures (playbook, checklist, gap analysis)
- Security governance (secret management, threat model)
opencode-workbench— an MCP server that installs this profile on any Linux box
No important knowledge exists only in human memory.
Clone This Workbench to Another Linux Machine
Register the MCP server with OpenCode:
Then ask the agent to run inspect_target → plan_clone → apply_clone { confirm: true } → verify_clone, for { "mode": "local" } or { "mode": "ssh", "host": "<your-box>", "user": "<your-user>" }. apply_clone is consent-gated: without confirm:true it returns a plan (components + privileged-command preview) and changes nothing. Run list_required_credentials to see which keys the box still needs and how to acquire them, and bash scripts/selftest/run-selftest.sh to verify it works. See mcp-server/README.md and docs/architecture/clone-mcp.md.
The clone is key-resilient: with no model key it still boots on the OpenCode Zen free floor, and MCP servers whose credentials are absent are disabled and reported (not left to fail at runtime).
The connector never reads or transmits secret values; it writes an empty ~/.env.workbench template for you to fill in.
Quick Start
Architecture
What's Inside
Workstation Governance
This workstation operates under a formal charter. Key principles:
- Single Source of Truth: Runtime must match repository. Drift is a bug.
- Secrets Never Touch Disk: All secrets flow through the build box Secrets.
- Immutable History: Changelog is append-only. Every change is traceable.
- Documentation Lives With Code: Docs describe the system as it is, not as imagined.
Read the full charter: docs/WORKBENCH_CHARTER.md
Backup Workflow
Or use OpenCode prompts:
docs/prompts/RUN_MASTER_BACKUP.md— execute backup via AIdocs/prompts/QUICK_BACKUP.md— rapid state preservation
Recovery Workflow
Assume the build box is deleted. Only Git repo + build box Secrets survive.
Full details: docs/recovery/RECOVERY_PLAYBOOK.md
MCP Architecture
Totals: 35 configured (33 enabled, 2 disabled: google-search, google-workspace).
See: docs/architecture/mcp-inventory.md
Secrets Management
All secrets stored in the build box Secrets. Never in repository files.
Additional keys for opt-in servers (EXA_API_KEY, CLOUDFLARE_API_TOKEN,
STRIPE_SECRET_KEY, SURREAL_*, ALIBABA_CLOUD_*, AZURE_*, FIRECRAWL_API_KEY,
FRED_API_KEY, COMPANIES_HOUSE_API_KEY) are catalogued in
docs/architecture/secrets.md — never by value.
See: docs/architecture/secrets.md
Documentation Index
Adding to the Workbench
- MCP Server: Add npm package to
.devcontainer/setup.sh, add toopencode.json, document indocs/architecture/mcp-inventory.md - Agent Skill: Create
.opencode/skills/<name>/SKILL.md, follow naming convention - Tool: Add to
scripts/bootstrap-tools.sh - Prompt: Create in
docs/prompts/, updateprompt-index.md - After any change: Update
CHANGELOG_WORKBENCH.md, run master backup
Recovery Score: 94/100
Validated disaster recovery within < 10 minutes using repository + build box Secrets alone.
Use with Context7
Up-to-date OpenCode Workbench documentation is indexed on Context7, so coding agents can pull it into context on demand. With the Context7 MCP server or ctx7 CLI installed, name the library in your prompt:
License
MIT — see LICENSE.
A tool by Simon Mak.
If this saves you time, a ⭐ on GitHub helps others find it.
來源:README.md,提交 091e373
工具
0版本歷史
1- v2.0.0最新Oct 2, 2026

