<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Relates to #43544 Security review + hardening of the experimental Fleet MCP server. Issues were reproduced against a live dev Fleet; this PR fixes the MCP-layer ones. | Finding | Before → After | Where | |---|---|---| | **A** least privilege | No signal about the token's power → startup `/me` check **refuses any non-API-only token** (fails closed if unreachable). API-only users can be scoped to specific endpoints/teams and their token revoked. Who-can-do-what is documented (Fleet RBAC), not inferred at runtime. | `main.go` `requireAPIOnlyUser`; `fleet_integration.go` `WhoAmI` | | **B** rate-limit XFF bypass | Per-IP keyed on spoofable `X-Forwarded-For` → Removed rate-limiting (assuming Fleet handles this). | N/A | | **C** token egress / SSRF | `FLEET_BASE_URL` unchecked → This is configured at deployment time and not per-request, so no action is taken. | N/A | | **D** error-body leak | Raw Fleet JSON (incl. internal `uuid`) → trimmed, e.g. `Fleet API returned HTTP 409: Resource Already Exists`. | `fleet_integration.go` `fleetErrMsg` | | **E** dead code / docs / tests | Removed dead `GetFleetConfig`; README 18→19 / 16→17; added validator/role tests. | `fleet_integration.go`, `README.md`, `*_test.go` | | **F** writes auto-runnable | Only the advisory `destructive=true` annotation → `fleetMCPInstructions` now tells the client to show the SQL + targets and confirm before running `run_live_query`. **Advisory, not a server control.** | `mcp_server.go` | | **G** abrupt SIGTERM shutdown | `ListenAndServe` blocked with no signal handling → on SIGTERM the process was killed immediately (**exit 143**), resetting any in-flight connection at once. Now a signal-aware root context (`signal.NotifyContext`) drains in-flight requests via `http.Server.Shutdown` (10s cap), logs `shutting down`, and **exits 0** — and the startup `/me` check + temp-query sweep + stdio loop all honor it. Matters for Render redeploys (SIGTERM). | `main.go` | ### Key decisions - **Rate limit: removed**: assuming Fleet server handles this. - **`fleetMCPInstructions` / `destructive=true` are advisory** — a prompt-injected or raw client ignores them. The enforceable controls are the token role and `--disable_tables` flag. Added an explicit confirm-before-run instruction for `run_live_query` to `fleetMCPInstructions` as a cross-client complement to the `destructiveHint=true` annotation -- the annotation only prompts on clients that honor it, whereas the instruction reaches any client that forwards server instructions to the model (and raw JSON-RPC callers that have no approval UI at all). Both are advisory; the real bound on writes remains the `FLEET_API_KEY`'s Fleet role. - **Device-side `curl`/`carves` exfil is a Fleet/osquery capability**, equally reachable via the UI/`fleetctl`/REST — not an MCP bug. Comprehensive fix is agent `--disable_tables` (separate Fleet-server/agent issue). ### Residual attack surface (re: *"no new attack vectors"*) None of these is a vector the MCP invents beyond what Fleet already exposes: | Config choice | Residual vector | Mitigation | |---|---|---| | Non-API-only / admin token | Leak = arbitrary osquery everywhere | API-only **required** (refuses to start otherwise); use **observer** for read-only. As an API-only user it can also be **scoped to specific endpoints/teams** and its **token revoked** on leak — neither possible with a UI session token. | | `run_live_query` via an auto-approving / prompt-injected client | Arbitrary osquery on currently-online hosts - read/exfil-capable (`curl`, `curl_certificate`, `file`, `carves`). No data mutation. | Non-advisory: `FLEET_API_KEY` role - **observer-plus** needed to run live queries. A "read-only" deployment (**observer** token) removes the vector entirely; plus agent-side `--disable-tables` to drop exfil tables. Advisory: `destructiveHint=true` + confirm-before-run instruction (F) - an auto-approving client ignores these. | | Live query at all | `curl`/`carves`/`file` device SSRF + exfil | Agent `--disable_tables` (separate issue) — not an MCP-layer fix | | Public SSE, no edge | Unauth flood `429`s operators (shared bucket — fails safe) | We assume Fleet server handles rate-limiting. | **Bottom line:** with an API-only observer/+ token (now enforced) over stdio, `ip` mode, or SSE-behind-an-edge, the MCP adds no new attack vector beyond Fleet's existing live-query capability; the residual `curl`/`carves` risk is a Fleet-layer concern tracked separately. # Checklist for submitter If some of the following don't apply, delete the relevant line. - [ ] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Startup now verifies the Fleet API key belongs to an **API-only** Fleet user * Added `/healthz` endpoint * Hardened Fleet base URL validation to prevent token leakage to unsafe hosts * Improved rate limiting behavior (429 includes `Retry-After: 1`; per-IP uses the direct client address host) * Signal-driven graceful shutdown and stricter `MCP_AUTH_TOKEN` length checks * More robust schema fetching by blocking cross-host and overly long redirect chains * **Documentation** * Expanded/clarified write-operation guidance and confirmation requirements * **Chores / Tests** * Updated `.env` docs/ignores, added developer Makefile helpers, and refreshed Fleet base URL tests <!-- end of auto-generated comment: release notes by coderabbit.ai -->
News · Report a bug · Docs · Why open source? · Art
Open-source platform for IT and security teams with thousands of computers. Designed for APIs, GitOps, webhooks, YAML, and humans.
What's it for?
Fleet gives you a single system to secure and maintain all your computing devices over the air. You can do MDM, patch stuff, deploy software, and verify anything, all from one place, across every OS your organization uses.
Fleet works directly with data and events from the native operating system, down to the bare metal. Strong diagnostics let you investigate errors on end-user devices and collect accurate audit evidence in minutes.
Get started
You can try Fleet out for yourself, or grab time with one of the maintainers to chat.
Is it any good?
Fleet is used in production by IT and security teams managing thousands of devices. Many deployments support tens of thousands of hosts, and a few large organizations manage 400,000 or more.
Supported platforms
- Linux (all distros)
- macOS
- Windows
- Chromebooks
- iOS and Android (BYOD or corporate-owned)
- Amazon Web Services (AWS)
- Google Cloud (GCP)
- Azure (Microsoft cloud)
- Data centers
- Containers (kube, etc)
- Linux-based IoT devices
Infrastructure as code
Manage your fleet with GitOps, or use the GUI, REST API, webhook events, and the fleetctl command-line tool.
Linux support
First-class support for all major distros. Linux gets the same attention and visibility as macOS and Windows.
Visibility and compliance
Fleet can report on hundreds of attributes across your devices and ships with CIS benchmarks for macOS and Windows and comprehensive operating system, hardware, and software data. Check out the table reference documentation to see what's available.
Open by design
Fleet is open source and transparent about what it can and can't see. End users can verify exactly how the agent works and what data their company collects. Fleet collects only the data needed to manage and secure devices, not private activity like keystrokes, emails, or webcams.
Good neighbors
Ready-to-use, enterprise-friendly integrations exist for Snowflake, Splunk, GitHub Actions, Vanta, Elastic Jira, Zendesk, and more. Fleet also works with tools such as Munki, Chef, Puppet, Ansible, CrowdStrike, and SentinelOne.
Lighter than air
Fleet is lightweight and modular. You can use it for MDM without using it for security, and vice versa. You can turn off features you are not using.
Free as in free
The free version of Fleet will always be free. Fleet is independently backed and actively maintained with the help of many amazing contributors.
Longevity
The company behind Fleet is founded (and majority-owned) by true believers in open source. The company's business model is influenced by GitLab (NYSE: GTLB), with great investors, happy customers, and the capacity to become profitable at any time.
Fleet Device Management's company handbook is public and open source. You can read about the history of Fleet and our commitment to improving the product.
Chat
The Fleet community is full of kind and helpful people. Whether or not you are a paying customer, if you need help, just reach out.
Contributing
Contributions are welcome, whether you answer questions on Slack / GitHub / LinkedIn, improve the documentation or website, write a tutorial, give a talk at a conference or local meetup, give an interview on a podcast, troubleshoot reported issues, or submit a patch. The Fleet code of conduct is on GitHub.
License
The free version of Fleet is available under the MIT license. The commercial license is also designed to allow contributions to paid features for users whose employment agreements allow them to contribute to open source projects. (See LICENSE.md for details.)
Fleet is built on osquery, nanoMDM, Nudge, and swiftDialog.