Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

cloud.redu/mcp

REMOTE · MCP.REDU.CLOUD · SCANNED AUG 3

Agent-native cloud, EU-hosted. Provision VMs, networks & databases on redu.cloud via MCP.

Available components

+10 this week 71 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security94
Transport & Reachability100
Schema Quality & AI Usability24
  • AI-judged instruction clarity (poor).Fail
  • Context-footprint check failed: tool/resource definitions use about 21109 tokens (~289/item across 73 items; 73 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage96
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 87% of tool parameters carry a description.Partial
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · mcp.redu.cloud

# add to Claude Code
claude mcp add --transport http cloud-redu-mcp https://mcp.redu.cloud/mcp
# ~/.codex/config.toml
[mcp_servers.cloud-redu-mcp]
url = "https://mcp.redu.cloud/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "cloud-redu-mcp": {
      "type": "remote",
      "url": "https://mcp.redu.cloud/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add cloud-redu-mcp --url https://mcp.redu.cloud/mcp --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  cloud-redu-mcp:
    url: "https://mcp.redu.cloud/mcp"
// mcp.json
{
  "mcpServers": {
    "cloud-redu-mcp": {
      "type": "http",
      "url": "https://mcp.redu.cloud/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 31 Jul 26 +8
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 29 Jul 26 +1
    • The server rewrote its instructions, which are the text every model session reads security
    • Tool “update_cluster” rewrote its description, which is the text the model reads security
    • Tool “upgrade_to_cluster” rewrote its description, which is the text the model reads security
    • “upgrade_to_cluster” added an optional parameter “high_availability” cosmetic
    • “upgrade_to_cluster” reworded the description of “max_size” cosmetic
  • 28 Jul 26 0
    • New tool “delete_volume”, which the server declares destructive security
    • Tool “restore_backup” rewrote its description, which is the text the model reads security
    • “create_instance” added an optional parameter “boot_volume_id” cosmetic
  • 27 Jul 26 +2
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Jul 26 59

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Probed https://mcp.redu.cloud/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=*.redu.cloud CN=YE2,O=Let's Encrypt,C=US 7 Jun 2026 5 Sept 2026 ECDSA 384 ECDSA-SHA384 53c6e6799a05b45d592175b4714fc4cc8ac
SANs: *.redu.cloud, redu.cloud
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd
DNSSEC insecure

Validation of mcp.redu.cloud. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
cloud. present 7041 13 Verified
redu.cloud. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer resource_metadata="https://mcp.redu.cloud/.well-known/oauth-protected-resource", scope="openid"

Bearer resource_metadata="https://mcp.redu.cloud/.well-known/oauth-protected-resource", scope="openid"
Header Value
strict-transport-security max-age=63072000; preload

Protected resource metadata

Document https://mcp.redu.cloud/.well-known/oauth-protected-resource
Retrieved Yes
Resource https://mcp.redu.cloud
Authorisation server https://login.redu.cloud/realms/eu-central-1
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.redu.cloud/mcp Verified 200
http (plaintext) http://mcp.redu.cloud/mcp HTTPS enforced 301 https://mcp.redu.cloud/mcp
MCP tools — 73 exposed · ~18,431 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
architecture_diagram ~245

Read-only. Fetches EVERY resource on your redu.cloud account (VMs, volumes, private networks, managed databases: Postgres/MySQL/MariaDB/ClickHouse/Redis/Qdrant, load balancers, and DNS access points) and renders ONE Mermaid diagram of the whole account, grouped into per-private-network subgraphs with repetition collapsed into count nodes (e.g. "App VM x12"). Returns report_markdown to save as redu_architecture_diagram.md at the repo root, PLUS a redu_md_section that enriches the repo's redu.md with the current account topology, so the NEXT deploy is account-aware: it integrates with services that already exist and picks models/versions/sizes that fit the stack (better decisions, not just avoiding duplicate networks/databases). Nothing is created or changed.

NameTypeReqDescription
include_load_balancersbooleanInclude load balancers in the map (default true).
include_managedbooleanInclude managed databases (Postgres/MySQL/MariaDB/ClickHouse/Redis/Qdrant) in the map (default true).
include_volumesbooleanInclude block volumes in the map (default true).
NameTypeReqDescription
counts
modestring
nextstring
redu_md_filenamestring
redu_md_sectionstring
report_filenamestring
report_markdownstring
resources

No examples provided.

attach_volume ~236

Attaches an EXISTING block volume to a running instance as an extra disk. This is how you finish a RESTORE after a VM is gone: restore_backup (volumeName) rebuilds the data into a new volume, then attach_volume puts that volume on a replacement instance — then SSH in (get_ssh_command) and mount it (`lsblk` to find it, usually /dev/vdb, then `mount /dev/vdb /mnt/...`). The volume must be 'available' (not already in-use — detach_volume it first) and in the same project. Attaching does NOT mount or boot from it: the instance keeps booting from its own root disk, the volume shows up as an extra block device. Poll list_volumes until status is 'in-use'.

NameTypeReqDescription
instance_idstringyesInstance to attach it to / detach it from — from list_instances (id).
volume_idstringyesVolume to attach/detach — from list_volumes (id). For a recovery, this is the volume restore_backup created (restore_backup with volumeName makes a NEW volume from a backup).
NameTypeReqDescription
available_keypairsarray
duplicateboolean
errorboolean
idempotency_keystring
invalid_keypair_nameboolean
modestring
needs_keypairboolean
needs_keypair_nameboolean
needs_planboolean
nextstring
plan_toolstring
request
result
validation

No examples provided.

check_agent_prerequisites ~78

Checks if your account has everything needed to run autonomous coding agents. Returns a checklist: API key validity, private network, SSH keypair, and billing. Safe to call anytime — read-only. Call this first before create_controller.

NameTypeReqDescription
github_patstringGitHub Personal Access Token to validate (repo + workflow scopes required)
NameTypeReqDescription
all_okboolean
checks

No examples provided.

check_deploy_prerequisites ~245

The deploy ENTRY GATE — run this first when a user wants to deploy. Verifies the account is ready and AUTO-SELECTS the network_id + keypair_name to pass to deploy_app (so you never hunt for them): (1) account reachable + quota, (2) a private network (picks your default — every account has one), (3) an SSH keypair (if you have none, returns ssh_key_recipe: the exact local ssh-keygen → import_keypair → write SSH_KEY_LOCATION-to-.env steps — run them, in yolo mode without asking). Returns { ready, network_id, keypair_name, missing, ssh_key_recipe }.

NameTypeReqDescription
modestringguided = confirm each choice with the user; yolo = auto-proceed with sensible defaults (auto-select the default network, auto-create a keypair). STICKY for the session once set — OMIT it on later re-…
NameTypeReqDescription
account_okboolean
keypair_namestring|null
missingarray
modestring
network_idstring|null
nextstring
quota
readyboolean
ssh_key_recipearray

No examples provided.

create_api_key ~289

Mints a NEW least-privilege redu API key for a deployed app or automation to use (e.g. to add a backup feature). GUARDRAIL: the first call does NOT create anything. It returns a confirmation the user must approve, because a key is a long-lived credential that acts on the account and ANY usage of it is BILLED to the account owner. Show the user the name, the exact scopes, and the billing notice, get their explicit approval, then call again with confirm:true. This is required even in yolo/auto mode. The secret is returned ONCE.

NameTypeReqDescription
confirmbooleanSet true ONLY after the user has explicitly approved (see the confirmation the first call returns). Leave unset to get the approval prompt first. Do NOT set it yourself.
expires_in_daysintegerOptional: auto-expire the key after N days.
namestringyesA recognizable name for the key, e.g. 'supabase-backups'.
scopesarrayyesLEAST-PRIVILEGE scopes the key may use, e.g. ['instance:read','backup:read','backup:create','backup:restore']. Grant only what the feature needs. Discover the catalog via GET /v1/capabilities (gramma…
NameTypeReqDescription
billing_noticestring
errorboolean
expires_at
keystring
modestring
namestring
needs_confirmationboolean
nextstring
scopes
validation
warningstring

No examples provided.

create_backup ~136

Creates a backup, by volumeId or by instanceId (the instance's volume is resolved for you). The backup is held independently of the instance, so it survives the VM. Poll list_backups until the new backup is available.

NameTypeReqDescription
backupNamestringyesA name for the backup.
instanceIdstringID of the instance to back up — its bootable (else first) attached volume is resolved automatically, so no volume:list scope is needed. Provide this OR volumeId.
volumeIdstringID of the volume to back up (see list_volumes). Provide this OR instanceId.
NameTypeReqDescription
available_keypairsarray
duplicateboolean
errorboolean
idempotency_keystring
invalid_keypair_nameboolean
modestring
needs_keypairboolean
needs_keypair_nameboolean
needs_planboolean
nextstring
plan_toolstring
request
result
validation

No examples provided.

create_clickhouse ~378

Provisions a managed ClickHouse database (OLAP / columnar analytics engine, Apache-2.0) on a dedicated VM on your private network — its OWN resource, NOT a relational database. Requires a recent plan_managed_datastore. Use it for analytics / observability workloads that need a column store (PostHog, Langfuse, event analytics, time-series). It is PRIVATE — reachable only from another instance on the same private network, via the DB's internal/private IP on the ClickHouse HTTP port 8123 (CLICKHOUSE_HOST/PORT/USER/PASSWORD/DB env, http://host:8123). Get the ids from plan_managed_datastore/list_flavors (use m1.small+ — ClickHouse needs >=2GB RAM), list_private_networks, list_keypairs. Provisioning takes ~5 min; poll list_clickhouse_databases until status='ready'.

NameTypeReqDescription
db_namestringThe database to create (default 'analytics').
db_passwordstringPassword for the db user (letters/numbers/_/- only). Auto-generated and returned once if omitted.
db_userstringThe database user (default 'appuser').
flavor_idstringyesInstance size for the ClickHouse VM — from list_flavors. ClickHouse is RAM-hungry; pick m1.small (2GB) or larger.
idempotency_keystring
keypair_namestringyesSSH keypair name — from list_keypairs.
namestringyesName for the managed ClickHouse database (lowercase letters, numbers, hyphens).
network_idstringyesPrivate network id — from list_private_networks. The DB is reachable only from this network.
security_group_namesarray
NameTypeReqDescription
available_keypairsarray
duplicateboolean
errorboolean
idempotency_keystring
invalid_keypair_nameboolean
modestring
needs_keypairboolean
needs_keypair_nameboolean
needs_planboolean
nextstring
plan_toolstring
request
result
validation

No examples provided.

create_controller ~141

Creates a self-configuring controller VM on redu.cloud. Auto-discovers your network, Ubuntu image, and flavor. Generates and uploads an SSH keypair if you don't have one. The VM bootstraps itself — no SSH or VPN needed. After ~7 minutes, authorize the fleet (run the authorize.sh one-liner it returns) then call trigger_agent_batch.

NameTypeReqDescription
github_patstringyesGitHub Personal Access Token (repo + workflow scopes)
repostringyesGitHub repo to run agents on, e.g. 'owner/repo'
worker_countintegerNumber of worker VMs to provision (default 3)
NameTypeReqDescription
authorize_commandstring
controller_hoststring
dnsstring
instance_idstring
log_tokenstring
modestring
nextarray
ssh_key_namestring
ssh_private_keystring
ssh_userstring
statusstring
trigger_tokenstring

No examples provided.

create_database ~469

Provisions a managed PostgreSQL database on a dedicated VM on your private network. Requires a recent plan_managed_datastore. For app deployments, prefer deploy_app database:'managed' so plan_deploy includes and wires the DB automatically. It is PRIVATE — reachable only from another instance on the same private network, via the DB's internal/private IP (not a public address). Get the ids from plan_managed_datastore/list_flavors/list_private_networks/list_keypairs. Provisioning takes ~5 min; poll list_databases until status='ready', then the connection details (private_ip, port 5432, db_name, db_user) are populated.

NameTypeReqDescription
db_namestringThe database to create (default 'app').
db_passwordstringPassword for the db user. Auto-generated and returned once if omitted.
db_userstringThe database user (default 'appuser').
extensionsarrayPostgres extensions to pre-install at provision time (allowlisted): 'pgvector'/'vector' (embeddings), 'postgis' (geo), 'pgaudit', 'pg_trgm', 'pgcrypto', 'hstore', 'uuid-ossp', 'citext', 'ltree', 'pg_…
flavor_idstringyesInstance size for the DB VM — from list_flavors.
idempotency_keystring
keypair_namestringyesSSH keypair name — from list_keypairs (for operating the DB VM).
namestringyesName for the managed database (lowercase letters, numbers, hyphens).
network_idstringyesPrivate network id — from list_private_networks. The DB is reachable only from this network.
security_group_namesarray
superuserbooleanGrant the db user SUPERUSER — safe here (a dedicated single-tenant DB VM). Use when the app's own migrations must CREATE EXTENSION or alter roles.
versionstringPostgres major version (default 16).
NameTypeReqDescription
available_keypairsarray
duplicateboolean
errorboolean
idempotency_keystring
invalid_keypair_nameboolean
modestring
needs_keypairboolean
needs_keypair_nameboolean
needs_planboolean
nextstring
plan_toolstring
request
result
validation

No examples provided.

create_instance ~405

Creates a raw compute instance for custom OS/cloud-init workflows. For app/source deployments, prefer check_deploy_prerequisites -> plan_deploy -> deploy_app/deploy_compose; do not use create_instance as a shortcut around the deployment plan. Requires a recent plan_instance. For reduOS, set cloud_init_template='reduos' and flavor m1.xlarge (16GB). SSH keypair must exist. For a public web app on a raw VM, pass dns_entries (gives a .redu.cloud URL through redu's automatic public proxy). The origin app should listen on dns_entries[].port; do not install nginx on the VM unless the app itself needs it, because redu.cloud already creates the public Nginx proxy host.

NameTypeReqDescription
boot_volume_idstringDISASTER RECOVERY: boot this new VM from an EXISTING volume (one restore_backup just created) instead of a fresh image, so the machine comes back with the restored filesystem AS its root disk. The vo…
cloud_init_templatestring
dnamestring
dns_entriesarrayPublic DNS/proxy entries to create automatically. Use [{ dname:'', port:8080 }] to generate a redu.cloud URL pointing at an origin process on port 8080.
flavor_idstringyes
idempotency_keystring
imageNamestring
image_idstringyes
keypair_namestringyes
namestringyes
network_idstringyes
portinteger
security_group_namesarray
user_datastring
volumeobject
NameTypeReqDescription
available_keypairsarray
duplicateboolean
errorboolean
idempotency_keystring
invalid_keypair_nameboolean
modestring
needs_keypairboolean
needs_keypair_nameboolean
needs_planboolean
nextstring
plan_toolstring
request
result
validation

No examples provided.

create_media_space ~244

Creates a private Redu media space: a small NFS VM backed by a persistent volume, intended for WordPress/WooCommerce wp-content/uploads in autoscaling clusters. Prefer letting deploy_app/deploy_compose create this by passing create_media_space:true after plan_deploy approval; use this tool when manually preparing or reusing shared uploads storage.

NameTypeReqDescription
flavor_idstringSmall VM flavor id for the NFS media server. m1.small is enough for most WordPress uploads.
idempotency_keystring
keypair_namestringyesExisting SSH keypair name.
mount_pathstringHost mount path that app VMs will use before binding into /var/www/html/wp-content/uploads.
namestringyesName for the media space, e.g. myshop-media.
network_idstringPrivate network id. Use the same network as the WordPress app and managed DB.
security_group_namesarraySecurity groups for the media VM. Redu opens NFS 2049 from private networks only.
size_gbintegerPersistent media volume size in GB.
NameTypeReqDescription
available_keypairsarray
duplicateboolean
errorboolean
idempotency_keystring
invalid_keypair_nameboolean
modestring
needs_keypairboolean
needs_keypair_nameboolean
needs_planboolean
nextstring
plan_toolstring
request
result
validation

No examples provided.

create_redis ~353

Provisions a managed Redis instance on a dedicated VM on your private network. Requires a recent plan_managed_datastore. It is PRIVATE — reachable only from another instance on the same private network, via its internal/private IP on port 6379 (not a public address). AUTH (requirepass) is always enabled. Get the ids from plan_managed_datastore/list_flavors, list_private_networks (or check_deploy_prerequisites), list_keypairs — use the SAME network_id as the app that will connect. Provisioning takes ~5 min; poll list_redis until status='ready', then the connection details (private_ip, port 6379) are populated. Wire an app with REDIS_URL=redis://:<password>@<private_ip>:6379 (pass it via deploy_app env).

NameTypeReqDescription
flavor_idstringyesInstance size for the Redis VM — from list_flavors. m1.small (2GB) is plenty for most caches/queues.
idempotency_keystring
keypair_namestringyesSSH keypair name — from list_keypairs (for operating the Redis VM).
namestringyesName for the managed Redis instance (lowercase letters, numbers, hyphens).
network_idstringyesPrivate network id — from list_private_networks (or check_deploy_prerequisites). Redis is reachable only from this network; use the SAME network as the app that will connect.
passwordstringRedis AUTH password (requirepass). Auto-generated and returned once if omitted.
security_group_namesarray
versionstringRedis major version (default '7').
NameTypeReqDescription
available_keypairsarray
duplicateboolean
errorboolean
idempotency_keystring
invalid_keypair_nameboolean
modestring
needs_keypairboolean
needs_keypair_nameboolean
needs_planboolean
nextstring
plan_toolstring
request
result
validation

No examples provided.

create_relational_database ~505

Provisions a managed MySQL (or MariaDB) database on a dedicated VM on your private network — the relational-database resource (use this instead of create_database when the app needs MySQL/MariaDB, e.g. WordPress, NextCloud, Matomo, many PHP/LAMP apps). Requires a recent plan_managed_datastore. For app deployments, prefer deploy_app database:'managed' with db_engine mysql/mariadb so plan_deploy includes and wires the DB automatically. It is PRIVATE — reachable only from another instance on the same private network, via the DB's internal/private IP (port 3306), not a public address. Get the ids from plan_managed_datastore/list_flavors/list_private_networks/list_keypairs. Provisioning takes ~5 min; poll list_relational_databases until status='ready', then the connection details (private_ip, port 3306, db_name, db_user) are populated. MySQL is created with mysql_native_password auth so older clients/apps connect cleanly. (ClickHouse is a separate resource — use create_clickhouse / list_clickhouse_databases.)

NameTypeReqDescription
db_namestringThe database to create (default 'app').
db_passwordstringPassword for the db user (letters/numbers/_/- only). Auto-generated and returned once if omitted.
db_userstringThe database user (default 'appuser').
enginestringDatabase engine: 'mysql' (default) or 'mariadb'. Both speak the MySQL protocol (mysql:// URL). Pick the one your app/stack uses. (For analytics/column-store needs use create_clickhouse instead — Clic…
flavor_idstringyesInstance size for the DB VM — from list_flavors.
idempotency_keystring
keypair_namestringyesSSH keypair name — from list_keypairs (for operating the DB VM).
namestringyesName for the managed database (lowercase letters, numbers, hyphens).
network_idstringyesPrivate network id — from list_private_networks. The DB is reachable only from this network.
security_group_namesarray
versionstringEngine version (e.g. mysql '8.0', mariadb '11.4'). Defaults to the engine's current major if omitted.
NameTypeReqDescription
available_keypairsarray
duplicateboolean
errorboolean
idempotency_keystring
invalid_keypair_nameboolean
modestring
needs_keypairboolean
needs_keypair_nameboolean
needs_planboolean
nextstring
plan_toolstring
request
result
validation

No examples provided.

create_snapshot ~32

Creates a snapshot of a running instance.

NameTypeReqDescription
instanceIdstringyes
snapshotNamestringyes
NameTypeReqDescription
available_keypairsarray
duplicateboolean
errorboolean
idempotency_keystring
invalid_keypair_nameboolean
modestring
needs_keypairboolean
needs_keypair_nameboolean
needs_planboolean
nextstring
plan_toolstring
request
result
validation

No examples provided.

create_volume ~28

Creates a block storage volume.

NameTypeReqDescription
namestringyes
sizeintegeryes
NameTypeReqDescription
available_keypairsarray
duplicateboolean
errorboolean
idempotency_keystring
invalid_keypair_nameboolean
modestring
needs_keypairboolean
needs_keypair_nameboolean
needs_planboolean
nextstring
plan_toolstring
request
result
validation

No examples provided.

delete_backup ~27

Deletes a backup by ID.

NameTypeReqDescription
idstringyesID of the resource to delete.
NameTypeReqDescription
deletedboolean
idstring
modestring
nextstring

No examples provided.

delete_clickhouse ~49

Deletes a managed ClickHouse database and its underlying VM. Pass the numeric id from list_clickhouse_databases. This cannot be undone.

NameTypeReqDescription
idstringyesID of the resource to delete.
NameTypeReqDescription
deletedboolean
idstring
modestring
nextstring

No examples provided.

delete_cluster ~206

Deletes an autoscaling cluster — tears down the WHOLE Heat stack: every autoscaled EXTRA member VM, the Octavia load balancer, the pool, the cluster security group, and the cluster's *.redu.cloud proxy host. Your SOURCE (hero) VM is NOT part of the stack and is NOT deleted — it was the always-on baseline member but it is your own VM; delete_instance it separately if you no longer need it. Pass stack_name + stack_id from list_clusters. Deleting extra members individually does NOT work (the autoscaling group re-creates them under load) — this deletes the group itself. The managed database / external store the cluster used is NOT touched (data safety); delete_database it separately when you are done with the data. Cannot be undone.

NameTypeReqDescription
stack_idstringyesCluster (Heat stack) id — from list_clusters (id).
stack_namestringyesCluster (Heat stack) name — from list_clusters (stack_name).
NameTypeReqDescription
deletedboolean
modestring
nextstring
stack_idstring

No examples provided.

delete_database ~47

Deletes a managed Postgres database and its underlying VM. Pass the numeric database id from list_databases. This cannot be undone.

NameTypeReqDescription
idstringyesID of the resource to delete.
NameTypeReqDescription
deletedboolean
idstring
modestring
nextstring

No examples provided.

delete_deployment ~87

Deletes a deployment and its underlying app VM. Pass the numeric id from list_deployments. IMPORTANT: if the deployment used database:'managed', the managed Postgres VM is NOT deleted (data safety) — this tool returns its id so you can delete_database it when you're done with the data. Cannot be undone.

NameTypeReqDescription
idintegeryesDeployment id from list_deployments.
NameTypeReqDescription
deletedboolean
idnumber
managed_db
modestring
nextstring

No examples provided.

delete_instance ~32

Permanently deletes an instance. This cannot be undone.

NameTypeReqDescription
idstringyesID of the resource to delete.
NameTypeReqDescription
deletedboolean
idstring
modestring
nextstring

No examples provided.

delete_keypair ~34

Removes an SSH keypair from your account by name.

NameTypeReqDescription
namestringyesName of the keypair to delete.
NameTypeReqDescription
deletedboolean
modestring
namestring

No examples provided.

delete_redis ~46

Deletes a managed Redis instance and its underlying VM. Pass the numeric id from list_redis. This cannot be undone.

NameTypeReqDescription
idstringyesID of the resource to delete.
NameTypeReqDescription
deletedboolean
idstring
modestring
nextstring

No examples provided.

delete_relational_database ~53

Deletes a managed MySQL/MariaDB database and its underlying VM. Pass the numeric id from list_relational_databases. This cannot be undone.

NameTypeReqDescription
idstringyesID of the resource to delete.
NameTypeReqDescription
deletedboolean
idstring
modestring
nextstring

No examples provided.

delete_snapshot ~27

Deletes a snapshot by ID.

NameTypeReqDescription
idstringyesID of the resource to delete.
NameTypeReqDescription
deletedboolean
idstring
modestring
nextstring

No examples provided.

delete_volume ~101

Permanently deletes a block storage volume and the data on it. This cannot be undone. The volume must be 'available' (detached) — detach_volume it first, and note you cannot detach a running instance's boot disk. A volume left behind after a restore keeps billing, so delete the ones you no longer need. Any BACKUP the volume was restored from is independent and survives this.

NameTypeReqDescription
idstringyesID of the resource to delete.
NameTypeReqDescription
deletedboolean
idstring
modestring
nextstring

No examples provided.

deploy_app ~2,376

Deploys an app to a VM and exposes it at a public https://<name>-<id>.redu.cloud URL. The container is built ON the VM. PREREQS — run check_deploy_prerequisites first for network_id + keypair_name, then plan_deploy for cost approval. Source can be git repo or prepare_upload source_token. PORT must be the real app listen port. To wire a DB, pass database:'managed' (dedicated managed datastore VM on the same private network, reused on same-name redeploy) or database:'single_vm' for Postgres on the app VM. Choose db_engine ('postgres' default; 'mysql'/'mariadb' for WordPress/Matomo/LAMP, managed only). For WordPress/WooCommerce cluster intent, do not use generic stateless deploy: pass app_profile, cluster_target:true, database:'managed', db_engine:'mariadb' or 'mysql', cluster_media_mode:'media_space', and either media_space_id or create_media_space:true. Redu mounts the media space into wp-content/uploads and refuses unsafe local uploads. Build+provision takes minutes; poll list_deployments/get_deployment.

NameTypeReqDescription
app_profilestringDetected app profile from source inspection. For WordPress/WooCommerce pass wordpress/woocommerce so cluster deploys enforce managed DB + shared media instead of treating local uploads as stateless.
cluster_media_modestringRecord the WordPress media strategy for future clustering. For real WordPress clusters use media_space by default: Redu mounts a shared uploads filesystem into every member. local_uploads is single-V…
cluster_targetbooleanSet TRUE when the user asked to deploy this app as an autoscaling cluster. For WordPress/WooCommerce this makes the backend require managed MySQL/MariaDB plus media_space/central_media_origin before…
contextstringBuild-context dir within the source (default: repo root, or `subdir`). Set when the Dockerfile lives in a subfolder but builds from the repo root.
create_media_spacebooleanFor WordPress/WooCommerce cluster_target:true: set TRUE when no suitable media space exists. Redu creates an NFS media VM + persistent volume and mounts it into /var/www/html/wp-content/uploads.
databasestringDB wiring (auto-injects the connection env + DATABASE_URL — zero setup): 'single_vm' = Postgres ON the app VM (cheapest, data dies when the VM is replaced; Postgres only); 'managed' = a SEPARATE mana…
db_enginestringManaged-DB engine (default 'postgres'). 'mysql'/'mariadb' provision a managed MySQL/MariaDB VM and wire MYSQL_HOST/MYSQL_PORT/MYSQL_USER/MYSQL_PASSWORD/MYSQL_DATABASE + a mysql:// DATABASE_URL — use…
db_extensionsarraymanaged/single_vm Postgres only: extensions to pre-install (pgvector, postgis, pgaudit, pg_trgm, …). Pass when the app needs one — e.g. langfuse/lantern need pgvector — so you don't have to CREATE EX…
db_flavor_idstringmanaged only: VM size for the dedicated Postgres (from list_flavors). Defaults to the app flavor; m1.small is plenty for most. plan_deploy sizes this for you.
db_idintegerInformational link to a managed Postgres (from create_database/list_databases).
db_namestringDB name for single_vm/managed (default 'app').
db_superuserbooleanmanaged/single_vm Postgres only: grant the app DB user SUPERUSER (dedicated single-tenant DB VM, so safe). Use when the app's migrations create extensions/roles themselves.
db_userstringDB user for single_vm/managed (default 'appuser').
db_versionstringDB version for single_vm/managed. Postgres: '16'|'15'|'14' (default 16). MySQL: '8.0'. MariaDB: '11.4'|'10.11'. Defaults per engine if omitted.
dnamestringCustom *.redu.cloud subdomain. For a STABLE, KNOWN-AHEAD URL (needed when the app must be told its OWN url — OAuth callbacks, cookie domain, a frontend that calls its API), generate the FULL auto-gen…
dockerfilestringPath within the source to the Dockerfile (e.g. 'scripts/Dockerfile') when it's NOT at the root. Pair with `context` when the Dockerfile is in a subfolder but COPYs from the repo root.
dockerfile_contentstringA Dockerfile to write into the build dir before building — pass the Dockerfile that plan_deploy generated when the repo has none, or to override a broken one. (In upload mode you can instead just inc…
envobjectEnv vars injected into the container at deploy time (e.g. PGHOST/PGPORT/PGUSER/PGPASSWORD/PGDATABASE from a managed Postgres). Never baked into the image.
flavor_idstringInstance size — from list_flavors. Default m1.medium (enough RAM to build on the VM). For a RAM-heavy app whose state is in a managed DB (Next.js/cal.com, Rails, JVM), prefer m1.mem16/m1.mem32: full…
git_refstringgit mode only: branch/tag/commit to deploy (default: the repo's default branch).
git_tokenstringgit mode only: token to clone a PRIVATE repo. Omit for public repos.
idempotency_keystring
keypair_namestringyesREQUIRED. An EXISTING SSH keypair name — call list_keypairs and reuse one, or import_keypair first.
media_mount_pathstringHost mount path on the app VM/member. Redu mounts this into /var/www/html/wp-content/uploads.
media_origin_urlstringPublic base URL where WordPress wp-content/uploads is served when using central_media_origin. Do not put this on the DB VM.
media_space_flavor_idstringFlavor id for the media VM when create_media_space:true. Defaults to m1.small/backend default.
media_space_idintegerExisting Redu media space id to mount at WordPress wp-content/uploads. Get it from list_media_spaces.
media_space_namestringOptional media space name when create_media_space:true. Defaults to <deployment-name>-media.
media_space_size_gbintegerMedia space data volume size in GB when create_media_space:true (default 20).
namestringyesName for the deployment / VM (lowercase letters, numbers, hyphens).
network_idstringExisting private network id — from check_deploy_prerequisites (auto-selects your default) or list_private_networks. Optional: if omitted, redu auto-selects your default network.
portintegerREQUIRED in practice: the port the app actually listens on inside the container — pass the port plan_deploy detected / the Dockerfile EXPOSE / the framework default. redu probes THIS port for health,…
redisstringRedis wiring (auto-injects REDIS_URL/REDIS_HOST/REDIS_PORT/REDIS_PASSWORD — zero setup): 'managed' = a SEPARATE managed Redis VM auto-provisioned + wired on the same private network (data persists ac…
redis_flavor_idstringmanaged Redis only: the dedicated Redis VM size (from list_flavors). Defaults to the app flavor; m1.small is plenty for a cache.
redis_passwordstringmanaged Redis only: a specific password to set (otherwise auto-generated).
redis_versionstringmanaged Redis only: version (default '7').
repostringGIT MODE: public git repo URL (https). For a PRIVATE repo also pass git_token. Omit when using source_token (upload mode).
runtimestringInformational: node/python/go/… (e.g. from plan_deploy).
security_group_namesarray
source_tokenstringUPLOAD MODE: token from prepare_upload's curl step — deploys an uploaded tarball of your LOCAL working dir (no git, no PAT). Use this to deploy uncommitted code, a fixed clone of a repo you don't own…
subdirstringBuild context within the source (e.g. 'demo-go') when the Containerfile/Dockerfile isn't at the root.
workerbooleanHEADLESS WORKER / daemon mode. Deploys a long-running container with NO HTTP server, NO public URL, and NO health probe — ready = the container stays running. The VM still gets a floating IP + SSH st…
NameTypeReqDescription
available_keypairsarray
duplicateboolean
errorboolean
idempotency_keystring
invalid_keypair_nameboolean
modestring
needs_keypairboolean
needs_keypair_nameboolean
needs_planboolean
nextstring
plan_toolstring
request
result
validation

No examples provided.

deploy_compose ~2,012

Deploys a MULTI-CONTAINER app — a repo that ships docker-compose.yml / compose.yaml — onto ONE VM via podman-compose, and exposes one or more services at redu.cloud URLs. Use this instead of deploy_app when the repo is a compose stack. Same prereqs + source modes as deploy_app; always run plan_deploy first. PORT is the HOST port for the exposed service. DB: 'compose' uses the stack's own db container; 'managed' provisions a separate managed Postgres/MySQL/MariaDB VM and appends connection env. For WordPress/WooCommerce cluster intent, do not leave the compose db service/local uploads as state: pass app_profile, cluster_target:true, database:'managed', db_engine:'mariadb' or 'mysql', cluster_media_mode:'media_space', and either media_space_id or create_media_space:true. Redu writes an override file that points the WordPress service at managed DB env and mounts the media space into /var/www/html/wp-content/uploads. Poll get_deployment until ready.

NameTypeReqDescription
app_profilestringDetected app profile from source inspection. For WordPress/WooCommerce pass wordpress/woocommerce so cluster deploys enforce managed DB + shared media instead of treating local uploads as stateless.
cluster_media_modestringRecord the WordPress media strategy for future clustering. For real WordPress clusters use media_space by default: Redu mounts a shared uploads filesystem into every member. local_uploads is single-V…
cluster_targetbooleanSet TRUE when the user asked to deploy this compose app as an autoscaling cluster. For WordPress/WooCommerce this requires managed MySQL/MariaDB plus media_space/central_media_origin.
compose_enginestringContainer engine for the compose build (default: the server's choice, usually podman). Set 'docker' to force the docker engine.
compose_filestringPath within the source to the compose file (e.g. 'deploy/docker-compose.yml'). Auto-detected (docker-compose.yml / compose.yaml / …) if omitted.
create_media_spacebooleanFor WordPress/WooCommerce cluster_target:true: set TRUE when no suitable media space exists. Redu creates an NFS media VM + persistent volume and mounts it into /var/www/html/wp-content/uploads.
databasestringDB mode: 'compose' (default) = use the compose file's OWN db service (self-contained, nothing extra provisioned); 'single_vm' = Postgres ON the app VM; 'managed' = a SEPARATE managed-PG/MySQL VM. For…
db_enginestringmanaged only: 'postgres' (default) → PG* env; 'mysql'/'mariadb' → MYSQL_* env. mysql/mariadb require database:'managed'.
db_extensionsarraysingle_vm/managed Postgres: extensions to pre-install (pgvector, postgis, pgaudit, …).
db_flavor_idstringmanaged only: the dedicated DB VM size (from list_flavors). Defaults to the app flavor.
db_namestringDB name for single_vm/managed (default 'app').
db_superuserbooleansingle_vm/managed Postgres: grant the DB user SUPERUSER (dedicated DB VM, so safe).
db_userstringDB user for single_vm/managed (default 'appuser').
db_versionstringDB version for single_vm/managed (Postgres '16'|'15'|'14'; MySQL '8.0'; MariaDB '11.4').
dnamestringCustom *.redu.cloud subdomain. For a STABLE, KNOWN-AHEAD URL (needed when the app must be told its OWN url — OAuth callbacks, cookie domain, a frontend that calls its API), generate the FULL auto-gen…
envobjectEnv vars APPENDED to the compose project's .env (for ${VAR} interpolation). We never rewrite your compose file.
exposearrayMULTI-SURFACE apps: expose several services, each gets its OWN *.redu.cloud URL. The FIRST entry is the primary one redu health-gates (its port overrides `port`). CRITICAL when one surface must KNOW…
flavor_idstringApp VM size — from list_flavors. A multi-container stack often wants m1.large+; plan_deploy sizes it.
git_refstringgit mode only: branch/tag/commit (default: the repo's default branch).
git_tokenstringgit mode only: token to clone a PRIVATE repo.
idempotency_keystring
keypair_namestringyesREQUIRED. An EXISTING SSH keypair name — from list_keypairs / import_keypair.
media_mount_pathstringHost mount path on the app VM/member. Redu mounts this into /var/www/html/wp-content/uploads.
media_origin_urlstringPublic base URL where WordPress wp-content/uploads is served when using central_media_origin. Do not put this on the DB VM.
media_space_flavor_idstringFlavor id for the media VM when create_media_space:true. Defaults to m1.small/backend default.
media_space_idintegerExisting Redu media space id to mount at WordPress wp-content/uploads. Get it from list_media_spaces.
media_space_namestringOptional media space name when create_media_space:true. Defaults to <deployment-name>-media.
media_space_size_gbintegerMedia space data volume size in GB when create_media_space:true (default 20).
migrate_commandstringOne-time DB prepare/migrate/seed, run AFTER `up -d` and BEFORE the app is marked ready — redu runs `podman-compose run --rm <migrate_service|service> <cmd>` (Rails `bundle exec rails db:prepare`, Dja…
migrate_servicestringCompose service to run migrate_command in (defaults to `service`).
namestringyesName for the deployment / VM (lowercase letters, numbers, hyphens).
network_idstringPrivate network id — auto-selected from check_deploy_prerequisites if omitted.
portintegerREQUIRED in practice: the HOST port the exposed service publishes (the LEFT side of its compose `ports:` mapping) — redu health-probes + proxies THIS port, so a wrong value fails the deploy. plan_dep…
redisstring'managed' = a SEPARATE managed Redis VM, auto-provisioned + wired; its REDIS_URL/REDIS_* is APPENDED to the project .env — your compose service must REFERENCE it to use it (we never rewrite your comp…
redis_flavor_idstringmanaged Redis only: the dedicated Redis VM size (from list_flavors). Defaults to the app flavor.
redis_passwordstringmanaged Redis only: a specific password to set (otherwise auto-generated).
redis_versionstringmanaged Redis only: version (default '7').
repostringGIT MODE: public git repo URL that ships a docker-compose file. Private repo also needs git_token. Omit when using source_token.
security_group_namesarray
servicestringThe compose SERVICE to expose at the public URL (informational; the exposed port is `port`).
source_tokenstringUPLOAD MODE: token from prepare_upload — deploys an uploaded tarball of your LOCAL dir (no git). Omit `repo` when set.
subdirstringDirectory within the source that contains the compose file (if not at the root).
NameTypeReqDescription
available_keypairsarray
duplicateboolean
errorboolean
idempotency_keystring
invalid_keypair_nameboolean
modestring
needs_keypairboolean
needs_keypair_nameboolean
needs_planboolean
nextstring
plan_toolstring
request
result
validation

No examples provided.

deploy_overview ~95

Orientation for deploying an app on redu.cloud: the end-to-end flow, the two source modes (git vs upload), how to handle a missing Dockerfile or a database, when (and when NOT) to split a deploy across multiple VMs, verifying a deploy functionally, and how to debug a failed build. Call this first when a user asks to deploy/ship/host an app and you're unsure where to start.

Input schema present but exposes no named parameters.

NameTypeReqDescription
flowarray
multi_vmarray
nextstring
source_modes
tipsarray

No examples provided.

deploy_vpn ~418

Stands up a redu VPN gateway (WireGuard tunnelled over wstunnel on WSS/443) on your PRIVATE network, so you (or your team) can reach the private IPs of the VMs you deployed on redu, over a single https endpoint — no UDP, no extra ports. This is the TENANT VPN for reaching your OWN deployed resources; it is NOT a general internet VPN. GUARDRAIL: the first call does NOT deploy — it returns the plan + hourly cost for approval, because it creates a BILLED VM. Show the user, get their explicit 'go', then call again with confirm:true (required even in yolo mode). The gateway asset is redu's, deployed onto YOUR VM (you can SSH in to read it). Fresh WireGuard keys are generated per deploy; the client PRIVATE key is returned ONCE and is never stored server-side.

NameTypeReqDescription
client_cidrstringYour tenant PRIVATE-network CIDR (e.g. '10.1.0.0/24') so the client routes it through the tunnel. If omitted, the returned client config only routes the tunnel subnet and you add your CIDR to Allowed…
confirmbooleanSet true ONLY after the user has explicitly approved (the first call returns the plan + cost). Do NOT set it yourself.
flavor_idstringGateway VM size (from list_flavors). The gateway is light; m1.small ('2') is plenty.
keypair_namestringyesREQUIRED. An EXISTING SSH keypair name (from list_keypairs / import_keypair) for the gateway VM.
namestringDeployment name (default auto 'vpn-<id>'). Becomes the VM name + the wss://<name>.redu.cloud endpoint.
network_idstringPrivate network id (from list_networks). Auto-selected from your default private network if omitted — the VMs you want to reach must be on this network.
NameTypeReqDescription
access_pointstring
billing_noticestring
client_configstring
client_launcharray
deployment
errorboolean
modestring
needs_confirmationboolean
nextstring
server_public_keystring
validation
warningstring

No examples provided.

detach_volume ~173

Detaches a block volume from an instance, leaving the volume (and its data) intact and 'available' to attach elsewhere. Unmount it INSIDE the guest first (`umount /mnt/...`) or you risk a dirty filesystem. You cannot detach an instance's ROOT/boot disk while it runs. Use this to move a data volume to another VM, or to free a restore target before restore_backup writes into it. Poll list_volumes until status is 'available'.

NameTypeReqDescription
instance_idstringyesInstance to attach it to / detach it from — from list_instances (id).
volume_idstringyesVolume to attach/detach — from list_volumes (id). For a recovery, this is the volume restore_backup created (restore_backup with volumeName makes a NEW volume from a backup).
NameTypeReqDescription
available_keypairsarray
duplicateboolean
errorboolean
idempotency_keystring
invalid_keypair_nameboolean
modestring
needs_keypairboolean
needs_keypair_nameboolean
needs_planboolean
nextstring
plan_toolstring
request
result
validation

No examples provided.

get_agent_status ~107

Returns the current status of your controller VM. On a freshly set-up VM also returns the trigger token needed to authorize the fleet and to call trigger_agent_batch. Call this after setup_agent_fleet to confirm the VM is ready.

NameTypeReqDescription
controller_urlstringyesHTTPS URL of your controller VM, e.g. https://redu-controller-abc123.redu.cloud
log_tokenstringLog token for fetching controller logs (optional — returned by this tool on first call)
NameTypeReqDescription
status

No examples provided.

get_deployment ~118

Fetches ONE deployment by its numeric id (from list_deployments). Returns its current status, the public access_point URL, the underlying VM id, AND the build_log — read this when status is 'build_failed' or 'error' to see exactly why the on-VM build/run failed (no SSH needed). Also returns a reality report_markdown showing the REAL provisioned size + cost (the plan was only an estimate; the user may have up-sized).

NameTypeReqDescription
idintegeryesDeployment id from list_deployments.
NameTypeReqDescription
build_logstring|null
deployment
modestring
nextstring
redu_md_filenamestring
redu_md_markdownstring
report_markdownstring

No examples provided.