Skip to content
MisterShell

One control plane. Workers everywhere.

A self-hosted core server runs the UI, API, event bus, and session gateway; lightweight workers connect outbound from each site to reach your resources. Sensors and proxies follow the same model. State lives in the core, so workers stay stateless and disposable.

Self-hosted Outbound-only workers Single container or scaled Docker & Kubernetes
What a large-scale deployment looks like
Workers, sensors and proxies checking in to the core over outbound connections
Workers, sensors and proxies checking in to the core — outbound only, no inbound rules

MisterShell at a Glance

Click any component to see what it does and how it connects.

How it fits together

Three cooperating tiers

Core server (control plane)

A single container serving the web UI, REST API, real-time event bus, and session gateway. It stores inventory, configuration history, session recordings, automation playbooks, licenses, and identities — backed by a relational store and a high-performance in-memory store, embedded by default or pointed at services you operate.

Workers & remote components

Workers deploy close to your resources and open a single authenticated outbound connection to the core — no inbound firewall rules. They handle connectivity checks, snapshots, session proxying, and automation actions. IDS sensors and external-guest proxies are remote components that follow the same outbound, token-enrolled, live-status model.

Surfaces: UI, SSH, API, Terraform & MCP

Multiple surfaces over one data model and a shared real-time event stream: the browser UI for everything across the platform; an SSH surface served by the core itself, so engineers can work from their own terminal — with the resource tree, tabbed sessions and in-session AI — and automation such as Ansible can reach devices through MisterShell rather than around it; a REST API for scripts, CI pipelines, and integrations; an official Terraform provider to manage inventory, locations, and credentials as code; and a built-in MCP endpoint that gives external AI agents permission-scoped, read-only-by-default access to inventory, changelog, and diagnostics — audited end to end, with agent platforms signing in through your own identity provider (Pro edition). Whichever surface you come in by, the same permissions, policy, approvals and recording apply.

Deployment

Start in one container. Scale when you need to.

Embedded

A single command brings up a complete workspace — embedded data services and an embedded worker handle everything reachable from the core host. Ideal for evaluation and single-zone estates.

External data services

Point the cores at the PostgreSQL and Redis you already run, plus an object store for recordings — the hot cache can stay per-core — to decouple backup, DR, and upgrade cadence, and to run MisterShell horizontally.

Remote workers

Add workers per site, region, or network segment to reach resources in separate zones, with task routing by location. Add them to a live deployment at any time (remote workers come with the Pro edition).

Self-hosted, your data

Distributed as core, worker, proxy, and sensor container images for Docker or Kubernetes. You install it on your own infrastructure; your data never leaves your environment. A built-in operator console covers the day-two chores — scheduled database backups, validated single-core restores, licence install, and admin recovery.

From one container to a global fleet

Start on a single container and grow to an external database with worker fleets across regions and segmented sites.

What a large-scale deployment looks like

Get in Touch

Want a guided demo, or a trial license to evaluate Pro or Enterprise on your own infrastructure? Tell us — we'd love to hear from you.