Zerto's tagged checkpoint insert takes exactly one field. The 10.x swagger model VpgInsertTagCheckpointDataApi has a single property, checkpointName, and the 9.0 API reference lists CheckpointName as the only request value. There is no description field, so who the agent is and what it is about to do have to live inside the name. Old name: ai:claude:chg-412:20260921T170829Z New name: ai:claude | edit /home/justin/app-config.yaml | vm=jp-ubuntu | change=chg-412 | 20260921T170829Z zerto_create_tagged_checkpoint and zerto_guard_before_mutate take a new action argument: free text saying what the agent is about to do. The VM name is filled in from the find result. An operator reading the journal in the Zerto UI can now see which agent inserted a checkpoint and why, without the agent transcript. Field text is sanitised so the name stays one readable line: control characters and runs of whitespace collapse to single spaces, ';' becomes ',' because Zerto appends "; Used for File Level Restore" to its own tags, and '|' becomes '/' because ' | ' is our field separator. Capped at TAG_MAX_LEN (250). Measured against ZVM 10.x while picking the format: - names of at least 400 chars are accepted, and spaces, slashes, parentheses, '=' and '|' all survive the round trip - tagged checkpoint inserts fired back to back at one VPG are silently dropped. The POST returns 200 and queues a task, but only the first checkpoint appears. tag_vpgs already inserts then waits per VPG, so it is correct; added a comment so nobody turns that loop into an asyncio.gather(). Verified end to end: guard inserted cp 1197 on VPG jp-ubuntu, the name read back byte-identical from the journal, and FLR from that checkpoint returned the 158 byte pre-mutation file. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]> Claude-Session: https://claude.ai/code/session_016yVfC5nvZowoLFnEGWhLGn
75 lines
2.5 KiB
Markdown
75 lines
2.5 KiB
Markdown
# zerto-ai-rewind
|
|
|
|
PoC MCP that makes an agent pin a Zerto tagged checkpoint before it changes a VM, then pull a file back from that tag.
|
|
|
|
If the loop works, these tools are the delta to add to official ZVM MCP (`ZVM.MCP`, 10.9). This repo is one MCP process for the demo. It is not a second full ZVM catalog.
|
|
|
|
## What it does
|
|
|
|
1. `zerto_find_protection` — VM name, hostname, or vmIdentifier to exactly one VM and every VPG. Zero or two-plus VMs: stop.
|
|
2. `zerto_create_tagged_checkpoint` / `zerto_guard_before_mutate` — same tag on every protecting VPG, wait until listed. The name records which agent and what it is doing: `ai:<agent> | <action> | vm=<vm> | change=<id> | <utc>`.
|
|
3. `zerto_recover_file` — FLR after a human sets `confirmed=true`.
|
|
4. Mutating catalog — opt-in list of MCP tools that must be guarded. Unlisted tools pass through. Users add entries.
|
|
|
|
Official ZVM MCP already has inventory and failover test. It does not insert tagged checkpoints or run FLR.
|
|
|
|
## Setup
|
|
|
|
Python 3.12+.
|
|
|
|
```bash
|
|
python3 -m venv .venv
|
|
source .venv/bin/activate
|
|
pip install -e ".[dev]"
|
|
cp config.example.json config.json
|
|
# edit zerto_url, username, password
|
|
```
|
|
|
|
Keycloak password-grant, client_id `zerto-client` on 10.x. Appliance certs are self-signed; `verify_tls` defaults to false.
|
|
|
|
stdio MCP (Claude Desktop, VS Code, Cursor, OpenCode):
|
|
|
|
```json
|
|
{
|
|
"mcpServers": {
|
|
"zerto-rewind": {
|
|
"command": "zerto-rewind-mcp",
|
|
"env": {
|
|
"ZERTO_REWIND_CONFIG": "/absolute/path/to/config.json"
|
|
}
|
|
}
|
|
}
|
|
}
|
|
```
|
|
|
|
Copy `skills/zerto-rewind/SKILL.md` into the client's skill path.
|
|
|
|
```bash
|
|
pytest
|
|
```
|
|
|
|
## Demo
|
|
|
|
Protected app VM. Agent is about to edit a guest config file.
|
|
|
|
1. Guard: discover VPG set, insert tagged checkpoint, wait.
|
|
2. Agent writes the bad config.
|
|
3. Human confirms.
|
|
4. `zerto_recover_file` from that tag.
|
|
|
|
Git never had the file. RPO is the journal, not last night's backup.
|
|
|
|
## Certified for this PoC
|
|
|
|
vSphere ZVM 10.x and ZCA on AWS/Azure, same REST paths. HVM is out (separate swagger). Failover Live is not a tool.
|
|
|
|
Tagged checkpoints cannot be inserted when the **protected** site is Azure or AWS (Zerto API). Point this server at the vSphere protected ZVM.
|
|
|
|
## Not this product
|
|
|
|
[Moholo Agent Rewind](https://github.com/moholo-founder/agent-rewind) snapshots the agent's laptop tools. This server uses the Zerto journal as the snapshot store. Do not copy their file blobs.
|
|
|
|
## Upstream
|
|
|
|
Ask Zerto engineering to add to `ZVM.MCP`: find-by-unique-VM-with-all-VPGs, tagged checkpoint insert that waits, FLR. Keep VPG settings CRUD where it already is.
|