A free, open-source, self-hosted alternative to Vercel/InstaPods and other centralized deploy platforms. An MCP server that runs persistent app containers on your own machine (via Docker/colima) and exposes them publicly with Cloudflare quick tunnels.
InstaServer has 12 well-named tools with clear verb-noun patterns (deploy_pod, create_pod, delete_pod, etc.). All tools have descriptions (avg ~150 chars, within baseline 194). Input schemas are present and use Zod with type constraints (enums for presets/actions, string for names). However, several parameter descriptions are minimal or missing entirely. Output schemas are not documented, LLMs cannot predict response structure. Error handling returns generic fail() responses without recovery guidance. No tool annotations (readOnlyHint/destructiveHint) despite clear risk levels. The deploy_pod tool is well-designed for composition, but exec_command and write_file lack safety guardrails.
Create a new empty pod (a persistent Docker container + volume) without deploying app files yet. Usually you can skip this and call deploy_pod directly.
Permanently delete a pod: removes its container, volume, and tunnel.
Deploy files to a pod. Creates the pod if it doesn't exist, uploads the given files, installs dependencies, (re)starts the app, opens a public HTTPS URL via a Cloudflare quick tunnel, and checks it answers. This is the main tool — one call to go from source files to a live URL.
Run a shell command inside a pod's container and return stdout/stderr/exit code.
Get the recent stdout/stderr logs from a pod's app process.
Get details for one pod, including its public URL and status.
No output schemas documented. LLMs cannot predict response structure (fields, types, pagination). Forces agents to guess what data is available after each call.
Missing tool annotations (readOnlyHint, destructiveHint, idempotentHint). Tools like delete_pod and exec_command have clear risk levels but are not marked. Agents cannot distinguish safe reads from destructive writes.
Error handling returns generic fail() with only error message text. No recovery guidance, error classification, or actionable next steps. LLMs cannot self-correct or plan recovery.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 72 | 2026-07-28+ | v2 |
List files under a path inside a pod's app root.
List all pods and their status.
List the runtime presets InstaServer can deploy (static/nginx, nodejs, python) and what each expects.
Start, stop, restart, or reload (alias for restart) a pod's container.
Read a text file from inside a pod's app root.
Write (or overwrite) a single file inside a pod's app root without a full redeploy.
exec_command and write_file lack input validation and safety guardrails. No mention of command injection prevention, path traversal checks, or confirmation for destructive operations.
Parameter descriptions are minimal. 'name' appears in 11 tools with identical description 'Pod name', no guidance on format, constraints, or examples. 'command' in exec_command has no length limits or injection warnings.