# Local Ydb MCP server

Agent View of the PolicyLayer registry record for Local Ydb: identity, probed posture, risk grade, and all 38 tools classified. HTML page: https://policylayer.com/tools/local-ydb

## Facts

- Server id: `@astandrik/local-ydb-mcp`
- Install: `npx -y @astandrik/local-ydb-mcp`
- Homepage: git+https://github.com/astandrik/local-ydb-toolkit.git
- Registry record: grade F, identity unverified
- Lifecycle: active
- Rate-limited: no
- Tools: 38
- Tool categories present: Destructive, Execute, Read, Write
- Tags: local ydb, admin, automation
- Record last modified: 2026-06-29T15:39:23.409Z

## Tools (38)

| Tool | Category | Risk | Record |
| --- | --- | --- | --- |
| `local_ydb_cleanup_storage` | Destructive | Critical | https://policylayer.com/tools/local-ydb/local-ydb-cleanup-storage.md |
| `local_ydb_destroy_stack` | Destructive | Critical | https://policylayer.com/tools/local-ydb/local-ydb-destroy-stack.md |
| `local_ydb_remove_dynamic_nodes` | Destructive | Critical | https://policylayer.com/tools/local-ydb/local-ydb-remove-dynamic-nodes.md |
| `local_ydb_add_dynamic_nodes` | Execute | High | https://policylayer.com/tools/local-ydb/local-ydb-add-dynamic-nodes.md |
| `local_ydb_apply_auth_hardening` | Execute | High | https://policylayer.com/tools/local-ydb/local-ydb-apply-auth-hardening.md |
| `local_ydb_bootstrap` | Execute | High | https://policylayer.com/tools/local-ydb/local-ydb-bootstrap.md |
| `local_ydb_bootstrap_root_database` | Execute | High | https://policylayer.com/tools/local-ydb/local-ydb-bootstrap-root-database.md |
| `local_ydb_check_prerequisites` | Execute | High | https://policylayer.com/tools/local-ydb/local-ydb-check-prerequisites.md |
| `local_ydb_pull_image` | Execute | High | https://policylayer.com/tools/local-ydb/local-ydb-pull-image.md |
| `local_ydb_restart_stack` | Execute | High | https://policylayer.com/tools/local-ydb/local-ydb-restart-stack.md |
| `local_ydb_start_dynamic_node` | Execute | High | https://policylayer.com/tools/local-ydb/local-ydb-start-dynamic-node.md |
| `local_ydb_upgrade_version` | Execute | High | https://policylayer.com/tools/local-ydb/local-ydb-upgrade-version.md |
| `local_ydb_auth_check` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-auth-check.md |
| `local_ydb_container_logs` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-container-logs.md |
| `local_ydb_database_status` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-database-status.md |
| `local_ydb_dump_tenant` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-dump-tenant.md |
| `local_ydb_generate_schema` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-generate-schema.md |
| `local_ydb_graphshard_check` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-graphshard-check.md |
| `local_ydb_healthcheck` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-healthcheck.md |
| `local_ydb_inventory` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-inventory.md |
| `local_ydb_list_dumps` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-list-dumps.md |
| `local_ydb_list_versions` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-list-versions.md |
| `local_ydb_nodes_check` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-nodes-check.md |
| `local_ydb_pull_status` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-pull-status.md |
| `local_ydb_reduce_storage_groups` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-reduce-storage-groups.md |
| `local_ydb_scheme` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-scheme.md |
| `local_ydb_status_report` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-status-report.md |
| `local_ydb_storage_leftovers` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-storage-leftovers.md |
| `local_ydb_storage_placement` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-storage-placement.md |
| `local_ydb_tenant_check` | Read | Low | https://policylayer.com/tools/local-ydb/local-ydb-tenant-check.md |
| `local_ydb_add_storage_groups` | Write | Medium | https://policylayer.com/tools/local-ydb/local-ydb-add-storage-groups.md |
| `local_ydb_apply_schema` | Write | Medium | https://policylayer.com/tools/local-ydb/local-ydb-apply-schema.md |
| `local_ydb_create_tenant` | Write | Medium | https://policylayer.com/tools/local-ydb/local-ydb-create-tenant.md |
| `local_ydb_permissions` | Write | Medium | https://policylayer.com/tools/local-ydb/local-ydb-permissions.md |
| `local_ydb_prepare_auth_config` | Write | Medium | https://policylayer.com/tools/local-ydb/local-ydb-prepare-auth-config.md |
| `local_ydb_restore_tenant` | Write | Medium | https://policylayer.com/tools/local-ydb/local-ydb-restore-tenant.md |
| `local_ydb_set_root_password` | Write | Medium | https://policylayer.com/tools/local-ydb/local-ydb-set-root-password.md |
| `local_ydb_write_dynamic_auth_config` | Write | Medium | https://policylayer.com/tools/local-ydb/local-ydb-write-dynamic-auth-config.md |

## Tool descriptions

- `local_ydb_cleanup_storage` — Delete only the explicitly supplied local-ydb host paths or Docker volumes. Use after inspecting local_ydb_storage_leftovers; without confirm=true this returns the cleanup plan and removes nothing.
- `local_ydb_destroy_stack` — Remove tenant metadata, local-ydb containers, network, and storage for a profile, with optional host-path cleanup.
- `local_ydb_remove_dynamic_nodes` — Remove extra dynamic tenant nodes one at a time and verify nodelist disappearance when the node IC port can be resolved.
- `local_ydb_add_dynamic_nodes` — Add extra dynamic tenant nodes beyond the configured primary dynamic node, one at a time. Without confirm=true it returns container/port plans; with confirm=true it starts each node, verifies its IC port appears in viewer/json nodelist, …
- `local_ydb_apply_auth_hardening` — Apply a reviewed hardened YDB config file and restart local-ydb so auth settings take effect. Use only after preparing and reviewing the config; without confirm=true this returns the apply/restart plan only.
- `local_ydb_bootstrap` — Bootstrap a tenant topology: static node with GraphShard flags, configured CMS tenant, and primary dynamic tenant node. Use only for tenant, GraphShard, dump/restore, or dynamic-node scenarios; without confirm=true this returns the full …
- `local_ydb_bootstrap_root_database` — Bootstrap a plain local YDB database at /local with only a static node. Use for generic local database requests that do not need a CMS tenant, GraphShard, or dynamic nodes; without confirm=true this returns the image preflight, Docker ne…
- `local_ydb_check_prerequisites` — Check target-host prerequisites for Docker, curl, ruby, and the configured rootPasswordFile when present. Without confirm=true it returns checks, missing items, manual actions, and any apt-get install plan; with confirm=true it may insta…
- `local_ydb_pull_image` — Plan or start a background Docker pull for a local-ydb image on the selected target. Without confirm=true it returns inspect and pull commands only; with confirm=true it returns a jobId for local_ydb_pull_status unless the image is alrea…
- `local_ydb_restart_stack` — Restart the selected profile by stopping dynamic and static containers, starting the static node, ensuring the configured tenant, then starting the dynamic node. Use after config or runtime changes; without confirm=true this returns the …
- `local_ydb_start_dynamic_node` — Start the configured primary dynamic tenant node for an existing CMS tenant. Use after local_ydb_create_tenant or when admin status is PENDING_RESOURCES; use local_ydb_add_dynamic_nodes for extra nodes. Without confirm=true this returns …
- `local_ydb_upgrade_version` — Upgrade a file-backed, volume-backed local-ydb profile to a target image tag. Use only for version upgrades on profiles without bindMountPath; it preflights source and target images, dumps, rebuilds, restores, reapplies auth when configu…
- `local_ydb_auth_check` — Read-only auth audit that checks anonymous viewer whoami status and configured YDB CLI tenant access, using root credentials when rootPasswordFile is configured. Use after auth hardening or password rotation to verify the expected posture.
- `local_ydb_container_logs` — Read recent Docker logs from the configured static or primary dynamic local-ydb container. Use when bootstrap, restart, or readiness checks fail; target selects the container role and lines controls the tail length.
- `local_ydb_database_status` — Read-only YDB admin database status for the configured tenant path. Returns the command, stdout, stderr, and ok flag; use this for tenant state before bootstrap/restart troubleshooting, and use local_ydb_tenant_check for scheme reachabil…
- `local_ydb_dump_tenant` — Dump the configured tenant or a tenant-relative path using a local-ydb helper container on the static container network. It creates profile.dumpHostPath/dumpName, excludes .sys objects, writes the dump under dumpName/tenant, and without …
- `local_ydb_generate_schema` — Read-only structured YDB table DDL generator. It renders strict JSON specs for CREATE TABLE, ALTER TABLE, DROP TABLE, and secondary indexes, returns the generated script with official references and warnings, and can optionally validate …
- `local_ydb_graphshard_check` — Read-only GraphShard check through viewer/json capabilities and tabletinfo for the configured tenant. Returns graphShardExists, tablet ids, and viewer status details; use after tenant bootstrap when GraphShard support or tablet visibilit…
- `local_ydb_healthcheck` — Read-only YDB monitoring healthcheck for the configured tenant or root database. Uses the official YDB CLI SelfCheck path, returns selfCheckResult, issue counts, issue types, capped raw output, and whether the database is healthy; use af…
- `local_ydb_inventory` — Read-only Docker inventory for a local-ydb target profile. Returns the public profile, Docker containers and volumes visible on the selected target, and inspect data for the configured static and primary dynamic containers; use before mu…
- `local_ydb_list_dumps` — Read-only list of available tenant dumps under profile.dumpHostPath. Use before restore to choose a dumpName; it only reports top-level dump directories that contain the existing tenant dump folder.
- `local_ydb_list_versions` — List published registry tags for a local-ydb container image, with numeric version tags sorted newest first. Use before local_ydb_upgrade_version to choose a target tag; pageSize and maxPages bound registry pagination and the response re…
- `local_ydb_nodes_check` — Read-only check of dynamic node registration through viewer/json nodelist. Use after starting, adding, or removing dynamic nodes; use local_ydb_tenant_check first when tenant reachability is unknown.
- `local_ydb_pull_status` — Check the status of a background Docker image pull started by local_ydb_pull_image.
- `local_ydb_reduce_storage_groups` — Reduce NumGroups for a tenant storage pool by dumping the tenant, rebuilding the profile stack with a smaller storagePoolCount, restoring the dump, and reapplying auth when needed.
- `local_ydb_scheme` — Read-only YDB scheme list or describe with capped stdout/stderr. It uses the root database for rootDatabase paths and the tenant database otherwise; list supports recursive/long/onePerLine flags, describe supports stats, and incompatible…
- `local_ydb_status_report` — Read-only aggregate report for quick diagnosis. Runs local_ydb_inventory, local_ydb_auth_check, local_ydb_tenant_check, local_ydb_nodes_check, and local_ydb_healthcheck, returning each result; use this first for broad stack health, then …
- `local_ydb_storage_leftovers` — Read-only search for candidate leftover local-ydb Docker volumes, dumps, and PDisk/data paths. It scans Docker volume names plus profile.storageSearchPaths and deletes nothing; use before local_ydb_cleanup_storage to decide exact paths o…
- `local_ydb_storage_placement` — Read-only storage inspection that returns ReadStoragePool output and BSC physical placement. Use before adding or reducing storage groups to confirm the exact pool shape.
- `local_ydb_tenant_check` — Read-only check that uses the YDB CLI to verify the configured tenant path is reachable. Use after bootstrap or restore to confirm tenant metadata before node or GraphShard checks.
- `local_ydb_add_storage_groups` — Increase NumGroups for one tenant storage pool using the current ReadStoragePool definition. Without confirm=true this returns the DefineStoragePool plan, rollback, target pool, and target count; when the update succeeds it verifies NumG…
- `local_ydb_apply_schema` — Validate or apply YDB table DDL through the official YDB JS SDK. It accepts raw YQL DDL for PRAGMA plus CREATE TABLE, ALTER TABLE, and DROP TABLE; action=apply validates first and executes only with confirm=true.
- `local_ydb_create_tenant` — Create the configured CMS tenant when the static node is already running. Use before local_ydb_start_dynamic_node for tenant topologies; without confirm=true this returns the planned status/create command and creates nothing.
- `local_ydb_permissions` — Inspect or change YDB scheme permissions for a path. The default list action is read-only; grant, revoke, set, clear, chown, and inheritance changes return a plan unless confirm=true.
- `local_ydb_prepare_auth_config` — Generate a hardened YDB config from the current static-node config. Use before local_ydb_write_dynamic_auth_config and local_ydb_apply_auth_hardening; without confirm=true this returns the planned write only.
- `local_ydb_restore_tenant` — Restore the configured tenant or destination path from a dump under profile.dumpHostPath, with optional post-restore scheme describe and bounded count-query verification. Use after bootstrap or rebuild when the target tenant is ready; wi…
- `local_ydb_set_root_password` — Rotate the runtime root password with ALTER USER and sync the host auth config and root password file to match. YDB may reject passwords that violate auth_config.password_complexity; this tool requires a non-empty password value.
- `local_ydb_write_dynamic_auth_config` — Write the text-proto dynamic-node auth token file needed for mandatory-auth startup. Use after choosing the SID for auth hardening; without confirm=true this returns the planned file write only.

## Related servers

- UnClick (1658 tools) — https://policylayer.com/tools/io-github-malamutemayhem-unclick-mcp-server.md
- Nodebench (824 tools) — https://policylayer.com/tools/io-github-homenshum-nodebench.md
- Yaver (811 tools) — https://policylayer.com/tools/io-github-kivanccakmak-yaver.md
- Binance MCP Server (734 tools) — https://policylayer.com/tools/nirholas-binance-mcp.md
- Crow (587 tools) — https://policylayer.com/tools/kh0pper-crow.md
- Fortimanager (584 tools) — https://policylayer.com/tools/jmpijll-fortimanager-mcp.md
- TinyFn (572 tools) — https://policylayer.com/tools/io-tinyfn-tinyfn.md
- Mcp (571 tools) — https://policylayer.com/tools/io-github-2s-io-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=local-ydb · API: https://policylayer.com/registry/api · Recommended policies for every tool: https://policylayer.com/policies/local-ydb
