Install
openclaw skills install @zw008/nutanix-aiopsUse this skill whenever the user needs to operate a Nutanix estate through Prism Central (v4 REST API) — an estate/cluster health overview, cluster & host inventory and utilization, VM lifecycle across AHV and ESXi (list/get/power/create/update/clone/delete/migrate), storage containers, subnets/network, images & categories, data protection / DR (snapshots, recovery points, protection domains, VM protect, failover), alerts & events with alert RCA (analyze_alert), LCM firmware/software upgrades, capacity runway forecasting, and read-only diagnostics/RCA over the whole estate (cluster_health_rca, alert_triage_rca). Always use this skill for "Nutanix", "Prism Central", "AHV", "cluster health", "list VMs", "power on/off a VM", "clone/migrate a VM", "delete a VM", "snapshot", "recovery point", "protection domain", "failover", "why did this alert fire" / "root cause this alert", "LCM upgrade / firmware", "days until storage is full" / "capacity runway", "what's wrong with my cluster" / "diagnose the estate", "triage my alerts", when the context is a Nutanix cluster or Prism Central. Do NOT use when the target is a non-Nutanix platform — those belong to their own AIops-tools sibling; this skill is Prism Central v4 only. Governed Nutanix Prism Central operations with a built-in governance harness (audit, token budget, undo, descriptive risk-tier labels).
openclaw skills install @zw008/nutanix-aiopsDisclaimer: Community-maintained open-source project, not affiliated with, endorsed by, or sponsored by Nutanix. Product and trademark names belong to their owners. Source at github.com/AIops-tools/Nutanix-AIops under the MIT license.
Governed Nutanix Prism Central (v4 REST API) operations — 51 MCP tools, every one wrapped with the bundled @governed_tool harness: a local unified audit log under ~/.nutanix-aiops/, token/runaway budget guard, undo-token recording, and descriptive risk-tier labels. The Prism Central password is stored encrypted (~/.nutanix-aiops/secrets.enc, Fernet + scrypt) — never plaintext on disk.
What sets it apart from read-only Nutanix MCPs: (1) automatic ETag / If-Match on every mutation — the v4 footgun handled for you; (2) automatic pagination; (3) mixed-hypervisor VM listing (AHV + ESXi, relevant to hypervisor-migration estates); and (4) the governance harness with dry-run + double-confirm on destructive writes.
Standalone: the governance harness is bundled in the package (
nutanix_aiops.governance) — no external skill-family dependency.
| Group | Tools | Count | Read / Write |
|---|---|---|---|
| Clusters | cluster_list, cluster_health, host_list, cluster_utilization | 4 | 4 read |
| VMs | list, get, power_on, guest_shutdown, power_off, reboot, create, update, clone, delete, migrate | 11 | 2 read · 9 write |
| Storage | container list / create / update / delete | 4 | 1 read · 3 write |
| Network | subnet list / get / create / delete | 4 | 2 read · 2 write |
| Catalog | image list / delete, category list / create / assign | 5 | 2 read · 3 write |
| Data protection / DR | snapshot list/create/delete/restore, recovery_point_list, protection_domain_list, vm_protect, pd_failover | 8 | 3 read · 5 write |
| Alerts | alert_list, event_list, audit_list, analyze_alert (RCA), alert_acknowledge, alert_resolve | 6 | 4 read · 2 write |
| LCM (upgrades) | lcm_inventory, lcm_precheck, lcm_update | 3 | 1 read · 2 write |
| Capacity | task_list, capacity_runway | 2 | 2 read |
| Diagnostics / RCA | cluster_health_rca, alert_triage_rca | 2 | 2 read |
| Undo | undo_list, undo_apply | 2 | 1 read · 1 write |
| Total | 51 | 24 read · 27 write |
The CLI is a convenience subset; the full 51-tool surface is via the MCP server. See references/capabilities.md for the tool → API-path → returns map.
uv tool install nutanix-aiops
nutanix-aiops init # interactive wizard: PC host/port 9440/username + encrypted password
nutanix-aiops doctor # connectivity + REST-RBAC preflight
diagnose cluster-health): degraded resiliency, storage pools/containers over 80% / 90%, nodes down or missing — worst-first, each finding citing the measured numberdiagnose alert-triage): per-severity counts, unacknowledged criticals, the oldest unresolved alert and its ageoverview, cluster health, cluster util): clusters, hosts, resiliency, utilizationvm list/get/power/create/update/clone), and guarded destructive ops (vm delete, vm migrate) with dry-run + double-confirmanalyze_alert) — correlate it with related events into a probable-cause + suggested-actions summaryvm_protect, pd_failoverlcm_inventory → lcm_precheck → lcm_update) and capacity forecasting (capacity_runway)Do NOT use when the target is a non-Nutanix platform — this skill is Prism Central v4 only. For other infrastructure, use the appropriate other AIops-tools sibling.
nutanix-aiops diagnose cluster-health → worst-first findings, e.g.
critical · prod-cluster · storage container near full · 93.0% used >= 90.0% thresholdstorage_container_list → confirm which container it is and what its
maxCapacityBytes / logicalUsageBytes actually arerecovery_point_list / snapshot_list <vm_ext_id> → the usual culprit is
snapshot sprawl in that containersnapshot_delete <…> --dry-run to preview, then re-run to reclaim space —
optionally set NUTANIX_AUDIT_APPROVED_BY first to annotate who authorized
it; each deletion is audited and records an undo descriptordiagnose cluster-health → the finding should drop below the 80%
warning threshold; the before/after percentages are your evidencenutanix-aiops diagnose alert-triage (or alert_list) → per-severity counts and the oldest unresolved alert, so you know which extId to open firstanalyze_alert <alert_ext_id> → probable cause + suggested actions, built by correlating the alert with related event_list recordscluster_health / cluster_utilization, then alert_acknowledge (or alert_resolve once fixed)vm_get <vm_ext_id> → confirm it's the right VM (and see its ETag)nutanix-aiops vm delete <vm_ext_id> --dry-run → preview the exact DELETE callexport NUTANIX_AUDIT_APPROVED_BY=… NUTANIX_AUDIT_RATIONALE=…--dry-run (double-confirm at the CLI); the call is audited with
tier and any approver/rationale suppliedrecovery_point_list (or per-VM snapshot_list <vm_ext_id>) → find stale / redundant snapshotssnapshot_delete <…> --dry-run on each candidate → previewcluster_utilization <cluster_ext_id> → current CPU / memory / storage / IOPScapacity_runway → days-to-full forecast per resource; use it to schedule an lcm expansion or storage add before you hit the wallhost_list → pick the destination host extIdnutanix-aiops vm migrate <vm_ext_id> <target_host_ext_id> --dry-run → previewThe skill delivers reads and writes and records them; it does not decide whether a write is permitted. That is your agent's judgement, or the permission of the account you connect it with (connect with a Prism Central account holding only a read-only (Viewer) role — writes then fail at the server). There is no read-only switch, policy file, or approval gate.
~/.nutanix-aiops/audit.db (relocatable via NUTANIX_AIOPS_HOME): params, result, status, duration, and the risk tier. The CLI writes the same row the MCP path does.NUTANIX_AUDIT_APPROVED_BY / NUTANIX_AUDIT_RATIONALE are optional annotations recorded on the audit row (who/why); they are never required and never block.NUTANIX_RUNAWAY_MAX=0.dry_run / --dry-run and, at the CLI, double confirmation.vm_update → prior CPU/memory, vm_migrate → prior host).references/capabilities.md — full 51-tool + API-path referencereferences/cli-reference.md — CLI command referencereferences/setup-guide.md — onboarding, credentials, REST-RBAC, CE self-testreferences/agent-guardrails.md — which guardrails the harness enforces for you, and a ready-to-paste system prompt for smaller / local models