Self-hosted code intelligence: cross-repo Q&A, dependency audits and PR review, over MCP
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Self-hosted β from the alert your monitoring already sent, through to a pull request someone can review
celmis-labs.github.io Β· Documentation Β· Quick start Β· Results
An alert arrives from a service you run. Celmis already knows which repository that service is and who owns it, so the fix starts there: an embedded Claude Code session β on your subscription, inside your installation β edits the code, and the runner commits, pushes a branch and opens a pull request. On one measured finding that took 220 seconds, from whatever device the alert reached first.
Celmis does not watch your services. Grafana, or whatever you already run, does that and does it well. This is the part that comes after the alert: the walk from a firing rule to a diff someone can review.
To be exact, because the line is easy to blur. The application ingests no logs of its own β it starts from the alert. But the repository ships an optional observability overlay, and that does collect them:
That brings up Prometheus, Loki, Promtail and Grafana.
docker-compose.observability.yml is deliberately
platform-wide rather than Celmis-only: Promtail tails the Docker daemon's container
logs and labels each stream by container name, so every service on that host β all
thirty of them, if you run thirty β shows up in Grafana's Loki explorer, filterable by
container. Prometheus scrapes api:8000/metrics for Celmis's own counters alongside.
Every port binds to 127.0.0.1 and is reached over an SSH tunnel:
That is not caution for its own sake. Loki has no authentication, so
POST /loki/api/v1/push accepts writes from anyone who can reach it, and a log store
strangers can write to is not a log store. GRAFANA_ADMIN_PASSWORD is required β the
stack will not start without one.
That loop is the product. It closes because everything sits on one index: a symbol graph Celmis builds from your repositories once. The same index answers questions that cross repository boundaries, reviews pull requests, audits dependencies into a CycloneDX SBOM and a verifiable evidence pack, generates documentation, and serves twenty-three tools over MCP β surfaces worth having, and none of them the point on their own.
It runs on one machine under docker compose, with the model provider of your
choice behind it, and nothing leaves your network except the calls you configure.
In the oldest telling, Kelmis was the smelter β one of the three Idaean Dactyls, alongside Damnameneus the hammer and Acmon the anvil, to whom the working of iron was credited. The index does the reducing here; the surfaces are what work the result.
Ask a question that spans two repositories, and the answer quotes both:

That is not a search result. The gateway and the payments service are separate repositories with no shared code, and the answer traces the call chain between them β then notices, unprompted, that the Kafka topic name is hardcoded in both and that changing one silently breaks the other.
A reviewer that reads only the diff structurally cannot say that. It never had the other repository open.
| You are a PM, a delivery lead or the client and want to know what state a group of projects is in, or how something actually works | Ask it. From any device, anywhere, without booking time from an engineer and without a meeting whose only output is a paragraph β Ask the code |
| A new engineer has a question a senior would have to answer | Every one of those pulls someone experienced out of flow, at the moment they are already covering. The codebase answers instead, with file:line citations β Ask the code |
| Two teams share an integration and neither can read the other's repository | Load it, grant the right to ask, and deny the paths that must stay private. They get answers; the credentials are refused at the source β Who can see what |
| A customer or an auditor asks for your SBOM | One button, CycloneDX, plus an evidence pack whose manifest they recompute themselves β against a hash you publish where the pack is not β Dependencies, SBOM and the evidence pack |
| A vulnerability lands in a dependency | Fix from here hands an embedded session the repository, the package and the finding. It edits, the runner pushes a branch and opens a PR β Fix from here |
| A pull request needs reviewing | Agents read the diff β and, where the graph is built, who else calls what is being changed, including from another repository β Pull-request review |
| Forty services need the same thing done to them | Write the sentence. Celmis shows which repositories it resolves to and waits for a second press, rather than finding them among forty and pressing a button forty times β Ask for work across repositories |
| An alert fires at 02:00 and you are not at a desk | It lands in Celmis and goes out to the workspace's chat channel, and Fix from here opens a session already holding the alert. The runner opens the pull request β Alerts, and fixing from a phone |
| Your own agent or editor needs to understand the codebase | Point it at /mcp/. Twenty-three tools over the same index, eighteen of them read-only, under the same access rules β no second copy of your code anywhere β Connect Claude Code and other MCP clients |
The first three are the ones a code-review tool does not do at all, and they are the reason this is a platform rather than a reviewer: index once, then read that index from whichever side of the work you are standing on.
| 197 seconds | from git clone to six healthy services, measured on a clean server |
| $0.118 | per pull request reviewed, on the model this ships with |
| 17th of 50 | on the Martian Code Review Bench offline set, under all three judges |
That last one is deliberately unflattering, and it stays. It measures one of the surfaces below β pull-request review on isolated single-repository PRs β and that set has no sibling service for a symbol to have consumers in, so the thing this product is built around is not in the number at all. The table, the audit of every finding it scored false, and the command that reproduces both are in Results.
| Docker | 24+ with Compose v2 | Docker Desktop on macOS/Windows, the native engine on Linux |
| A model API key | one of | Google Gemini, Anthropic, OpenAI, OpenRouter, Groq or Mistral. A free Gemini key is enough to evaluate: https://aistudio.google.com/app/apikey |
| RAM | ~4 GB free | Measured on a real indexing run: 1.1 GB peak across all five containers, 565 MB at rest |
Postgres and Qdrant are bundled β no external cluster to provision. No Python or Node.js install is needed for the Docker flow.
Open http://localhost.
Nothing is built here. The three images are pulled from the registry named by
CELMIS_REGISTRY at the tag in CELMIS_TAG, for linux/amd64 and
linux/arm64 β Apple Silicon and an ARM server both get a native image.
Building them on the machine that runs them was measured at 485 seconds and
4.2GB of disk for api alone, which is why installing no longer means
compiling.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/celmis)<a href="https://allmcps.com/mcp/celmis"><img src="https://allmcps.com/api/badge/celmis?style=directory" alt="Celmis on AllMCPs" /></a>