Architecture

How ssh-manager's components fit together — web frontend, API, database, and integrations.

Three moving parts: a React single-page app, a Fastify API that does the actual SSH/WinRM/SNMP work, and Postgres holding everything from encrypted key material to five-minute metric samples.

System Diagram

Browser (React SPA / Vite build)
        │  HTTPS / WSS
        ▼
apps/api — Fastify
  ├─ REST + WebSocket routes
  ├─ SSH2 / WinRM / SNMP connection layer
  └─ Background workers — metrics · backups · scans · HR sync · power sequences
        │
        ├──▶ PostgreSQL
        ├──▶ Redis (sessions + cache)
        │
        ▼  SSH · WinRM · SNMP
  Linux servers · Windows servers · Routers/switches/APs
        │  LDAP                 │  OAuth REST
        ▼                      ▼
  Active Directory      Google Workspace / Microsoft 365

Stack at a Glance

LayerTechnologyNotes
FrontendReact · TypeScript · ViteHand-rolled SVG for every chart/diagram — no charting library dependency
BackendNode.js · Fastify · ZodOne Fastify plugin per feature module, ~35 route files
DatabasePostgreSQL · Kysely150+ migrations, typed query builder, no ORM magic
Sessions/cacheRedisSession store + rate-limit counters
Remote accessssh2 · WinRM · SNMP · GuacamoleGuacamole (guacd) powers the in-browser RDP client
PackagingDocker ComposeSeparate prod (built images) and dev (hot-reload, bind-mounted source) stacks

Secrets

SSH private keys, passwords, and API credentials are encrypted at rest with a vault key before ever reaching the database — nothing sensitive is stored in plaintext.

Stats

  • 150+ database migrations
  • 35+ route modules
  • 30-day metric retention
  • 3 built-in UI themes with Dark/Light mode