Infrastructure

Servers, network devices, racks, Active Directory, and HR Sync — the system of record for everything that exists.

The system of record for everything that exists — servers, network gear, racks, and the identity systems tying them together.

Servers — /servers

The core inventory for Linux and Windows hosts. Each server's detail panel is a full operations console, not just a record.

  • Live system info (OS, uptime, disk, packages) pulled over the same SSH connection used for Terminal
  • Monitoring — CPU, memory, swap/page file, disk, inodes, network throughput, process count, and SSH login success/failure, all as historical charts (24h/7d/30d) with gridlines, hover tooltips, and absolute totals (e.g. "3.2 / 8.0 GB") alongside the percentage
  • Firewall (UFW) management, OS user/group administration, capacity-risk recommendations
  • Alert pausing — mute "unreachable via SSH" alerts for a specific window (1h/24h/7d/indefinitely) when a server is intentionally down for maintenance, without hiding it from inventory the way deleting would
  • SSH credential management with automatic fallback keys, host-key fingerprint pinning and re-verification
  • Live TLS check against a configured host:port records expiry, issuer, subject, SANs, and self-signed status
  • Validate and deploy new cert/key/chain files already staged on the server to a live service (nginx/apache/custom), with an optional scheduled future apply
  • Runs an automatic re-check every 24 hours across every server with a certificate configured, so expiry doesn't go unnoticed until something breaks

Server Dashboard

Network Devices — /network-overview

AI Assist. Routers, switches, access points, and firewalls — SSH, web UI, SNMP, and a purpose-built toolset for each.

  • Devices tab — SNMP-based vendor/model/firmware identification with vendor-specific fallbacks (e.g. MikroTik, whose SNMP implementation doesn't expose firmware version the normal way, is read from its system description instead)
  • Firmware AI — an AI model checks each device's firmware against known CVEs and EOL status; pulls the real version over SSH first when SNMP can't provide one, so the analysis isn't guessing from "Unknown"
  • Ping Monitor — continuous reachability tracking across the whole network fleet
  • Port Dashboard — live switch port status/VLAN assignment via SNMP walk, with a vendor-aware CLI generator for applying changes
  • SNMP Profiles — reusable community-string/v3 credential sets shared across devices

Network Devices

Inventory & Infrastructure (Racks) — /inventory · /infrastructure · /racks/:id

Physical asset tracking — warranty status, serials, purchase dates — plus a visual rack-elevation editor (front and rear faces side by side) for mapping exactly where equipment lives, with per-port cabling and a site-map view for multi-building layouts.

Inventory

Domain (Active Directory) — /domain

AD user and computer lifecycle management over a domain controller's own SSH/PowerShell connection — no separate AD agent to deploy. Create, disable, and delete accounts, with TOTP-gated confirmation on destructive actions and a live "must be disabled first" safety check before any computer object can be deleted.

Domain Users Locked

HR Sync — /hr-sync

Admin. Polls an HR database hourly and turns new-hire/termination events into a review queue — approve an event and it provisions or suspends the matching Active Directory account, and optionally Google Workspace or Microsoft 365 (mutually exclusive, matching how a real org actually assigns one cloud identity provider per user). A monthly reconciliation pass catches drift — accounts that exist in HR but not AD, or vice versa — including name-consistency checks across all three systems.

HR Sync Review

AP Watchdog — /ap-watchdog

Auto-restarts access points that drop off the network, on a rule you define — ping-loss detection triggers an SSH-based reboot instead of waiting for someone to notice a dead AP.

SSH Profiles — /ssh-profiles

A shared SSH credential set — key-based or username/password — that many servers can point at instead of each one holding its own duplicate login. Define a profile once, then apply it to a whole batch of servers in one bulk action rather than editing credentials on each server individually. Any server can still be given its own individually-set credentials that override the profile, so a shared profile is a convenience default, not a hard requirement.

Key capabilities

  • Two auth types — an existing SSH key (from Keys) or a username/password pair, per profile
  • Bulk apply — assign one profile to many servers at once instead of a per-server credential edit
  • Override-safe — a server's own individually-set credentials always take priority over an applied profile, so switching a batch to a shared profile can't silently break a server that intentionally needs different access
  • Vault-linked — profile secrets are stored the same encrypted way as every other credential in the system, not a separate weaker store