Infrastructure
Servers, network devices, racks, Active Directory, and HR Sync — the system of record for everything that exists.
The system of record for everything that exists — servers, network gear, racks, and the identity systems tying them together.
Servers — /servers
The core inventory for Linux and Windows hosts. Each server's detail panel is a full operations console, not just a record.
- Live system info (OS, uptime, disk, packages) pulled over the same SSH connection used for Terminal
- Monitoring — CPU, memory, swap/page file, disk, inodes, network throughput, process count, and SSH login success/failure, all as historical charts (24h/7d/30d) with gridlines, hover tooltips, and absolute totals (e.g. "3.2 / 8.0 GB") alongside the percentage
- Firewall (UFW) management, OS user/group administration, capacity-risk recommendations
- Alert pausing — mute "unreachable via SSH" alerts for a specific window (1h/24h/7d/indefinitely) when a server is intentionally down for maintenance, without hiding it from inventory the way deleting would
- SSH credential management with automatic fallback keys, host-key fingerprint pinning and re-verification
- Live TLS check against a configured host:port records expiry, issuer, subject, SANs, and self-signed status
- Validate and deploy new cert/key/chain files already staged on the server to a live service (nginx/apache/custom), with an optional scheduled future apply
- Runs an automatic re-check every 24 hours across every server with a certificate configured, so expiry doesn't go unnoticed until something breaks
Server Dashboard
Network Devices — /network-overview
AI Assist. Routers, switches, access points, and firewalls — SSH, web UI, SNMP, and a purpose-built toolset for each.
- Devices tab — SNMP-based vendor/model/firmware identification with vendor-specific fallbacks (e.g. MikroTik, whose SNMP implementation doesn't expose firmware version the normal way, is read from its system description instead)
- Firmware AI — an AI model checks each device's firmware against known CVEs and EOL status; pulls the real version over SSH first when SNMP can't provide one, so the analysis isn't guessing from "Unknown"
- Ping Monitor — continuous reachability tracking across the whole network fleet
- Port Dashboard — live switch port status/VLAN assignment via SNMP walk, with a vendor-aware CLI generator for applying changes
- SNMP Profiles — reusable community-string/v3 credential sets shared across devices
Network Devices
Inventory & Infrastructure (Racks) — /inventory · /infrastructure · /racks/:id
Physical asset tracking — warranty status, serials, purchase dates — plus a visual rack-elevation editor (front and rear faces side by side) for mapping exactly where equipment lives, with per-port cabling and a site-map view for multi-building layouts.
Inventory
Domain (Active Directory) — /domain
AD user and computer lifecycle management over a domain controller's own SSH/PowerShell connection — no separate AD agent to deploy. Create, disable, and delete accounts, with TOTP-gated confirmation on destructive actions and a live "must be disabled first" safety check before any computer object can be deleted.
Domain Users Locked
HR Sync — /hr-sync
Admin. Polls an HR database hourly and turns new-hire/termination events into a review queue — approve an event and it provisions or suspends the matching Active Directory account, and optionally Google Workspace or Microsoft 365 (mutually exclusive, matching how a real org actually assigns one cloud identity provider per user). A monthly reconciliation pass catches drift — accounts that exist in HR but not AD, or vice versa — including name-consistency checks across all three systems.
HR Sync Review
AP Watchdog — /ap-watchdog
Auto-restarts access points that drop off the network, on a rule you define — ping-loss detection triggers an SSH-based reboot instead of waiting for someone to notice a dead AP.
SSH Profiles — /ssh-profiles
A shared SSH credential set — key-based or username/password — that many servers can point at instead of each one holding its own duplicate login. Define a profile once, then apply it to a whole batch of servers in one bulk action rather than editing credentials on each server individually. Any server can still be given its own individually-set credentials that override the profile, so a shared profile is a convenience default, not a hard requirement.
Key capabilities
- Two auth types — an existing SSH key (from Keys) or a username/password pair, per profile
- Bulk apply — assign one profile to many servers at once instead of a per-server credential edit
- Override-safe — a server's own individually-set credentials always take priority over an applied profile, so switching a batch to a shared profile can't silently break a server that intentionally needs different access
- Vault-linked — profile secrets are stored the same encrypted way as every other credential in the system, not a separate weaker store