SSH Manager
Self-hosted operations console for infrastructure teams — unified SSH, RDP, VNC, credentials, and automation.
Overview
SSH Manager is a self-hosted operations console purpose-built for small-to-mid-sized infrastructure teams. It consolidates: - Server and network device inventory with health monitoring - In-browser SSH/RDP/VNC terminal access without separate tools - Encrypted credential vault with automatic password rotation and history - Scheduled power operations and safe infrastructure maintenance sequences - SSH key pair generation, storage, and rotation - Active Directory lifecycle automation synced with your HR system - Database query runner with multiple backend support (PostgreSQL, MySQL, MongoDB, MSSQL, SQLite) - Telegram bot as a second interactive surface for on-call operations - Network scanning, RADIUS configuration, AP management, and more Built from real operational workflows, grown feature-by-feature, and battle-tested in production environments.
Features
- Terminal: In-browser SSH access
- Remote Desktop: RDP/VNC via browser
- File Manager: SFTP file transfer
- Servers: Inventory, SSH keys, health monitoring
- Network Devices: SNMP, AP management, RADIUS configuration
- Vault: Centralized encrypted credentials with history
- Active Directory: User management, domain health scanning
- HR Sync: Automated account lifecycle from HR database
- Database Connector: Ad-hoc queries across 5+ database types
- Power Sequence: Scheduled infrastructure maintenance with confirmations
- Backups: Automated server/database backups with restore
- Security: Posture scanning, access auditing
- Telegram Bot: Full CLI over Telegram with TOTP gates
Requirements
- Docker + Docker Compose v2PostgreSQL-compatible databaseLinux host for network scanningTelegram bot token (optional)
Installation
1. Clone repository
git clone https://github.com/mrsloth-labs/ssh-manager.git
cd ssh-manager2. Create environment file
cp .env.example .env
# Edit .env with your configuration3. Start with Docker
docker compose up -d --build
# Access at http://localhost:40044. Production deployment
docker compose -f docker-compose.yml -f docker-compose.prod.yml up -d --build
# See documentation for full setupConfiguration
# SSH Manager .env configuration
FRONTEND_URL=https://ops.example.com
DATABASE_URL=postgresql://user:password@postgres:5432/ssh_manager
REDIS_URL=redis://redis:6379
# Security keys (generate with: openssl rand -hex 32)
SESSION_SECRET=<generate-with-openssl-rand-hex-32>
VAULT_ENCRYPTION_KEY=<generate-with-openssl-rand-hex-32>
CORS_ORIGIN=https://ops.example.com
# Bootstrap admin
BOOTSTRAP_ADMIN_EMAIL=admin@example.com
# Optional: Telegram bot
TELEGRAM_BOT_TOKEN=<your-bot-token>
TELEGRAM_ADMINS=123456789,987654321Example Output
Dashboard displays:
- Infrastructure health (servers, network devices, backups status)
- Pending alerts (power operations, AP watchdog, HR sync approvals)
- Recent activity log (SSH sessions, deployments, changes)
- Quick access to Terminal, RDP, File Manager
Terminal session output:
$ ssh admin@prod-server
Last login: Wed Aug 12 02:00:00 2026
prod-server:~ # uptime
02:47:33 up 45 days, 3:21, load average: 0.12, 0.15, 0.18
prod-server:~ #
Vault interface shows:
- Encrypted credentials (SSH keys, iDRAC logins, vCenter creds)
- Password history with rotation dates
- Tags and search functionalityFAQ
Is this a managed SaaS product?
No, it's entirely self-hosted. One deployment serves one organization's infrastructure.
How are credentials encrypted?
All Vault credentials use AES-256-GCM encryption with VAULT_ENCRYPTION_KEY. Keep the key backed up separately from your database.
Can I use it with multiple teams?
Current version supports a single organization/team with role-based access control (admin, operator, read-only).
What SSH key types are supported?
Ed25519 and RSA (2048+ bits). ECDSA support is partial.
Does it work with all network vendors?
Yes, via SSH. Features like RADIUS include vendor-specific CLI templates for Cisco, Juniper, Fortigate, etc.
Can I automate operations via API?
Yes. Nearly every operation in the web app has a REST API endpoint. Telegram bot provides alternative CLI.
Roadmap
- Multi-factor authentication (TOTP, hardware keys)
- Kubernetes cluster management integration
- Enhanced vendor hardware support (Dell iLO, HPE IRM, SuperMicro)
- Custom scripting engine for complex automation workflows
- Ansible/Terraform state management integration
- Audit log archival and compliance reporting
- Advanced network monitoring and anomaly detection
Known Issues
- Multi-tenant support is not planned; one deployment = one organization
- Some vendor CLI templates are text-based, not verified against all firmware versions
- Simulator mode exists but real hardware is the source of truth
- AD health scanning (PingCastle) is informational, not a certified security audit
- SAN readiness is TCP-reachability only, not real LUN/replication state
Changelog
- - Enhanced Network Scanner with mDNS discovery
- - Database Connector with ERD visualization and AI query assistant
- - Migration feature with dry-run, rollback, and recurring schedules
- - Power Sequence improvements for safer infrastructure maintenance
- - RADIUS configuration push with vendor-specific CLI templates
- - Active Directory health scanning with PingCastle integration
- - Telegram bot enhancements for on-call operations
- - Initial public release
- - Core infrastructure management features
- - SSH/RDP/VNC terminal access
- - Vault credential management
- - Power Sequence orchestration
Technologies
Latest Release
🚀 This Project is Under Development
SSH Manager is actively being developed and improved. If you're interested in using it, contributing, or becoming a collaborator, I'd love to hear from you!
Related Projects
PyServer Manager
Self-hosted dashboard for managing Python services on Linux without SSH
PVD Library
Full-featured bilingual library management system
PyPing
Production-ready Python network monitor with alerting and a web portal