or
Demo mode — this is a read-only sandbox with fake data. Browse anything. Nothing here can be modified. Run your own →
Live
Status board

A glanceable wall view — rolled up by group/site/tag so it stays readable on a large fleet, with every problem host surfaced regardless of fleet size.

Loading…
Documentation
Fleet at a glance
Everything that needs your attention, in one screen. Documentation
Upcoming
next events from the calendar & scheduler
Open alerts
Recently acknowledged
Fleet health
Fleet heat map
health score per device — green healthy, red needs attention
Needs attention
Recent activity
Fleet roster · 7-day status
Post-it
Offline hosts
Pending updates
CVE exposure
Config drift
Resource pressure
Fleet by group
Monitoring coverage
Stale agents
Mailbox watch
On-call now
Devices by OS
Agent versions
Device types
Top tags
Ungrouped devices
Recent activity
Attention by severity
Top attention items
Health score
Fleet size
Critical / high CVEs
Updates pending
Drifted files
Recent check-ins
Open alerts by severity
Maintenance windows
Monitor status
Container issues
Disk fill ETA
Devices by subnet
Patch compliance
Agent vs agentless
Never checked in
Lowest health hosts
Longest uptime
Helpdesk tickets
Health grade spread
Agent version skew
Offline by group
Reboot required
World-exposed ports
Failed services
Failed timers
Disk SMART failures
UPS on battery
Over temperature
Backup jobs
Mount issues
Clock skew
Gateway unreachable
Recent OOM kills
Storage degraded
New ports (recent)
Firewall changes
SSH keys added
Expiring certificates
Active brute-force
Top bandwidth
Checks roll-up
Integration health
Alerts
Device Control
Manage and remotely control enrolled devices Documentation
0
Total devices
0
Online
0
Offline
Enrolled Devices
0 selected
Monitoring
Probes, device metrics, ports, and custom health checks Documentation
Remote Checks
LabelTypeTargetStatusDetailChecked
No monitors configured.
Import / export monitors

Paste an existing monitoring config and RemotePower proposes equivalent monitors. Preview first (dry-run) to see what maps and what doesn't, then apply. Accepts an Uptime Kuma backup JSON, Nagios/Icinga object config (define host/service), a Zabbix XML export — or a RemotePower export from another instance. Duplicates (same type + target) are skipped.

Export downloads your monitor definitions in a format this same Import accepts, so moving a set between your own instances is copy-paste rather than retyping. Definitions only — no history, and a monitor's satellite assignment is left out (it's local to this install).

SLA / SLO objects

Define an availability target (e.g. 99.9% over 30 days), then tick the SLO on each remote probe that should count toward it. Availability is check-weighted across the attached probes; the error budget shows how much downtime allowance is left. Also exported as Prometheus gauges at GET /api/slo.

NameTargetWindowProbesAvailabilityError budget leftStatus
No SLO objects yet — define an availability target (e.g. 99.9% over 30 days), then tick it on the probes that should count toward it.
Device metrics
Device Alert Memory Swap CPU load Disks
SNMP devices
Device Alert CPU Memory Storage Temp Uptime
No SNMP devices yet — enable SNMP on an agentless device's Settings tab.
Listening Ports
Loading…
Scripts
Running on
Failing
All OK
Monitoring profiles
A named bundle of scripts you can apply to many assets at once.
Script Device Group Status Last output Last run Duration
Click Refresh to load results.
Top Processes
Process PID Device CPU % Mem %
Click Refresh to load.
Users & Roles
Manage who can access this dashboard and what they can do. Built-in roles: admin (full control) and viewer (read-only). Define custom roles to grant specific actions on specific device groups/tags. Documentation
Accounts
UsernameCreatedRoleMFASource
Custom roles
A custom role grants a subset of actions — exec, reboot, upgrade — limited to a scope (all devices, or only named groups/tags). Members can act on their scope and see only those devices on the Devices roster; server config, user/role management and saved scripts stay admin-only.
Loading…
Timesheet watchers
Let specific users view another user's timesheet — read-only, hours only, never rates. Grant a watcher a single user or a whole team. Admins and the finance role already see everyone, so they need no grant. Watchers switch view with the "Watch for" box on the Timesheet page.
Loading…
My Account
Your personal settings — these apply to you only, not the whole server.
My timesheet

Your weekly time log — record billable (debtable) and internal hours by day. Hours you log on a ticket land here too.

Team

Your team name — used by the Tickets "My team's open tickets" view to group tickets assigned to your teammates. Everyone who types the same team name is on that team.

Email signature

HTML signature appended to ticket emails you send (sent as a rich HTML part, with a plain-text fallback). Paste HTML — e.g. your full contact block with links.

Profile
?
Signed in as

PNG, JPEG, GIF or WEBP, up to 512 KB. It's downscaled in your browser before upload.

Language

Choose the interface language. Saved to your account and synced across devices.

Appearance

Pick a theme for this browser. Follow system tracks your OS light/dark setting; Time of day switches on the clock instead — which is what you want when the OS is pinned to dark, as it is on most servers and kiosks. The accent tints buttons and highlights on top of any theme.

Theme
Time-of-day schedule

Applies live — the boundary is crossed without a reload, so a wall-mounted dashboard switches on its own. A window that wraps midnight (day from 21 to 5) works, for night shifts.

Accent
Navigation

Auto-hide pauses while there are open alerts — the sidebar stays visible so nothing needing attention is concealed.

Background
My notifications

Get alerts on your own webhook or email, with your own filters — in addition to the org-wide channels (this never turns those off). You only receive alerts for devices you're allowed to see.

Permissions

What your role lets you do. Managed by an administrator under Users & roles.

Two-Factor Authentication (2FA)

Protect your account with an authenticator app (Google Authenticator, Authy, etc.).

SSH preferences

Your default SSH username. Used by the quick-SSH link on the Devices page so you don't retype it each time. Stored per-user, not shared.

Display units

How temperatures are shown to you. Everything is stored and alerted on in Celsius — this only changes what you read, so switching it can't move a threshold. Per-user, so operators on the same instance can disagree.

New-alert announcements

The tab badge is passive — it only helps if you look at the tab. These are the active half, for a dashboard sitting on a second monitor. Both are off by default and are per-user: a sound is the most intrusive thing a page can do. Only a rise in the open-alert count announces, so opening the dashboard with existing alerts stays silent — announcing history rather than news is how people learn to ignore an alert sound.

My acknowledged alerts

Open alerts you've taken ownership of (acknowledged but not yet resolved).

Active sessions

Browsers and devices currently signed in as you. Revoke any you don't recognise.

IaC Generator
Generate Infrastructure-as-Code (Terraform, Ansible, Pulumi, Cloud-init) for any managed device. Server collects live state on demand, then the configured AI provider transforms it into IaC. Sensitive env vars and SSH keys are masked before leaving the host. Documentation
Generated code will appear here
Click Generate IaC to begin.
No conversation yet. Generate something first.
Command History
Log of all commands sent to devices Documentation
Recent commands
TimeActorDeviceCommand
Scheduled Commands
Queue shutdown or reboot at a specific time Documentation
Pending jobs
DeviceCommandScheduled forBy
No scheduled jobs.
Plain English → a standard 5-field cron expression, validated and previewed with its next runs. Requires the AI assistant to be configured.
AI Assistant
Free-form chat against the configured provider. Local-model stats when running Ollama or LocalAI. Documentation
AI is disabled
Enable it in Settings → AI assistant first.
Provider
Status
Version
Loaded models
AI Insights
One-click AI reports and advisors over your fleet state — each runs against the configured provider with RAG context attached. Documentation.
No messages yet — type a prompt below.
Conversation history is kept in your browser (localStorage) — not on the server. Clearing the conversation clears only your view.
Server status
RemotePower watching itself — disk, devices, webhooks, audit, backups. Documentation.
Loading…
Internal health — maintenance sweeps

Each background maintenance sweep's last successful run and any recent error. A sweep that silently stops running or starts failing shows up here instead of quietly taking a feature down with it.

Loading…
Client-side JS errors

Uncaught browser-side errors reported by operators' sessions (window.onerror beacon). A JS failure dies silently in the user's console otherwise — anything listed here is a bug worth a look. Newest first, ring capped at 200.

Loading…
Detection self-test

Silence isn't clearance: a green dashboard proves the monitoring found nothing, not that it would. This verifies every alertable event type routes to at least one channel that reaches a human, and flags the silent gaps — an alert kind you've muted on every channel, sandbox mode left on, or a recover event that can never close its alert. Documentation

Click Run.
Compliance
Control-mapped PCI DSS / HIPAA / SOC 2 / Essential Eight / SMB1001 checklist, scored from data RemotePower already collects. A control it cannot back up reads Not assessed, never a pass. An audit-prep aid — never a formal attestation. Documentation.
Loading…
Regulated data (PII)
Where your regulated data actually lives. Agents report which files contain emails, card numbers (Luhn-checked), national IDs, IBANs or phone numbers — by kind and count only. The values themselves are never sent, stored, or hashed: hashing does not anonymise a national ID, since there are few enough possible values to reverse one. Enable it under Settings → Security.
Configuration baseline (CIS-style)
A named set of pass/fail checks evaluated against each host's reported state — patches, reboot, failed units, disk, CVEs, agent integrity. Severity-weighted across applicable checks; the daily trend is below. Toggle a check off to exclude it fleet-wide.
Loading…
OpenSCAP scan (auditor-grade)
Runs oscap xccdf eval on the endpoint against its SCAP Security Guide datastream and reports the score, pass/fail tallies and failing rule ids. Requires openscap-scanner plus the SSG content for the host's OS — on RHEL/Fedora that's scap-security-guide; on Debian/Ubuntu it's ssg-debian / ssg-debderived. The profile list below is what your fleet's datastreams actually contain (it fills in after the first scan). Profiles are OS-specific: Debian/Ubuntu ship the ANSSI BP-028 profiles (anssi_np_nt28_minimal…_high) — those have real rules and produce a meaningful score; the Debian standard profile selects almost no rules (expect 0). CIS / PCI-DSS / STIG / OSPP exist only in the RHEL/Fedora scap-security-guide, not on Debian. A profile that isn't in the host's datastream, or that evaluates no applicable rules, reports "not available" with the reason. The content must match the host's OS release — oscap scores 0 if it doesn't (every rule "not applicable"). Best results per OS: Ubuntu — install Canonical's usg (Ubuntu Security Guide); the agent uses it automatically for CIS/STIG profiles and it ships content for the exact release (incl. 24.04, where the distro ssg-ubuntu datastream lags). Debianssg-debian matching the release, then an ANSSI BP-028 profile. RHEL/Fedorascap-security-guide. If a scan reports "not available", the reason names exactly what to install. Scans run in the background and report on the next heartbeat. The full oscap / usg HTML report is uploaded with each successful scan — click Report in the results row to open it.
Loading…
Fleet anomaly scan
Sends a compact live snapshot of the fleet to the model and ranks anomalies. On-demand — costs one AI request. Requires the AI assistant to be configured.
Forecast
Per-mount disk-fill projection across the fleet, from each host's daily metrics history. A least-squares trend on observed usage, extrapolated to capacity — lead time, not a guarantee. Ephemeral mounts (/tmp, /run, /dev/shm, …) are excluded, and a heavily-fluctuating mount shows fluctuating instead of a misleading date. Documentation.
Loading…
Timeline
A single chronological history — fleet events and command runs merged into one stream — for the whole fleet or one device. Pick the scope below. Documentation.
Loading…
Checks
Every monitored signal on every host as OK / WARN / CRIT / UNKNOWN, with output. Sort and filter; toggle a check off to silence it on a host. Documentation
Host Group Check Status Output
Loading…
Automation
When an event fires on matching devices, run a saved script and/or notify a destination. Rules are evaluated on every event; each has a cooldown. Documentation.
Rules
Loading…
New rule

The guard and verify fields apply to the run-script action: per-host cooldown and the hosts/hour cap bound the blast radius, and verification fires a remediation_failed alert — and eventually disables the rule — when the fix doesn't clear the triggering alert. Documentation

Recent auto-remediations

Every run-script firing lands here: queued, verified (the triggering alert cleared inside the verify window), failed (it didn't — a remediation_failed alert fired), or suppressed (a blast-radius guard stopped it).

Loading…
Release Signing
Sign the agent release so agents refuse any self-update that isn't validly signed by your key. Documentation.

Server-side signing is the convenient mode. The private key lives on this server, so it protects against tampering of the published files at rest (mirror/CDN), but not a full compromise of this server. For the strongest guarantee, sign off-server in CI with tools/sign-agent-release.sh and only publish the public key here.

Loading…
Distribute the public key to agents

Pin this on each agent host at /etc/remotepower/release.pub. Once present, that agent enforces signatures (fail-closed). No key pinned → agent keeps using sha256-only verification.

Commands are signed with the same key (v6.4.0): every dispatched command carries a detached signature bound to the target device + a fresh timestamp. Hosts that also create /etc/remotepower/require-signed-commands refuse unsigned, tampered or replayed commands outright — database/queue tampering alone can no longer execute anything. Documentation

About
RemotePower — self-hosted device management
RemotePower
RemotePower
Server version:
Agent version
GitHubgithub.com/tyxak/remotepower
LicenseMIT
Latest releasechecking…
Report a bug

A self-hosted fleet manager for Linux, Windows and macOS — far more than remote control. Real-time monitoring, metrics and forecasting; security posture (CVE/KEV scanning, patch management, config-drift, CIS/compliance, firewall & fail2ban, AV/rootkit, IP-reputation/DMARC); an AI assistant grounded in your own fleet (RAG) with per-subject advisors and a searchable knowledge base; a built-in helpdesk (tickets, SLAs, email threading) plus time-tracking & billing; DNS management, homelab integrations and a WireGuard access VPN; virtualization control across Proxmox, VMware (vSphere/vCenter, Cloud Director) and OpenShift; infrastructure provisioning with server-side Terraform, Ansible and cloud-init; staged rollouts, alerting with escalation and per-host tuning, audit & governance, optional hard multi-tenancy — and of course full remote control: shutdown, reboot, Wake-on-LAN, scheduled commands, custom scripts and agent self-update.

No inbound firewall rules on clients — agents poll the server over HTTPS. Runs on Nginx + Python (gunicorn + Flask); a single install provisions PostgreSQL, an out-of-band scheduler and a scanner satellite by default, with a lighter flat-JSON/SQLite backend available for constrained or dev installs. Deploy from source or the official multi-arch Docker image. No Node.js, no build step.

Did you know?

Command Queue
Commands waiting to be picked up by each agent on its next heartbeat — handy when a host is offline and you want to see (or cancel) what's pending before it comes back. Anything already delivered to the agent has left the queue. Documentation
Pending per device
Loading…
Data Explorer
Build a filter across devices, CVEs, or drift — run it, save it as a template. Read-only; scoped to what you can already see. Documentation
Query builder
Saved queries
No saved queries yet.
Results
Run a query to see results.
Package Snapshots
Freeze the fleet's current package versions into a named snapshot, diff two snapshots, promote one as a tag's reference state, and see which devices have drifted from it. Read-only reporting — does not change what auto-patch installs. Documentation
Snapshots
No snapshots yet.
Diff two snapshots
vs
Drift vs. a promoted snapshot
Click "Drift" on a promoted snapshot above.
API Keys
Named non-expiring keys for scripts and CI pipelines Documentation
Keys
NameRoleUserRate limitCreatedExpires
Sites & teams
Group the fleet by location, team, or customer — one level above device groups. Assign a device to a site from its drawer. Super-admins always see every site. Documentation
Site map

Sites with coordinates plotted on a world map, colored by rolled-up device health (green all-online · amber some-offline · red all-offline). Set a site's latitude/longitude from its row. Click a dot to filter the table below.

Sites
NameSlugDevicesCreated
Loading…
Auto-placement rules

When a new device enrols, the first matching rule stamps its group / site / tags automatically — by hostname (regex) or source-IP range (CIDR). Enrolment-token defaults always win: a rule only fills a group left empty and merges extra tags. Rules never touch already-enrolled devices.

Device profiles

A named bundle of per-device settings — poll interval, watched systemd units, log watches, drift-watched files, metric thresholds. Applying a profile stamps those fields onto the devices you pick; it's a one-shot copy, so each device stays individually editable afterwards.

Loading…
Smart groups

A saved fleet query whose membership is re-evaluated every ~60s. Use it as a targeting scope — reference it as smart:<name> in alert-routing, auto-patch, report and service-baseline scopes. It doesn't change a device's real group.

Loading…
Racks

Model your racks and place assets in them (set rack, bottom U and height on an asset in the CMDB). Overlapping units are flagged. Front elevation view. Documentation

Loading…
IP address management

Define subnets; occupancy is derived from known device addresses (device IP + CMDB interfaces incl. NAT) plus static reservations. A duplicate IP across two devices raises an ip_conflict alert. Documentation

Loading…
Timesheet
Your week — log billable (debtable) and internal hours by day. Hours you log on a ticket appear here too. Documentation
Loading…
Billing
Turn logged hours and recurring fees into invoices, per customer (site). Admins manage rates and issue invoices; the finance role can view and export. Documentation
Loading…
Patch Report
Overview of pending system updates across all devices — percentage only counts online devices with data Documentation
Export (filtered):
Total
Fully Patched
With Patches
Total Pending
Patch Rate
DeviceGroupOSStatusPkg ManagerPendingPatch StatusRecent Patch Cmds
Click Refresh to load patch report.
Patch SLA

Flag hosts whose pending updates have gone unpatched too long. Set a maximum age (days) for security and/or all updates, scoped to a group, tag, or the whole fleet — first matching rule wins. Breaches raise a patch_sla_violation alert. Reporting only; nothing is auto-installed.

Software inventory search
Find which hosts have a package — e.g. openssl older than a version. Searches the collected package inventory.
Patch catalog
Pending updates aggregated by package — which update is waiting, and on how many hosts. The inverse of the device table above.
Loading…
Install software
Install one or more packages from the host's own repositories — on a single device, or across a whole group or tag. Detects the package manager (apt / dnf / yum / zypper / pacman / apk). Requires the exec permission; honours quarantine and change-windows.
Package names only (no shell). Space- or comma-separated, up to 30. Uninstall removes the named packages (no dependency auto-removal or config purge). Hold/Unhold pins a package at its current version so a fleet upgrade skips it.
CVE Findings
Package vulnerabilities per device, via OSV.dev — scan checks installed packages against known CVEs. Documentation
0
Critical
0
High
0
Medium
0
Low
0
Devices Scanned
DeviceGroupEcosystemKEVCriticalHighMediumLowLast scan
Click Refresh to load findings.
Container image CVEs (trivy)

Vulnerabilities found in the images of running containers, grouped by image across the fleet. Enable per-fleet in Settings → Security (needs trivy on the hosts). Trivy re-scans every ~24h; Scan now triggers it on the next heartbeat.

Click Refresh.
Remediation campaigns

Group CVEs into an owned, deadlined effort and track the affected-host burn-down. Scope by severity/KEV or an explicit CVE list. A campaign completes (and fires campaign_completed) when zero hosts remain affected. Burn-down is sampled daily.

Pentest
Authorized vulnerability scans against enrolled hosts you manage and ownership-verified domains. The target is derived server-side — you can only scan assets you own. Network scans run on a scanner satellite; on-host audits run on the device's agent. Documentation →
0
Running / queued
0
Critical findings
0
High findings
0
Scans
Scans
TargetStatusCritHighMedLowInfoCreated
No scans yet. Select an enrolled device and queue one.
Verified web targets — scan domains / IPs you own that aren't enrolled hosts. Prove ownership once, then scan.
Scheduled scans — recurring scans on a cron. They use the device/target + tool/profile/intensity selected in the toolbar above. High/critical findings raise an alert.
Scheduled LAN discovery — recurring subnet netscan from the device selected above, turning unmanaged-host discovery into a living list instead of a one-off snapshot.
Services 0 maintenance window(s) active
systemd units watched per device. Click a row to see history, logs, and configuration. Documentation
0
Services Up
0
Services Down
0
Devices Reporting
0
Units Watched
DeviceGroupWatchedUpDownLast report
Click Refresh to load.
Service baselines
Default watched units applied fleet-wide by scope

A baseline watches a default set of systemd units across every device its scope covers — merged with each host's own list, so you don't edit each host. Also reachable from a device's Configure watched services → Edit baselines.

Loading…
Logs
6-hour rolling buffer across the fleet. Search, tail live, or manage alert rules. Documentation
0
Lines in buffer
0
Devices reporting
Last line
0
Alert rules
Live tail — auto-refreshing every 30s
Alert rules
Regex match on incoming log lines fires a log_alert webhook.
DeviceGroupUnitPatternThreshold
No per-device rules configured.
Fleet-wide rules apply to every device that submits logs for the named unit. Use * for the unit to match any unit on any device.
UnitPatternExclude patternThresholdCreated
Cleared lines

A rule matches a class of lines, so one routine message re-fires forever. Clearing a line stops it counting toward the rule's threshold — a genuinely different message still alerts. Un-clear one to hear about it again. Documentation

LineScopeUnitCaught sinceCleared
Nothing cleared yet.
Maintenance Windows
Scheduled windows suppress webhook alerts for specific devices, groups, or the whole fleet. Documentation
ReasonScopeTargetWhenEventsStatus
Click Refresh.
Recent Suppressions
WhenEventDeviceWindowReason
Auto-patch
Apply package updates automatically on a schedule across a group, tag, site, or the whole fleet. Queued upgrades respect maintenance windows and device quarantine. Documentation
Policies
NameTargetScheduleRebootEnabled
Loading…
Backups
Define a backup command per device (restic / borg / rsync / …), run it on demand, or schedule it with cron. Pairs with the backup-freshness monitoring in each device's drawer. Documentation
Backup jobs
NameDeviceScheduleLast runEnabled
Loading…
Proxmox guest backups
Recency of each guest's vzdump backup archives on the connected Proxmox node — distinct from VM/LXC snapshots. Stale or missing backups also raise a dashboard attention item.
days
Loading…
Provisioning
A catalog of infrastructure blueprints — Terraform, cloud-init, Ansible and iPXE templates organised in folders. Fill in a blueprint's variables and render it to copy or download; Terraform blueprints can also be run on the server (plan / apply / destroy) when execution is enabled. Documentation
Blueprints
Loading…
Ansible playbooks
Run Ansible playbooks against the fleet, with this server as the control node. Define a playbook, then run it against a group / tag / site over SSH.
NameLast runResult
Loading…
Knowledge base
Operator-authored IT documentation — SOPs, how-tos and runbooks as markdown articles in a category folder tree. Searchable, and fed to the AI assistant so it can answer from your own docs. Documentation
Articles
Loading…
No article selected
Pick an article on the left to read it, or click New article.
Runbook links

Attach a KB article to an alert type. When an alert of that type fires, operators see a one-click Runbook link on it in the Alerts inbox — straight to your response procedure.

Tuning
Find your noisiest alerts and silence them at the source — per host + alert type. A silenced alert stops reaching the inbox, webhooks and the needs-attention card, but history keeps recording so you can always lift it. Counts are over the last 30 days. Documentation
Noisiest alerts
Loading…
Noisiest sources
Loading…
Active mutes
Loading…
Rollouts
Push an upgrade or saved script to the fleet in ordered rings — canary, then pilot, then broad. Each ring is verified (upgrades use post-deploy verification) before the next is released, automatically or on your approval. Documentation
A one-time install is the un-staged sibling of a rollout: it installs a package straight away through each target's package manager (apt/dnf/yum/zypper/pacman/apk), on a single device or a whole tag.
Rolling reboot

Reboot a scope in dependency-ordered waves — devices nothing depends on first, upstreams last (from each device's declared depends_on). Each wave is health-gated and verified before the next, exactly like a rollout. Preview the waves, then create the rollout.

Click Refresh.
Recent installs & jobs
Follow one-time installs and batch script runs here — each host shows a checkmark when it finishes (red on a non-zero exit). Updates live while anything is still running.
No recent jobs.
Calendar
Shared events across all users — backups, deploys, renewals, anything you want to remember. Documentation
Mon
Tue
Wed
Thu
Fri
Sat
Sun
Tasks
Shared kanban board. Drag cards between columns. Optionally link a task to a device. Documentation
● Upcoming 0
● Ongoing 0
● Pending 0
● Closed 0
CMDB
Configuration Management Database — asset metadata, documentation, and encrypted credentials per enrolled device. Documentation
Checking vault status…
Assets
Name Asset ID Function OS IP Hypervisor Docs Creds
Break-glass requests
Pending requests to reveal a break-glass credential. A second admin (not the requester) must approve before the secret is shown — every request, approval and reveal is immutably audit-logged.
Credential checkouts
Who currently holds active, justified, expiring access to a credential — and why. Each grant is scoped to one credential and one person, and lapses on its own. Revoking a checkout ends the window immediately.
Scoped credentials
Shared logins defined once per site, group or tag and inherited by every member device — a customer's domain admin, a site's switch password. Encrypted with the same vault; unlock it above to add or reveal.
ScopeLabelUsernameDevices
Loading…
Containers
Docker / Podman / Kubernetes pods reported by enrolled agents. For Docker/Podman you can start, stop, restart, and pull logs — and deploy compose stacks (below). Actions queue to the agent and run on its next heartbeat. Documentation
DeviceOSTotalRunningStoppedRestarting (≥5)DiskRuntimesReported
Image updates
Containers whose pulled image is behind the registry's current digest for that tag. Notify-only — RemotePower flags staleness, you decide when to pull.
ImageTagHostsStatusRegistryLast checked
Compose stacks
Upload a docker-compose file and deploy it to a device — up / down / redeploy. Admin-only and audited, and only to devices where you've turned on compose deploys. RemotePower runs the file as-is on the host; it doesn't sandbox it.
StackDeviceStatusLast action
Proxmox LXC containers
LXC containers on the Proxmox node. Actions hit the Proxmox API directly.
Virtualization
Virtual machines across your hypervisors — Proxmox VE plus any VMware or OpenShift Virtualization platform configured under Settings → Virtualization. List, power and snapshot actions call each platform's API directly from the RemotePower server. Documentation
Network map
Topology view from manually-set connected_to links and tunnels (peer links). Drag nodes to reposition — positions persist across refresh. Add agentless devices on the Devices page. Documentation
Internet (WAN)
Loading…
Job check-ins (dead-man's switch)

For cron jobs on things that aren't in the fleet — the router's backup script, a VPS, a task on the NAS. Those fail silently and you find out months later. Give the job a URL, have it curl that URL when it finishes, and if a check-in doesn't arrive within its period + grace, RemotePower alerts. (This is the inverse of the outbound healthchecks.io pinger, which watches RemotePower.)

Loading…
LAN services (mDNS)

The netscan finds hosts — it tells you an IP is alive, not what it is. mDNS is how the rest of a homelab announces itself: Chromecasts, AirPlay speakers, printers, HomeKit bridges, NAS boxes. Those are exactly the devices nobody enrols an agent on, so without this they're just anonymous IPs on the map. Enable under Settings → Security; needs avahi-browse on at least one agent per segment.

Loading…
Suggested dependencies

Edges inferred from actual outbound connections between your devices (private IPs only). Accept adds a real depends_on link (used for downstream alert suppression); dismiss hides it.

Click Refresh.
Dependency link health

Verifies each declared depends_on edge against observed traffic (agent peer-conns and the NetFlow/IPFIX receiver). A Broken edge carried traffic before and went silent while both hosts stayed online — a firewall/route/service break the offline alert never catches. Enable alerting under Settings → Alerts.

Click Refresh.
Suggested physical links (LLDP)

Physical neighbor links discovered via LLDP (needs lldpd on the hosts). Accept sets a connected_to edge (a manual/physical link that always wins over inferred ones); dismiss hides it.

Click Refresh.
Unmanaged hosts on the LAN

Hosts seen by agents that ran a LAN scan (device drawer → Health & Hardware → Scan LAN) and that aren't enrolled in RemotePower.

No scan data yet — run a LAN scan from a device's Health & Hardware card.
Network metrics

Per-device network throughput (RX/TX) from agent samples — fleet-wide, or rolled up by group, tag or site (a site represents a customer). Unmonitored and decommissioned hosts are shown but flagged.

Loading…
Documentation
Configuration drift
Watched config files across the fleet. Agent hashes each file every few heartbeats; server alerts when a hash diverges from the stored baseline. Hash-only — no file content crosses the wire. Documentation.
Drift profiles

Reusable named sets of watched files. Assign a profile to a device, tag, or group and every matching host monitors that set. A device's own explicit file list (set in its drawer) still overrides any profile; an unassigned host falls back to the global default.

Loading…
Enforcement policy

Auto-apply the desired config for every device matching a tag or group — apply pushes it every poll, correct on drift re-applies only when a host diverges. A device's own per-device setting (in its drawer) still wins. Only devices that already have a desired host config are affected.

Loading…
DeviceGroupFiles watched DriftMissingLast check
Security Advisory
What to fix first, in order, across every layer — built from data already collected, so nothing is scanned or contacted. Documentation
Choose a scope and build the advisory.
Protect
Integrity Guard neutralises files that appear where they shouldn't. A directory-integrity check with auto-quarantine moves any new file into a vault on the host instead of leaving it live — here you review what was taken, put it back, or delete it for good. Enable it per check under Monitoring → Checks. Documentation
Protect checks

Hardening and tamper-detection checks applied to this fleet. They evaluate exactly like any other check — results show per host on Monitoring → Checks and alert through your normal channels. A guard badge means auto-quarantine is enabled for that check. Agent-side results arrive on the next sysinfo report (up to ~10 min), so new rows read unknown until then. Documentation

NameTypeParamApplies to
Loading…
Quarantine vault

Restore returns a file to its original path — only if that path is still free, so a replacement is never overwritten. Delete removes it from the vault permanently. Both are applied by the agent on its next check-in. Quarantine is suppressed during an active maintenance window, and a mass change (a deploy) is reported rather than quarantined.

HostOriginal pathQuarantined
Loading…
Exposure
Every listening socket across the fleet, classified by where it can be reached from. World = bound to a public/wildcard address; LAN = private network; Local = loopback only. A service first becoming world-reachable raises an alert. Documentation.
Listening sockets
DeviceProto/PortProcess Bind addressScope
Loading…
Exposed secrets on disk
Redacted findings from the opt-in agent scan — keys, tokens and passwords found in files. Values are never collected; each row shows a masked preview and a fingerprint. Enable the scan in Settings → Security. Mute a false positive to stop it alerting. Documentation
DeviceType PathPreview Line
Loading…
File manager
Browse, view and edit files on a host without SSH. Confined to allowlisted roots, gated on the command permission, and fully audited. Reads work on quarantined / audit-mode hosts; writes do not. Enable per-server under Settings → Advanced. Documentation
Host
App catalog
One-click deploy of curated, self-contained apps to a host via Docker Compose. Requires compose deploys enabled on the target device (per-device opt-in, Devices → drawer). Gated on the containers permission and audited; the deploy rides the existing compose path. Documentation
Target host
Apps
Cron & timers
View and manage crontabs and systemd timers on a host. Edits run through the audited, permission-gated command queue (quarantined / audit-mode hosts are skipped); crontab content is installed via a temp file, never a shell. Documentation
Host
Firewall
Host firewall rulesets (nftables / iptables / ufw / firewalld) and fail2ban jails across the fleet — view posture and drift, and edit rules, bans and jails. Every change runs through the audited, permission-gated command queue (quarantined hosts are skipped). Documentation
Host firewalls
DeviceBackends StateRules Drift fingerprint
Loading…
fail2ban
Intrusion-prevention jails and the IPs they have banned. Ban or unban an address, or start/stop a jail. Hosts without fail2ban report it as not available.
DeviceJails Banned IPsStatus
Loading…
KMIP
A built-in KMIP key server: Synology DSM, TrueNAS and VMware vSphere store their encryption keys here instead of on the appliance that holds the encrypted data. Clients authenticate with mutual TLS; every connection and key operation lands in the activity log. Do not run this server on a machine that depends on it to unlock. Documentation
Server
Loading…
Recovery

The master key and every stored key travel ONLY in a passphrase-encrypted recovery bundle — scheduled backups deliberately hold ciphertext without the master key. Export a bundle after setup and whenever keys change, and keep it away from the appliances that depend on this server.

Start over

Destroys the master key, the CA, every client and every stored key on this server, so you can reinstall from scratch. Anything still relying on it for encryption keys becomes unrecoverable without a bundle exported beforehand.

Clients

Appliances allowed to talk to this KMIP server. Each holds a client certificate issued here; revoke to cut an appliance off, re-issue to replace a lost certificate without losing its keys.

NameType CertificateLast seen KeysStatus
Loading…
Stored keys

Managed objects held for the clients above — metadata only; key material is never shown. Destroying a key that an appliance still needs makes its encrypted data permanently unrecoverable. A destroyed key stays listed as a record until you remove it.

IDName TypeAlgorithm StateClient Last access
Loading…
Activity log
TimeEvent ClientOperation ObjectResult Detail
Loading…
Risk
A per-asset risk score (0–100) computed on demand from everything RemotePower already knows — open CVEs, world-reachable services, software-policy violations, pending updates, contract/license expiry, mount issues and more. Every point is attributed. Findings you've ignored (CVEs) or muted (Exposure) don't count. Risk is a security-posture lens, independent of fleet health. Documentation
DeviceRisk LevelTop factors
Loading…
EDR coverage
Which hosts your endpoint-protection platform is actually protecting — and which it has never heard of. A host with a stale agent is listed separately from a covered one: an agent that installed and then stopped reporting is protecting nothing, and it is the failure an EDR rollout is most likely to get wrong.
HostEDR Protected byAgent
Integrations
Live health of the homelab/fleet software you've connected — Pi-hole, TrueNAS, the *arr suite, download clients and more. Each tile shows status plus key stats pulled from the service's own API. Documentation.
Loading…
GPUs
GPU state across the fleet — NVIDIA and AMD. Utilisation, VRAM, temperature, power and fan for every reporting host, hottest/busiest first. Hosts report via nvidia-smi / rocm-smi (or the amdgpu sysfs fallback). A GPU at or above the thermal threshold (default 85 °C, set in Settings) raises a High Temperature alert and auto-resolves when it cools. Documentation.
Loading…
Storage health
ZFS, mdadm and btrfs pool/array state across the fleet. Degraded or faulted arrays are listed first and raise an alert; ZFS scrub freshness is tracked. Documentation.
DevicePoolType StateCapacityLast scrub
Loading…

Pools with a Maintain… button can run scrubs, trims/balances, status checks and snapshot cleanup directly — the command is built server-side and queued on the host (admin-only, audited). Output appears under Devices → the host.

Thermal health
Hottest hosts across the fleet — CPU, chipset and disk temperatures the agents already report. Each host shows its single hottest sensor; the list is sorted hottest-first and anything ≥75 °C is flagged. Documentation.
DeviceMax temp Hottest sensorType ThresholdHeadroom Trend (~24h) Sensors
Loading…
SSH key audit
Every authorized_keys entry across the fleet, with OpenSSH SHA256 fingerprints. Weak key types and keys reused across multiple hosts are listed first. Documentation.
DeviceUser TypeComment FingerprintHosts
Loading…
Power & energy
UPS status and measured power draw across the fleet. Hosts on battery are listed first. Set your electricity price to estimate energy cost from the live total. Documentation.
DeviceUPS status BatteryLoad RuntimePower
Loading…
Cost allocation (chargeback)

Estimated monthly energy cost per group and per tag, from each host's measured draw × your price/kWh above. A rough allocation for showback/chargeback — instantaneous watts projected to a 30-day month.

Loading…
Predictive health
Hardware predicted at risk before it fails — disks (reactive SMART verdict + trends in reallocated/pending sectors and SSD wear) and hosts restarting unusually often. Most urgent first; an ETA appears once there's enough history. Documentation.
Disks at risk
RiskDevice DiskWear ETASignals
Loading…
Frequently restarting hosts
DeviceRestarts (7d) Last boot reason
Hosts likely to fail
ScoreDevice Why
Software policy
Rules evaluated against every host's installed-package inventory: banned (must not be installed), required (must be installed), min version. Optionally scope a rule to device tags. Documentation.
Policy rules
Current violations
DeviceRulePackage ExpectedFound
Loading…
Software center

Every package installed across the fleet, with the versions in use and how many hosts run each. Type to filter; click a row to see which hosts (and versions) on the Patches → inventory search.

Loading…
Tickets
Helpdesk — incidents, requests and changes, linked to alerts and devices. Documentation
New tickets
#SubjectTypePriorityStatusSLAAssigneeDeviceUpdated
Loading…
My open tickets
#SubjectTypePriorityStatusSLAAssigneeDeviceUpdated
Loading…
My team's open tickets
#SubjectTypePriorityStatusSLAAssigneeDeviceUpdated
Set your team under Profile to use this view.
Other tickets (open & closed)
#SubjectTypePriorityStatusSLAAssigneeDeviceUpdated
Loading…
Contacts
Internal contact directory — your team's shared phonebook of people, roles and companies. Documentation
NameRoleCompanyEmailPhoneActions
Loading…
MCP Confirmations
Pending write actions queued by MCP clients against devices with require_confirmation=true. Each entry shows the originating AI host and the natural-language prompt that led to the action. Approve to run, reject to discard. Pending entries expire after 1 hour. Documentation
Status Requested Action Device AI host Prompt
Loading…
Audit Log
Security audit trail — logins, commands, session revocations Documentation
Security posture — how the live config measures against secure defaults.
TimeActorActionDetailSource IP
Command Library
Saved shell command snippets — pick from the exec modal Documentation
Snippets
NameCommandDescription
No snippets yet.
Scripts
Multi-line bash scripts. Lint with bash -n + dangerous-command detection before they go anywhere. Run on a single device from the device dropdown, or on a batch via the multi-select bar. Documentation
Saved scripts
Name Description Size Updated Flags