release-2.7.0 (#1264)

* feat: redesign host/credential sidebars with synced preferences and manual drag-to-reorder

* chore: run format

* chore(deps-dev): bump @types/pg in the dev-patch-updates group (#1162)

Bumps the dev-patch-updates group with 1 update: [@types/pg](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/pg).


Updates `@types/pg` from 8.20.0 to 8.20.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/pg)

---
updated-dependencies:
- dependency-name: "@types/pg"
  dependency-version: 8.20.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-patch-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the dev-minor-updates group with 4 updates (#1163)

Bumps the dev-minor-updates group with 4 updates: [react-hook-form](https://github.com/react-hook-form/react-hook-form), [react-icons](https://github.com/react-icons/react-icons), [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) and [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite).


Updates `react-hook-form` from 7.79.0 to 7.84.0
- [Release notes](https://github.com/react-hook-form/react-hook-form/releases)
- [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md)
- [Commits](https://github.com/react-hook-form/react-hook-form/compare/v7.79.0...v7.84.0)

Updates `react-icons` from 5.6.0 to 5.7.0
- [Release notes](https://github.com/react-icons/react-icons/releases)
- [Commits](https://github.com/react-icons/react-icons/compare/v5.6.0...v5.7.0)

Updates `typescript-eslint` from 8.61.1 to 8.66.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.66.0/packages/typescript-eslint)

Updates `vite` from 8.0.16 to 8.2.0
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/create-vite@8.2.0/packages/vite)

---
updated-dependencies:
- dependency-name: react-hook-form
  dependency-version: 7.84.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor-updates
- dependency-name: react-icons
  dependency-version: 5.7.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor-updates
- dependency-name: typescript-eslint
  dependency-version: 8.66.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor-updates
- dependency-name: vite
  dependency-version: 8.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the prod-patch-updates group with 3 updates (#1164)

Bumps the prod-patch-updates group with 3 updates: [jose](https://github.com/panva/jose), [js-yaml](https://github.com/nodeca/js-yaml) and [nanoid](https://github.com/ai/nanoid).


Updates `jose` from 6.2.7 to 6.2.8
- [Release notes](https://github.com/panva/jose/releases)
- [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md)
- [Commits](https://github.com/panva/jose/compare/v6.2.7...v6.2.8)

Updates `js-yaml` from 5.2.2 to 5.2.3
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/5.2.2...5.2.3)

Updates `nanoid` from 6.0.0 to 6.0.1
- [Release notes](https://github.com/ai/nanoid/releases)
- [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md)
- [Commits](https://github.com/ai/nanoid/compare/6.0.0...6.0.1)

---
updated-dependencies:
- dependency-name: jose
  dependency-version: 6.2.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-patch-updates
- dependency-name: js-yaml
  dependency-version: 5.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-patch-updates
- dependency-name: nanoid
  dependency-version: 6.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-patch-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump undici in the prod-minor-updates group (#1165)

Bumps the prod-minor-updates group with 1 update: [undici](https://github.com/nodejs/undici).


Updates `undici` from 8.9.0 to 8.10.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](https://github.com/nodejs/undici/compare/v8.9.0...v8.10.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 8.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps-dev): bump the major-updates group with 2 updates (#1166)

Bumps the major-updates group with 2 updates: [@types/better-sqlite3](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/better-sqlite3) and [jsdom](https://github.com/jsdom/jsdom).


Updates `@types/better-sqlite3` from 7.6.13 to 9.6.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/better-sqlite3)

Updates `jsdom` from 29.1.1 to 30.0.1
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](https://github.com/jsdom/jsdom/compare/v29.1.1...v30.0.1)

---
updated-dependencies:
- dependency-name: "@types/better-sqlite3"
  dependency-version: 9.6.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: major-updates
- dependency-name: jsdom
  dependency-version: 30.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: major-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix: stop resyncAutoIncrement failing on tables without an id column (#1173)

The Postgres branch asked pg_get_serial_sequence(table, 'id') about every
table a fixture had inserted into. That function raises 42703 when the
column does not exist, rather than returning null, so any seed touching a
table keyed on something else took down the fixture.

host_sidebar_preferences is keyed on user_id and has no id at all, which
is why the Postgres job on dev-2.7.0 fails for every pull request.

Drive the lookup from information_schema so a missing id column yields no
row instead of an error. A text primary key still returns a null sequence
and is still skipped, as before.

* chore: install the git hooks that were already configured (#1174)

husky, lint-staged, commitlint and their config have been in the repo
since v1.8.0 (#429): .husky/pre-commit runs lint-staged, .husky/commit-msg
runs commitlint, the lint-staged globs are in package.json and the
commitlint rules in .commitlintrc.json.

None of it has ever run. husky only takes effect once it sets
core.hooksPath, and that happens in the prepare lifecycle script, which
the package did not define -- so every clone installed the tooling and
left the hooks unwired.

That is why formatting keeps failing in CI rather than locally: three of
the four open pull requests fail lint-and-build on prettier alone,
touching between one and five files each, and the check is the first place
anyone finds out.

prepare falls back to true so a checkout without a .git directory cannot
break installation. The Docker build passes --ignore-scripts, so it never
runs this at all.

Also pin the Prettier extension to the repo's own copy via
prettier.prettierPath, and let .vscode/settings.json out of .gitignore so
it applies to everyone. The extension bundles its own prettier otherwise,
which formats to a different version's rules than the one CI enforces.

* fix: derive the ssh_credentials rebuild from the live schema (#1172)

The startup rebuild that drops the old username NOT NULL constraint
restated the table's columns as a literal and then copied rows with
INSERT INTO temp SELECT <every live column>. The table has gained columns
since that literal was written — cert_public_key, pin, sort_order and
sync_id are all added by addColumnIfNotExists before the rebuild runs —
so the destination was narrower than the source. SQLite rejected the
INSERT on a column count mismatch, the error was swallowed as a warning,
and the constraint survived every restart.

Read the CREATE TABLE statement back from sqlite_master and rewrite just
the table name and the username constraint, so the replacement table
cannot fall behind the real one. Copy rows by explicit column name rather
than positionally, and replay the table's indexes, which DROP TABLE would
otherwise take with it along with the sync_id uniqueness.

* fix: make audit_logs.user_id nullable on fresh SQLite installs (#1171)

The audit trail is meant to outlive the account it belongs to: deleting a
user nulls user_id and keeps username for attribution. schema.ts, the
Drizzle migrations and AuditLogRepository.anonymizeByUserId were all
written against that, but the runtime bootstrap still created
user_id TEXT NOT NULL.

A second CREATE TABLE IF NOT EXISTS further down migrateSchema() had the
correct nullable column, but it can never run — the primary bootstrap has
already created the table, so IF NOT EXISTS is a no-op. Every fresh
install therefore got the old constraint, and user deletion failed with
"NOT NULL constraint failed: audit_logs.user_id" for any account that had
logged in at least once, via both the admin delete path and the OIDC
account-link cleanup.

Fix the primary bootstrap, and rebuild the table on existing databases
using the same pattern already used for ssh_credentials.username, since
SQLite cannot ALTER a column.

* fix: key the sync upsert on the row it just looked up (#1175)

A sync push locates the stored row twice -- once to decide insert vs
update, once to write it -- and the two lookups were spelled out
separately. Only the read knew about singleton entities; the write always
keyed on table.id.

userPreferences is the only singleton, and user_preferences is the one
synced table with no id column: its primary key is user_id. table.id was
therefore undefined, and drizzle emitted a comparison with nothing on its
left:

  ( = ? and "user_preferences"."user_id" = ?)

The insert branch was unaffected, so the first push of preferences
succeeded and every push after it -- the steady state -- failed with
SqliteError: near "=": syntax error. Preference sync never converged, and
both sides ship the same handler, so the desktop's embedded backend failed
identically.

Extract the lookup into locateSyncRow() and use it for the read, the
update and the tombstone delete, so the three cannot drift apart again.
The tombstone path already handled singletons correctly; it now shares the
one expression rather than keeping a third copy of it.

* fix: refuse an SSH connection whose host id resolves elsewhere (#1176)

A client identifies a host by the numeric row id of the database it is
displaying. With the desktop connection origin set to "Remote server",
that id is resolved against the sync server's ssh_data instead, and the
two autoincrement sequences need not line up -- they diverge as soon as
each side accumulates inserts and deletes in a different order.

resolveHostById() then returns whichever row owns that id here, and the
handler takes the address, the credentials, the jump hosts and the stored
host key from it. The session opens on a machine the user did not pick,
while the host list, host details and export all keep showing the right
one. Commands run on the wrong server, a host key mismatch is reported
for the wrong reason, and anything typed at the prompt goes to the wrong
place.

Compare the resolved address against the one the client sent, and refuse
when they disagree. Checking at the point the row is loaded covers every
use of it rather than each site separately. Addresses are compared with
brackets stripped and casing folded, so an IPv6 literal or a hostname
written differently is not treated as a different machine; when the
server has no address stored, the client's own details are used as
before.

This stops the wrong-machine session. It does not make delegated
connections work when the ids have drifted -- that needs the host to be
addressed by syncId across the boundary, which the connection protocol
does not currently carry.

* fix: refuse SFTP and Docker console on a mismatched host id too (#1177)

The wrong-machine guard added for SSH covered one of the paths that
resolve a client-supplied host id against this server's ssh_data. The
file manager and the Docker console take the same id from the same client
and dial whatever row owns it here.

The file manager then browses, edits and deletes files on that machine,
and the Docker console attaches to its daemon -- both while the UI shows
the host the user actually picked.

Reuse hostAddressMismatch at each point the row is loaded. The two file
manager sites sit inside "failed to resolve credentials, carry on"
handlers, so the refusal is a distinct error type those catches rethrow;
swallowing it would resume the connection this is meant to stop. The
Docker console reports over its socket, as it does for every other
refusal.

The user-facing wording now lives next to the check instead of being
written out at each site.

Still uncovered, and not fixable this way: file-manager's transfer
session, jump-host-chain and the proxmox routes resolve an id with no
client-supplied address to compare it against. Those need the host to be
addressed by syncId across the boundary.

* feat: address hosts by syncId when a connection is delegated (#1178)

A numeric host id belongs to the database that produced it. The desktop
app lists hosts from its embedded database and names them by row id, so
when a connection is delegated to a sync server that id is resolved
against a different table, whose autoincrement sequence has no reason to
agree. The row it lands on is a different machine, and it supplies the
address, the credentials, the jump hosts and the stored host key.

#1176 and #1177 made that refuse rather than connect. Refusing is right,
but it leaves "Remote server" unusable once the ids have drifted, which
is the state the reporter was in.

syncId already names a host identically on both sides -- remote sync
relies on it, ssh_data.sync_id is unique, and the API already returns it.
It just never reached the backend: hostToSSHHost() builds its result field
by field and dropped it.

Carry it through, and resolve with it when it is present:

  resolveHostBySyncId(syncId, userId)   // translate, then reuse
    -> findHostIdBySyncId(syncId)       // this database's own row id
    -> resolveHostById(hostId, userId)  // permissions, decryption, audit

The translation is deliberately not scoped to a user -- sync_id is unique
across the table and a shared host belongs to someone else -- so access
stays with the permission check in the id-based path, which the new tests
cover.

An unknown syncId resolves to nothing rather than falling back to the
numeric id: an unknown host is precisely where guessing picks the wrong
machine. Clients that send no syncId are unchanged, address comparison
included, so an older desktop keeps its safety net instead of breaking.

* fix(homepage): make the System Overview update indicator able to fire (#1168)

The widget's "Update available" row and orange version text were unreachable,
for two independent reasons that each alone would have been enough.

It called `getVersionInfo(false)`, and `checkRemote=false` makes /version return
early with `{localVersion, status: "update_check_disabled"}` -- no GitHub fetch,
no remote version, nothing to compare. It then read `info.updateAvailable`, a
field the route does not return in either mode; the success response carries
status, localVersion, version, remoteVersion, latest_release, cached and
cache_age. `Boolean(undefined)` is false, always. The read type-checked only
because `getVersionInfo()` is declared as `Record<string, unknown>`, so a
property name that does not exist is indistinguishable from one that does.

Let the endpoint do the comparison and read `status === "requires_update"`,
which is what the dashboard stats bar and the profile panel badge already do.

The row's label was `homepage.overviewUpdate`, whose English string is "Up to
date" -- as the label of an update-available row it read "Up to date / Update
available". Nobody has seen that, because the row has never rendered; fixing
the indicator without the label would have shipped it. Give it its own key.
That leaves `homepage.overviewUpdate` unused; it is left in place rather than
removed, since it would be the natural value for an always-visible row and that
is a product decision, not part of this fix.

* fix: capture real client IP for SSH login alerts behind reverse proxy (#1169)

* fix: capture real client IP for SSH login alerts behind reverse proxy

The WebSocket terminal handler used req.socket.remoteAddress for the
"user logged in" alert message, which is the immediate TCP peer (the
reverse proxy) rather than the actual client IP forwarded via
X-Forwarded-For. This made trust-proxy config on Traefik irrelevant
since Termix never read the header for this code path.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* test: cover getClientIp forwarded-header and socket fallback paths

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix: keep already-shared hosts sharing their SSH authentication (#1179)

Sharing a host used to hand the owner's SSH authentication to the
recipient unconditionally. 2.6.1 put that behind ssh_data.share_ssh_auth,
added as NOT NULL DEFAULT 0.

Existing rows took the default, so every host shared before the upgrade
stopped supplying credentials the moment the column appeared. The snapshot
in collectProtocolSnapshots() is guarded by host.shareSshAuth, so nothing
was captured; resolveRecipientSharedHostAuthentication() then fell through
to "required" and the recipient got "No valid authentication method
provided" on a host that had worked the day before. Downgrading to 2.6.0
restored it, since that code has no such column to consult.

Backfill the flag for hosts that already appear in host_access. That is
where the previous behaviour was in effect and where the owner had already
agreed to share; hosts nobody has shared keep the new default and stay off
until their owner shares them.

Guarded by a settings key so it runs once. Without that, an owner who
turns sharing back off would have it turned on again by the next restart.

* fix: let a single credential disable 2FA again (#1180)

The disable dialog has one field, labelled "Enter TOTP code or password",
and its caller passes that value as disableTOTP(input) -- so it arrives as
`password` with `totp_code` undefined. That call has been unchanged since
v2.3.0.

2.5.1 changed the route to require both:

  if (!totp_code || (!userRecord.isOidc && !password)) -> 400

replacing `const credential = password || totp_code`. The first check has
rejected every attempt since, whatever the user typed, so nobody has been
able to turn 2FA off -- the client reports the generic "Failed to disable
2FA", which hides which check failed.

Take one credential again and try it as a TOTP code, a backup code, then
the account password. verifyTotpReauth still refuses the password itself,
so that comparison stays in the route; an OIDC user has no password hash
and reaches neither.

The backup-codes route has the same shape but no caller in the UI -- its
codes are returned when TOTP is enabled -- so it is left alone rather than
changed blind.

* fix: attach user-managed CA certificates over SFTP too (#1181)

opkssh-cert-auth.ts exports two helpers that end in the same
_applyCertToConnection: setupOPKSSHCertAuth, and setupCACertAuth for
user-managed CA-signed -cert.pub files. The file manager called the first
one twice and the second one never.

So a host whose key is paired with a CA-signed certificate authenticated
in a terminal and failed over SFTP, while OPKSSH certificates -- going
through the other helper -- worked in both. The file manager was not
missing certificate support in general; it was missing one of the two
paths into it.

The connection also never carried the certificate to begin with:
cert_public_key was not among the fields copied into resolvedCredentials,
so both places that build an SFTP connection now read it and attach it
where the private key is prepared -- the dedicated transfer session and
the main connect route.

An unusable certificate is logged and skipped rather than failing the
connection. The key alone may still be accepted, which is what happened
while this was not wired up at all, and turning that into a hard failure
would break setups that currently work.

Reported in #1160 with the call-site asymmetry already traced; the
reporter noted they could not confirm the link to their failure, having
moved off SSH CAs. The asymmetry is real either way and reproduces the
symptom exactly.

* fix: authenticate the desktop Docker console WebSocket (#1182)

The console WS opted out of the query token:

  buildOriginWsUrl({ ..., includeLocalJwt: false })

leaving it with no credential at all on the desktop. The browser
WebSocket API cannot set an Authorization header, and while Electron's
main process injects a remembered JWT cookie, it requires an exact origin
match -- the cookie belongs to the API origin (localhost:30001) while the
console connects to 127.0.0.1:30009, so nothing is attached.

The backend then closes the handshake with 1008 before it logs anything,
which is why the log has no docker-console entries while stats and logs
polling keep succeeding on the same host. The web build is unaffected: it
connects same-origin and its cookie is sent normally.

Drop the opt-out so the console carries the local JWT like the SSH
terminal does -- the same token, the same query parameter, and the
backend already reads it there.

Guacamole passes includeLocalJwt: false too, but rdp/vnc/telnet always
resolve to "remote", so that call never reaches the local branch.

* fix: use getClientIp in getRequestMeta for correct audit-log IPs (#1183)

* fix: capture real client IP for SSH login alerts behind reverse proxy

The WebSocket terminal handler used req.socket.remoteAddress for the
"user logged in" alert message, which is the immediate TCP peer (the
reverse proxy) rather than the actual client IP forwarded via
X-Forwarded-For. This made trust-proxy config on Traefik irrelevant
since Termix never read the header for this code path.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* test: cover getClientIp forwarded-header and socket fallback paths

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix: use getClientIp in getRequestMeta for correct audit-log IPs

getRequestMeta had near-duplicate, strictly worse forwarded-header
logic: the array branch didn't split/trim, there was no socket-peer
fallback, and it returned "" instead of "unknown". Delegate to
getClientIp so the audit trail gets the same correctness as the
terminal login-alert path.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat: add terminal image handoff (#1170)

* chore: sync Crowdin translations

* fix(homepage): make the System Overview update indicator able to fire (#1168)

The widget's "Update available" row and orange version text were unreachable,
for two independent reasons that each alone would have been enough.

It called `getVersionInfo(false)`, and `checkRemote=false` makes /version return
early with `{localVersion, status: "update_check_disabled"}` -- no GitHub fetch,
no remote version, nothing to compare. It then read `info.updateAvailable`, a
field the route does not return in either mode; the success response carries
status, localVersion, version, remoteVersion, latest_release, cached and
cache_age. `Boolean(undefined)` is false, always. The read type-checked only
because `getVersionInfo()` is declared as `Record<string, unknown>`, so a
property name that does not exist is indistinguishable from one that does.

Let the endpoint do the comparison and read `status === "requires_update"`,
which is what the dashboard stats bar and the profile panel badge already do.

The row's label was `homepage.overviewUpdate`, whose English string is "Up to
date" -- as the label of an update-available row it read "Up to date / Update
available". Nobody has seen that, because the row has never rendered; fixing
the indicator without the label would have shipped it. Give it its own key.
That leaves `homepage.overviewUpdate` unused; it is left in place rather than
removed, since it would be the natural value for an always-visible row and that
is a product decision, not part of this fix.

* fix: capture real client IP for SSH login alerts behind reverse proxy (#1169)

* fix: capture real client IP for SSH login alerts behind reverse proxy

The WebSocket terminal handler used req.socket.remoteAddress for the
"user logged in" alert message, which is the immediate TCP peer (the
reverse proxy) rather than the actual client IP forwarded via
X-Forwarded-For. This made trust-proxy config on Traefik irrelevant
since Termix never read the header for this code path.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* test: cover getClientIp forwarded-header and socket fallback paths

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* feat: add terminal image handoff

Add authenticated browser upload and clipboard image handoff for terminal agents. Normalize images through Sharp, enforce storage and request limits, preserve host-visible paths, and provide a stable three-button terminal toolbar.

* docs: document terminal image handoff deployment

---------

Co-authored-by: LukeGus <bugattiguy527@gmail.com>
Co-authored-by: kacperpietrzyk <105545577+kacperpietrzyk@users.noreply.github.com>
Co-authored-by: Brennan Neoh <497569+brennanneoh@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix(desktop): stop suppressing the update prompt, and make the version badge reachable (#1167)

* fix(desktop): stop suppressing the update prompt for users who need it

The startup update modal stored its dismissal under the local app version
rather than the remote version being offered, and the up-to-date branch
wrote that key with no user interaction at all. A user who launched while
current had their own version recorded; once the next release shipped,
`dismissedVersion === currentVersion` still held and the modal was skipped
on every launch. It reappeared only after the user had already updated --
the inverse of what it is for. Present since v2.3.0.

Key the dismissal on the offered remote version instead. The change is
backward compatible: an existing key holding 2.6.0 compares unequal against
a remote 2.6.1, so affected installs are prompted on their next launch. When
the check itself fails there is no remote version, so nothing is recorded and
no future prompt is suppressed.

That left the version badge as the only remaining signal, and it was an inert
span on both surfaces that render it -- the profile panel and the dashboard
stats bar -- even though the `getVersionInfo()` response it is built from
already carries `latest_release.html_url`. Extract the duplicated badge into
`components/version-badge.tsx` and make the update case a link to the release,
with an accessible name that says where it goes. The beta and stable cases
stay inert.

`getVersionInfo()` returned `Record<string, unknown>`, so the release URL was
unreachable without a cast; give it a `VersionInfo` type that keeps an index
signature, since `SystemOverviewWidget` reads `updateAvailable` off the same
response.

* test: cover the read that actually reaches the badge

The extracted VersionBadge is unit-tested, but the line that decides whether
it ever receives a URL -- pulling `latest_release.html_url` out of the version
response -- was duplicated at both call sites and asserted nowhere. A wrong
property there compiles (the response type keeps an index signature) and every
existing test still passes.

Give it a name, `releaseUrlFrom`, use it from both surfaces, and test it: the
happy path, a response with no release, a release with no URL, and a missing
response, since the caller's fetch can reject. Empty string is the contract the
badge reads as "nothing to link to", so it stays an inert span rather than
rendering a dead anchor.

* docs: state the index signature's real reason

The comment claimed the version endpoint carries fields beyond the typed ones,
citing `updateAvailable`. It does not -- `GET /version` returns status,
localVersion, version, remoteVersion, latest_release, cached and cache_age, and
nothing else. SystemOverviewWidget reads `updateAvailable` off it regardless,
which is why the permissive index signature has to stay, but that is a stale
read rather than an undocumented field. Say so accurately.

* Send alerts in Discord channels with Webhooks (#1158)

* feat(utils): add discord webhook sender

Add a utility to send alert embeds to Discord webhooks.

* fix(utils): validate DNS and use global fetch for outbound requests

Prevent private destination access and rely on global fetch after DNS validation.

* chore(logger): include extra context in logs

Show additional sanitized context entries for clearer diagnostics.

* feat(alerts): support discord channel type in routes and engine

Accept discord channels and route alerts to the Discord sender.

* feat(ui): add Discord option to notification channel dialog

Allow creating/editing Discord webhook channels with username/avatar.

* fix(ui/api): accept structured config payload for notification channels

Allow the client to pass structured config objects (or strings) when creating/updating channels.

* chore: sync Crowdin translations

* fix(homepage): make the System Overview update indicator able to fire (#1168)

The widget's "Update available" row and orange version text were unreachable,
for two independent reasons that each alone would have been enough.

It called `getVersionInfo(false)`, and `checkRemote=false` makes /version return
early with `{localVersion, status: "update_check_disabled"}` -- no GitHub fetch,
no remote version, nothing to compare. It then read `info.updateAvailable`, a
field the route does not return in either mode; the success response carries
status, localVersion, version, remoteVersion, latest_release, cached and
cache_age. `Boolean(undefined)` is false, always. The read type-checked only
because `getVersionInfo()` is declared as `Record<string, unknown>`, so a
property name that does not exist is indistinguishable from one that does.

Let the endpoint do the comparison and read `status === "requires_update"`,
which is what the dashboard stats bar and the profile panel badge already do.

The row's label was `homepage.overviewUpdate`, whose English string is "Up to
date" -- as the label of an update-available row it read "Up to date / Update
available". Nobody has seen that, because the row has never rendered; fixing
the indicator without the label would have shipped it. Give it its own key.
That leaves `homepage.overviewUpdate` unused; it is left in place rather than
removed, since it would be the natural value for an always-visible row and that
is a product decision, not part of this fix.

* fix: capture real client IP for SSH login alerts behind reverse proxy (#1169)

* fix: capture real client IP for SSH login alerts behind reverse proxy

The WebSocket terminal handler used req.socket.remoteAddress for the
"user logged in" alert message, which is the immediate TCP peer (the
reverse proxy) rather than the actual client IP forwarded via
X-Forwarded-For. This made trust-proxy config on Traefik irrelevant
since Termix never read the header for this code path.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* test: cover getClientIp forwarded-header and socket fallback paths

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* chore: add url to SENSITIVE_FIELDS for discord url

* fix: enforce SSRF protection on outbound fetches

Use `undici.fetch` with the custom DNS lookup hook to ensure the validated
DNS resolution is the one used for the connection. Fix DNS lookup/address
validation bugs and add coverage for private, public and invalid addresses,
including the resolution issue affecting Discord endpoints.

* chore: prettier format

* fix: validate all DNS addresses and close dispatcher

* fix DNS lookup validation and callback handling
* update safe outbound fetch tests
* ensure created dispatcher is properly closed

* chore: remode url from SENSITIVE_FIELDS for other logs

---------

Co-authored-by: LukeGus <bugattiguy527@gmail.com>
Co-authored-by: kacperpietrzyk <105545577+kacperpietrzyk@users.noreply.github.com>
Co-authored-by: Brennan Neoh <497569+brennanneoh@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

* fix tmux UTF-8 path handling (#1157)

Co-authored-by: Carl <scarlettme@qq.com>

* chore: update package lock

* chore: update gitnore

* fix: [BUG] (#1049)

https://github.com/Termix-SSH/Support/issues/1049

* fix: test commitlint path fix (#1021)

* fix: SGR mouse-tracking escape codes printed as text (#1023)

* fix: quote $1 in commit-msg hook so it works from git worktrees

* fix: [BUG] could not connect to the database (#1057)

https://github.com/Termix-SSH/Support/issues/1057

* fix: [BUG] VNC connect macOS screen sharing failed (#1063)

https://github.com/Termix-SSH/Support/issues/1063

* fix: [BUG] Meta key (#1075)

https://github.com/Termix-SSH/Support/issues/1075

* fix: [BUG] Remote sync doesn't work with Termix behind nginx proxy (#1085)

https://github.com/Termix-SSH/Support/issues/1085

* fix: [BUG] webhook not working (#1080)

https://github.com/Termix-SSH/Support/issues/1080

* fix: [BUG] First server sync doesn't refresh UI (#1084)

https://github.com/Termix-SSH/Support/issues/1084

* fix: [BUG] How to enable SSL using custom certificate (#1083)

https://github.com/Termix-SSH/Support/issues/1083

* fix: [BUG] Sudo Password Auto-fill Persistance (#1098)

https://github.com/Termix-SSH/Support/issues/1098

* feat: [FEATURE] Expand Snippets Function (#1031)

https://github.com/Termix-SSH/Support/issues/1031

* feat: [FEATURE] (#1055)

https://github.com/Termix-SSH/Support/issues/1055

* feat: [FEATURE] Support for Headscale API Keys (hskey prefix) and Custom API Endpoints (#1013)

https://github.com/Termix-SSH/Support/issues/1013

* feat: [FEATURE] Allow paste on non https (#1026)

https://github.com/Termix-SSH/Support/issues/1026

* feat: be-azerty layout (#1073)

https://github.com/Termix-SSH/Support/issues/1073

* feat: Keyboard shortcuts to move between open tabs (#1069)

https://github.com/Termix-SSH/Support/issues/1069

* feat: Session Logs as a downloadable text file (#1058)

https://github.com/Termix-SSH/Support/issues/1058

* fix: persist and auto-fill saved SSH and sudo passwords

* fix: persist docker runtime selection and docker manager UI issues

* feat: Allow excluding specific mounts from disk usage metrics (#1046)

https://github.com/Termix-SSH/Support/issues/1046

* feat: Expand Snippets Function (#1031)

https://github.com/Termix-SSH/Support/issues/1031

* chore: restore the prettier baseline on dev-2.7.0 (#1185)

Five files on dev-2.7.0 do not match prettier, so `npx prettier --check .`
fails and takes lint-and-build with it — on every pull request, whatever
it changes.

Formatting only, produced by `npx prettier --write` on exactly the files
the check names. No logic touched: tsc passes for both configs, backend
148 files / 1106 tests and UI 71 files / 479 tests all pass.

* test: keep the tmux escaping test runnable on Windows (#1184)

The escaping check ran its command through /bin/sh. That binary does not
exist on Windows, and Windows is a supported platform for the desktop
app, so `npm test` fails there on a test about string quoting. CI is
ubuntu-only and would never see it.

Assert the escaped string directly, which covers the rule on every
platform, and keep the round trip through a real shell as a separate case
guarded by platform -- it is the stronger evidence where a shell exists.

* chore: drop the unreachable table probes from migrateSchema (#1186)

Eleven blocks in migrateSchema() guarded a CREATE TABLE IF NOT EXISTS
behind SELECT id FROM <table> LIMIT 1, for tables the primary bootstrap
had already created earlier in the same startup. The probe could not
throw, so the catch never ran.

Two of those unreachable copies had drifted from the definition actually
in use. sessions had lost ON DELETE CASCADE, and session_recordings still
carried user_id TEXT NOT NULL with ON DELETE CASCADE and no username --
the shape from before audit trails were made to outlive the account. They
would have taken effect had anything ever reordered startup.

Kept, because they are not the same thing:

  - blocks whose catch runs ALTER TABLE ADD COLUMN. CREATE TABLE IF NOT
    EXISTS is a no-op on a table that exists, so a database created before
    a column was added still needs the ALTER. Those probe a column, not a
    table.
  - blocks that are a table's only creation point.
  - the user_open_tabs block, which is a data migration; its SELECT is a
    precondition, not a probe.

Deletion only, no behaviour change.

* fix: repair the frontend type-check and clear the 299 errors behind it (#1189)

* fix: repair frontend type-check configuration and the errors it exposed

The root tsconfig.json is solution-style with "files": [], so the
`npx tsc --noEmit` that CI runs compiles nothing at all. Frontend types
have therefore never been checked, and 299 errors had accumulated behind
that no-op. This clears just over half of them; nothing here changes
runtime behaviour.

Configuration:
- "@/types" resolved through the "@/*" fallback to src/ui/types, which
  does not exist. Added an explicit mapping to src/types/index.ts.
- src/vite-env.d.ts sits outside the include list, so import.meta.env and
  the ?url import suffix were unknown. Added.
- src/ui/types/ held a single file, keybindings.ts, while every other
  shared type lives in src/types/. Six modules imported it as
  "@/types/keybindings" and silently resolved to nothing. Moved.

Type definitions that had fallen behind the code:
- guacamoleConfig and terminalConfig were Record<string, unknown> in
  ui-types while the editor read concrete fields off them. Both now use
  the real interfaces; GuacamoleConfig is extracted from its inline
  definition in guacamole-api.ts so the two cannot drift again.
- customThemeColors and TerminalTheme["colors"] described the same object
  with different optionality. Aligned.
- FileWindow declared its own SSHHost whose authType was "password" | "key",
  which no longer matches the eight the app supports.
- connectSSH and listSSHFiles returned Record<string, unknown>, so every
  field the callers destructured arrived as unknown.
- AxiosRequestConfig and AxiosResponse were used without being imported.

Also adds asHttpError() for the handful of catch blocks that reached into
an unknown binding, and narrows the Host | HostFolder comparator and the
RailItem union at the points where the discriminant was not carrying.

Note: dbHealthMonitor.reportDatabaseError was being called with a second
argument it does not accept, so the authenticated-or-not flag was already
being discarded at runtime. Dropped the argument to match the signature;
whether that flag was meant to gate the report is worth a separate look.

* fix: clear more of the frontend type-check baseline

Continues the previous commit; 140 errors down to 70. Three of these were
real defects rather than missing annotations.

Defects:
- DashboardTab counted active tunnels by comparing status to "CONNECTED",
  but CONNECTION_STATES.CONNECTED is "connected" and that is what the
  tunnel manager emits, so the count was always zero. Now compares against
  the constant.
- QuickActionsCard requires isAdmin and gates a block of admin-only actions
  on it, but neither call site passed it — those actions never rendered.
  Both call sites also passed isAdmin to HostStatusCard, which does not
  accept it; the prop had evidently been moved and the call sites missed.
- The host editor stores jump host ids as strings and sent them straight to
  an API typed for numbers. Backend host lookups compare against an integer
  column, which a string does not match on Postgres or MySQL. Converted.

Types brought in line with the data:
- Host and HostData were missing hasPassword, hasSudoPassword, sortOrder,
  instanceId, connectionOrigin, vaultProfileId, syncId, and the "vault"
  authType; TabContextTab was missing the "tunnel" tab, which TabContext
  already branched on.
- statsConfig and terminalConfig used inline shapes that had drifted from
  StatsConfig and TerminalConfig. Both now reference the real interfaces;
  excludedMounts, which the editor reads, was added to StatsConfig.
- downloadSSHFile, generateKeyPair and generatePublicKeyFromPrivate all
  returned Record<string, unknown> while callers read named fields.
- The Guacamole declarations were missing Keyboard.reset, Client.onfile,
  InputStream.sendAck, Status.Code and BlobReader, all already in use.
- NetworkTopologyNode/Edge could not be discriminated, though the graph
  code tells them apart by testing for source/target.

ProxyNode.type is now 4 | 5 | "http" | "socks4" | "socks5". The editor
writes the string spellings while proxy-helper.ts tests for "http" and
casts everything else to 4|5 before handing it to the socks client, so a
chained proxy reaches it as "socks5" rather than 5. Typed as what is
actually stored; reconciling the two spellings needs a migration decision
and is left alone here.

* fix: continue clearing the frontend type-check baseline

70 errors down to 44.

Dead configuration removed:
- Terminal set terminal.options.bellStyle on xterm, which dropped the
  option in v5. The host editor still exposes the setting and stores it;
  it has simply had no effect on the terminal since that upgrade. Making
  the bell work again means handling the onBell event and is left alone.
- CodeEditor passed scrollPastEnd to basicSetup, which has no such option.
- FileManager passed an id to openWindow, which assigns its own and
  discards what it is given — the component was already being rendered
  under a different id than the one the caller held.

Widgets that were registered but unreachable:
- DockerActivityWidget and SshQuickConnectWidget register under
  "docker_activity" and "ssh_quick_connect", neither of which was in
  WidgetTypeId, and both referenced config interfaces that did not exist.
  Added the ids and the two interfaces, inferred from their edit forms and
  defaultConfig.

More endpoints given their real return types: getRecentFiles,
getPinnedFiles, getFolderShortcuts (arrays, not records), downloadSSHFile,
copySSHItem, generateKeyPair, generatePublicKeyFromPrivate and getSnippets.

parseGuacamoleConfig() handles the host row carrying guacamoleConfig either
parsed or as raw JSON, which GuacamoleApp was reading fields off directly.
TerminalHostConfig was missing name, which it reads for the activity log.

* fix: continue clearing the frontend type-check baseline

44 errors down to 17.

Host and AuditLog are now type aliases rather than interfaces. An
interface has no implicit index signature, so neither could be assigned
to the `[key: string]: unknown` shapes that TerminalHostConfig,
HostMetricsTab's HostConfig and several helpers declare — eight errors
came from that alone.

More dead configuration:
- i18n passed checkWhitelist to the language detector, which no longer
  has that option; supportedLngs already covers it.
- SSHAuthDialog passed scrollPastEnd to basicSetup, same as CodeEditor.
- AudioPreview's onLoadedMetadata never fired: react-h5-audio-player
  spells the prop onLoadedMetaData.
- MarkdownRenderer destructured `inline` from code(), which react-markdown
  removed in v9, so the flag was always undefined and every inline span
  took the block branch when it happened to carry a language class. Now
  derived from whether a className is present at all.
- SnippetsPanel put a title prop on a lucide icon, which does not forward
  it; changed to aria-label so the hint is actually reachable.

updateHostConfig in TabContext replaced tab.hostConfig wholesale with the
six-field literal it receives, dropping everything else the tab held about
the host. It now merges onto the existing config.

Also: getReleasesRSS, getUserAlerts and getVersionInfo have real return
types (UpdateLog kept private copies of two of them, and VersionInfo was
missing `version`, which the endpoint sends and the panel renders);
wakeOnLan and vncCredentialId get the numeric ids they are typed for; and
the tmux formatter takes i18next's TFunction instead of a hand-written
signature it does not satisfy.

* fix: clear the last frontend type errors and make CI actually run the check

Baseline is now zero, so the check can be turned on.

`npx tsc --noEmit` — what CI ran and what `npm run type-check` was — compiles
nothing: the root tsconfig.json is solution-style with "files": [], and
plain tsc does not follow project references. Both are now `tsc -b`, which
builds tsconfig.app.json and tsconfig.node.json. Verified by planting a type
error and watching the command fail.

Last defects in this batch:
- patchOpenTab could not carry hostId, so quick-connect's "save this host
  and attach the tab to it" call was passing a field excluded from the
  type all the way down. The column exists and updateForUser spreads
  whatever it receives, so the write worked; only the types disagreed.
  Widened front to back.
- The file-comparison window opened without x, y, width or height — every
  other openWindow call passes them — and sent a `type` field WindowInstance
  does not have.
- HostEditor gated a block on authType === "warpgate", which is not one of
  the eight authType values. Unreachable, and it held only a label and a
  description. Removed.
- FileManager passed onLoadDirectory to a sidebar that neither declares nor
  reads it, and FileManagerApp passed embedded to a FileManager that has no
  such prop.
- TunnelApp's minimal Host was missing three required flags.

The remainder were assertions at boundaries that are genuinely loose: bulk
host import takes rows assembled from untyped input and validates them
server-side, and a vi.fn() whose body only throws infers never.

* feat: add drive file browser and drag-and-drop upload for RDP (#1187)

Drive redirection could already be enabled per host, but the redirected
drive lived inside guacd with no way to reach it from the browser: the
client never handled onfilesystem, so the mounted volume was writable
from Windows and invisible from Termix.

Add a file browser panel that lists the drive, downloads files, and
uploads them, plus drag-and-drop onto the display which opens the panel
and uploads into the directory currently shown. The disable-upload and
disable-download connection settings are honoured by the UI, not just
passed to guacd.

A rejected upload stops the BlobWriter without firing onerror or
oncomplete, so the error ack is watched explicitly; otherwise the
transfer would hang forever. Directory reads carry a deadline for the
same reason.

Also declares Guacamole.Object, Client.onfilesystem, BlobReader and
BlobWriter in the local type definitions, which previously omitted them.

* fix: keep the mouse working on touch-capable devices in RDP/VNC (#1190)

Reported as "mouse input broken, keyboard fine" after 2.5.1 (#1102).

2.5.1 bound Guacamole.Mouse unconditionally. 2.6.0 replaced that with a
three-way branch on touchMode, and the touch branches replace the mouse
binding instead of adding to it:

    if (touchMode === "touchscreen")      new Guacamole.Mouse.Touchscreen(el)
    else if (touchMode === "touchpad")    new Guacamole.Mouse.Touchpad(el)
    else                                  new Guacamole.Mouse(el)

The two do not overlap. Guacamole.Mouse listens for mousedown/mousemove/
mouseup; Touchscreen and Touchpad listen only for touchstart/touchmove/
touchend. So in a touch mode nothing is listening for the mouse at all.

touchMode defaults to "touchscreen" whenever navigator.maxTouchPoints > 0,
which is true of every laptop with a touchscreen — machines that are still
driven by a mouse. Those users lost the pointer entirely while the keyboard
kept working, because Guacamole.Keyboard is bound independently.

The physical pointer is now always bound and a touch emulator is layered on
top when one is selected. Extracted to bindPointerInput() so the binding is
testable; the test fails against the old branch.

Note the issue also carries a second, unrelated report where well-formed
mouse frames do reach guacd and the VNC leg ignores them. That one is not
this, and the guacd image is pinned to 1.6.0 in both 2.5.1 and 2.6.1, so it
is not an upgrade either.

* fix: deduplicate /api/folders requests to prevent intermittent folder disappearance (#1191)

* chore: sync Crowdin translations

* fix: deduplicate /api/folders requests to prevent intermittent folder disappearance

getSSHFolders() had no request deduplication while getSSHHosts() used a TTL
cache with in-flight dedupe. When loadHosts() fired multiple times during
rapid navigation between Credentials and Hosts panels, the folder response
could arrive after the hosts response, causing the sidebar tree to render
without folder metadata.

- Add foldersCache (10s TTL) in hosts-request-cache.ts
- Wrap getSSHFolders() API call in getCachedSSHFolders()
- Invalidate folders cache on renameFolder, updateFolderMetadata,
  deleteAllHostsInFolder, and renameCredentialFolder
- Include foldersCache in invalidateHostsAndStatusCaches()

Closes Termix-SSH/Support#1103

Signed-off-by: RawNuke <67506722+RawNuke@users.noreply.github.com>

---------

Signed-off-by: RawNuke <67506722+RawNuke@users.noreply.github.com>
Co-authored-by: LukeGus <bugattiguy527@gmail.com>

* chore(deps): bump undici from 8.9.0 to 8.10.0 in the prod-minor-updates group (#1195)

* chore: sync Crowdin translations

* chore(deps): bump undici in the prod-minor-updates group

Bumps the prod-minor-updates group with 1 update: [undici](https://github.com/nodejs/undici).


Updates `undici` from 8.9.0 to 8.10.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](https://github.com/nodejs/undici/compare/v8.9.0...v8.10.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 8.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor-updates
...

Signed-off-by: dependabot[bot] <support@github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: LukeGus <bugattiguy527@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat: proxmox metrics integration

* feat: add folder select to the host multi select feature

* feat: implement context aware terminal toolbar with quick links, host info, image pasting, etc

* feat: made toolbar open file manager at path

* fix: delete folder route not invalidating host list cache

* fix: match host list icons with tab bar iconfix

* fix: change sidebar reset button icon to seperate against fullscreen button

* feat: unify connection system and add connection logs to guacd hosts

* fix: make mobile terminal scrollback match xterm wheel behavior (#1198)

* fix: route mobile terminal scrolling through xterm viewport

* docs: document mobile terminal touch scrolling

* chore: add a note to not place files in docs

* chore: remove touch imput from docs

* feat: improve snippet system with variable snippets and collapse settings

* feat: new fleet system with snippet, packages, files, and inventory features

* fix: command pallete not loading new activity and made enter load first item

* feat: add subhost from parent host organization feature

* feat: add workspaces feature to save tab layout

* perf: greatly improved performance across metrics polling and host management for enterprise users

* feat: add a onboarding system with a new interface simplicity system

* feat: finalize the multi dialect database system

* fix: bind trusted MFA devices to client installs (#1202)

* fix: merge OIDC group claims across sources (#1203)

* fix: allow disabling SSH keepalives (#1204)

* fix: distinguish reachable and available hosts (#1206)

* fix: throttle session activity persistence (#1207)

* fix: preserve saved RDP connection settings (#1208)

* fix: authenticate tunnel status stream (#1209)

* fix: select quick-created credentials (#1210)

* fix: stagger initial metrics collection (#1211)

* fix: stagger initial metrics collection

* fix: admit reachable hosts to initial metrics

* fix: prevent long host names shifting dashboard metrics (#1205)

* feat: add global touch input settings (#1201)

Co-authored-by: ZacharyZcR <zacharyzcr1984@gmail.com>

* fix: keep host list row sizing stable (#1213)

* fix(guacamole): correct Windows key mapping (#1216)

* fix: normalize OIDC discovery issuer URLs (#1218)

* fix: prompt for RDP domain credentials (#1212)

* fix: route status checks by connection origin (#1214)

* fix: restore desktop Tailscale configuration (#1215)

* fix(docker): restore Node 24 for ssh2 native crypto (#1217)

* feat: added new automations feature with events, channels, and steps

* feat: allowed some tabs in the app rail to be opened as its own tab or in a new right sidebar

* feat: expand onboarding process with more customization/features

* feat: initial implementation of the termix ai feature

* chore: run linter

* fix: issue #424 (#424)

https://github.com/Termix-SSH/Support/issues/424

* fix: Not working without internet connection. Missing OPKSSH binary in pre-built image. (#1133)

https://github.com/Termix-SSH/Support/issues/1133

* fix: SQLite forceSave on telemetry writes causes periodic SSH terminal stalls in 2.6.x (#1109)

https://github.com/Termix-SSH/Support/issues/1109

* feat: How to enable SSL using custom certificate (#1083)

https://github.com/Termix-SSH/Support/issues/1083

* fix: show profile API key after creation (#1221)

* feat: add trusted proxy authentication (#1222)

* fix: clarify SSH agent authentication (#1224)

* feat: add first-class split screen tabs (#1226)

* feat: add split tab data model

* feat: make split screens top-level tabs

* feat: persist and manage split layouts

* feat: launch native RDP on Windows desktop (#1223)

* feat: launch native RDP on Windows

* style: format native RDP launcher

* feat: enhance custom disk and network metrics (#1220)

* feat: enhance host disk and network metrics

* fix: align enhanced metrics types

* fix: preserve Proxmox guest identity on edit (#1219)

* fix: preserve Proxmox guest identity on edit

* fix: type Proxmox guest source metadata

* chore: dead-code cleanup and small refactors (#1225)

* chore: remove dead code and unused exports

* chore: remove unused api client functions

* chore: remove unused backend helpers

* refactor: extract getErrorMessage helper for repeated error extraction

* refactor: unify error message extraction across backend with getErrorMessage

* refactor: unify error message extraction in frontend with getErrorMessage

* refactor: merge duplicate imports from the same module

* refactor: use Array.includes in TabBar

* chore: drop biome, keep prettier as the single formatter

* style: apply prettier formatting to refactored files

* fix: close active tab with Ctrl+W on Windows

* fix: make tray Quit terminate the desktop app

* feat: verify host transfer integrity

* fix: reuse transfer sessions during verification

* feat: select the fastest host transfer route

* feat: tune host transfers adaptively

* feat: adapt background polling to activity (#1233)

* feat: adapt background polling to activity

* feat: extend adaptive polling coverage

* feat: make polling cost and network aware (#1234)

* feat: make repeat navigation feel instant (#1235)

* feat: make file operations feel immediate (#1236)

* feat: preload likely user actions (#1237)

* feat: preload likely file previews

* feat: preload likely host tools

* feat: preload likely file viewers

* fix: replace stale terminal input listeners

* feat: add links to docs for all new features

* chore: update readme

* fix: warn before discarding host changes (#1229)

* feat: learn local host action preferences (#1238)

* feat(terminal-toolbar): add bounded movable desktop toolbar (#1239)

* feat: add local adaptive decision engine (#1240)

* feat: adapt speculative resource usage (#1241)

* feat: persist adaptive transfer profiles (#1242)

* Fix .preferred_username when using LDAP login. (#1243)

* chore: sync Crowdin translations

* Fix .preferred_username when using LDAP login. Strips internal LDAP prefix from username.

---------

Co-authored-by: LukeGus <bugattiguy527@gmail.com>

* feat: learn direct transfer routes (#1244)

* feat: learn speculative preload usefulness (#1245)

* fix: - Adjusting the SSH Authentication from Vault to something else fails (#1152)

https://github.com/Termix-SSH/Support/issues/1152

* fix: terminal graphical display, special characters inserted, distorted - `midnight comma... (#1145)

https://github.com/Termix-SSH/Support/issues/1145

* feat: single click on host in list opens session - should be only on double click (#1146)

https://github.com/Termix-SSH/Support/issues/1146

* feat: Terminal: custom font/ font selection/ how-to for adding a font - `MesloLGS NF` (#1140)

https://github.com/Termix-SSH/Support/issues/1140

* fix: revert host single click to open session, make double click an option (#1146)

Single click opens a session again by default. The old double click
behavior can be turned on in Customize Sidebar.

* chore: drop prettier check from beta release workflow, run formatter

* chore: patch dependabot vulnerabilities via npm overrides

* fix: reset adaptive resource state between tests to stop cross-test leaks

* feat: replace terminal toolbar density popover with a native select

* fix: pin hardwareConcurrency in adaptive budget tests so CI cores don't change the tier

* fix: allow dylib files in mac universal arch rules so mas build packages sharp

* feat: add file manager trash (#1250)

* feat: add inheritable connection defaults (#1246)

* feat: add desktop local terminal (#1247)

* feat: add interactive terminal macros (#1248)

* feat: add adaptive SSH local echo (#1249)

* fix: sync desktop host changes immediately (#1252)

* fix: route desktop sharing through synced server (#1253)

* Fix terminal image uploads and add safe diagnostics (#1254)

* feat: add configurable terminal image storage backends

* feat: add admin image storage settings

* fix: preserve native clipboard PNG uploads

* fix: quote terminal image paths safely

* docs: record image storage security remediation plan

* fix: close remote image SFTP channels

* fix: restrict remote image SFTP permissions

* fix: bound remote image SFTP writes

* fix: add best effort remote image retention

* fix: cap normalized image output size

* fix: bound concurrent image processing

* fix: fail closed on local image inspection errors

* test: cover fail closed image storage and atomic settings

* fix: enforce remote image quota and upload admission

* fix: serialize remote quota and verify existing paths

* fix: use synchronous sqlite settings transaction

* fix: keep settings transactions portable across dialects

* fix: bound image processing admission queue

* fix: serialize remote image quota across processes

* fix: recover stale remote image locks safely

* fix: preserve remote storage errors during unlock

* fix: fail closed when stale lock removal fails

* fix: harden image upload resource and storage cleanup

* fix: bound SFTP operations and lock lifetime

* fix: bound SFTP acquisition and cleanup callbacks

* fix: close late SFTP channels and test cleanup stalls

* fix: preserve SFTP inspection client context

* feat: add image upload source metadata

* fix: expose image upload metadata in logs

* chore: exclude internal plan from pull request

* style: apply prettier formatting

---------

Co-authored-by: ZacharyZcR <zacharyzcr1984@gmail.com>

* fix: batch of security hardening fixes (#1255)

* fix: bind desktop auto-session loopback check to the TCP peer address

* fix: escape HTML entities in Vault OIDC callback responses

* fix: route homepage ping and rss through the SSRF-safe outbound fetch

* fix: scope tunnel status endpoints to hosts the caller can access

* chore: update release notes

* chore: update release notes to write more about the ai integration

* fix: unbreak windows and macos electron builds after node-pty

Install Spectre-mitigated MSVC libs on the Windows runner and cover
node-pty's spawn-helper in the macOS universal arch rules.

* fix: rework connection defaults ui into a dialog and add missing i18n keys

* fix: rework macros panel with i18n, plain text matching, and list layout

* feat: add docs links for trash, connection defaults, and local echo

* fix: make image storage and trash tests pass on windows

* fix: stop docs links squeezing sidebar panel headers

* fix: put automations docs link back on the tabs row

* fix(desktop): keep Linux credential storage working on unrecognised desktops (#1261)

Chromium resolves safeStorage's backend from XDG_CURRENT_DESKTOP and falls
back to the basic_text store for any desktop it has no mapping for, which
covers every wlroots-style compositor (Hyprland, sway, niri, river).
isEncryptionAvailable() reports false for that store, so saveRemoteSyncJwt
refused every write and the OIDC sign-in it was storing appeared to succeed.
The sync engine then found no JWT and reported the session as expired, which
sent users looking at their OIDC provider for a fault that was never there.

Name the libsecret backend explicitly on those desktops. They run an ordinary
Secret Service, so that is enough to make encryption available again. KWallet
desktops keep their auto-detected backend, an explicit --password-store still
wins, and no stored secret can be orphaned by the switch because
isEncryptionAvailable() gated every write that would have created one.

Also stop discarding the {success: false} the main process returns when it
cannot store a credential: on a machine with no Secret Service at all, the
sign-in now says so instead of silently completing.

Co-authored-by: alexandre-vl <rafaelsenchais@gmail.com>

* chore: update release notes

* chore: update release notes

* fix(file-manager): widen trash dialog so names and paths are not cut off

* fix(sidebar): stop hover action tray overlapping the row below it

* fix(hosts): make real status colors toggle actually apply

* feat(local-terminal): add rail button and fix hardcoded tab label

* chore: update release notes

* fix(ai): hide assistant everywhere when admin disables it globally

* fix(automations): fix concurrency race, wire docker and internal event triggers

Claim the in-flight slot in the same tick it is checked, poll container
state for docker_event triggers, emit the internal events, apply the
schedule time zone, and expose the concurrency policy in the editor.

* fix(sidebar): rework host and credential drag-to-reorder

Adds a lock toggle in the sort menu and fixes reorder positioning,
cross-folder drops, and the duplicate drop indicator.

* chore(sidebar): drop unused sortKey prop from host and credential trees

* fix(sidebar): fix row height in click tray mode so status stripes stop overlapping

* fix(onboarding): remove add-first-host step that closed onboarding mid-flow

* fix(release): upload release notes so Mac App Store review submission stops failing

* chore: sync Crowdin translations for 2.7.0

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: RawNuke <67506722+RawNuke@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: ZacharyZcR <zacharyzcr1984@gmail.com>
Co-authored-by: kacperpietrzyk <105545577+kacperpietrzyk@users.noreply.github.com>
Co-authored-by: Brennan Neoh <497569+brennanneoh@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: T3rM1nAt0-R <niraj.sangani91@gmail.com>
Co-authored-by: Horziox <horziox.dev@gmail.com>
Co-authored-by: William Shi <184219650@qq.com>
Co-authored-by: Carl <scarlettme@qq.com>
Co-authored-by: Raw_Nuke <67506722+RawNuke@users.noreply.github.com>
Co-authored-by: njz-cvm <njz@cvm.com>
Co-authored-by: Alexandre VARGAS <alexandre.vargas.lopez@gmail.com>
Co-authored-by: alexandre-vl <rafaelsenchais@gmail.com>
This commit is contained in:
Luke Gustafson
2026-08-19 14:12:06 -05:00
committed by GitHub
co-authored by dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> ZacharyZcR kacperpietrzyk Brennan Neoh Claude Sonnet 5 T3rM1nAt0-R Horziox William Shi Carl Raw_Nuke njz-cvm Alexandre VARGAS alexandre-vl
parent 5021ccf3e2
commit 7ae1648c25
837 changed files with 387941 additions and 15831 deletions
+1 -4
View File
@@ -78,11 +78,8 @@ jobs:
- name: Run ESLint - name: Run ESLint
run: npx eslint . run: npx eslint .
- name: Run Prettier check
run: npx prettier --check .
- name: Type check - name: Type check
run: npx tsc --noEmit run: npm run type-check
- name: Run unit tests - name: Run unit tests
run: npm run test run: npm run test
+54 -1
View File
@@ -77,6 +77,43 @@ jobs:
node-version-file: ".nvmrc" node-version-file: ".nvmrc"
cache: "npm" cache: "npm"
- name: Install Spectre-mitigated MSVC libraries
shell: pwsh
run: |
# node-pty's binding.gyp sets SpectreMitigation, so MSBuild refuses to
# build without these. They are not on the runner image by default.
$vswhere = "${env:ProgramFiles(x86)}\Microsoft Visual Studio\Installer\vswhere.exe"
$installPath = & $vswhere -latest -products * -property installationPath
if (-not $installPath) { throw "Visual Studio installation not found" }
# Derive the toolset version from the installed MSVC so the component
# id keeps matching when the runner image bumps the compiler.
$toolsetDir = Get-ChildItem -Path "$installPath\VC\Tools\MSVC" -Directory |
Sort-Object Name -Descending | Select-Object -First 1
if (-not $toolsetDir) { throw "No MSVC toolset found under $installPath" }
$parts = $toolsetDir.Name.Split(".")
$shortVer = "$($parts[0]).$($parts[1].Substring(0,2))"
Write-Host "MSVC toolset $($toolsetDir.Name) -> component version $shortVer"
$installer = "${env:ProgramFiles(x86)}\Microsoft Visual Studio\Installer\vs_installer.exe"
$components = @(
"Microsoft.VisualStudio.Component.VC.$shortVer.17.14.x86.x64.Spectre",
"Microsoft.VisualStudio.Component.VC.Runtimes.x86.x64.Spectre"
)
$args = @("modify", "--installPath", "`"$installPath`"", "--quiet", "--norestart", "--nocache")
foreach ($c in $components) { $args += @("--add", $c) }
Write-Host "Installing: $($components -join ', ')"
$proc = Start-Process -FilePath $installer -ArgumentList $args -Wait -PassThru -NoNewWindow
if ($proc.ExitCode -ne 0 -and $proc.ExitCode -ne 3010) {
Write-Host "vs_installer exited with $($proc.ExitCode); verifying libraries anyway"
}
$found = Get-ChildItem -Path "$installPath\VC\Tools\MSVC" -Recurse -Filter "*.lib" -ErrorAction SilentlyContinue |
Where-Object { $_.FullName -match "\\spectre\\" } | Select-Object -First 1
if (-not $found) { throw "Spectre-mitigated libraries still missing after install" }
Write-Host "Spectre libs present: $($found.FullName)"
- name: Install dependencies - name: Install dependencies
run: npm ci run: npm ci
@@ -1117,6 +1154,18 @@ jobs:
BUILD_VERSION="${{ steps.build_number.outputs.build_version || github.run_number }}" BUILD_VERSION="${{ steps.build_number.outputs.build_version || github.run_number }}"
npm run build && npx electron-builder --mac mas --universal --config.buildVersion="$BUILD_VERSION" npm run build && npx electron-builder --mac mas --universal --config.buildVersion="$BUILD_VERSION"
- name: Generate App Store release notes
id: asc_notes
if: steps.check_certs.outputs.has_certs == 'true' && steps.check_asc_creds.outputs.has_credentials == 'true'
run: |
META_DIR="$RUNNER_TEMP/asc_metadata"
rm -rf "$META_DIR"
node scripts/generate-appstore-notes.cjs \
--notes RELEASE_NOTES.md \
--out-dir "$META_DIR" \
--locales "en-US"
echo "metadata_path=$META_DIR" >> "$GITHUB_OUTPUT"
- name: Upload and submit to Mac App Store - name: Upload and submit to Mac App Store
if: steps.check_certs.outputs.has_certs == 'true' && steps.check_asc_creds.outputs.has_credentials == 'true' if: steps.check_certs.outputs.has_certs == 'true' && steps.check_asc_creds.outputs.has_credentials == 'true'
run: | run: |
@@ -1133,8 +1182,12 @@ jobs:
--pkg "$PKG_FILE" \ --pkg "$PKG_FILE" \
--api_key_path "$API_KEY_JSON" \ --api_key_path "$API_KEY_JSON" \
--app_version "$VERSION" \ --app_version "$VERSION" \
--skip_metadata true \ --platform osx \
--app_identifier "com.karmaa.termix" \
--skip_metadata false \
--metadata_path "${{ steps.asc_notes.outputs.metadata_path }}" \
--skip_screenshots true \ --skip_screenshots true \
--skip_app_version_update false \
--submit_for_review true \ --submit_for_review true \
--automatic_release true \ --automatic_release true \
--precheck_include_in_app_purchases false \ --precheck_include_in_app_purchases false \
+1 -1
View File
@@ -33,7 +33,7 @@ jobs:
run: npx prettier --check . run: npx prettier --check .
- name: Type check - name: Type check
run: npx tsc --noEmit run: npm run type-check
- name: Build - name: Build
run: npm run build run: npm run build
+6 -3
View File
@@ -13,7 +13,8 @@ dist-ssr
coverage coverage
*.local *.local
.vscode/ .vscode/*
!.vscode/settings.json
.idea .idea
.DS_Store .DS_Store
*.suo *.suo
@@ -33,5 +34,7 @@ electron/build-info.cjs
/.mcp.json /.mcp.json
/CLAUDE.md /CLAUDE.md
/old_db/ /old_db/
/scripts/fix-bugs.mjs /scripts/auto-fix.mjs
/scripts/fix-features.mjs /scripts/auto-fix-blocklist.json
/scripts/auto-fix-state.json
/scripts/auto-fix-report-*.json
+1 -1
View File
@@ -1 +1 @@
npx --no -- commitlint --edit $1 npx --no -- commitlint --edit "$1"
+22
View File
@@ -0,0 +1,22 @@
{
"editor.formatOnSave": true,
"editor.defaultFormatter": "esbenp.prettier-vscode",
"prettier.prettierPath": "./node_modules/prettier",
"editor.codeActionsOnSave": {
"source.fixAll.eslint": "explicit"
},
"eslint.validate": [
"javascript",
"javascriptreact",
"typescript",
"typescriptreact"
],
"files.eol": "\n",
"files.insertFinalNewline": true,
"files.trimTrailingWhitespace": true,
"[markdown]": {
"files.trimTrailingWhitespace": false
},
"typescript.tsdk": "node_modules/typescript/lib",
"typescript.enablePromptUseWorkspaceTsdk": true
}
+127 -70
View File
@@ -4,7 +4,7 @@
<h1>Termix</h1> <h1>Termix</h1>
<p>Self-hosted SSH management and remote desktop access</p> <p>Self-hosted server management, from SSH and remote desktop to automations</p>
<p> <p>
English · English ·
@@ -58,7 +58,7 @@ Termix is free and open source. If you find it useful, consider [donating](https
## Overview ## Overview
Termix is an open-source, forever-free, self-hosted all-in-one server management platform. It provides a multi-platform solution for managing your servers and infrastructure through a single, intuitive interface. Termix offers SSH terminal access, remote desktop control (RDP, VNC, Telnet), SSH tunneling capabilities, remote file management, and many other tools. Termix is the perfect free and self-hosted alternative to Termius available for all platforms. Termix is a free, open source, self-hosted platform for managing your servers. It puts SSH terminals, remote desktops (RDP, VNC, Telnet), file transfers, tunnels, Docker, metrics, and automations in one place, on web, desktop, and mobile. It is a self-hosted alternative to Termius that stays free forever.
<br /> <br />
@@ -68,42 +68,42 @@ Termix is an open-source, forever-free, self-hosted all-in-one server management
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH Terminal Access:** **SSH Terminal:**
Full-featured terminal with split-screen support (up to 4 panels) with a browser-like tab system. Includes support for customizing the terminal including common terminal themes, fonts, and other components. A full terminal with browser-like tabs and split screen, up to 6 panels at once. Pick your theme, font, and colors. A toolbar sits above each session with live CPU, memory, and disk, plus quick links to that host's files, Docker, tunnels, and metrics.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Remote Desktop Access:** **Remote Desktop:**
RDP, VNC, and Telnet support over the browser with complete customization and split screening. RDP, VNC, and Telnet in the browser, in tabs and split screen like any other session. Includes a file browser for RDP drives and drag-and-drop upload. On Windows desktop you can also open a host in the native RDP client.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH Tunnel Management:** **SSH Tunnels:**
Create and manage server-to-server SSH tunnels with automatic reconnection, health monitoring, and local, remote, or dynamic SOCKS forwarding. Desktop client-to-server tunnel settings are stored locally per desktop install, optional C2S preset snapshots can be saved to the server, renamed, loaded, or deleted when you want to move a local tunnel configuration between clients. Local, remote, and dynamic SOCKS forwarding with auto reconnect and health checks. Client-to-server tunnels on the desktop app are stored on that machine, and you can save presets to the server to move a setup to another client.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Remote File Manager:** **File Manager:**
Manage files directly on remote servers with support for viewing and editing code, images, audio, and video. Upload, download, rename, delete, and move files seamlessly with sudo support. Includes support for moving files from server to server. Browse, edit, upload, download, rename, move, and delete files over SFTP, with sudo support. View and edit code, images, audio, and video. Copy files straight from one server to another, with the fastest route picked for you and transfers checked for integrity.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Docker and Podman Management:** **Docker and Podman:**
Start, stop, pause, remove containers. View container stats. Control containers using a docker exec terminal. Supports both Docker and Podman as the container runtime. It was not made to replace Portainer or Dockge but rather to simply manage your containers compared to creating them. Start, stop, pause, and remove containers, watch their stats, and open a shell inside one. Works with both Docker and Podman. It is not meant to replace Portainer or Dockge, just to manage containers you already have.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH Host Manager:** **Host Manager:**
Save, organize, and manage your SSH connections with tags and folders (folder customization and nested folder support), and easily save reusable login info while being able to automate the deployment of SSH keys. Save and organize hosts with tags and nested folders you can name and color. Reuse saved credentials across hosts, deploy SSH keys automatically, group hosts under a parent host, bulk edit and export, and use Quick Connect for one-off connections you do not want to save.
</td> </td>
</tr> </tr>
@@ -111,97 +111,139 @@ Save, organize, and manage your SSH connections with tags and folders (folder cu
<td width="50%" valign="top"> <td width="50%" valign="top">
**Host Metrics:** **Host Metrics:**
View CPU, memory, disk usage, network, uptime, system information, firewall, port monitor, log viewer, users/permissions, certificates, and many more which work on most Linux based servers. Includes time-series history graphs and threshold-based alerts with ntfy and webhook support. CPU, memory, disk, network, temperature, uptime, processes, ports, logins, and system info on most Linux servers, with history graphs. Manager cards let you handle services, cron jobs, packages, users, firewall rules, WireGuard, Tailscale, SSL certs, logs, and health checks without leaving Termix.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**User Authentication:** **Automations:**
Secure user management with admin controls (can edit other users information) and OIDC/LDAP/SSO (with access control), 2FA (TOTP), and passkey (WebAuthn) support. View active user sessions across all platforms and revoke permissions. Link your OIDC/Local accounts together. View audit log of all users actions. Pick a trigger, then say what should happen. Triggers include a metric crossing a threshold, a host going up or down, a health check changing, a schedule, a container event, or an incoming webhook. Steps can run commands and snippets, control containers and tunnels, wake a host, call a URL, wait, branch on a condition, run another automation, and notify you over ntfy, Discord, or a webhook. Test runs let you try it safely first.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Tailscale Integration:** **Fleets:**
List devices from your tailnet to quickly add them as hosts, and connect using Tailscale SSH as an authentication method, letting your tailnet ACLs handle authorization without storing credentials. Group hosts into a fleet by picking them or with tag rules, so new hosts join on their own. Run one command on every host at once, push and pull files across all of them, install packages, and collect an inventory of OS, kernel, arch, and uptime.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**RBAC/Sharing:** **AI Assistant:**
Create roles and share hosts across users/roles. Supports all auth types and all host protocols. Optional, and off until you turn it on. Connect OpenAI, Anthropic, Gemini, Ollama, or any OpenAI compatible endpoint and ask about your setup. It reads hosts, fleets, snippets, and alerts, and proposes changes for you to approve instead of making them. It can never touch credentials, users, or settings. Admins can leave it off for the whole instance, and you can hide it during setup.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Serial Connections:** **Login and Users:**
Connect to serial devices (routers, switches, microcontrollers, etc.) directly from the browser or desktop app. Configure baud rate, data bits, stop bits, and parity. Uses the Web Serial API in supported browsers or a native backend in the Electron app. Local accounts plus OIDC, LDAP, GitHub, and Google sign-in, with 2FA (TOTP), passkeys (WebAuthn), and trusted devices. Admins can manage users, map OIDC groups to roles, see every active session across platforms, and revoke them. Link your local and OIDC accounts together, and read the audit log of what everyone did.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Roles and Sharing:**
Create roles and share hosts with users or roles at four levels: connect, view, edit, and manage. Works with every auth type and every protocol, and you can override the credentials used for a shared host.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Alerts:** **Alerts:**
Set threshold-based alert rules on host metrics (CPU, memory, disk, etc.) and get notified via ntfy or webhooks when they fire. View firing and resolved alerts in a history log. Set rules on host metrics like CPU, memory, and disk, and get notified over ntfy, Discord, or a webhook when they fire. See firing and resolved alerts in a history log, and dismiss the ones you do not care about.
</td> </td>
</tr>
<tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Homepage:** **Homepage:**
A fully customizable homepage with a drag-and-drop widget grid. Add widgets for host status, service links, clocks, notes, RSS feeds, weather, Docker containers, host metrics charts, embedded terminals, iframes, and more. A drag-and-drop widget grid you build yourself. Widgets for host status, pings, service links, bookmarks, search, clocks, calendars, countdowns, notes, RSS, weather, images, iframes, Docker, tunnels, metrics charts, custom APIs, and even a live terminal.
</td>
<td width="50%" valign="top">
**Database Encryption:**
Backend stored as encrypted SQLite database files. View [docs](https://docs.termix.site) for more.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Network Graph:** **Snippets and Tools:**
Customize your Dashboard to visualize your homelab based off your SSH connections with status support. Save commands you run often and fire them off in one click, with variables for the host and your own inputs. Run a single command across every open terminal, and search your command history with autocomplete.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH Tools:** **Session Sharing:**
Create reusable command snippets that execute with a single click. Run one command simultaneously across multiple open terminals. Share a live terminal, RDP, VNC, or Telnet session in real time. Send a link anyone can join without an account, or share with a specific Termix user, in read-only or read-write mode. Shares can expire on their own or be revoked, and can be turned off globally or per host.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Persistent Tabs:** **Session Recording and Logs:**
SSH sessions and tabs stay open across devices/refreshes if enabled in user profile. Record terminal, RDP, and VNC sessions and play them back later. Download plain text logs of a session, and check the connection log to see exactly what happened during a connection.
</td>
<td width="50%" valign="top">
**Serial Connections:**
Talk to serial devices like routers, switches, and microcontrollers from the browser or desktop app. Set baud rate, data bits, stop bits, and parity. Uses the Web Serial API in supported browsers, or a native backend in the desktop app.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Tailscale:**
Pull devices from your tailnet to add them as hosts in a couple of clicks, and connect with Tailscale SSH so your tailnet ACLs handle access and no credentials are stored. Headscale and custom endpoints work too.
</td>
<td width="50%" valign="top">
**Proxmox:**
Import hosts straight from a Proxmox instance, and watch node and guest stats, including CPU, memory, and storage, in their own tab.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Workspaces and Tabs:**
Save a set of tabs with their split layout and reopen the whole thing in one click. Termix also remembers your last session, so your tabs come back across refreshes and devices.
</td>
<td width="50%" valign="top">
**Guided Setup:**
A short setup walks you through picking an interface preset, your theme, the features you want, and your first host. Simple mode hides what you do not use, and you can rerun setup or switch presets any time.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Desktop Standalone and Sync:**
The desktop app runs on its own with a local backend and database, no server needed. You can also connect it to a Termix server for two-way sync of hosts, credentials, snippets, and more, and choose whether connections start locally or through the server.
</td>
<td width="50%" valign="top">
**Command Line Interface:**
A `termix` CLI for your shell and your scripts. Open terminals, run a command on one host or a whole fleet, move files over SFTP, and manage hosts, snippets, and credentials. Install with `npm install -g @termix-cli/cli` or grab a standalone binary. See the [CLI docs](https://docs.termix.site/cli).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Security:**
Passwords, keys, and other secrets are encrypted per user, and the database files themselves can be encrypted on disk. See the [docs](https://docs.termix.site/security) for how it works.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Languages:** **Languages:**
Built-in support ~30 languages (managed by [Crowdin](https://docs.termix.site/translations)). Around 30 languages built in, managed through [Crowdin](https://docs.termix.site/translations).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Session Sharing:**
Share a live terminal, RDP, VNC, or Telnet session with others in real time. Share via a link (joined anonymously, no account needed) or with a specific Termix user, and choose read-only or read-write access. Shares can expire automatically or be revoked at any time, and session sharing can be toggled globally or per-host.
</td>
<td width="50%" valign="top">
**Desktop Standalone + 2-Way Sync:**
The Electron desktop app runs fully standalone with its own local backend and database, no server required. Optionally connect it to a remote Termix server for automatic two-way sync of hosts, credentials, snippets, and more, and choose whether SSH connections are started locally or through the remote server.
</td> </td>
</tr> </tr>
@@ -213,17 +255,20 @@ The Electron desktop app runs fully standalone with its own local backend and da
<summary><b>More features</b></summary> <summary><b>More features</b></summary>
<br /> <br />
- **Dashboard** - View server information at a glance on your dashboard - **Dashboard** - Your servers at a glance, with cards you arrange yourself
- **API Keys** - Create user-scoped API keys with expiration dates to be used for automation/CI - **Network Graph** - See your homelab drawn out from your hosts, with live status
- **Data Export/Import** - Export and import SSH hosts, credentials, and file manager data - **Tmux Monitor** - Browse tmux sessions, windows, and panes, with previews and search
- **Automatic SSL Setup** - Built-in SSL certificate generation and management with HTTPS redirects - **API Keys** - User-scoped keys with expiry dates for scripts and CI
- **Modern UI** - Clean desktop/mobile-friendly interface built with React, Tailwind CSS, and Shadcn. Choose between many different UI themes including light, dark, Dracula, etc. Use URL routes to open any connection in full-screen. - **Export and Import** - Move hosts, credentials, and file manager data in and out
- **Command History** - Auto-complete and view previously ran SSH commands - **Automatic SSL** - Certificates generated and renewed for you, with HTTPS redirects, or bring your own
- **Quick Connect** - Connect to a server without having to save the connection data - **Databases** - SQLite by default, with PostgreSQL and MySQL supported too
- **Command Palette** - Double tap left shift to quickly access SSH connections with your keyboard - **Modern UI** - Clean React interface that works on desktop and mobile, with themes like light, dark, and Dracula. Any connection can open full screen from a URL
- **Proxmox Integration** - Auto-add hosts into Termix from your Proxmox instance - **Command Palette** - Double tap left shift to jump to a host from the keyboard
- **SSH Feature Rich** - Supports jump hosts, Warpgate, TOTP based connections, SOCKS5, host key verification, password autofill, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, terminal logging, SSH agent forwarding, Bitwarden SSH agent, HashiCorp Vault SSH signing, and more. - **Keyboard Shortcuts** - Move between tabs, close tabs, and more, all rebindable
- **Termix ID** - A sshid.io equivalent built into Termix. Claim a handle, publish your public SSH keys at a resolver URL, and use a built-in CA to issue SSH certificates. - **Wake-on-LAN** - Wake a machine from Termix or from an automation step
- **Trusted Proxy Auth** - Let a reverse proxy handle sign-in and pass the user through
- **SSH Feature Rich** - Jump hosts, Warpgate, TOTP prompts, SOCKS5, host key verification, password autofill, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, terminal logging, agent forwarding, Bitwarden SSH agent, HashiCorp Vault SSH signing, and more
- **Termix ID** - A built-in take on sshid.io. Claim a handle, publish your public keys at a resolver URL, and issue SSH certificates from the built-in CA
</details> </details>
@@ -305,19 +350,31 @@ networks:
driver: bridge driver: bridge
``` ```
### Command Line Interface
Termix also has a CLI, so you can manage your servers from a terminal and use Termix in your own scripts.
```bash
npm install -g @termix-cli/cli
termix login --url https://termix.example.com
termix ssh 1
```
It can open terminals, run a command on one host or a whole fleet, move files over SFTP, and manage hosts, snippets and credentials. Full documentation is at [docs.termix.site/cli](https://docs.termix.site/cli).
### Cloud Hosting ### Cloud Hosting
You can also run the Termix server on a cloud VPS instead of inside your own network. If Termix runs on the network it manages, an outage takes Termix with it, and your hosts and saved sessions are stuck inside the system you are trying to fix. Hosting it externally keeps it reachable no matter what happens to your network, and gives you a static IP and access from anywhere without a VPN or port forward. You can run the Termix server on a VPS instead of inside your own network. If Termix runs on the network it manages, an outage takes Termix down with it, right when you need it to fix things. Running it elsewhere keeps it reachable, gives you a static IP, and lets you get in from anywhere without a VPN or port forward.
[GINERNET](https://docs.termix.site/install/ginernet) is a sponsor of Termix, and there is a full step by step guide for deploying to their VPS platform in the docs. [GINERNET](https://docs.termix.site/install/ginernet) sponsors Termix, and the docs have a step by step guide for deploying to their VPS platform.
<br /> <br />
## Telemetry ## Telemetry
Termix sends a small anonymous usage ping once every 24 hours to help understand how many instances are running and which features are actually used. This only includes a randomly generated instance ID, a count of users and hosts, the app version, and whether certain features (terminal, file manager, tunnels, docker, etc.) were used in the last 24 hours. It never includes usernames, hostnames, IP addresses, credentials, or any other identifying or connection data. Termix sends a small anonymous ping once a day so I can see how many instances are running and which features get used. It contains a random instance ID, how many users and hosts you have, the app version, and which features (terminal, file manager, tunnels, docker, etc.) were used in the last 24 hours. It never contains usernames, hostnames, IP addresses, credentials, or anything else that identifies you or your servers.
This is opt-out and enabled by default. You can disable it at any time in Admin Settings under General, or set `ENABLE_TELEMETRY=false` to turn it off before you ever spin-up Termix. It is on by default. Turn it off in Admin Settings under General, or set `ENABLE_TELEMETRY=false` before you ever start Termix.
<br /> <br />
@@ -374,7 +431,7 @@ Interested in a paid placement to support development? Email [mail@termix.site](
## Support ## Support
If you need help or want to request a feature with Termix, visit the [Issues](https://github.com/Termix-SSH/Support/issues) page, log in, and press `New Issue`. Please be as detailed as possible in your issue, preferably written in English. You can also join the [Discord](https://discord.gg/jVQGdvHDrf) server and visit the support channel, however, response times may be longer. Need help or want to request a feature? Open a [new issue](https://github.com/Termix-SSH/Support/issues) and add as much detail as you can, in English if possible. You can also ask in the support channel on [Discord](https://discord.gg/jVQGdvHDrf), though replies there can take longer.
<br /> <br />
+106 -52
View File
@@ -1,71 +1,125 @@
<!-- SUMMARY --> <!-- SUMMARY -->
Enterprise audit logging with SIEM export, OIDC group-to-RBAC mapping, Tailscale SSH check mode, multi-disk metrics, and bug fixes across sync, jump hosts, RDP/VNC, and auth. Termix AI, automations, fleets, workspaces, subhosts, Proxmox metrics, a context aware terminal toolbar, split screen tabs, onboarding, PostgreSQL/MySQL support, and a large batch of fixes.
<!-- /SUMMARY --> <!-- /SUMMARY -->
<!-- YOUTUBE --> <!-- YOUTUBE -->
https://youtu.be/g0QjNdV3YYY https://youtu.be/lngaePO96tM
<!-- /YOUTUBE --> <!-- /YOUTUBE -->
<!-- UPDATE_LOG --> <!-- UPDATE_LOG -->
- Added support for multi disk usage in file manager/host metrics - Added completely optional and disabled/removed by default Termix AI, an assistant that can work with your hosts and terminals
- Added better Ctrl + F terminal search - This feature was added based off a 60% (yes) to 40% (no) Discord vote.
- Added right click menu on app rail to pin sidebar faster - The assistant cannot change anything on its own. It can only read a limited set of your Termix data and propose actions, and every change or command runs only after you approve it, using your own account and permissions.
- Support for overriding shared SSH credential - It has no access to credentials, SSH keys, vaults, users, roles, sessions, SSO, certificates, audit logs, or instance settings. Secrets are also stripped from anything sent to a model provider.
- Added mapping for OIDC provider groups to RBAC roles - Both an admin and each user must turn it on before it does anything, and it stays off after upgrading.
- Added host export dialog for more customizable host exporting - Added automations with events, channels, and steps
- Initial groundwork for supporting more database types (postgres and mysql) - Added a fleet system with snippets, packages, files, and inventory
- Added audit log export (CSV/NDJSON) and optional live forwarding to a SIEM - Added workspaces to save and restore your tab layout
- Added configurable audit log retention by age and row count - Added subhosts so hosts can be organized under a parent host
- Audit entries for file manager, RDP/VNC/Telnet, Docker and tunnel sessions - Added Proxmox metrics integration
- Encrypted SSO secrets instead of BASE64 encoding them - Added a context aware terminal toolbar with quick links, host info, image pasting, and a movable desktop layout
- Added support for Tailscale SSH check mode with in-terminal browser authentication - Added interactive terminal macros
- Added ENABLE_TELEMETRY variable to disable the usage ping before startup - Added first-class split screen tabs
- Added a file manager trash instead of permanent deletes
- Added a local terminal to the desktop app
- Added inheritable connection defaults so hosts can share settings
- Added an onboarding flow with an interface simplicity system
- Added PostgreSQL and MySQL support alongside SQLite
- Added a redesigned host and credential sidebar with synced preferences and drag-to-reorder
- Added the option to open some app rail tabs as their own tab or in a right sidebar
- Added folder select to host multi select
- Added connection logs for RDP, VNC, and Telnet hosts
- Added native RDP launching on Windows desktop
- Added a drive file browser and drag-and-drop upload for RDP
- Added terminal image handoff so images open on your local machine
- Added custom terminal font selection
- Added trusted proxy authentication
- Added global touch input settings
- Added adaptive transfers that pick the fastest route and verify integrity
- Added adaptive polling and preloading that respond to activity and network cost
- Added adaptive SSH local echo for high latency connections
- Added custom disk and network metric options
- Added the ability to exclude specific mounts from disk usage metrics
- Added expanded snippet options
- Added downloadable session logs as text files
- Added keyboard shortcuts to move between open tabs
- Added Discord webhook notification channels
- Added paste support when not running over HTTPS
- Added Headscale API key and custom API endpoint support
- Added a Meta key option for terminals
- Added BE-AZERTY keyboard layout for remote desktop
- Added PKCE to the OIDC login flow
- Added Proxmox VMID and Docker tags to discovered guests
- Added custom SSL certificate support in admin settings
- Greatly improved performance across metrics polling and host management for large setups
<!-- /UPDATE_LOG --> <!-- /UPDATE_LOG -->
<!-- BUG_FIXES --> <!-- BUG_FIXES -->
- Hardened nginx headers/asset caching - Periodic SSH terminal stalls caused by SQLite telemetry writes
- Deleting an account no longer deletes its audit entries and session recordings - Missing OPKSSH binary breaking installs without internet access
- Made logger display expanded error messages - Session recording writes slowing down terminals
- Removed phantom port knocking - SGR mouse tracking escape codes printing as text
- Fixed Proxmox guest discovery failures over jump host - Terminal display distortion with special characters
- Compare sync cursors independently of timestamp layout - Windows Ctrl+W not closing the active tab
- Fixed sync deleting not reaching other side - Tray Quit not terminating the desktop app
- Remote sync stalling after first pass and never propagating deletions - Mobile terminal scrollback not matching xterm wheel behavior
- DB_FILE_ENCRYPTION variable loading DB file as empty - tmux breaking on UTF-8 paths
- Removed unneeded field encryption boundaries - Sudo password auto-fill not persisting
- SSH login alerts being dropped silently - SSH and sudo passwords not being saved or auto-filled
- Honor lookupOptions.all in custom DNS lookup hook - Switching SSH authentication away from Vault failing
- Jump host SOCKS proxy settings being ignored - Host edits being discarded without a warning
- Jump host tunnels not reachable by guacd - Quick-created credentials not being selected
- Per-host RDP/VNC recording flags being ignored - Saved RDP connection settings not being preserved
- RDP sessions not using the configured resolution - RDP domain credentials not being prompted for
- OIDC login failing with unverifiable ID tokens or JWKs without alg - Windows key mapping in remote desktop sessions
- Refuse to start with an empty database when data exists elsewhere - VNC failing to connect to macOS screen sharing
- Database not persisting during container shutdown - Mouse input breaking on touch-capable devices in RDP and VNC
- Host command history setting not saving - Docker runtime selection not persisting, plus Docker manager UI issues
- Desktop preference sync and remote sync account identity - Desktop Docker console WebSocket not being authenticated
- Desktop guacd calls not routed to the connected remote server - Folders intermittently disappearing from duplicate requests
- File manager navigation getting stuck after permission errors - Folder deletion not refreshing the host list
- Read-only shared hosts could be dragged into folders - Proxmox guest identity being lost on edit
- Terminal highlighting breaking inside split control strings - Long host names shifting dashboard metrics
- Windows terminal Tab key and Android hardware keyboard keys - Host list rows resizing unexpectedly
- tmux monitor failing on Tailscale-authenticated hosts - Metrics collection all firing at once on startup
- Database export not staying same-origin on localhost - Session activity writes hitting the database too often
- Snippet execution results not reported correctly - Reachable and available hosts being treated the same
- Shared hosts appearing twice - SSH keepalives could not be disabled
- Wake-on-LAN broadcast address being dropped - OIDC group claims from multiple sources not being merged
- Sharing an empty folder was rejected - OIDC discovery issuers with trailing slashes failing
- Remote sync losing references between linked records - LDAP logins not using preferred_username
- Desktop app failing to find its backend on some architectures - Trusted MFA devices not being bound to a specific client install
- Centralized outbound address validation for homepage proxy requests - 2FA could not be disabled with a single credential
- Default font size to medium instead of large - Profile API keys not being shown after creation
- Tailscale hosts hanging on connect when the tailnet ACL requires a periodic check - SSH agent authentication being unclear in the host editor
- Tunnel status stream not requiring authentication
- SFTP and Docker console accepting a mismatched host id
- SSH connections whose host id resolved elsewhere being accepted
- User-managed CA certificates not being applied over SFTP
- Already-shared hosts losing their SSH authentication
- Real client IP not being captured for SSH login alerts behind a reverse proxy
- Audit log IPs not using the real client IP
- Homepage System Overview update indicator never firing
- Webhook notification channels not working
- Remote sync failing behind an nginx proxy
- First server sync not refreshing the UI
- Desktop app not showing update prompts and hiding the version badge
- Desktop Tailscale configuration being lost
- Command palette not loading new activity, plus Enter now opens the first result
- Database connection failures during login not being reported clearly
- audit_logs.user_id not being nullable on fresh SQLite installs
- Sync upserts writing to the wrong row
- Database migration failures on tables without an id column
- ssh_credentials rebuilds not matching the live schema
- Sidebar reset and fullscreen buttons sharing the same icon
- Host list icons not matching the tab bar icons
- Keep Linux credential storage working on unrecognized desktops
<!-- /BUG_FIXES --> <!-- /BUG_FIXES -->
-58
View File
@@ -1,58 +0,0 @@
{
"$schema": "https://biomejs.dev/schemas/2.5.1/schema.json",
"vcs": {
"enabled": true,
"clientKind": "git",
"useIgnoreFile": true,
"defaultBranch": "dev-2.6.1"
},
"files": {
"ignoreUnknown": true,
"includes": [
"**",
"!!build",
"!!coverage",
"!!dist",
"!!dist-ssr",
"!!release",
"!!node_modules",
"!!src/mcp-server/node_modules",
"!!db",
"!!.env",
"!!**/*.min.js",
"!!**/*.min.css",
"!!openapi.json"
]
},
"formatter": {
"enabled": true,
"indentStyle": "space",
"indentWidth": 2,
"lineWidth": 80,
"lineEnding": "lf"
},
"linter": {
"enabled": false
},
"javascript": {
"formatter": {
"quoteStyle": "double",
"semicolons": "always",
"trailingCommas": "all",
"arrowParentheses": "always"
}
},
"json": {
"formatter": {
"trailingCommas": "none"
}
},
"css": {
"parser": {
"tailwindDirectives": true
}
},
"assist": {
"enabled": false
}
}
+24 -5
View File
@@ -1,5 +1,5 @@
# Stage 1: Install dependencies # Stage 1: Install dependencies
FROM node:26-slim AS deps FROM node:24-slim AS deps
WORKDIR /app WORKDIR /app
RUN apt-get update && apt-get install -y python3 make g++ && rm -rf /var/lib/apt/lists/* RUN apt-get update && apt-get install -y python3 make g++ && rm -rf /var/lib/apt/lists/*
@@ -35,8 +35,26 @@ RUN npm rebuild better-sqlite3
RUN npm run build:backend RUN npm run build:backend
# Stage 4: Production dependencies only # Stage 4: Download OPKSSH binary for the target platform so the image works offline
FROM node:26-slim AS production-deps FROM node:24-slim AS opkssh-downloader
ARG TARGETARCH
ARG OPKSSH_VERSION=v0.16.0
WORKDIR /opkssh
RUN apt-get update && apt-get install -y curl ca-certificates && rm -rf /var/lib/apt/lists/*
RUN case "$TARGETARCH" in \
amd64) OPKSSH_ARCH=amd64 ;; \
arm64) OPKSSH_ARCH=arm64 ;; \
*) echo "Unsupported architecture: $TARGETARCH" && exit 1 ;; \
esac && \
curl -fSL -o "opkssh-linux-${OPKSSH_ARCH}" \
"https://github.com/openpubkey/opkssh/releases/download/${OPKSSH_VERSION}/opkssh-linux-${OPKSSH_ARCH}" && \
chmod 755 "opkssh-linux-${OPKSSH_ARCH}" && \
echo -n "$OPKSSH_VERSION" > version.txt
# Stage 5: Production dependencies only
FROM node:24-slim AS production-deps
WORKDIR /app WORKDIR /app
RUN apt-get update && apt-get install -y python3 make g++ && rm -rf /var/lib/apt/lists/* RUN apt-get update && apt-get install -y python3 make g++ && rm -rf /var/lib/apt/lists/*
@@ -52,8 +70,8 @@ RUN npm ci --omit=dev --ignore-scripts && \
npm rebuild better-sqlite3 bcryptjs ssh2 && \ npm rebuild better-sqlite3 bcryptjs ssh2 && \
npm cache clean --force npm cache clean --force
# Stage 5: Final optimized image # Stage 6: Final optimized image
FROM node:26-slim FROM node:24-slim
WORKDIR /app WORKDIR /app
ENV DATA_DIR=/app/data \ ENV DATA_DIR=/app/data \
@@ -75,6 +93,7 @@ COPY --chown=node:node --from=frontend-builder /app/dist /app/html
COPY --chown=node:node --from=production-deps /app/node_modules /app/node_modules COPY --chown=node:node --from=production-deps /app/node_modules /app/node_modules
COPY --chown=node:node --from=backend-builder /app/dist/backend ./dist/backend COPY --chown=node:node --from=backend-builder /app/dist/backend ./dist/backend
COPY --chown=node:node --from=opkssh-downloader /opkssh /app/opkssh-bundled
COPY --chown=node:node package.json ./ COPY --chown=node:node package.json ./
# Schema for Postgres and MySQL. Unused by the default SQLite deployment, which # Schema for Postgres and MySQL. Unused by the default SQLite deployment, which
# builds its tables at startup instead. # builds its tables at startup instead.
+7
View File
@@ -12,6 +12,13 @@ services:
GUACD_HOST: "guacd" GUACD_HOST: "guacd"
GUACD_TUNNEL_HOST: "termix" GUACD_TUNNEL_HOST: "termix"
GUACD_RECORDING_PATH: "/termix-data/session_recordings/guacamole" GUACD_RECORDING_PATH: "/termix-data/session_recordings/guacamole"
# Trusted reverse-proxy authentication is disabled by default. When
# enabled, do not expose this container directly to untrusted clients.
# TRUSTED_PROXY_AUTH_ENABLED: "true"
# TRUSTED_PROXY_AUTH_TRUSTED_PROXIES: "172.16.0.0/12"
# TRUSTED_PROXY_AUTH_ROLE_MAP: '{"operators":["user"]}'
# TRUSTED_PROXY_AUTH_USERNAME_HEADER: "x-forwarded-username"
# TRUSTED_PROXY_AUTH_ROLE_HEADER: "x-forwarded-role"
depends_on: depends_on:
- guacd - guacd
networks: networks:
+10 -2
View File
@@ -22,6 +22,14 @@ if [ "$(id -u)" = "0" ]; then
fi fi
fi fi
DATA_DIR=${DATA_DIR:-/app/data}
if [ -f "$DATA_DIR/.env" ]; then
echo "Loading persisted SSL settings from $DATA_DIR/.env"
set -a
. "$DATA_DIR/.env"
set +a
fi
export PORT=${PORT:-8080} export PORT=${PORT:-8080}
export ENABLE_SSL=${ENABLE_SSL:-false} export ENABLE_SSL=${ENABLE_SSL:-false}
export SSL_PORT=${SSL_PORT:-8443} export SSL_PORT=${SSL_PORT:-8443}
@@ -60,8 +68,8 @@ fi
OPKSSH_DIR="${DATA_DIR:-/app/data}/opkssh" OPKSSH_DIR="${DATA_DIR:-/app/data}/opkssh"
if [ ! -d "$OPKSSH_DIR" ]; then if [ ! -d "$OPKSSH_DIR" ]; then
echo "WARNING: OPKSSH binary directory not found at $OPKSSH_DIR" echo "OPKSSH binary directory not found at $OPKSSH_DIR"
echo "OPKSSH will be downloaded automatically on first use." echo "OPKSSH will be installed from the bundled copy on first use (falls back to downloading if unavailable)."
else else
echo "OPKSSH binary directory found at $OPKSSH_DIR" echo "OPKSSH binary directory found at $OPKSSH_DIR"
fi fi
+105
View File
@@ -23,6 +23,22 @@ http {
sendfile on; sendfile on;
keepalive_timeout 65; keepalive_timeout 65;
# Static assets only. API responses arrive already gzipped from the node
# backend, and gzip_proxied would otherwise have nginx decompress and
# recompress them for nothing.
gzip on;
gzip_vary on;
gzip_min_length 2048;
gzip_comp_level 5;
gzip_types
text/plain
text/css
text/javascript
application/javascript
application/json
application/wasm
image/svg+xml;
client_header_timeout 300s; client_header_timeout 300s;
set_real_ip_from 127.0.0.1; set_real_ip_from 127.0.0.1;
@@ -63,6 +79,7 @@ http {
server { server {
listen ${SSL_PORT} ssl; listen ${SSL_PORT} ssl;
server_name _; server_name _;
client_max_body_size 50m;
absolute_redirect off; absolute_redirect off;
@@ -195,6 +212,30 @@ http {
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto; proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
} }
location ~ ^/ai(/.*)?$ {
proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
# The chat endpoint streams server-sent events; buffering would
# hold tokens back until the whole reply finished.
proxy_read_timeout 600s;
proxy_buffering off;
proxy_cache off;
}
location ~ ^/automations(/.*)?$ {
proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
}
location ~ ^/alert-rules(/.*)?$ { location ~ ^/alert-rules(/.*)?$ {
proxy_pass http://127.0.0.1:30001; proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1; proxy_http_version 1.1;
@@ -253,6 +294,21 @@ http {
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto; proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
} }
location ~ ^/fleets(/.*)?$ {
client_max_body_size 200m;
proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
proxy_connect_timeout 60s;
proxy_send_timeout 600s;
proxy_read_timeout 600s;
}
location ~ ^/vault(/.*)?$ { location ~ ^/vault(/.*)?$ {
proxy_pass http://127.0.0.1:30001; proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1; proxy_http_version 1.1;
@@ -328,6 +384,15 @@ http {
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto; proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
} }
location ~ ^/workspaces(/.*)?$ {
proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
}
location ~ ^/user-preferences(/.*)?$ { location ~ ^/user-preferences(/.*)?$ {
proxy_pass http://127.0.0.1:30001; proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1; proxy_http_version 1.1;
@@ -337,6 +402,33 @@ http {
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto; proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
} }
location ~ ^/host-sidebar(/.*)?$ {
proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
}
location ~ ^/credential-sidebar(/.*)?$ {
proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
}
location ~ ^/ui-preferences(/.*)?$ {
proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
}
location ~ ^/database(/.*)?$ { location ~ ^/database(/.*)?$ {
client_max_body_size 5G; client_max_body_size 5G;
client_body_timeout 300s; client_body_timeout 300s;
@@ -693,6 +785,19 @@ http {
proxy_read_timeout 600s; proxy_read_timeout 600s;
} }
location ~ ^/proxmox-stats(/.*)?$ {
proxy_pass http://127.0.0.1:30005;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
proxy_connect_timeout 600s;
proxy_send_timeout 600s;
proxy_read_timeout 600s;
}
location ~ ^/global-settings(/.*)?$ { location ~ ^/global-settings(/.*)?$ {
proxy_pass http://127.0.0.1:30005; proxy_pass http://127.0.0.1:30005;
proxy_http_version 1.1; proxy_http_version 1.1;
+105
View File
@@ -23,6 +23,22 @@ http {
sendfile on; sendfile on;
keepalive_timeout 65; keepalive_timeout 65;
# Static assets only. API responses arrive already gzipped from the node
# backend, and gzip_proxied would otherwise have nginx decompress and
# recompress them for nothing.
gzip on;
gzip_vary on;
gzip_min_length 2048;
gzip_comp_level 5;
gzip_types
text/plain
text/css
text/javascript
application/javascript
application/json
application/wasm
image/svg+xml;
client_header_timeout 300s; client_header_timeout 300s;
set_real_ip_from 127.0.0.1; set_real_ip_from 127.0.0.1;
@@ -56,6 +72,7 @@ http {
server { server {
listen ${PORT}; listen ${PORT};
server_name _; server_name _;
client_max_body_size 50m;
absolute_redirect off; absolute_redirect off;
@@ -177,6 +194,30 @@ http {
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto; proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
} }
location ~ ^/ai(/.*)?$ {
proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
# The chat endpoint streams server-sent events; buffering would
# hold tokens back until the whole reply finished.
proxy_read_timeout 600s;
proxy_buffering off;
proxy_cache off;
}
location ~ ^/automations(/.*)?$ {
proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
}
location ~ ^/alert-rules(/.*)?$ { location ~ ^/alert-rules(/.*)?$ {
proxy_pass http://127.0.0.1:30001; proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1; proxy_http_version 1.1;
@@ -235,6 +276,21 @@ http {
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto; proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
} }
location ~ ^/fleets(/.*)?$ {
client_max_body_size 200m;
proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
proxy_connect_timeout 60s;
proxy_send_timeout 600s;
proxy_read_timeout 600s;
}
location ~ ^/vault(/.*)?$ { location ~ ^/vault(/.*)?$ {
proxy_pass http://127.0.0.1:30001; proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1; proxy_http_version 1.1;
@@ -310,6 +366,15 @@ http {
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto; proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
} }
location ~ ^/workspaces(/.*)?$ {
proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
}
location ~ ^/user-preferences(/.*)?$ { location ~ ^/user-preferences(/.*)?$ {
proxy_pass http://127.0.0.1:30001; proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1; proxy_http_version 1.1;
@@ -319,6 +384,33 @@ http {
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto; proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
} }
location ~ ^/host-sidebar(/.*)?$ {
proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
}
location ~ ^/credential-sidebar(/.*)?$ {
proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
}
location ~ ^/ui-preferences(/.*)?$ {
proxy_pass http://127.0.0.1:30001;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
}
location ~ ^/database(/.*)?$ { location ~ ^/database(/.*)?$ {
client_max_body_size 5G; client_max_body_size 5G;
client_body_timeout 300s; client_body_timeout 300s;
@@ -671,6 +763,19 @@ http {
proxy_read_timeout 600s; proxy_read_timeout 600s;
} }
location ~ ^/proxmox-stats(/.*)?$ {
proxy_pass http://127.0.0.1:30005;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $proxy_x_forwarded_proto;
proxy_connect_timeout 600s;
proxy_send_timeout 600s;
proxy_read_timeout 600s;
}
location ~ ^/global-settings(/.*)?$ { location ~ ^/global-settings(/.*)?$ {
proxy_pass http://127.0.0.1:30005; proxy_pass http://127.0.0.1:30005;
proxy_http_version 1.1; proxy_http_version 1.1;
-240
View File
@@ -1,240 +0,0 @@
# Database backends
Termix runs on SQLite by default. Postgres and MySQL are supported for
self-hosted deployments; this document records how the three differ, because the
differences are not only about SQL.
## This is multi-backend, not a migration
SQLite is not going away. The desktop app embeds its own backend and cannot ship
a database server, so it will always run on SQLite. Postgres and MySQL exist for
self-hosted deployments that need more than one process to reach the data —
multiple replicas, an external backup story, or an existing database estate.
Anything that assumes a single engine is wrong.
## Where the schema comes from
`src/backend/database/db/schema.ts` is the single source of truth, written
against `drizzle-orm/sqlite-core`.
`schema.pg.ts` and `schema.mysql.ts` are **generated** from it:
```bash
npm run schema:generate # rewrite the generated modules
npm run schema:check # fail if they are out of date (runs as part of lint)
```
Never edit the generated files. `npm run lint` fails if they drift from the
source, so a schema change that forgets to regenerate cannot reach main.
The transforms are mechanical:
| sqlite | postgres | mysql |
| ------------------------------------------------ | ----------------- | ----------------------- |
| `integer(…, { mode: "boolean" })` | `boolean` | `boolean` |
| `integer(…).primaryKey({ autoIncrement: true })` | `serial` | `int().autoincrement()` |
| `integer` | `integer` | `int` |
| `real` | `doublePrecision` | `double` |
| `text` used as a key | `varchar(255)` | `varchar(255)` |
A column becomes `varchar` if it is a primary key, is unique, or sits on either
end of a foreign key — MySQL cannot index an unbounded `TEXT`, and both sides of
a foreign key must agree.
## Durability
On SQLite the database is loaded into memory and serialised back to an encrypted
file, so every write needs an explicit flush. That is what the `onWrite` hook
each repository receives is for.
On Postgres and MySQL a committed write is already durable. No hook is installed
at all — see `needsExplicitPersist` in `db/dialect.ts`.
## Encryption: what changes, and what does not
This is the part most likely to be misread, so it is spelled out.
### Unchanged on every backend
**Field-level encryption still applies.** Credentials and other sensitive values
are encrypted in the application before they reach the database, under a
per-user data key:
- `ssh_data` — passwords, private keys, key passphrases, sudo/RDP/VNC/Telnet
secrets
- `ssh_credentials` — passwords, private and public keys
- `users` — TOTP secret and backup codes
- `vault_tokens`, `opkssh_tokens`, `termix_identity_ca` — certificates and keys
- `shared_host_secrets` — re-encrypted per recipient
Installation-level secrets — the OIDC client secret and LDAP bind password —
are encrypted under the system key, since they have no owning user and must be
readable during login.
This is the protection that matters most, and it is identical on all three
engines.
### Different on Postgres and MySQL
**Whole-file encryption does not exist.** On SQLite the database file itself is
encrypted at rest. There is no equivalent for a client-server engine: the data
lives in the server's storage, not in a file Termix owns.
Concretely, on Postgres/MySQL the following are readable by anyone with database
access, where on SQLite they were covered by the file encryption:
- host names, addresses, ports and usernames
- folder and snippet names, and **snippet contents**
- audit log entries
- session recording metadata and paths
- user names, roles and API key hashes
None of these are credentials — those stay encrypted — but together they
describe your estate.
**If you run Postgres or MySQL, encryption at rest is your responsibility**:
transparent data encryption, an encrypted volume, or an encrypted filesystem.
Termix does not provide it and cannot.
### Threat model, side by side
| | SQLite | Postgres / MySQL |
| ----------------------------------------------- | ------------------------------------------------ | ------------------------------------------------------------------ |
| Stolen database file / volume | credentials encrypted, everything else encrypted | credentials encrypted, **rest depends on your storage encryption** |
| Database access without app access | credentials unreadable | credentials unreadable |
| Application compromise while a user is unlocked | that user's secrets readable | same |
| Backups | inherit file encryption | **plain unless you encrypt them** |
The second row is the point of field-level encryption, and it holds everywhere.
The first and last rows are where the backends genuinely differ.
## Running on Postgres or MySQL
Two variables. Unset, nothing changes and SQLite is used exactly as before.
```
DATABASE_DIALECT=postgres
DATABASE_URL=postgres://user:password@host:5432/termix
```
```
DATABASE_DIALECT=mysql
DATABASE_URL=mysql://user:password@host:3306/termix
```
`mariadb://` is accepted for MySQL. The scheme is checked against the dialect
before a connection is attempted, so a mismatch fails with a readable message
rather than a driver error deep in a stack.
Point it at an **empty** database. Migrations are applied at startup, from
`drizzle/postgres` or `drizzle/mysql`, and drizzle records what it has applied —
so several instances against one database are safe, and so is restarting.
There is no migration path from an existing SQLite database. Exporting one and
importing it into Postgres is not something this branch does.
### Docker
`drizzle/` ships in the image. A compose service needs only the two variables:
Added to the compose file in the README, that is one service and two variables:
```yaml
services:
termix:
image: ghcr.io/lukegus/termix:latest
environment:
PORT: "8080"
DATABASE_DIALECT: postgres
DATABASE_URL: postgres://termix:termix@db:5432/termix
depends_on:
- db
db:
image: postgres:16
restart: unless-stopped
environment:
POSTGRES_USER: termix
POSTGRES_PASSWORD: termix
POSTGRES_DB: termix
volumes:
- pgdata:/var/lib/postgresql/data
volumes:
pgdata:
```
`DATA_DIR` is still used for uploads and recordings on every backend. Only the
database itself moves.
## What is verified, and how
`npm run verify:dialect -- <url>` applies the migrations to an empty database and
drives the real repository classes against it, asserting values rather than the
absence of exceptions.
The repository test suite also runs against each engine:
```
TEST_DIALECT=postgres TEST_DATABASE_URL=<url> npx vitest run \
src/backend/tests/database/repositories --no-file-parallelism
```
CI runs both, against PostgreSQL 16 and MySQL 8 service containers. Eighteen
tests assert on bytes stored by the SQLite driver and skip on other engines;
they still run in the SQLite pass.
Tested against PostgreSQL 16 and MySQL 8. **MariaDB is not a substitute for
MySQL when testing** — it accepts DDL that MySQL 8 rejects, which has hidden a
real defect here more than once.
### What neither of them covers
Both harnesses build a `DatabaseContext` of their own, so neither runs
`createCurrentRepositoryContext()` — the one the application actually uses.
That gap hid a hardcoded `dialect: "sqlite"` in it: every engine reported
itself as SQLite at runtime while all three test passes stayed green, which on
MySQL meant `upsert` reached for `onConflictDoUpdate` and died with a
TypeError on the first write.
Anything the factory decides from the dialect needs its own test against the
factory. Asserting it through a hand-built context proves nothing about what
runs in production.
## Known limits
- The desktop app always uses SQLite. It embeds its own backend and cannot ship
a database server.
- Repositories import the SQLite table definitions on every engine. That is
correct — the query builder needs identifiers and value encoders, and those
agree — but it means `PortableDatabase` is a named approximation rather than a
guarantee. See `repositories/database-context.ts`.
- `getCurrentSettingValue` is a synchronous read. On Postgres and MySQL it comes
from a cache primed at startup and kept current by `SettingsRepository`,
because those drivers have no synchronous query.
That cache is per-process, so on a **multi-replica** deployment a setting
changed on one instance does not reach the others through the write path. Each
replica re-reads the settings table every 30 seconds
(`SETTINGS_CACHE_REFRESH_SECONDS`, 0 to disable), which does not make settings
immediately consistent — it bounds how long they can disagree. Changing a
setting takes effect on the replica that made the change at once, and on the
others within the interval.
- **Importing a backup is SQLite-only.** The restore writes tables in an order
that is not dependency-safe and relies on `PRAGMA foreign_keys = OFF`, which
has no equivalent here: Postgres needs superuser to disable triggers, and
MySQL's session-scoped switch is not guaranteed across a pool. It refuses with
a message rather than failing partway through and leaving a half-restored
database. Restore into Postgres or MySQL with their own tooling.
- **`LIKE` is case-insensitive on SQLite and case-sensitive on Postgres.** The
four places that use it match folder path prefixes and settings keys, so the
practical effect is that renaming a folder `prod` on SQLite also catches
`PROD / api` and on Postgres does not. Postgres is arguably the more correct
of the two; nothing was changed to make them agree, because that would alter
SQLite behaviour for existing deployments.
- The SQLite-era data migrations — legacy shared-credential cleanup, the
shared-host-secrets rebuild, per-user field-encryption backfill — do not run on
the other engines. A database created by the drizzle migrations never had the
shapes they repair.
+1
View File
@@ -0,0 +1 @@
If you are an AI agent, do not place documentation files here. This is for maintainers only.
+157 -87
View File
@@ -4,7 +4,7 @@
<h1>Termix</h1> <h1>Termix</h1>
<p>إدارة SSH ذاتية الاستضافة والوصول إلى سطح المكتب البعيد</p> <p>إدارة خوادم ذاتية الاستضافة، من SSH وسطح المكتب البعيد إلى الأتمتة</p>
<p> <p>
<a href="../README.md">English</a> · <a href="../README.md">English</a> ·
@@ -37,7 +37,7 @@
<br /> <br />
Termix مجاني ومفتوح المصدر. إذا وجدته مفيدًا، فكّر في [التبرع](https://donate.termix.site/) للمساعدة في تغطية تكاليف الخادم ووقت التطوير. Termix مجاني ومفتوح المصدر. إذا كان مفيدًا لك، فكّر في [التبرع](https://donate.termix.site/) للمساعدة في تغطية تكاليف الخوادم ووقت التطوير.
<br /> <br />
@@ -58,7 +58,7 @@ Termix مجاني ومفتوح المصدر. إذا وجدته مفيدًا، ف
## نظرة عامة ## نظرة عامة
Termix هي منصة مفتوحة المصدر ومجانية للأبد وذاتية الاستضافة لإدارة الخوادم بشكل شامل. توفر حلاً متعدد المنصات لإدارة خوادمك وبنيتك التحتية من خلال واجهة واحدة وسهلة الاستخدام. يوفر Termix الوصول إلى طرفية SSH، والتحكم في سطح المكتب البعيد (RDP، VNC، Telnet)، وقدرات إنشاء أنفاق SSH، وإدارة ملفات SSH عن بُعد، والعديد من الأدوات الأخرى. يُعد Termix البديل المثالي المجاني وذاتي الاستضافة لـ Termius المتاح لجميع المنصات. Termix منصة مجانية ومفتوحة المصدر وذاتية الاستضافة لإدارة خوادمك. تجمع في مكان واحد طرفيات SSH وأسطح المكتب البعيدة (RDP وVNC وTelnet) ونقل الملفات والأنفاق وDocker والمقاييس والأتمتة، على الويب وسطح المكتب والهاتف. إنه بديل ذاتي الاستضافة لـ Termius ويبقى مجانيًا إلى الأبد.
<br /> <br />
@@ -68,42 +68,42 @@ Termix هي منصة مفتوحة المصدر ومجانية للأبد وذا
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**الوصول إلى طرفية SSH:** **طرفية SSH:**
طرفية كاملة الميزات مع دعم تقسيم الشاشة (حتى 4 لوحات) مع نظام علامات تبويب شبيه بالمتصفح. يتضمن دعم تخصيص الطرفية بما في ذلك سمات الطرفية الشائعة والخطوط والمكونات الأخرى. طرفية كاملة بعلامات تبويب مثل المتصفح وتقسيم للشاشة، حتى 6 لوحات في وقت واحد. اختر السمة والخط والألوان. يوجد فوق كل جلسة شريط يعرض المعالج والذاكرة والقرص لحظيًا، مع روابط سريعة إلى ملفات ذلك المضيف وDocker والأنفاق والمقاييس.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**الوصول إلى سطح المكتب البعيد:** **سطح المكتب البعيد:**
دعم RDP و VNC و Telnet عبر المتصفح مع تخصيص كامل وتقسيم الشاشة. RDP وVNC وTelnet داخل المتصفح، في علامات تبويب وشاشة مقسّمة مثل أي جلسة أخرى. يتضمن متصفح ملفات لأقراص RDP ورفعًا بالسحب والإفلات. على سطح مكتب Windows يمكنك أيضًا فتح المضيف في عميل RDP الأصلي.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**إدارة أنفاق SSH:** **أنفاق SSH:**
إنشاء وإدارة أنفاق SSH بين الخوادم مع إعادة الاتصال التلقائي ومراقبة الحالة وإعادة التوجيه المحلي أو البعيد أو SOCKS الديناميكي. يتم تخزين إعدادات نفق العميل-المكتبي إلى السيرفر محلياً لكل تثبيت مكتبي، ويمكن حفظ لقطات C2S الاختيارية على الخادم وإعادة تسميتها وتحميلها أو حذفها عندما تريد نقل تكوين النفق المحلي بين العملاء. إعادة توجيه محلية وبعيدة وSOCKS ديناميكية، مع إعادة اتصال تلقائية وفحوص للحالة. تُحفظ أنفاق العميل إلى الخادم في تطبيق سطح المكتب على ذلك الجهاز، ويمكنك حفظ إعدادات جاهزة على الخادم لنقل التهيئة إلى جهاز آخر.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**مدير الملفات عن بُعد:** **مدير الملفات:**
إدارة الملفات مباشرة على الخوادم البعيدة مع دعم عرض وتحرير الكود والصور والصوت والفيديو. رفع وتنزيل وإعادة تسمية وحذف ونقل الملفات بسلاسة مع دعم sudo. يتضمن دعم نقل الملفات من خادم إلى آخر. تصفح الملفات وحرّرها وارفعها ونزّلها وأعد تسميتها وانقلها واحذفها عبر SFTP، مع دعم sudo. اعرض وحرّر الشيفرة والصور والصوت والفيديو. انسخ الملفات مباشرة من خادم إلى آخر، مع اختيار أسرع مسار تلقائيًا والتحقق من سلامة النقل.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**إدارة Docker و Podman:** **Docker وPodman:**
تشغيل وإيقاف وتعليق وحذف الحاويات. عرض إحصائيات الحاويات. التحكم في الحاوية باستخدام طرفية docker exec. يدعم كلاً من Docker و Podman كبيئة تشغيل للحاويات. لم يُصمم ليحل محل Portainer أو Dockge بل لإدارة حاوياتك ببساطة مقارنة بإنشائها. شغّل الحاويات وأوقفها وعلّقها واحذفها، وتابع إحصاءاتها، وافتح طرفية داخل إحداها. يعمل مع Docker وPodman معًا. ليس بديلاً عن Portainer أو Dockge، بل وسيلة لإدارة الحاويات الموجودة لديك.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**مدير مضيفات SSH:** **مدير المضيفات:**
حفظ وتنظيم وإدارة اتصالات SSH الخاصة بك باستخدام العلامات والمجلدات (مع دعم تخصيص المجلدات والمجلدات المتداخلة)، وحفظ بيانات تسجيل الدخول القابلة لإعادة الاستخدام بسهولة مع إمكانية أتمتة نشر مفاتيح SSH. احفظ مضيفاتك ونظّمها بالوسوم ومجلدات متداخلة يمكنك تسميتها وتلوينها. أعد استخدام بيانات الدخول المحفوظة عبر عدة مضيفات، وانشر مفاتيح SSH تلقائيًا، واجمع المضيفات تحت مضيف رئيسي، وحرّر وصدّر دفعة واحدة، واستخدم الاتصال السريع للاتصالات العابرة التي لا تريد حفظها.
</td> </td>
</tr> </tr>
@@ -111,97 +111,139 @@ Termix هي منصة مفتوحة المصدر ومجانية للأبد وذا
<td width="50%" valign="top"> <td width="50%" valign="top">
**مقاييس المضيف:** **مقاييس المضيف:**
عرض استخدام المعالج والذاكرة والقرص والشبكة ووقت التشغيل ومعلومات النظام وجدار الحماية ومراقب المنافذ وعارض السجلات والمستخدمين/الصلاحيات والشهادات وغيرها الكثير، تعمل على معظم الخوادم المبنية على Linux. يتضمن رسوم بيانية تاريخية زمنية السلسلة وتنبيهات قائمة على الحدود مع دعم ntfy والـ webhook. المعالج والذاكرة والقرص والشبكة والحرارة ومدة التشغيل والعمليات والمنافذ وتسجيلات الدخول ومعلومات النظام على معظم خوادم Linux، مع رسوم بيانية للسجل. تتيح لك بطاقات الإدارة التعامل مع الخدمات ومهام cron والحزم والمستخدمين وقواعد الجدار الناري وWireGuard وTailscale وشهادات SSL والسجلات وفحوص السلامة دون مغادرة Termix.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**مصادقة المستخدمين:** **الأتمتة:**
إدارة آمنة للمستخدمين مع ضوابط إدارية (يمكن تعديل معلومات المستخدمين الآخرين) ودعم OIDC/LDAP/SSO (مع التحكم في الوصول) و 2FA (TOTP) ودعم مفاتيح المرور (WebAuthn). عرض جلسات المستخدمين النشطة عبر جميع المنصات وإلغاء الصلاحيات. ربط حسابات OIDC/المحلية معاً. عرض سجل تدقيق لجميع إجراءات المستخدمين. اختر مُشغِّلًا ثم حدّد ما ينبغي أن يحدث. تشمل المشغّلات تجاوز مقياس لحد معين، أو مضيفًا يسقط أو يعود، أو تغيّر فحص السلامة، أو جدولًا زمنيًا، أو حدث حاوية، أو webhook واردًا. يمكن للخطوات تشغيل أوامر ومقتطفات، والتحكم في الحاويات والأنفاق، وإيقاظ مضيف، واستدعاء رابط، والانتظار، والتفرع حسب شرط، وتشغيل أتمتة أخرى، وإشعارك عبر ntfy أو Discord أو webhook. تتيح لك عمليات التشغيل التجريبي التجربة بأمان أولًا.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**تكامل Tailscale:** **الأساطيل:**
عرض أجهزة شبكتك من Tailscale لإضافتها بسرعة كمضيفات، والاتصال عبر Tailscale SSH كطريقة مصادقة، مما يتيح لقوائم تحكم الوصول في Tailscale التعامل مع التفويض دون الحاجة لتخزين بيانات اعتماد. اجمع المضيفات في أسطول باختيارها يدويًا أو بقواعد الوسوم، لتنضم المضيفات الجديدة تلقائيًا. شغّل أمرًا واحدًا على كل المضيفات دفعة واحدة، وادفع الملفات واسحبها من جميعها، وثبّت الحزم، واجمع جردًا بنظام التشغيل والنواة والمعمارية ومدة التشغيل.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**RBAC/المشاركة:** **مساعد الذكاء الاصطناعي:**
إنشاء الأدوار ومشاركة المضيفات عبر المستخدمين/الأدوار. يدعم جميع أنواع المصادقة وجميع بروتوكولات المضيف. ميزة اختيارية ومعطلة حتى تفعّلها بنفسك. اربط OpenAI أو Anthropic أو Gemini أو Ollama أو أي نقطة وصول متوافقة مع OpenAI واسأل عن إعداداتك. يمكنه قراءة المضيفات والأساطيل والمقتطفات والتنبيهات، ويقترح التغييرات لتوافق عليها بدلًا من تنفيذها بنفسه. لا يمكنه أبدًا الوصول إلى بيانات الدخول أو المستخدمين أو الإعدادات. يستطيع المسؤولون تعطيله للنظام بالكامل، ويمكنك إخفاؤه أثناء الإعداد.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**الاتصالات التسلسلية:** **تسجيل الدخول والمستخدمون:**
الاتصال بالأجهزة التسلسلية (أجهزة التوجيه والمفاتيح والمتحكمات الدقيقة وغيرها) مباشرة من المتصفح أو تطبيق سطح المكتب. ضبط معدل نقل البيانات وبتات البيانات وبتات التوقف والتكافؤ. يستخدم Web Serial API في المتصفحات المدعومة أو خلفية أصلية في تطبيق Electron. حسابات محلية إضافة إلى تسجيل الدخول عبر OIDC وLDAP وGitHub وGoogle، مع التحقق بخطوتين (TOTP) ومفاتيح المرور (WebAuthn) والأجهزة الموثوقة. يستطيع المسؤولون إدارة المستخدمين وربط مجموعات OIDC بالأدوار ورؤية كل الجلسات النشطة على جميع المنصات وإلغاؤها. اربط حسابك المحلي بحساب OIDC، واطّلع على سجل التدقيق لما فعله الجميع.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**الأدوار والمشاركة:**
أنشئ أدوارًا وشارك المضيفات مع المستخدمين أو الأدوار على أربعة مستويات: الاتصال والعرض والتحرير والإدارة. يعمل مع جميع أنواع المصادقة وجميع البروتوكولات، ويمكنك تجاوز بيانات الدخول المستخدمة لمضيف مشترك.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**التنبيهات:** **التنبيهات:**
ضبط قواعد تنبيه قائمة على الحدود لمقاييس المضيف (المعالج والذاكرة والقرص وغيرها) والحصول على إشعارات عبر ntfy أو webhooks عند إطلاقها. عرض التنبيهات النشطة والمحلولة في سجل التاريخ. ضع قواعد على مقاييس المضيف مثل المعالج والذاكرة والقرص، وتلقَّ إشعارًا عبر ntfy أو Discord أو webhook عند تفعيلها. اطّلع على التنبيهات النشطة والمنتهية في سجل، وتجاهل ما لا يهمك منها.
</td> </td>
</tr>
<tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**الصفحة الرئيسية:** **الصفحة الرئيسية:**
صفحة رئيسية قابلة للتخصيص بالكامل مع شبكة أدوات قابلة للسحب والإفلات. أضف أدوات لحالة المضيف وروابط الخدمات والساعات والملاحظات وخلاصات RSS والطقس وحاويات Docker ومخططات مقاييس المضيف والطرفيات المضمنة والإطارات المضمنة وأكثر. شبكة عناصر تبنيها بنفسك بالسحب والإفلات. هناك عناصر لحالة المضيفات وnping وروابط الخدمات والإشارات المرجعية والبحث والساعات والتقويمات والعد التنازلي والملاحظات وRSS والطقس والصور والإطارات المضمّنة وDocker والأنفاق ورسوم المقاييس وواجهات API الخاصة بك، وحتى طرفية حية.
</td>
<td width="50%" valign="top">
**تشفير قاعدة البيانات:**
يُخزَّن الخادم الخلفي كملفات قاعدة بيانات SQLite مشفرة. اطلع على [الوثائق](https://docs.termix.site) لمزيد من المعلومات.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**الرسم البياني للشبكة:** **المقتطفات والأدوات:**
تخصيص لوحة التحكم لتصور مختبرك المنزلي بناءً على اتصالات SSH مع دعم الحالة. احفظ الأوامر التي تستخدمها كثيرًا وشغّلها بنقرة واحدة، مع متغيرات للمضيف ولمدخلاتك الخاصة. شغّل أمرًا واحدًا على كل الطرفيات المفتوحة، وابحث في سجل أوامرك مع الإكمال التلقائي.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**أدوات SSH:** **مشاركة الجلسة:**
إنشاء مقتطفات أوامر قابلة لإعادة الاستخدام تُنفَّذ بنقرة واحدة. تشغيل أمر واحد في وقت واحد عبر عدة طرفيات مفتوحة. شارك جلسة طرفية أو RDP أو VNC أو Telnet مباشرة. أرسل رابطًا يمكن لأي شخص الانضمام إليه دون حساب، أو شارك مع مستخدم Termix محدد، للقراءة فقط أو مع صلاحية الكتابة. يمكن أن تنتهي المشاركات تلقائيًا أو تُلغى في أي وقت، ويمكن إيقافها كليًا أو لكل مضيف على حدة.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**علامات التبويب الدائمة:** **تسجيل الجلسات والسجلات:**
تبقى جلسات SSH وعلامات التبويب مفتوحة عبر الأجهزة/التحديثات إذا تم تفعيلها في ملف تعريف المستخدم. سجّل جلسات الطرفية وRDP وVNC وشاهدها لاحقًا. نزّل سجلات نصية للجلسة، واطّلع على سجل الاتصال لترى بالضبط ما جرى أثناء الاتصال.
</td>
<td width="50%" valign="top">
**الاتصالات التسلسلية:**
تواصل مع الأجهزة التسلسلية مثل الموجّهات والمبدّلات والمتحكمات الدقيقة من المتصفح أو تطبيق سطح المكتب. اضبط معدل الباود وبتات البيانات وبتات التوقف والتماثل. يستخدم واجهة Web Serial في المتصفحات المدعومة، أو خلفية أصلية في تطبيق سطح المكتب.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Tailscale:**
اسحب الأجهزة من شبكة tailnet لإضافتها كمضيفات ببضع نقرات، واتصل عبر Tailscale SSH لتتولى قوائم صلاحيات tailnet أمر الوصول دون تخزين بيانات دخول. يعمل أيضًا مع Headscale ونقاط الوصول المخصصة.
</td>
<td width="50%" valign="top">
**Proxmox:**
استورد المضيفات مباشرة من نسخة Proxmox، وتابع إحصاءات العقد والأنظمة الضيفة، بما فيها المعالج والذاكرة والتخزين، في تبويب خاص بها.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**مساحات العمل وعلامات التبويب:**
احفظ مجموعة من علامات التبويب بتقسيمها، وأعد فتحها كلها بنقرة واحدة. يتذكر Termix أيضًا جلستك الأخيرة، فتعود علامات التبويب بعد التحديث وعلى الأجهزة الأخرى.
</td>
<td width="50%" valign="top">
**إعداد موجَّه:**
إعداد قصير يرشدك إلى اختيار نمط الواجهة والسمة والميزات التي تريدها وأول مضيف لك. يخفي الوضع البسيط ما لا تستخدمه، ويمكنك إعادة الإعداد أو تغيير النمط في أي وقت.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**تطبيق سطح المكتب المستقل والمزامنة:**
يعمل تطبيق سطح المكتب بمفرده بخلفية وقاعدة بيانات محلية، دون حاجة إلى خادم. يمكنك أيضًا ربطه بخادم Termix لمزامنة المضيفات وبيانات الدخول والمقتطفات وغيرها في الاتجاهين، واختيار ما إذا كانت الاتصالات تبدأ من جهازك أم عبر الخادم.
</td>
<td width="50%" valign="top">
**سطر الأوامر:**
أداة `termix` لسطر الأوامر تعمل في الطرفية وفي سكربتاتك. افتح الطرفيات، ونفّذ أمرًا على مضيف واحد أو على أسطول كامل، وانقل الملفات عبر SFTP، وأدر المضيفات والمقتطفات وبيانات الدخول. ثبّتها عبر `npm install -g @termix-cli/cli` أو استخدم ملفًا تنفيذيًا مستقلًا. راجع [وثائق سطر الأوامر](https://docs.termix.site/cli).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**الأمان:**
تُشفَّر كلمات المرور والمفاتيح والأسرار الأخرى لكل مستخدم على حدة، ويمكن تشفير ملفات قاعدة البيانات نفسها على القرص. راجع [الوثائق](https://docs.termix.site/security) لمعرفة آلية العمل.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**اللغات:** **اللغات:**
دعم مدمج لحوالي 30 لغة (تُدار بواسطة [Crowdin](https://docs.termix.site/translations)). نحو 30 لغة مدمجة، تُدار عبر [Crowdin](https://docs.termix.site/translations).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**مشاركة الجلسة:**
شارك جلسة طرفية أو RDP أو VNC أو Telnet مباشرة مع الآخرين في الوقت الفعلي. شارك عبر رابط (الانضمام بشكل مجهول، بدون الحاجة لحساب) أو مع مستخدم Termix محدد، واختر الوصول للقراءة فقط أو للقراءة والكتابة. يمكن أن تنتهي صلاحية المشاركات تلقائيًا أو يتم إلغاؤها في أي وقت، ويمكن تبديل مشاركة الجلسة عالميًا أو لكل مضيف على حدة.
</td>
<td width="50%" valign="top">
**تطبيق سطح مكتب مستقل + مزامنة ثنائية الاتجاه:**
يعمل تطبيق سطح المكتب Electron بشكل مستقل تمامًا مع خلفية وقاعدة بيانات محلية خاصة به، دون الحاجة لخادم. يمكن اختياريًا توصيله بخادم Termix عن بُعد للمزامنة التلقائية ثنائية الاتجاه للمضيفين وبيانات الاعتماد والمقتطفات والمزيد، واختيار ما إذا كانت اتصالات SSH تبدأ محليًا أو عبر الخادم البعيد.
</td> </td>
</tr> </tr>
@@ -209,40 +251,43 @@ Termix هي منصة مفتوحة المصدر ومجانية للأبد وذا
<br /> <br />
<details> <details dir="rtl">
<summary><b>المزيد من الميزات</b></summary> <summary><b>ميزات أخرى</b></summary>
<br /> <br />
- **لوحة التحكم** - عرض معلومات الخادم بنظرة واحدة على لوحة التحكم - **لوحة المعلومات** - خوادمك في لمحة واحدة، ببطاقات ترتّبها بنفسك
- **مفاتيح API** - إنشاء مفاتيح API محددة النطاق للمستخدم مع تواريخ انتهاء صلاحية للاستخدام في الأتمتة/CI - **رسم الشبكة** - مختبرك المنزلي مرسومًا انطلاقًا من مضيفاتك، مع الحالة لحظيًا
- **تصدير/استيراد البيانات** - تصدير واستيراد مضيفات SSH وبيانات الاعتماد وبيانات مدير الملفات - **مراقب tmux** - تصفح جلسات tmux ونوافذه ولوحاته، مع معاينة وبحث
- **إعداد SSL تلقائي** - إنشاء وإدارة شهادات SSL مدمجة مع إعادة التوجيه إلى HTTPS - **مفاتيح API** - مفاتيح خاصة بكل مستخدم لها تاريخ انتهاء، للسكربتات وأنظمة CI
- **واجهة مستخدم حديثة** - واجهة نظيفة متوافقة مع سطح المكتب والهاتف المحمول مبنية بـ React و Tailwind CSS و Shadcn. الاختيار بين العديد من سمات واجهة المستخدم بما في ذلك الفاتح والداكن و Dracula وغيرها. استخدام مسارات URL لفتح أي اتصال في وضع ملء الشاشة. - **التصدير والاستيراد** - انقل المضيفات وبيانات الدخول وبيانات مدير الملفات إلى الداخل والخارج
- **سجل الأوامر** - الإكمال التلقائي وعرض أوامر SSH التي تم تنفيذها سابقاً - **SSL تلقائي** - تُنشأ الشهادات وتُجدَّد نيابة عنك، مع إعادة التوجيه إلى HTTPS، أو استخدم شهاداتك الخاصة
- **الاتصال السريع** - الاتصال بخادم دون الحاجة إلى حفظ بيانات الاتصال - **قواعد البيانات** - SQLite افتراضيًا، مع دعم PostgreSQL وMySQL أيضًا
- **لوحة الأوامر** - اضغط مرتين على Shift الأيسر للوصول السريع إلى اتصالات SSH باستخدام لوحة المفاتيح - **واجهة حديثة** - واجهة React أنيقة تعمل على سطح المكتب والهاتف، بسمات مثل الفاتح والداكن وDracula. يمكن فتح أي اتصال بملء الشاشة من رابط
- **تكامل Proxmox** - إضافة المضيفات تلقائياً إلى Termix من نسخة Proxmox الخاصة بك - **لوحة الأوامر** - اضغط مفتاح Shift الأيسر مرتين للانتقال إلى مضيف من لوحة المفاتيح
- **ميزات SSH الغنية** - دعم مضيفات القفز، Warpgate، الاتصالات المبنية على TOTP، SOCKS5، التحقق من مفتاح المضيف، الملء التلقائي لكلمة المرور، [OPKSSH](https://github.com/openpubkey/opkssh)، tmux، port knocking، تسجيل الطرفية، إعادة توجيه وكيل SSH، وكيل Bitwarden SSH، توقيع SSH عبر HashiCorp Vault، وغيرها. - **اختصارات لوحة المفاتيح** - التنقل بين علامات التبويب وإغلاقها وغير ذلك، وكلها قابلة لإعادة التعيين
- **Termix ID** - مكافئ لـ sshid.io مدمج في Termix. احصل على اسم مستخدم، انشر مفاتيح SSH العامة الخاصة بك على رابط محلل (resolver URL)، واستخدم هيئة إصدار شهادات (CA) مدمجة لإصدار شهادات SSH. - **Wake-on-LAN** - أيقظ جهازًا من Termix أو من خطوة في الأتمتة
- **مصادقة الوكيل الموثوق** - دع وكيلًا عكسيًا يتولى تسجيل الدخول ويمرّر المستخدم
- **SSH بإمكانات واسعة** - مضيفات وسيطة وWarpgate وطلبات TOTP وSOCKS5 والتحقق من مفاتيح المضيف والتعبئة التلقائية لكلمات المرور و[OPKSSH](https://github.com/openpubkey/opkssh) وtmux وport knocking وسجلات الطرفية وتمرير الوكيل ووكيل SSH من Bitwarden وتوقيع SSH عبر HashiCorp Vault وغيرها
- **Termix ID** - نسخة مدمجة على غرار sshid.io. احجز معرّفًا، وانشر مفاتيحك العامة على رابط محلِّل، وأصدر شهادات SSH من سلطة التصديق المدمجة
</details> </details>
<br /> <br />
## دعم المنصات ## المنصات المدعومة
<table align="center"> <table align="center">
<tr> <tr>
<th align="center">المنصة</th> <th align="center">المنصة</th>
<th align="center">التوزيع</th> <th align="center">طريقة التوزيع</th>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Web</b></td> <td align="center"><b>Web</b></td>
<td>أي متصفح حديث (Chrome، Safari، Firefox) · دعم PWA</td> <td>أي متصفح حديث (Chrome وSafari وFirefox) · يدعم PWA</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Windows</b> <sub>x64/ia32</sub></td> <td align="center"><b>Windows</b> <sub>x64/ia32</sub></td>
<td>نسخة محمولة · مثبت MSI · Chocolatey</td> <td>نسخة محمولة · مثبّت MSI · Chocolatey</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Linux</b> <sub>x64/ia32</sub></td> <td align="center"><b>Linux</b> <sub>x64/ia32</sub></td>
@@ -266,9 +311,9 @@ Termix هي منصة مفتوحة المصدر ومجانية للأبد وذا
## التثبيت ## التثبيت
قم بزيارة [وثائق](https://docs.termix.site/install) Termix للحصول على تعليمات التثبيت الكاملة عبر جميع المنصات. راجع [وثائق Termix](https://docs.termix.site/install) للاطلاع على تعليمات التثبيت الكاملة لجميع المنصات.
نموذج ملف Docker Compose (يمكنك حذف `guacd` والشبكة إذا كنت لا تخطط لاستخدام ميزات سطح المكتب البعيد): مثال على ملف Docker Compose (يمكنك حذف `guacd` والشبكة إذا كنت لا تنوي استخدام سطح المكتب البعيد):
```yaml ```yaml
services: services:
@@ -305,19 +350,45 @@ networks:
driver: bridge driver: bridge
``` ```
### سطر الأوامر
يوفر Termix أيضًا أداة سطر أوامر، لتدير خوادمك من الطرفية وتستخدم Termix داخل سكربتاتك.
```bash
npm install -g @termix-cli/cli
termix login --url https://termix.example.com
termix ssh 1
```
تستطيع فتح الطرفيات، وتنفيذ أمر على مضيف واحد أو على أسطول كامل، ونقل الملفات عبر SFTP، وإدارة المضيفات والمقتطفات وبيانات الدخول. الوثائق الكاملة على [docs.termix.site/cli](https://docs.termix.site/cli).
### الاستضافة السحابية
يمكنك تشغيل خادم Termix على VPS بدلًا من داخل شبكتك. إذا كان Termix يعمل داخل الشبكة التي يديرها، فأي عطل سيأخذه معه، تحديدًا حين تحتاج إليه لإصلاح الأمور. تشغيله في الخارج يبقيه متاحًا، ويمنحك عنوان IP ثابتًا، ويتيح لك الدخول من أي مكان دون VPN أو فتح منافذ.
ترعى [GINERNET](https://docs.termix.site/install/ginernet) مشروع Termix، وتتضمن الوثائق دليلًا خطوة بخطوة للنشر على منصة الخوادم الافتراضية الخاصة بهم.
<br />
## بيانات الاستخدام
يرسل Termix إشارة صغيرة مجهولة مرة واحدة يوميًا، لأعرف عدد النسخ العاملة والميزات المستخدمة فعلًا. تحتوي على معرّف عشوائي للنسخة، وعدد المستخدمين والمضيفات لديك، وإصدار التطبيق، والميزات التي استُخدمت خلال آخر 24 ساعة (الطرفية ومدير الملفات والأنفاق وdocker وغيرها). ولا تحتوي أبدًا على أسماء مستخدمين أو أسماء مضيفات أو عناوين IP أو بيانات دخول أو أي شيء يعرّف بك أو بخوادمك.
وهي مفعّلة افتراضيًا. يمكنك إيقافها من إعدادات المسؤول ضمن قسم عام، أو ضبط `ENABLE_TELEMETRY=false` قبل تشغيل Termix أصلًا.
<br /> <br />
## التبرع ## التبرع
Termix مجاني ومفتوح المصدر بدون اشتراكات أو خطط مدفوعة. إذا وجدته مفيدًا، فكّر في التبرع للمساعدة في تغطية تكاليف الخادم والنطاقات ووقت التطوير. تساعد التبرعات أيضاً في تمويل الوقت اللازم للبحث وتعلم ما هو مطلوب لبناء ميزات مثل SAML و Kubernetes ودعم الوكلاء (Agent). تابع التقدم وتبرع أدناه. Termix مجاني ومفتوح المصدر، بلا اشتراكات ولا خطط مدفوعة. إذا كان مفيدًا لك، فكّر في التبرع للمساعدة في تغطية الخوادم والنطاقات ووقت التطوير. تموّل التبرعات أيضًا وقت البحث والتعلّم اللازم لبناء ميزات مثل SAML وKubernetes ودعم الوكلاء. تابع التقدم وتبرع من الرابط أدناه.
[تبرع](https://donate.termix.site/) [تبرّع](https://donate.termix.site/)
<br /> <br />
## الرعاة ## الرعاة
هل تريد إعلاناً مدفوعاً لدعم التطوير؟ راسلنا عبر البريد الإلكتروني [mail@termix.site](mailto:mail@termix.site). هل تهتم بمساحة إعلانية مدفوعة لدعم التطوير؟ راسلنا على [mail@termix.site](mailto:mail@termix.site).
<div align="center"> <div align="center">
@@ -339,10 +410,6 @@ Termix مجاني ومفتوح المصدر بدون اشتراكات أو خط
<img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" /> <img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" />
</a> </a>
&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;
<a href="https://tailscale.com/">
<img src="https://drive.google.com/uc?export=view&id=1lIxkJuX6M23bW-2FElhT0rQieTrzaVSL" height="40" alt="Tailscale" />
</a>
&nbsp;&nbsp;&nbsp;
<a href="https://akamai.com/"> <a href="https://akamai.com/">
<img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" /> <img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" />
</a> </a>
@@ -354,14 +421,17 @@ Termix مجاني ومفتوح المصدر بدون اشتراكات أو خط
<a href="https://rackgenius.com/"> <a href="https://rackgenius.com/">
<img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" /> <img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" />
</a> </a>
&nbsp;&nbsp;&nbsp;
<a href="https://ginernet.com/">
<img src="https://ginernet.com/img/logo-web.png" height="40" alt="Ginernet" />
</a>
</div> </div>
<br /> <br />
## الدعم ## الدعم
إذا كنت بحاجة إلى مساعدة أو ترغب في طلب ميزة لـ Termix، قم بزيارة صفحة [المشكلات](https://github.com/Termix-SSH/Support/issues)، وسجل الدخول، واضغط على `New Issue`. يرجى أن تكون مفصلاً قدر الإمكان في مشكلتك، ويُفضَّل كتابتها باللغة الإنجليزية. يمكنك أيضاً الانضمام إلى خادم [Discord](https://discord.gg/jVQGdvHDrf) وزيارة قناة الدعم، ومع ذلك قد تكون أوقات الاستجابة أطول. تحتاج مساعدة أو تريد طلب ميزة؟ افتح [مشكلة جديدة](https://github.com/Termix-SSH/Support/issues) واذكر أكبر قدر ممكن من التفاصيل، بالإنجليزية إن أمكن. يمكنك أيضًا السؤال في قناة الدعم على [Discord](https://discord.gg/jVQGdvHDrf)، وإن كانت الردود هناك قد تتأخر.
<br /> <br />
@@ -373,7 +443,7 @@ Termix مجاني ومفتوح المصدر بدون اشتراكات أو خط
[![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos) [![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos)
<sub>شاهد نظرة عامة على التحديثات على YouTube</sub> <sub>شاهد عروض التحديثات على YouTube</sub>
<br /> <br />
<br /> <br />
@@ -413,7 +483,7 @@ Termix مجاني ومفتوح المصدر بدون اشتراكات أو خط
</tr> </tr>
</table> </table>
<sub>قد تكون بعض مقاطع الفيديو والصور قديمة أو قد لا تعرض الميزات بشكل مثالي.</sub> <sub>قد تكون بعض المقاطع والصور قديمة أو لا تعرض الميزات على أفضل وجه.</sub>
</div> </div>
@@ -421,10 +491,10 @@ Termix مجاني ومفتوح المصدر بدون اشتراكات أو خط
## الميزات المخططة ## الميزات المخططة
راجع [المشاريع](https://github.com/orgs/Termix-SSH/projects/5) لعرض جميع الميزات المخططة. إذا كنت تتطلع للمساهمة، راجع [المساهمة](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md). جميع الميزات المخططة موجودة في [Projects](https://github.com/orgs/Termix-SSH/projects/5). إذا أردت المساهمة، راجع [Contributing](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md).
<br /> <br />
## الترخيص ## الترخيص
موزع بموجب رخصة Apache License الإصدار 2.0. راجع ملف `LICENSE` لمزيد من المعلومات. يوزَّع بموجب ترخيص Apache الإصدار 2.0. راجع ملف `LICENSE` لمزيد من المعلومات.
+157 -87
View File
@@ -4,7 +4,7 @@
<h1>Termix</h1> <h1>Termix</h1>
<p>自托管 SSH 管理与远程桌面访问平台</p> <p>自托管服务器管理,从 SSH 远程桌面到自动化</p>
<p> <p>
<a href="../README.md">English</a> · <a href="../README.md">English</a> ·
@@ -58,7 +58,7 @@ Termix 免费且开源。如果您觉得它有用,请考虑[捐赠](https://do
## 概览 ## 概览
Termix 是一个开源、永久免费、自托管的一体化服务器管理平台。它提供了一个多平台解决方案,通过一个直观的界面管理你的服务器和基础设施。Termix 提供 SSH 终端访问、远程桌面控制RDP、VNC、Telnet)、SSH 隧道功能、远程文件管理以及许多其他工具。Termix 是适用于所有平台的完美免费自托管 Termius 替代品 Termix 是一个免费、开源、自托管的服务器管理平台。它 SSH 终端、远程桌面(RDP、VNC、Telnet)、文件传输、隧道、Docker、指标和自动化集中在一个地方,支持网页端、桌面端和移动端。它是 Termius 的自托管替代品,并且永久免费
<br /> <br />
@@ -68,42 +68,42 @@ Termix 是一个开源、永久免费、自托管的一体化服务器管理平
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH 终端访问:** **SSH 终端:**
功能齐全的终端,支持分屏(最多 4 个面板),并配有类似浏览器的标签系统。包括对自定义终端的支持,如常用的终端主题、字体和其他组件 功能齐全的终端,配有类似浏览器的标签页和分屏,最多同时显示 6 个面板。可以选择主题、字体和配色。每个会话上方都有一个工具栏,显示实时的 CPU、内存和磁盘,并提供指向该主机文件、Docker、隧道和指标的快捷入口
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**远程桌面访问:** **远程桌面:**
通过浏览器支持 RDP、VNC 和 Telnet具有完整的自定义和分屏功能 浏览器中使用 RDP、VNC 和 Telnet和其他会话一样支持标签页和分屏。包含 RDP 驱动器的文件浏览器和拖放上传。在 Windows 桌面端,你还可以用原生 RDP 客户端打开主机
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH 隧道管理:** **SSH 隧道:**
创建和管理具有自动重连和健康监测功能的服务器间 SSH 隧道,支持本地、远程动态 SOCKS 转发。桌面客户端到服务器隧道设置按桌面安装本地存储,可选的 C2S 预设快照可保存到服务器、重命名、加载或删除,以便在客户端之间迁移本地隧道配置 支持本地、远程动态 SOCKS 转发,可自动重连并进行健康检查。桌面端的客户端到服务器隧道保存在本机,你也可以把预设保存到服务器,以便迁移到另一台客户端
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**远程文件管理器:** **文件管理器:**
直接在远程服务器上管理文件,支持查看和编辑代码、图、音频和视频。支持通过 sudo 无缝上传、下载、重命名、删除和移动文件。包括支持在服务器之间移动文件 通过 SFTP 浏览、编辑、上传、下载、重命名、移动和删除文件,支持 sudo。可以查看和编辑代码、图、音频和视频。文件可以直接从一台服务器复制到另一台,系统会自动选择最快的路径并校验传输完整性
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Docker 和 Podman 管理:** **Docker 和 Podman:**
启动、停止、暂停、移除容器查看容器统计信息。通过 docker exec 终端控制容器。同时支持 Docker 和 Podman 作为容器运行时。它的初衷不是取代 Portainer 或 Dockge而是为了比直接创建容器更简单地管理它们 启动、停止、暂停和删除容器查看它们的状态,并在容器内打开一个终端。同时支持 Docker 和 Podman。它不是取代 Portainer 或 Dockge只是用来管理你已有的容器
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH 主机管理:** **主机管理:**
通过标签和文件夹(支持文件夹自定义和嵌套文件夹)保存、组织和管理您的 SSH 连接,轻松保存可重用的登录信息,并能自动部署 SSH 密钥。 标签和可命名、可配色的嵌套文件夹来整理主机。在多台主机之间复用已保存的凭据,自动部署 SSH 密钥,把主机归到父主机下,批量编辑和导出,还可以用快速连接处理那些不想保存的一次性连接
</td> </td>
</tr> </tr>
@@ -111,97 +111,139 @@ Termix 是一个开源、永久免费、自托管的一体化服务器管理平
<td width="50%" valign="top"> <td width="50%" valign="top">
**主机指标:** **主机指标:**
在大多数基于 Linux 服务器上查看 CPU、内存、磁盘使用情况、网络、运行时间、系统信息、防火墙、端口监控、日志查看器、用户/权限、证书等更多信息。包括时间序列历史图表和支持 ntfy 与 webhook 的阈值告警 在大多数 Linux 服务器上查看 CPU、内存、磁盘、网络、温度、运行时间、进程、端口、登录记录和系统信息,并附带历史曲线图。管理卡片让你无需离开 Termix 就能处理服务、定时任务、软件包、用户、防火墙规则、WireGuard、Tailscale、SSL 证书、日志和健康检查
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**用户认证:** **自动化:**
安全的用户管理,具有管理员控制(可编辑其他用户信息)和 OIDC/LDAP/SSO(带访问控制)、2FA (TOTP) 以及通行密钥(WebAuthn)支持。查看所有平台上的活动用户会话并撤销权限。将您的 OIDC/本地账户链接在一起。查看所有用户操作的审计日志 先选一个触发条件,再决定要做什么。触发条件包括指标超过阈值、主机上线或下线、健康检查状态变化、定时计划、容器事件,或者一个传入的 Webhook。步骤可以执行命令和代码片段、控制容器和隧道、唤醒主机、调用某个网址、等待、按条件分支、运行另一个自动化,并通过 ntfy、Discord 或 Webhook 通知你。测试运行让你先安全地试一遍
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Tailscale 集成:** **机群:**
列出您 Tailscale 网络中的设备以快速添加为主机,并使用 Tailscale SSH 作为身份验证方式,让您的 Tailscale ACL 处理授权而无需存储凭据 通过手动挑选或标签规则把主机编成一个机群,新主机可以自动加入。一次在所有主机上执行同一条命令,向全部主机推送和拉取文件,安装软件包,并收集系统、内核、架构和运行时间的清单
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**RBAC/共享:** **AI 助手:**
创建角色并在用户/角色之间共享主机。支持所有认证类型和所有主机协议 可选功能,默认关闭,需要你手动开启。接入 OpenAI、Anthropic、Gemini、Ollama 或任何兼容 OpenAI 的接口,向它询问你的配置。它可以读取主机、机群、代码片段和告警,并把改动作为建议提交给你确认,而不会自行修改。它永远无法接触凭据、用户和设置。管理员可以对整个实例关闭它,你也可以在初始设置时把它隐藏
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**串口连接:** **登录与用户:**
直接从浏览器或桌面应用连接到串口设备(路由器、交换机、微控制器等)。配置波特率、数据位、停止位和奇偶校验。在支持的浏览器中使用 Web Serial API,或在 Electron 应用中使用原生后端 支持本地账户,以及 OIDC、LDAP、GitHub 和 Google 登录,还有两步验证(TOTP)、通行密钥(WebAuthn)和受信任设备。管理员可以管理用户、把 OIDC 群组映射到角色、查看所有平台上的活动会话并将其吊销。你可以把本地账户和 OIDC 账户关联起来,并查看记录所有人操作的审计日志
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**角色与共享:**
创建角色,并按四个级别把主机共享给用户或角色:连接、查看、编辑和管理。适用于所有认证方式和所有协议,并且可以覆盖共享主机所使用的凭据。
</td>
</tr>
<tr>
<td width="50%" valign="top">
**告警:** **告警:**
主机指标(CPU、内存、磁盘等)设置基于阈值的告警规则,并通过 ntfywebhook 接收触发通知。在历史日志中查看触发和已解决的告警。 CPU、内存、磁盘等主机指标设置规则,触发时通过 ntfy、DiscordWebhook 通知。在历史记录中查看正在触发和已恢复的告警,并忽略你不关心的那些
</td> </td>
</tr>
<tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**主页:** **主页:**
具有拖放小组件网格的完全可定制主页。添加主机状态、服务链接、时钟、笔记、RSS 订阅、天气、Docker 容器、主机指标图表、嵌入式终端、iframe 等小组件 一个由你自己搭建的拖放小组件网格。小组件包括主机状态、Ping、服务链接、书签、搜索、时钟、日历、倒计时、便签、RSS、天气、图片、内嵌网页、Docker、隧道、指标图表、自定义 API,甚至还有一个实时终端
</td>
<td width="50%" valign="top">
**数据库加密:**
后端存储为加密的 SQLite 数据库文件。查看[文档](https://docs.termix.site)了解更多。
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**网络图:** **代码片段与工具:**
自定义您的仪表板,根据您的 SSH 连接可视化您的家庭实验室,并支持状态监测 保存常用命令,一键执行,并支持主机变量和自定义输入。可以在所有已打开的终端中同时运行一条命令,也可以带自动补全地搜索命令历史
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH 工具:**
创建可重用的命令片段,只需点击一下即可执行。在多个打开的终端中同时运行一个命令。
</td>
</tr>
<tr>
<td width="50%" valign="top">
**持久标签页:**
如果在用户个人资料中启用,SSH 会话和标签页将在设备/刷新后保持打开状态。
</td>
<td width="50%" valign="top">
**语言:**
内置支持约 30 种语言(由 [Crowdin](https://docs.termix.site/translations) 管理)。
</td>
</tr>
<tr>
<td width="50%" valign="top">
**会话共享:** **会话共享:**
与他人实时共享终端、RDP、VNC 或 Telnet 会话。通过链接分享(匿名加入,无需帐户)或与特定的 Termix 用户分享,并选择只读或读写权限。共享可以自动过期或随时撤销,会话共享可以全局或按主机切换 实时共享终端、RDP、VNC 或 Telnet 会话。可以发送一个无需账户即可加入的链接,也可以共享给指定的 Termix 用户,并选择只读或读写。共享可以自动过期或随时撤销,可以全局或按主机关闭
</td>
</tr>
<tr>
<td width="50%" valign="top">
**会话录制与日志:**
录制终端、RDP 和 VNC 会话,之后可以回放。可以下载会话的纯文本日志,也可以查看连接日志,了解连接过程中究竟发生了什么。
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**桌面独立运行 + 双向同步:** **串口连接:**
Electron 桌面应用可完全独立运行,拥有自己的本地后端和数据库,无需服务器。也可以选择连接到远程 Termix 服务器,实现主机、凭据、代码片段等的自动双向同步,并选择 SSH 连接是在本地启动还是通过远程服务器启动 从浏览器或桌面应用连接路由器、交换机和单片机等串口设备。可设置波特率、数据位、停止位和校验位。在支持的浏览器中使用 Web Serial API,在桌面应用中使用原生后端
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Tailscale:**
从你的 tailnet 中拉取设备,点几下就能把它们添加为主机,并使用 Tailscale SSH 连接,由 tailnet ACL 负责访问控制,无需保存任何凭据。也支持 Headscale 和自定义接口地址。
</td>
<td width="50%" valign="top">
**Proxmox:**
直接从 Proxmox 实例导入主机,并在专属标签页中查看节点和虚拟机的状态,包括 CPU、内存和存储。
</td>
</tr>
<tr>
<td width="50%" valign="top">
**工作区与标签页:**
保存一组标签页及其分屏布局,一键就能把整套重新打开。Termix 还会记住你上次的会话,所以刷新页面或换设备后标签页都会回来。
</td>
<td width="50%" valign="top">
**引导设置:**
一个简短的引导流程会带你选择界面预设、主题、需要的功能,以及第一台主机。简洁模式会隐藏你用不到的东西,你随时可以重新运行引导或切换预设。
</td>
</tr>
<tr>
<td width="50%" valign="top">
**桌面独立运行与同步:**
桌面应用可以完全独立运行,自带本地后端和数据库,不需要服务器。你也可以把它连到 Termix 服务器,双向同步主机、凭据、代码片段等内容,并选择连接是在本地发起还是通过服务器发起。
</td>
<td width="50%" valign="top">
**命令行工具:**
`termix` 命令行工具,可用于你的终端和脚本。打开终端、在单台主机或整个机群上执行命令、通过 SFTP 传输文件,以及管理主机、代码片段和凭据。用 `npm install -g @termix-cli/cli` 安装,或者直接下载独立的可执行文件。详见 [CLI 文档](https://docs.termix.site/cli)。
</td>
</tr>
<tr>
<td width="50%" valign="top">
**安全:**
密码、密钥和其他机密按用户加密,数据库文件本身也可以在磁盘上加密。具体原理请查看[文档](https://docs.termix.site/security)。
</td>
<td width="50%" valign="top">
**多语言:**
内置约 30 种语言,通过 [Crowdin](https://docs.termix.site/translations) 管理。
</td> </td>
</tr> </tr>
@@ -213,17 +255,20 @@ Electron 桌面应用可完全独立运行,拥有自己的本地后端和数
<summary><b>更多功能</b></summary> <summary><b>更多功能</b></summary>
<br /> <br />
- **仪表** - 在仪表板上一目了然地查看服务器信息 - **仪表** - 一眼看清你的服务器,卡片由你自己排布
- **API 密钥** - 创建带有到期日期的用户范围 API 密钥,用于自动化/CI - **网络拓扑图** - 根据你的主机绘制出你的家庭实验室,并显示实时状态
- **数据导出/导入** - 导出和导入 SSH 主机、凭据和文件管理器数据 - **Tmux 监视器** - 浏览 tmux 的会话、窗口和面板,支持预览和搜索
- **自动 SSL 设置** - 内置 SSL 证书生成和管理,支持 HTTPS 重定向 - **API 密钥** - 面向用户的密钥,带有效期,可用于脚本和 CI
- **现代 UI** - 使用 React、Tailwind CSS 和 Shadcn 构建的整洁的桌面/移动友好界面。有多种 UI 主题可选,包括浅色、深色、Dracula 等。使用 URL 路由全屏打开任何连接。 - **导出与导入** - 把主机、凭据和文件管理器数据导入导出
- **命令历史** - 自动完成并查看之前运行过的 SSH 命令 - **自动 SSL** - 自动签发和续期证书,并配置 HTTPS 跳转,也可以使用你自己的证书
- **快速连接** - 无需保存连接数据即可连接到服务器 - **数据库** - 默认使用 SQLite,同时支持 PostgreSQL 和 MySQL
- **命令面板** - 双击左 Shift 键即可通过键盘快速访问 SSH 连接 - **现代界面** - 简洁的 React 界面,桌面和移动端都适用,提供浅色、深色和 Dracula 等主题。任何连接都能通过网址全屏打开
- **Proxmox 集成** - 从您的 Proxmox 实例自动将主机添加到 Termix - **命令面板** - 双击左 Shift,用键盘直接跳到某台主机
- **丰富的 SSH 功能** - 支持跳转主机、Warpgate、基于 TOTP 的连接、SOCKS5、主机密钥验证、密码自动填充、[OPKSSH](https://github.com/openpubkey/opkssh)、tmux、端口敲击、终端日志记录、SSH 代理转发、Bitwarden SSH 代理、HashiCorp Vault SSH 签名等 - **键盘快捷键** - 在标签页之间切换、关闭标签页等,全部可以重新绑定
- **Termix ID** - 内置于 Termix 中的 sshid.io 等效功能。认领一个用户名,在解析 URL 上发布您的公开 SSH 密钥,并使用内置 CA 签发 SSH 证书。 - **网络唤醒** - Termix 或自动化步骤中唤醒一台机器
- **受信任代理认证** - 由反向代理完成登录,并把用户信息传递进来
- **丰富的 SSH 功能** - 跳板机、Warpgate、TOTP 验证、SOCKS5、主机密钥验证、密码自动填充、[OPKSSH](https://github.com/openpubkey/opkssh)、tmux、端口敲门、终端日志、代理转发、Bitwarden SSH 代理、HashiCorp Vault SSH 签名等等
- **Termix ID** - 内置的 sshid.io 式功能。认领一个用户名,在解析地址上发布你的公钥,并用内置 CA 签发 SSH 证书
</details> </details>
@@ -234,11 +279,11 @@ Electron 桌面应用可完全独立运行,拥有自己的本地后端和数
<table align="center"> <table align="center">
<tr> <tr>
<th align="center">平台</th> <th align="center">平台</th>
<th align="center">发行</th> <th align="center">发行方式</th>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Web</b></td> <td align="center"><b>Web</b></td>
<td>任何现代浏览器(Chrome、Safari、Firefox)· PWA 支持</td> <td>任何现代浏览器(Chrome、Safari、Firefox)· 支持 PWA</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Windows</b> <sub>x64/ia32</sub></td> <td align="center"><b>Windows</b> <sub>x64/ia32</sub></td>
@@ -266,9 +311,9 @@ Electron 桌面应用可完全独立运行,拥有自己的本地后端和数
## 安装 ## 安装
访问 [Termix 文档](https://docs.termix.site/install) 了解有关如何在所有平台上安装 Termix 的完整说明。 访问 [Termix 文档](https://docs.termix.site/install) 查看所有平台的完整安装说明。
示例 Docker Compose 文件(如果不打算使用远程桌面功能,可以省略 `guacd`网络部分): Docker Compose 示例(如果不打算使用远程桌面功能,可以省略 `guacd`相关网络配置):
```yaml ```yaml
services: services:
@@ -305,11 +350,37 @@ networks:
driver: bridge driver: bridge
``` ```
### 命令行工具
Termix 还提供命令行工具,你可以在终端里管理服务器,也可以把 Termix 用在自己的脚本中。
```bash
npm install -g @termix-cli/cli
termix login --url https://termix.example.com
termix ssh 1
```
它可以打开终端、在单台主机或整个机群上执行命令、通过 SFTP 传输文件,以及管理主机、代码片段和凭据。完整文档见 [docs.termix.site/cli](https://docs.termix.site/cli)。
### 云端部署
你也可以把 Termix 服务端跑在 VPS 上,而不是自己的内网里。如果 Termix 就运行在它所管理的网络中,一旦网络出问题,Termix 也会跟着一起挂掉,而这恰恰是你最需要它的时候。放在外面运行可以保证它始终可达,还能获得固定 IP,不用 VPN 或端口转发就能从任何地方接入。
[GINERNET](https://docs.termix.site/install/ginernet) 是 Termix 的赞助商,文档里有部署到他们 VPS 平台的分步指南。
<br />
## 遥测
Termix 每天会发送一次匿名的小型统计信息,让我了解有多少实例在运行、哪些功能被用到。内容包括一个随机的实例 ID、你有多少用户和主机、应用版本,以及过去 24 小时内使用了哪些功能(终端、文件管理器、隧道、Docker 等)。它绝不包含用户名、主机名、IP 地址、凭据,或任何能识别你和你服务器的信息。
该功能默认开启。你可以在管理设置的“通用”中关闭它,或者在启动 Termix 之前设置 `ENABLE_TELEMETRY=false`
<br /> <br />
## 捐赠 ## 捐赠
Termix 免费且开源,没有订阅付费方案。如果觉得它有用,考虑捐赠以帮助支付服务器费用、域名和开发时间。捐赠还有助于资助研究和学习构建 SAML、KubernetesAgent 支持等功能所需的时间。在下方追踪进度并进行捐赠。 Termix 免费且开源,没有订阅也没有付费方案。如果觉得它有用,可以考虑捐赠,帮忙分担服务器、域名和开发时间的成本。捐赠还能支持研究和学习 SAML、KubernetesAgent 等功能所需的时间。可以在下方查看进展并捐赠。
[捐赠](https://donate.termix.site/) [捐赠](https://donate.termix.site/)
@@ -317,7 +388,7 @@ Termix 免费且开源,没有订阅或付费方案。如果您觉得它有用
## 赞助商 ## 赞助商
有意通过付费展示位支持开发吗?请发邮件 [mail@termix.site](mailto:mail@termix.site)。 有意通过付费展示位支持开发吗?请发邮件 [mail@termix.site](mailto:mail@termix.site)。
<div align="center"> <div align="center">
@@ -339,10 +410,6 @@ Termix 免费且开源,没有订阅或付费方案。如果您觉得它有用
<img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" /> <img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" />
</a> </a>
&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;
<a href="https://tailscale.com/">
<img src="https://drive.google.com/uc?export=view&id=1lIxkJuX6M23bW-2FElhT0rQieTrzaVSL" height="40" alt="Tailscale" />
</a>
&nbsp;&nbsp;&nbsp;
<a href="https://akamai.com/"> <a href="https://akamai.com/">
<img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" /> <img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" />
</a> </a>
@@ -354,14 +421,17 @@ Termix 免费且开源,没有订阅或付费方案。如果您觉得它有用
<a href="https://rackgenius.com/"> <a href="https://rackgenius.com/">
<img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" /> <img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" />
</a> </a>
&nbsp;&nbsp;&nbsp;
<a href="https://ginernet.com/">
<img src="https://ginernet.com/img/logo-web.png" height="40" alt="Ginernet" />
</a>
</div> </div>
<br /> <br />
## 支持 ## 支持
如果您需要 Termix 的帮助或想要请求功能,请访问 [Issues](https://github.com/Termix-SSH/Support/issues) 页面,登录并点击 `New Issue`。请尽可能详细地描述您的问题,建议使用英语。您也可以加入 [Discord](https://discord.gg/jVQGdvHDrf) 服务器并访问支持频道,但响应时间可能较长 需要帮助或想提功能建议?可以[新建一个 issue](https://github.com/Termix-SSH/Support/issues),尽量写清楚细节,如果方便请用英文。你也可以 [Discord](https://discord.gg/jVQGdvHDrf) 的支持频道提问,不过那边回复可能会慢一些
<br /> <br />
@@ -373,7 +443,7 @@ Termix 免费且开源,没有订阅或付费方案。如果您觉得它有用
[![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos) [![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos)
<sub>在 YouTube 上观看更新概览</sub> <sub>在 YouTube 上观看版本更新介绍</sub>
<br /> <br />
<br /> <br />
@@ -413,7 +483,7 @@ Termix 免费且开源,没有订阅或付费方案。如果您觉得它有用
</tr> </tr>
</table> </table>
<sub>某些视频和图可能已过时,或者可能无法完美展示功能。</sub> <sub>部分视频和图可能已过时,或者不能完整展示功能。</sub>
</div> </div>
@@ -421,10 +491,10 @@ Termix 免费且开源,没有订阅或付费方案。如果您觉得它有用
## 计划功能 ## 计划功能
查看 [Projects](https://github.com/orgs/Termix-SSH/projects/5) 了解所有计划功能。如果您想贡献代码,请参阅 [Contributing](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md)。 所有计划中的功能都在 [Projects](https://github.com/orgs/Termix-SSH/projects/5) 里。如果你想参与贡献,请查看[贡献指南](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md)。
<br /> <br />
## 许可证 ## 许可证
根据 Apache License Version 2.0 发布。更多信息请参`LICENSE` 基于 Apache License 2.0 发布。`LICENSE`
+154 -84
View File
@@ -4,7 +4,7 @@
<h1>Termix</h1> <h1>Termix</h1>
<p>Selbst gehostete SSH-Verwaltung und Remote-Desktop-Zugriff</p> <p>Selbst gehostete Serververwaltung, von SSH und Remotedesktop bis zu Automatisierungen</p>
<p> <p>
<a href="../README.md">English</a> · <a href="../README.md">English</a> ·
@@ -37,7 +37,7 @@
<br /> <br />
Termix ist kostenlos und Open Source. Wenn Sie es nützlich finden, erwägen Sie eine [Spende](https://donate.termix.site/), um Serverkosten und Entwicklungszeit zu decken. Termix ist kostenlos und quelloffen. Wenn es dir hilft, denk über eine [Spende](https://donate.termix.site/) nach, um Serverkosten und Entwicklungszeit zu decken.
<br /> <br />
@@ -56,9 +56,9 @@ Termix ist kostenlos und Open Source. Wenn Sie es nützlich finden, erwägen Sie
<br /> <br />
## Uberblick ## Überblick
Termix ist eine quelloffene, dauerhaft kostenlose, selbst gehostete All-in-One-Serververwaltungsplattform. Sie bietet eine plattformubergreifende Losung zur Verwaltung Ihrer Server und Infrastruktur uber eine einzige, intuitive Oberflache. Termix bietet SSH-Terminalzugriff, Remote-Desktop-Steuerung (RDP, VNC, Telnet), SSH-Tunneling-Funktionen, Remote-Dateiverwaltung und viele weitere Werkzeuge. Termix ist die perfekte kostenlose und selbst gehostete Alternative zu Termius, verfugbar fur alle Plattformen. Termix ist eine kostenlose, quelloffene und selbst gehostete Plattform zur Verwaltung deiner Server. Sie bringt SSH-Terminals, Remotedesktops (RDP, VNC, Telnet), Dateiübertragungen, Tunnel, Docker, Metriken und Automatisierungen an einem Ort zusammen, im Browser, auf dem Desktop und auf dem Handy. Eine selbst gehostete Alternative zu Termius, die dauerhaft kostenlos bleibt.
<br /> <br />
@@ -68,42 +68,42 @@ Termix ist eine quelloffene, dauerhaft kostenlose, selbst gehostete All-in-One-S
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH-Terminalzugriff:** **SSH-Terminal:**
Voll ausgestattetes Terminal mit Split-Screen-Unterstutzung (bis zu 4 Panels) mit einem browserahnlichen Tab-System. Enthalt Unterstutzung fur die Anpassung des Terminals einschliesslich gangiger Terminal-Themes, Schriftarten und anderer Komponenten. Ein vollwertiges Terminal mit Tabs wie im Browser und geteiltem Bildschirm, bis zu 6 Bereiche gleichzeitig. Thema, Schrift und Farben wählst du selbst. Über jeder Sitzung sitzt eine Leiste mit CPU, Speicher und Festplatte in Echtzeit sowie Verknüpfungen zu Dateien, Docker, Tunneln und Metriken dieses Hosts.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Remote-Desktop-Zugriff:** **Remotedesktop:**
RDP-, VNC- und Telnet-Unterstutzung uber den Browser mit vollstandiger Anpassung und Split-Screen. RDP, VNC und Telnet im Browser, in Tabs und geteiltem Bildschirm wie jede andere Sitzung. Mit Dateibrowser für RDP-Laufwerke und Hochladen per Drag-and-drop. Auf dem Windows-Desktop kannst du einen Host auch im nativen RDP-Client öffnen.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH-Tunnelverwaltung:** **SSH-Tunnel:**
Erstellen und verwalten Sie Server-zu-Server-SSH-Tunnel mit automatischer Wiederverbindung, Gesundheitsuberwachung sowie lokaler, entfernter oder dynamischer SOCKS-Weiterleitung. Desktop-Client-zu-Server-Tunneleinstellungen werden lokal pro Desktop-Installation gespeichert, optionale C2S-Preset-Snapshots konnen auf dem Server gespeichert, umbenannt, geladen oder geloscht werden, wenn Sie eine lokale Tunnelkonfiguration zwischen Clients ubertragen mochten. Lokale, entfernte und dynamische SOCKS-Weiterleitung mit automatischem Neuverbinden und Statusprüfungen. Client-zu-Server-Tunnel der Desktop-App bleiben auf diesem Rechner, und du kannst Voreinstellungen auf dem Server speichern, um eine Konfiguration auf einen anderen Rechner zu übernehmen.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Remote-Dateimanager:** **Dateimanager:**
Verwalten Sie Dateien direkt auf Remote-Servern mit Unterstutzung fur das Anzeigen und Bearbeiten von Code, Bildern, Audio und Video. Laden Sie Dateien hoch, herunter, benennen Sie sie um, loschen oder verschieben Sie sie nahtlos mit Sudo-Unterstutzung. Enthalt Unterstutzung fur das Verschieben von Dateien von Server zu Server. Dateien über SFTP durchsuchen, bearbeiten, hochladen, herunterladen, umbenennen, verschieben und löschen, auch mit sudo. Code, Bilder, Audio und Video ansehen und bearbeiten. Dateien direkt von einem Server zum anderen kopieren, wobei der schnellste Weg für dich gewählt und die Übertragung auf Fehler geprüft wird.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Docker- und Podman-Verwaltung:** **Docker und Podman:**
Container starten, stoppen, pausieren, entfernen. Container-Statistiken anzeigen. Container uber Docker-Exec-Terminal steuern. Unterstutzt sowohl Docker als auch Podman als Container-Laufzeitumgebung. Es wurde nicht entwickelt, um Portainer oder Dockge zu ersetzen, sondern um Ihre Container einfach zu verwalten, anstatt sie zu erstellen. Container starten, stoppen, pausieren und entfernen, ihre Auslastung ansehen und eine Shell darin öffnen. Funktioniert mit Docker und mit Podman. Es soll Portainer oder Dockge nicht ersetzen, sondern nur die Container verwalten, die du schon hast.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH-Host-Manager:** **Hostverwaltung:**
Speichern, organisieren und verwalten Sie Ihre SSH-Verbindungen mit Tags und Ordnern (Ordneranpassung und verschachtelte Ordner werden unterstutzt) und speichern Sie einfach wiederverwendbare Anmeldeinformationen mit der Moglichkeit, die Bereitstellung von SSH-Schlusseln zu automatisieren. Hosts mit Tags und verschachtelten Ordnern ordnen, die du benennen und einfärben kannst. Gespeicherte Zugangsdaten für mehrere Hosts wiederverwenden, SSH-Schlüssel automatisch verteilen, Hosts unter einem übergeordneten Host gruppieren, in großen Mengen bearbeiten und exportieren. Für einmalige Verbindungen, die du nicht speichern willst, gibt es Schnellverbindung.
</td> </td>
</tr> </tr>
@@ -111,97 +111,139 @@ Speichern, organisieren und verwalten Sie Ihre SSH-Verbindungen mit Tags und Ord
<td width="50%" valign="top"> <td width="50%" valign="top">
**Host-Metriken:** **Host-Metriken:**
CPU-, Arbeitsspeicher- und Festplattenauslastung, Netzwerk, Betriebszeit, Systeminformationen, Firewall, Port-Monitor, Log-Viewer, Benutzer/Berechtigungen, Zertifikate und vieles mehr anzeigen, was auf den meisten Linux-basierten Servern funktioniert. Enthalt Zeitreihen-Verlaufsdiagramme und schwellenwertbasierte Warnmeldungen mit ntfy- und Webhook-Unterstutzung. CPU, Speicher, Festplatte, Netzwerk, Temperatur, Laufzeit, Prozesse, Ports, Anmeldungen und Systeminfos auf den meisten Linux-Servern, mit Verlaufsgrafiken. Über Verwaltungskarten kümmerst du dich um Dienste, Cronjobs, Pakete, Benutzer, Firewallregeln, WireGuard, Tailscale, SSL-Zertifikate, Logs und Statusprüfungen, ohne Termix zu verlassen.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Benutzerauthentifizierung:** **Automatisierungen:**
Sichere Benutzerverwaltung mit Admin-Kontrollen (kann Informationen anderer Benutzer bearbeiten) und OIDC-/LDAP-/SSO-Unterstutzung (mit Zugriffskontrolle), 2FA (TOTP) und Passkey (WebAuthn)-Unterstutzung. Aktive Benutzersitzungen uber alle Plattformen anzeigen und Berechtigungen widerrufen. OIDC-/Lokale Konten miteinander verknupfen. Audit-Protokoll aller Benutzeraktionen anzeigen. Wähle einen Auslöser und lege fest, was passieren soll. Auslöser sind unter anderem eine Metrik über einem Schwellwert, ein Host der hoch- oder runtergeht, eine geänderte Statusprüfung, ein Zeitplan, ein Container-Ereignis oder ein eingehender Webhook. Schritte können Befehle und Snippets ausführen, Container und Tunnel steuern, einen Host aufwecken, eine URL aufrufen, warten, sich nach einer Bedingung verzweigen, eine andere Automatisierung starten und dich über ntfy, Discord oder einen Webhook benachrichtigen. Mit Testläufen probierst du alles gefahrlos aus.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Tailscale-Integration:** **Flotten:**
Gerate aus Ihrem Tailnet auflisten, um sie schnell als Hosts hinzuzufugen, und mit Tailscale SSH als Authentifizierungsmethode verbinden, sodass Ihre Tailnet-ACLs die Autorisierung ubernehmen, ohne Anmeldedaten speichern zu mussen. Fasse Hosts zu einer Flotte zusammen, entweder von Hand oder über Tag-Regeln, damit neue Hosts von selbst dazukommen. Führe einen Befehl auf allen Hosts gleichzeitig aus, schiebe und hole Dateien auf allen, installiere Pakete und sammle eine Übersicht über Betriebssystem, Kernel, Architektur und Laufzeit.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**RBAC/Freigabe:** **KI-Assistent:**
Erstellen Sie Rollen und teilen Sie Hosts uber Benutzer/Rollen hinweg. Unterstutzt alle Authentifizierungstypen und alle Host-Protokolle. Optional und aus, bis du ihn einschaltest. Verbinde OpenAI, Anthropic, Gemini, Ollama oder einen beliebigen OpenAI-kompatiblen Endpunkt und frag ihn zu deiner Umgebung. Er liest Hosts, Flotten, Snippets und Warnungen und schlägt Änderungen vor, die du bestätigst, statt sie selbst vorzunehmen. An Zugangsdaten, Benutzer und Einstellungen kommt er nie heran. Administratoren können ihn für die ganze Instanz auslassen, und du kannst ihn schon bei der Einrichtung ausblenden.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Serielle Verbindungen:** **Anmeldung und Benutzer:**
Verbinden Sie sich direkt vom Browser oder der Desktop-App aus mit seriellen Geraten (Router, Switches, Mikrocontroller usw.). Konfigurieren Sie Baudrate, Datenbits, Stoppbits und Paritat. Verwendet die Web Serial API in unterstutzten Browsern oder ein natives Backend in der Electron-App. Lokale Konten sowie Anmeldung über OIDC, LDAP, GitHub und Google, dazu Zwei-Faktor-Authentifizierung (TOTP), Passkeys (WebAuthn) und vertrauenswürdige Geräte. Administratoren können Benutzer verwalten, OIDC-Gruppen auf Rollen abbilden, alle aktiven Sitzungen über alle Plattformen hinweg sehen und beenden. Verknüpfe dein lokales Konto mit deinem OIDC-Konto und lies im Prüfprotokoll nach, wer was gemacht hat.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Warnmeldungen:** **Rollen und Freigaben:**
Legen Sie schwellenwertbasierte Warnregeln fur Host-Metriken (CPU, Arbeitsspeicher, Festplatte usw.) fest und erhalten Sie Benachrichtigungen uber ntfy oder Webhooks, wenn diese ausgelost werden. Zeigen Sie ausgeloste und aufgeloste Warnmeldungen in einem Verlaufsprotokoll an. Lege Rollen an und teile Hosts mit Benutzern oder Rollen auf vier Stufen: Verbinden, Ansehen, Bearbeiten und Verwalten. Das funktioniert mit jeder Authentifizierungsart und jedem Protokoll, und du kannst die Zugangsdaten für einen geteilten Host überschreiben.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Warnungen:**
Lege Regeln für Host-Metriken wie CPU, Speicher und Festplatte fest und lass dich über ntfy, Discord oder einen Webhook benachrichtigen, wenn sie greifen. Sieh dir aktive und wieder behobene Warnungen im Verlauf an und blende aus, was dich nicht interessiert.
</td>
<td width="50%" valign="top">
**Startseite:** **Startseite:**
Eine vollstandig anpassbare Startseite mit einem Drag-and-Drop-Widget-Raster. Fugen Sie Widgets fur Hoststatus, Service-Links, Uhren, Notizen, RSS-Feeds, Wetter, Docker-Container, Host-Metrik-Diagramme, eingebettete Terminals, iFrames und mehr hinzu. Ein Raster aus Widgets, das du selbst per Drag-and-drop zusammenstellst. Widgets für Hoststatus, Pings, Dienstlinks, Lesezeichen, Suche, Uhren, Kalender, Countdowns, Notizen, RSS, Wetter, Bilder, Iframes, Docker, Tunnel, Metrikdiagramme, eigene APIs und sogar ein laufendes Terminal.
</td>
<td width="50%" valign="top">
**Datenbankverschlusselung:**
Backend gespeichert als verschlusselte SQLite-Datenbankdateien. Weitere Informationen in der [Dokumentation](https://docs.termix.site).
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Netzwerkgraph:** **Snippets und Werkzeuge:**
Passen Sie Ihr Dashboard an, um Ihr Homelab basierend auf Ihren SSH-Verbindungen mit Statusunterstutzung zu visualisieren. Speichere Befehle, die du oft brauchst, und starte sie mit einem Klick, mit Variablen für den Host und eigene Eingaben. Führe einen Befehl in allen offenen Terminals zugleich aus und durchsuche deinen Befehlsverlauf mit Autovervollständigung.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH-Werkzeuge:** **Sitzungsfreigabe:**
Erstellen Sie wiederverwendbare Befehlsvorlagen, die mit einem einzigen Klick ausgefuhrt werden. Fuhren Sie einen Befehl gleichzeitig in mehreren geoffneten Terminals aus. Teile eine laufende Terminal-, RDP-, VNC- oder Telnet-Sitzung in Echtzeit. Verschicke einen Link, dem jeder ohne Konto beitreten kann, oder teile mit einem bestimmten Termix-Benutzer, nur lesend oder mit Schreibrechten. Freigaben können von selbst ablaufen oder zurückgezogen werden und lassen sich global oder pro Host abschalten.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Persistente Tabs:** **Sitzungsaufzeichnung und Protokolle:**
SSH-Sitzungen und Tabs bleiben uber Gerate/Aktualisierungen hinweg offen, wenn im Benutzerprofil aktiviert. Zeichne Terminal-, RDP- und VNC-Sitzungen auf und spiel sie später ab. Lade einfache Textprotokolle einer Sitzung herunter und sieh im Verbindungsprotokoll nach, was während einer Verbindung genau passiert ist.
</td>
<td width="50%" valign="top">
**Serielle Verbindungen:**
Sprich mit seriellen Geräten wie Routern, Switches und Mikrocontrollern, aus dem Browser oder der Desktop-App. Stelle Baudrate, Datenbits, Stoppbits und Parität ein. Nutzt die Web-Serial-API in passenden Browsern oder ein natives Backend in der Desktop-App.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Tailscale:**
Hol Geräte aus deinem Tailnet, um sie mit ein paar Klicks als Hosts anzulegen, und verbinde dich per Tailscale SSH, damit deine Tailnet-ACLs den Zugriff regeln und keine Zugangsdaten gespeichert werden. Headscale und eigene Endpunkte gehen auch.
</td>
<td width="50%" valign="top">
**Proxmox:**
Importiere Hosts direkt aus einer Proxmox-Instanz und beobachte Knoten- und Gastwerte wie CPU, Speicher und Storage in einem eigenen Tab.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Arbeitsbereiche und Tabs:**
Speichere eine Reihe von Tabs samt Aufteilung und öffne alles mit einem Klick wieder. Termix merkt sich auch deine letzte Sitzung, sodass deine Tabs nach einem Neuladen und auf anderen Geräten wieder da sind.
</td>
<td width="50%" valign="top">
**Geführte Einrichtung:**
Eine kurze Einrichtung führt dich durch die Wahl einer Oberflächenvorlage, deines Themas, der gewünschten Funktionen und deines ersten Hosts. Der einfache Modus blendet aus, was du nicht nutzt, und du kannst die Einrichtung jederzeit erneut starten oder die Vorlage wechseln.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Desktop eigenständig und Synchronisierung:**
Die Desktop-App läuft eigenständig mit lokalem Backend und eigener Datenbank, ganz ohne Server. Du kannst sie auch mit einem Termix-Server verbinden, um Hosts, Zugangsdaten, Snippets und mehr in beide Richtungen abzugleichen, und wählen, ob Verbindungen lokal oder über den Server aufgebaut werden.
</td>
<td width="50%" valign="top">
**Kommandozeile:**
Ein `termix`-CLI für deine Shell und deine Skripte. Terminals öffnen, einen Befehl auf einem Host oder einer ganzen Flotte ausführen, Dateien per SFTP verschieben und Hosts, Snippets und Zugangsdaten verwalten. Installiere es mit `npm install -g @termix-cli/cli` oder nimm eine eigenständige Binärdatei. Siehe die [CLI-Dokumentation](https://docs.termix.site/cli).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Sicherheit:**
Passwörter, Schlüssel und andere Geheimnisse werden pro Benutzer verschlüsselt, und die Datenbankdateien selbst lassen sich auf der Festplatte verschlüsseln. Wie das funktioniert, steht in der [Dokumentation](https://docs.termix.site/security).
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Sprachen:** **Sprachen:**
Integrierte Unterstutzung fur ca. 30 Sprachen (verwaltet uber [Crowdin](https://docs.termix.site/translations)). Rund 30 Sprachen sind eingebaut, verwaltet über [Crowdin](https://docs.termix.site/translations).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Sitzungsfreigabe:**
Teilen Sie eine Live-Terminal-, RDP-, VNC- oder Telnet-Sitzung in Echtzeit mit anderen. Freigabe uber einen Link (anonymer Beitritt, kein Konto erforderlich) oder mit einem bestimmten Termix-Benutzer, mit Wahl zwischen Nur-Lese- oder Lese-/Schreibzugriff. Freigaben konnen automatisch ablaufen oder jederzeit widerrufen werden, und die Sitzungsfreigabe kann global oder pro Host umgeschaltet werden.
</td>
<td width="50%" valign="top">
**Eigenstandiger Desktop + bidirektionale Synchronisierung:**
Die Electron-Desktop-App lauft vollstandig eigenstandig mit eigenem lokalem Backend und eigener Datenbank, kein Server erforderlich. Optional mit einem entfernten Termix-Server verbinden fur automatische bidirektionale Synchronisierung von Hosts, Zugangsdaten, Snippets und mehr, mit der Wahl, ob SSH-Verbindungen lokal oder uber den entfernten Server gestartet werden.
</td> </td>
</tr> </tr>
@@ -213,36 +255,39 @@ Die Electron-Desktop-App lauft vollstandig eigenstandig mit eigenem lokalem Back
<summary><b>Weitere Funktionen</b></summary> <summary><b>Weitere Funktionen</b></summary>
<br /> <br />
- **Dashboard** - Serverinformationen auf einen Blick auf Ihrem Dashboard anzeigen - **Dashboard** - Deine Server auf einen Blick, mit Karten, die du selbst anordnest
- **API-Schlussel** - Erstellen Sie benutzerbezogene API-Schlussel mit Ablaufdaten zur Verwendung fur Automatisierung/CI - **Netzwerkgrafik** - Dein Homelab aus deinen Hosts gezeichnet, mit Live-Status
- **Datenexport/-import** - SSH-Hosts, Anmeldeinformationen und Dateimanager-Daten exportieren und importieren - **Tmux-Monitor** - tmux-Sitzungen, Fenster und Bereiche durchsehen, mit Vorschau und Suche
- **Automatische SSL-Einrichtung** - Integrierte SSL-Zertifikatsgenerierung und -verwaltung mit HTTPS-Weiterleitungen - **API-Schlüssel** - Benutzerbezogene Schlüssel mit Ablaufdatum für Skripte und CI
- **Moderne Benutzeroberflache** - Saubere desktop-/mobilfreundliche Oberflache, erstellt mit React, Tailwind CSS und Shadcn. Wahlen Sie zwischen vielen verschiedenen UI-Themes einschliesslich Hell, Dunkel, Dracula usw. Verwenden Sie URL-Routen, um jede Verbindung im Vollbildmodus zu offnen. - **Export und Import** - Hosts, Zugangsdaten und Dateimanager-Daten rein- und rausholen
- **Befehlsverlauf** - Autovervollstandigung und Anzeige zuvor ausgefuhrter SSH-Befehle - **Automatisches SSL** - Zertifikate werden für dich erstellt und erneuert, samt HTTPS-Weiterleitung, oder du bringst eigene mit
- **Schnellverbindung** - Verbinden Sie sich mit einem Server, ohne die Verbindungsdaten speichern zu mussen - **Datenbanken** - Standardmäßig SQLite, dazu PostgreSQL und MySQL
- **Befehlspalette** - Doppeltippen Sie die linke Umschalttaste, um schnell auf SSH-Verbindungen mit Ihrer Tastatur zuzugreifen - **Moderne Oberfläche** - Aufgeräumte React-Oberfläche für Desktop und Handy, mit Themen wie Hell, Dunkel und Dracula. Jede Verbindung lässt sich über eine URL im Vollbild öffnen
- **Proxmox-Integration** - Automatisches Hinzufugen von Hosts zu Termix aus Ihrer Proxmox-Instanz - **Befehlspalette** - Zweimal linke Umschalttaste, um per Tastatur zu einem Host zu springen
- **SSH-Funktionsreich** - Unterstutzt Jump-Hosts, Warpgate, TOTP-basierte Verbindungen, SOCKS5, Host-Key-Verifizierung, automatisches Ausfullen von Passwortern, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, Port Knocking, Terminal-Protokollierung, SSH-Agent-Forwarding, Bitwarden SSH-Agent, HashiCorp Vault SSH-Signierung und mehr. - **Tastenkürzel** - Zwischen Tabs wechseln, Tabs schließen und mehr, alles neu belegbar
- **Termix ID** - Ein sshid.io-Aquivalent, integriert in Termix. Beanspruchen Sie einen Handle, veroffentlichen Sie Ihre offentlichen SSH-Schlussel unter einer Resolver-URL und nutzen Sie eine integrierte CA zur Ausstellung von SSH-Zertifikaten. - **Wake-on-LAN** - Einen Rechner aus Termix heraus oder aus einem Automatisierungsschritt aufwecken
- **Vertrauenswürdiger Proxy** - Einen Reverse Proxy die Anmeldung erledigen und den Benutzer durchreichen lassen
- **Viele SSH-Funktionen** - Sprunghosts, Warpgate, TOTP-Abfragen, SOCKS5, Prüfung von Hostschlüsseln, automatisches Ausfüllen von Passwörtern, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, Port Knocking, Terminalprotokolle, Agent-Weiterleitung, Bitwarden SSH-Agent, SSH-Signierung über HashiCorp Vault und mehr
- **Termix ID** - Eine eingebaute Variante von sshid.io. Sichere dir einen Namen, veröffentliche deine öffentlichen Schlüssel unter einer Resolver-URL und stelle SSH-Zertifikate über die eingebaute CA aus
</details> </details>
<br /> <br />
## Plattformunterstutzung ## Unterstützte Plattformen
<table align="center"> <table align="center">
<tr> <tr>
<th align="center">Plattform</th> <th align="center">Plattform</th>
<th align="center">Distribution</th> <th align="center">Bezugsquelle</th>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Web</b></td> <td align="center"><b>Web</b></td>
<td>Jeder moderne Browser (Chrome, Safari, Firefox) · PWA-Unterstutzung</td> <td>Jeder moderne Browser (Chrome, Safari, Firefox) · PWA-fähig</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Windows</b> <sub>x64/ia32</sub></td> <td align="center"><b>Windows</b> <sub>x64/ia32</sub></td>
<td>Portabel · MSI-Installationsprogramm · Chocolatey</td> <td>Portabel · MSI-Installer · Chocolatey</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Linux</b> <sub>x64/ia32</sub></td> <td align="center"><b>Linux</b> <sub>x64/ia32</sub></td>
@@ -266,9 +311,9 @@ Die Electron-Desktop-App lauft vollstandig eigenstandig mit eigenem lokalem Back
## Installation ## Installation
Besuchen Sie die [Termix-Dokumentation](https://docs.termix.site/install) fur vollstandige Installationsanleitungen fur alle Plattformen. In der [Termix-Dokumentation](https://docs.termix.site/install) findest du die vollständigen Installationsanleitungen für alle Plattformen.
Beispiel einer Docker-Compose-Datei (Sie konnen `guacd` und das Netzwerk weglassen, wenn Sie keine Remote-Desktop-Funktionen nutzen mochten): Beispiel für eine Docker-Compose-Datei (`guacd` und das Netzwerk kannst du weglassen, wenn du keinen Remotedesktop brauchst):
```yaml ```yaml
services: services:
@@ -305,11 +350,37 @@ networks:
driver: bridge driver: bridge
``` ```
### Kommandozeile
Termix hat auch ein CLI, damit du deine Server vom Terminal aus verwalten und Termix in eigenen Skripten nutzen kannst.
```bash
npm install -g @termix-cli/cli
termix login --url https://termix.example.com
termix ssh 1
```
Es kann Terminals öffnen, einen Befehl auf einem Host oder einer ganzen Flotte ausführen, Dateien per SFTP verschieben und Hosts, Snippets und Zugangsdaten verwalten. Die vollständige Dokumentation steht auf [docs.termix.site/cli](https://docs.termix.site/cli).
### Cloud-Hosting
Du kannst den Termix-Server auf einem VPS laufen lassen statt im eigenen Netz. Läuft Termix in dem Netz, das es verwaltet, reißt eine Störung es mit sich, und zwar genau dann, wenn du es zum Reparieren bräuchtest. Woanders bleibt es erreichbar, du bekommst eine feste IP und kommst von überall heran, ohne VPN und ohne Portfreigabe.
[GINERNET](https://docs.termix.site/install/ginernet) sponsert Termix, und in der Dokumentation steht eine Schritt-für-Schritt-Anleitung für die Bereitstellung auf deren VPS-Plattform.
<br />
## Telemetrie
Termix schickt einmal am Tag ein kleines anonymes Signal, damit ich sehen kann, wie viele Instanzen laufen und welche Funktionen genutzt werden. Enthalten sind eine zufällige Instanz-ID, wie viele Benutzer und Hosts du hast, die App-Version und welche Funktionen (Terminal, Dateimanager, Tunnel, Docker usw.) in den letzten 24 Stunden benutzt wurden. Niemals enthalten sind Benutzernamen, Hostnamen, IP-Adressen, Zugangsdaten oder irgendetwas anderes, das dich oder deine Server identifiziert.
Es ist standardmäßig an. Schalte es in den Administrationseinstellungen unter Allgemein aus oder setze `ENABLE_TELEMETRY=false`, bevor du Termix überhaupt startest.
<br /> <br />
## Spenden ## Spenden
Termix ist kostenlos und Open Source, ohne Abonnements oder kostenpflichtige Plane. Wenn Sie es nutzlich finden, erwagen Sie eine Spende, um Serverkosten, Domains und Entwicklungszeit zu decken. Spenden helfen auch dabei, die Zeit zu finanzieren, die benotigt wird, um zu erforschen und zu lernen, was fur Funktionen wie SAML-, Kubernetes- und Agent-Unterstutzung erforderlich ist. Verfolgen Sie den Fortschritt und spenden Sie unten. Termix ist kostenlos und quelloffen, ohne Abo und ohne Bezahlmodell. Wenn es dir hilft, denk über eine Spende nach, um Server, Domains und Entwicklungszeit zu decken. Spenden finanzieren auch die Zeit, um Funktionen wie SAML, Kubernetes und Agent-Unterstützung zu erarbeiten. Unten kannst du den Fortschritt verfolgen und spenden.
[Spenden](https://donate.termix.site/) [Spenden](https://donate.termix.site/)
@@ -317,7 +388,7 @@ Termix ist kostenlos und Open Source, ohne Abonnements oder kostenpflichtige Pla
## Sponsoren ## Sponsoren
Interessiert an einer bezahlten Platzierung zur Unterstutzung der Entwicklung? Schreiben Sie eine E-Mail an [mail@termix.site](mailto:mail@termix.site). Interesse an einer bezahlten Platzierung zur Unterstützung der Entwicklung? Schreib an [mail@termix.site](mailto:mail@termix.site).
<div align="center"> <div align="center">
@@ -339,10 +410,6 @@ Interessiert an einer bezahlten Platzierung zur Unterstutzung der Entwicklung? S
<img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" /> <img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" />
</a> </a>
&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;
<a href="https://tailscale.com/">
<img src="https://drive.google.com/uc?export=view&id=1lIxkJuX6M23bW-2FElhT0rQieTrzaVSL" height="40" alt="Tailscale" />
</a>
&nbsp;&nbsp;&nbsp;
<a href="https://akamai.com/"> <a href="https://akamai.com/">
<img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" /> <img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" />
</a> </a>
@@ -354,14 +421,17 @@ Interessiert an einer bezahlten Platzierung zur Unterstutzung der Entwicklung? S
<a href="https://rackgenius.com/"> <a href="https://rackgenius.com/">
<img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" /> <img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" />
</a> </a>
&nbsp;&nbsp;&nbsp;
<a href="https://ginernet.com/">
<img src="https://ginernet.com/img/logo-web.png" height="40" alt="Ginernet" />
</a>
</div> </div>
<br /> <br />
## Support ## Support
Wenn Sie Hilfe benotigen oder eine Funktion fur Termix anfragen mochten, besuchen Sie die [Issues](https://github.com/Termix-SSH/Support/issues)-Seite, melden Sie sich an und klicken Sie auf `New Issue`. Bitte beschreiben Sie Ihr Anliegen so detailliert wie moglich, vorzugsweise auf Englisch. Sie konnen auch dem [Discord](https://discord.gg/jVQGdvHDrf)-Server beitreten und den Support-Kanal besuchen, allerdings konnen die Antwortzeiten dort langer sein. Brauchst du Hilfe oder möchtest du eine Funktion vorschlagen? Erstelle ein [neues Issue](https://github.com/Termix-SSH/Support/issues) und beschreibe es so genau wie möglich, nach Möglichkeit auf Englisch. Du kannst auch im Support-Kanal auf [Discord](https://discord.gg/jVQGdvHDrf) fragen, dort dauern Antworten aber manchmal länger.
<br /> <br />
@@ -373,7 +443,7 @@ Wenn Sie Hilfe benotigen oder eine Funktion fur Termix anfragen mochten, besuche
[![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos) [![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos)
<sub>Update-Ubersichten auf YouTube ansehen</sub> <sub>Übersichten zu Updates auf YouTube ansehen</sub>
<br /> <br />
<br /> <br />
@@ -413,7 +483,7 @@ Wenn Sie Hilfe benotigen oder eine Funktion fur Termix anfragen mochten, besuche
</tr> </tr>
</table> </table>
<sub>Einige Videos und Bilder konnen veraltet sein oder Funktionen moglicherweise nicht perfekt darstellen.</sub> <sub>Manche Videos und Bilder sind vielleicht veraltet oder zeigen die Funktionen nicht perfekt.</sub>
</div> </div>
@@ -421,10 +491,10 @@ Wenn Sie Hilfe benotigen oder eine Funktion fur Termix anfragen mochten, besuche
## Geplante Funktionen ## Geplante Funktionen
Siehe [Projekte](https://github.com/orgs/Termix-SSH/projects/5) fur alle geplanten Funktionen. Wenn Sie beitragen mochten, siehe [Mitwirken](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md). Alle geplanten Funktionen stehen unter [Projects](https://github.com/orgs/Termix-SSH/projects/5). Wenn du mitarbeiten möchtest, sieh dir [Contributing](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md) an.
<br /> <br />
## Lizenz ## Lizenz
Verteilt unter der Apache License Version 2.0. Siehe `LICENSE` fur weitere Informationen. Veröffentlicht unter der Apache-Lizenz Version 2.0. Mehr dazu in `LICENSE`.
+156 -86
View File
@@ -4,7 +4,7 @@
<h1>Termix</h1> <h1>Termix</h1>
<p>Gestión SSH autoalojada y acceso a escritorio remoto</p> <p>Gestión de servidores autoalojada, desde SSH y escritorio remoto hasta automatizaciones</p>
<p> <p>
<a href="../README.md">English</a> · <a href="../README.md">English</a> ·
@@ -37,7 +37,7 @@
<br /> <br />
Termix es gratuito y de código abierto. Si lo encuentras útil, considera [donar](https://donate.termix.site/) para ayudar a cubrir los costos del servidor y el tiempo de desarrollo. Termix es gratuito y de código abierto. Si te resulta útil, considera [donar](https://donate.termix.site/) para ayudar a cubrir los costes de servidor y el tiempo de desarrollo.
<br /> <br />
@@ -49,159 +49,201 @@ Termix es gratuito y de código abierto. Si lo encuentras útil, considera [dona
<p> <p>
<img src="../repo-images/Repo of the Day.png" alt="Repo of the Day Achievement" width="280" /> <img src="../repo-images/Repo of the Day.png" alt="Repo of the Day Achievement" width="280" />
<br /> <br />
<sub>Logrado el 1 de septiembre de 2025</sub> <sub>Conseguido el 1 de septiembre de 2025</sub>
</p> </p>
</div> </div>
<br /> <br />
## Descripcion General ## Descripción general
Termix es una plataforma de gestion de servidores todo en uno, de codigo abierto, siempre gratuita y autoalojada. Proporciona una solucion multiplataforma para gestionar sus servidores e infraestructura a traves de una interfaz unica e intuitiva. Termix ofrece acceso a terminal SSH, control de escritorio remoto (RDP, VNC, Telnet), capacidades de tuneles SSH, gestion remota de archivos y muchas otras herramientas. Termix es la alternativa perfecta, gratuita y autoalojada a Termius, disponible para todas las plataformas. Termix es una plataforma gratuita, de código abierto y autoalojada para gestionar tus servidores. Reúne en un solo sitio terminales SSH, escritorios remotos (RDP, VNC, Telnet), transferencias de archivos, túneles, Docker, métricas y automatizaciones, en web, escritorio y móvil. Es una alternativa autoalojada a Termius que seguirá siendo gratuita.
<br /> <br />
## Caracteristicas ## Características
<table> <table>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Acceso a Terminal SSH:** **Terminal SSH:**
Terminal completo con soporte de pantalla dividida (hasta 4 paneles) con un sistema de pestanas similar al navegador. Incluye soporte para personalizar el terminal incluyendo temas comunes de terminal, fuentes y otros componentes. Un terminal completo con pestañas como las del navegador y pantalla dividida, hasta 6 paneles a la vez. Elige tu tema, tu fuente y tus colores. Sobre cada sesión hay una barra con CPU, memoria y disco en vivo, además de accesos rápidos a los archivos, Docker, túneles y métricas de ese host.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Acceso a Escritorio Remoto:** **Escritorio remoto:**
Soporte RDP, VNC y Telnet a traves del navegador con personalizacion completa y pantalla dividida. RDP, VNC y Telnet en el navegador, en pestañas y pantalla dividida como cualquier otra sesión. Incluye un explorador de archivos para las unidades RDP y subida arrastrando y soltando. En el escritorio de Windows también puedes abrir un host en el cliente RDP nativo.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gestion de Tuneles SSH:** **neles SSH:**
Cree y gestione tuneles SSH de servidor a servidor con reconexion automatica, monitoreo de estado y reenvio local, remoto o dinamico SOCKS. La configuracion de tuneles de cliente de escritorio a servidor se almacena localmente por instalacion de escritorio, los snapshots de presets C2S opcionales pueden guardarse en el servidor, renombrarse, cargarse o eliminarse cuando desee mover una configuracion de tunel local entre clientes. Reenvío local, remoto y SOCKS dinámico, con reconexión automática y comprobaciones de estado. Los túneles de cliente a servidor de la aplicación de escritorio se guardan en ese equipo, y puedes guardar ajustes en el servidor para llevarte una configuración a otro equipo.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gestor Remoto de Archivos:** **Gestor de archivos:**
Gestione archivos directamente en servidores remotos con soporte para visualizar y editar codigo, imagenes, audio y video. Suba, descargue, renombre, elimine y mueva archivos sin problemas con soporte sudo. Incluye soporte para mover archivos de servidor a servidor. Navega, edita, sube, descarga, renombra, mueve y borra archivos por SFTP, con soporte para sudo. Mira y edita código, imágenes, audio y vídeo. Copia archivos directamente de un servidor a otro, con la ruta más rápida elegida por ti y las transferencias verificadas.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gestion de Docker y Podman:** **Docker y Podman:**
Inicie, detenga, pause, elimine contenedores. Vea estadisticas de contenedores. Controle contenedores usando el terminal docker exec. Compatible con Docker y Podman como entorno de ejecucion de contenedores. No fue creado para reemplazar Portainer o Dockge, sino para simplemente gestionar sus contenedores en lugar de crearlos. Arranca, para, pausa y elimina contenedores, mira sus estadísticas y abre una consola dentro de uno. Funciona con Docker y con Podman. No pretende sustituir a Portainer ni a Dockge, solo gestionar los contenedores que ya tienes.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gestor de Hosts SSH:** **Gestor de hosts:**
Guarde, organice y gestione sus conexiones SSH con etiquetas y carpetas (con personalizacion de carpetas y soporte de carpetas anidadas), y guarde facilmente informacion de inicio de sesion reutilizable con la capacidad de automatizar el despliegue de claves SSH. Guarda y organiza hosts con etiquetas y carpetas anidadas que puedes nombrar y colorear. Reutiliza credenciales guardadas entre hosts, despliega claves SSH automáticamente, agrupa hosts bajo un host padre, edita y exporta en lote, y usa la conexión rápida para conexiones puntuales que no quieres guardar.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Metricas del Host:** **Métricas de host:**
Vea el uso de CPU, memoria y disco, red, tiempo de actividad, informacion del sistema, firewall, monitor de puertos, visor de registros, usuarios/permisos, certificados y muchos mas, que funcionan en la mayoria de los servidores basados en Linux. Incluye graficos de historial de series temporales y alertas basadas en umbrales con soporte para ntfy y webhooks. CPU, memoria, disco, red, temperatura, tiempo encendido, procesos, puertos, inicios de sesión e información del sistema en la mayoría de servidores Linux, con gráficas de histórico. Las tarjetas de gestión te dejan manejar servicios, tareas cron, paquetes, usuarios, reglas del cortafuegos, WireGuard, Tailscale, certificados SSL, registros y comprobaciones de estado sin salir de Termix.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Autenticacion de Usuarios:** **Automatizaciones:**
Gestion segura de usuarios con controles de administrador (puede editar la informacion de otros usuarios) y soporte para OIDC/LDAP/SSO (con control de acceso), 2FA (TOTP) y soporte para passkeys (WebAuthn). Vea sesiones activas de usuarios en todas las plataformas y revoque permisos. Vincule sus cuentas OIDC/Locales entre si. Vea el registro de auditoria de las acciones de todos los usuarios. Elige un disparador y luego di qué debe pasar. Los disparadores incluyen una métrica que supera un umbral, un host que se cae o vuelve, una comprobación de estado que cambia, una programación, un evento de contenedor o un webhook entrante. Los pasos pueden ejecutar comandos y fragmentos, controlar contenedores y túneles, despertar un host, llamar a una URL, esperar, ramificarse según una condición, ejecutar otra automatización y avisarte por ntfy, Discord o un webhook. Las ejecuciones de prueba te dejan probarlo sin riesgo.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Integracion con Tailscale:** **Flotas:**
Liste dispositivos de su red Tailscale para agregarlos rapidamente como hosts y conectese usando Tailscale SSH como metodo de autenticacion, permitiendo que las ACL de Tailscale gestionen la autorizacion sin almacenar credenciales. Agrupa hosts en una flota eligiéndolos o con reglas de etiquetas, para que los nuevos entren solos. Ejecuta un comando en todos los hosts a la vez, envía y recoge archivos de todos ellos, instala paquetes y reúne un inventario del sistema, el kernel, la arquitectura y el tiempo encendido.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**RBAC/Compartir:** **Asistente de IA:**
Cree roles y comparta hosts entre usuarios/roles. Compatible con todos los tipos de autenticacion y todos los protocolos de host. Es opcional y está apagado hasta que tú lo enciendas. Conecta OpenAI, Anthropic, Gemini, Ollama o cualquier punto de acceso compatible con OpenAI y pregúntale sobre tu instalación. Puede leer hosts, flotas, fragmentos y alertas, y propone cambios para que los apruebes en lugar de hacerlos él. Nunca puede tocar credenciales, usuarios ni ajustes. Los administradores pueden dejarlo apagado para toda la instancia, y tú puedes ocultarlo durante la configuración.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Conexiones Serie:** **Acceso y usuarios:**
Conectese a dispositivos serie (routers, switches, microcontroladores, etc.) directamente desde el navegador o la aplicacion de escritorio. Configure la tasa de baudios, bits de datos, bits de parada y paridad. Utiliza la Web Serial API en navegadores compatibles o un backend nativo en la aplicacion Electron. Cuentas locales más inicio de sesión con OIDC, LDAP, GitHub y Google, con doble factor (TOTP), llaves de acceso (WebAuthn) y dispositivos de confianza. Los administradores pueden gestionar usuarios, asignar grupos de OIDC a roles, ver todas las sesiones activas en cualquier plataforma y revocarlas. Enlaza tu cuenta local con la de OIDC y consulta el registro de auditoría de lo que ha hecho cada uno.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Roles y compartición:**
Crea roles y comparte hosts con usuarios o roles en cuatro niveles: conectar, ver, editar y gestionar. Funciona con todos los tipos de autenticación y todos los protocolos, y puedes cambiar las credenciales que se usan en un host compartido.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Alertas:** **Alertas:**
Configure reglas de alerta basadas en umbrales para metricas del host (CPU, memoria, disco, etc.) y reciba notificaciones a traves de ntfy o webhooks cuando se activen. Vea las alertas activas y resueltas en un historial de registros. Pon reglas sobre métricas de host como CPU, memoria y disco, y recibe avisos por ntfy, Discord o un webhook cuando salten. Consulta las alertas activas y resueltas en un histórico y descarta las que no te importan.
</td>
<td width="50%" valign="top">
**Página de inicio:**
Una rejilla de widgets que montas tú mismo arrastrando y soltando. Hay widgets para el estado de los hosts, pings, enlaces a servicios, marcadores, búsqueda, relojes, calendarios, cuentas atrás, notas, RSS, tiempo, imágenes, iframes, Docker, túneles, gráficas de métricas, APIs propias e incluso un terminal en vivo.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Pagina de Inicio:** **Fragmentos y herramientas:**
Una pagina de inicio completamente personalizable con una cuadricula de widgets de arrastrar y soltar. Agregue widgets para estado del host, enlaces de servicios, relojes, notas, feeds RSS, clima, contenedores Docker, graficos de metricas del host, terminales integrados, iframes y mas. Guarda los comandos que usas a menudo y lánzalos con un clic, con variables para el host y para lo que tú escribas. Ejecuta un mismo comando en todos los terminales abiertos y busca en tu historial con autocompletado.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Cifrado de Base de Datos:** **Compartir sesión:**
Backend almacenado como archivos de base de datos SQLite cifrados. Consulte la [documentacion](https://docs.termix.site) para mas informacion. Comparte en directo una sesión de terminal, RDP, VNC o Telnet. Manda un enlace al que cualquiera puede entrar sin cuenta, o compártela con un usuario concreto de Termix, en solo lectura o con escritura. Las comparticiones pueden caducar solas o revocarse, y se pueden desactivar globalmente o por host.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Grafico de Red:** **Grabación y registros de sesión:**
Personalice su Dashboard para visualizar su homelab basado en sus conexiones SSH con soporte de estado. Graba sesiones de terminal, RDP y VNC y reprodúcelas después. Descarga registros de texto de una sesión y mira el registro de conexión para ver exactamente qué pasó durante ella.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Herramientas SSH:** **Conexiones serie:**
Cree fragmentos de comandos reutilizables que se ejecutan con un solo clic. Ejecute un comando simultaneamente en multiples terminales abiertos. Habla con dispositivos serie como routers, switches y microcontroladores desde el navegador o la aplicación de escritorio. Ajusta velocidad, bits de datos, bits de parada y paridad. Usa la API Web Serial en los navegadores compatibles, o un backend nativo en la aplicación de escritorio.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Pestanas Persistentes:** **Tailscale:**
Las sesiones SSH y pestanas permanecen abiertas entre dispositivos/actualizaciones si esta habilitado en el perfil de usuario. Trae dispositivos de tu tailnet para añadirlos como hosts en un par de clics, y conéctate con Tailscale SSH para que las ACL de tu tailnet controlen el acceso sin guardar credenciales. También funcionan Headscale y los puntos de acceso personalizados.
</td>
<td width="50%" valign="top">
**Proxmox:**
Importa hosts directamente desde una instancia de Proxmox y observa las estadísticas de nodos e invitados, incluidas CPU, memoria y almacenamiento, en su propia pestaña.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Espacios de trabajo y pestañas:**
Guarda un conjunto de pestañas con su distribución dividida y reábrelo entero con un clic. Termix también recuerda tu última sesión, así que tus pestañas vuelven tras recargar y en otros dispositivos.
</td>
<td width="50%" valign="top">
**Configuración guiada:**
Una configuración corta te lleva por elegir un preajuste de interfaz, tu tema, las funciones que quieres y tu primer host. El modo sencillo esconde lo que no usas, y puedes repetir la configuración o cambiar de preajuste cuando quieras.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Escritorio independiente y sincronización:**
La aplicación de escritorio funciona sola, con su backend y su base de datos locales, sin necesidad de servidor. También puedes conectarla a un servidor Termix para sincronizar en ambos sentidos hosts, credenciales, fragmentos y más, y decidir si las conexiones salen de tu equipo o pasan por el servidor.
</td>
<td width="50%" valign="top">
**Línea de comandos:**
Un CLI `termix` para tu shell y tus scripts. Abre terminales, ejecuta un comando en un host o en una flota entera, mueve archivos por SFTP y gestiona hosts, fragmentos y credenciales. Instálalo con `npm install -g @termix-cli/cli` o coge un binario independiente. Consulta la [documentación del CLI](https://docs.termix.site/cli).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Seguridad:**
Las contraseñas, las claves y otros secretos se cifran por usuario, y los propios archivos de la base de datos se pueden cifrar en disco. Mira la [documentación](https://docs.termix.site/security) para saber cómo funciona.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Idiomas:** **Idiomas:**
Soporte integrado para aproximadamente 30 idiomas (gestionado por [Crowdin](https://docs.termix.site/translations)). Unos 30 idiomas incluidos, gestionados a través de [Crowdin](https://docs.termix.site/translations).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Uso compartido de sesion:**
Comparte una sesion en vivo de terminal, RDP, VNC o Telnet con otras personas en tiempo real. Comparte mediante un enlace (se une de forma anonima, sin necesidad de cuenta) o con un usuario especifico de Termix, y elige acceso de solo lectura o de lectura y escritura. Las comparticiones pueden expirar automaticamente o revocarse en cualquier momento, y el uso compartido de sesiones se puede activar globalmente o por host.
</td>
<td width="50%" valign="top">
**Aplicacion de escritorio independiente + sincronizacion bidireccional:**
La aplicacion de escritorio Electron funciona de forma totalmente independiente con su propio backend y base de datos locales, sin necesidad de servidor. Opcionalmente, conectala a un servidor Termix remoto para sincronizacion bidireccional automatica de hosts, credenciales, fragmentos y mas, y elige si las conexiones SSH se inician localmente o a traves del servidor remoto.
</td> </td>
</tr> </tr>
@@ -210,35 +252,38 @@ La aplicacion de escritorio Electron funciona de forma totalmente independiente
<br /> <br />
<details> <details>
<summary><b>Mas caracteristicas</b></summary> <summary><b>Más características</b></summary>
<br /> <br />
- **Dashboard** - Vea la informacion del servidor de un vistazo en su dashboard - **Panel** - Tus servidores de un vistazo, con tarjetas que colocas tú
- **Claves API** - Cree claves API con ambito de usuario y fechas de vencimiento para usar en automatizacion/CI - **Gráfico de red** - Tu homelab dibujado a partir de tus hosts, con estado en vivo
- **Exportacion/Importacion de Datos** - Exporte e importe hosts SSH, credenciales y datos del gestor de archivos - **Monitor de tmux** - Revisa sesiones, ventanas y paneles de tmux, con vista previa y búsqueda
- **Configuracion Automatica de SSL** - Generacion y gestion integrada de certificados SSL con redirecciones HTTPS - **Claves de API** - Claves por usuario con fecha de caducidad para scripts y CI
- **Interfaz Moderna** - Interfaz limpia compatible con escritorio/movil construida con React, Tailwind CSS y Shadcn. Elija entre muchos temas de UI diferentes, incluyendo claro, oscuro, Dracula, etc. Use rutas URL para abrir cualquier conexion en pantalla completa. - **Exportar e importar** - Mueve hosts, credenciales y datos del gestor de archivos
- **Historial de Comandos** - Autocompletado y visualizacion de comandos SSH ejecutados anteriormente - **SSL automático** - Certificados generados y renovados por ti, con redirección a HTTPS, o usa los tuyos
- **Conexion Rapida** - Conectese a un servidor sin necesidad de guardar los datos de conexion - **Bases de datos** - SQLite por defecto, y también PostgreSQL y MySQL
- **Paleta de Comandos** - Pulse dos veces la tecla Shift izquierda para acceder rapidamente a las conexiones SSH con su teclado - **Interfaz moderna** - Una interfaz React limpia que funciona en escritorio y móvil, con temas como claro, oscuro y Dracula. Cualquier conexión se puede abrir a pantalla completa desde una URL
- **Integracion con Proxmox** - Agregue automaticamente hosts a Termix desde su instancia de Proxmox - **Paleta de comandos** - Pulsa dos veces Mayús izquierda para ir a un host desde el teclado
- **SSH Rico en Funciones** - Soporta jump hosts, Warpgate, conexiones basadas en TOTP, SOCKS5, verificacion de clave de host, autocompletado de contrasenas, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, registro de terminal, reenvio de agente SSH, agente SSH de Bitwarden, firma SSH con HashiCorp Vault y mas. - **Atajos de teclado** - Moverte entre pestañas, cerrarlas y más, todo reasignable
- **Termix ID** - Un equivalente a sshid.io integrado en Termix. Reclame un identificador, publique sus claves publicas SSH en una URL de resolucion y use una CA integrada para emitir certificados SSH. - **Wake-on-LAN** - Enciende una máquina desde Termix o desde un paso de automatización
- **Proxy de confianza** - Deja que un proxy inverso gestione el acceso y pase al usuario
- **SSH muy completo** - Hosts de salto, Warpgate, peticiones TOTP, SOCKS5, verificación de claves de host, autorrelleno de contraseñas, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, registro del terminal, reenvío de agente, agente SSH de Bitwarden, firma SSH con HashiCorp Vault y más
- **Termix ID** - Una versión integrada de sshid.io. Reserva un identificador, publica tus claves públicas en una URL de resolución y emite certificados SSH desde la CA integrada
</details> </details>
<br /> <br />
## Soporte de Plataformas ## Plataformas compatibles
<table align="center"> <table align="center">
<tr> <tr>
<th align="center">Plataforma</th> <th align="center">Plataforma</th>
<th align="center">Distribucion</th> <th align="center">Distribución</th>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Web</b></td> <td align="center"><b>Web</b></td>
<td>Cualquier navegador moderno (Chrome, Safari, Firefox) · Soporte PWA</td> <td>Cualquier navegador moderno (Chrome, Safari, Firefox) · Compatible con PWA</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Windows</b> <sub>x64/ia32</sub></td> <td align="center"><b>Windows</b> <sub>x64/ia32</sub></td>
@@ -264,11 +309,11 @@ La aplicacion de escritorio Electron funciona de forma totalmente independiente
<br /> <br />
## Instalacion ## Instalación
Visite la [documentacion de Termix](https://docs.termix.site/install) para obtener instrucciones completas de instalacion en todas las plataformas. Visita la [documentación de Termix](https://docs.termix.site/install) para ver las instrucciones completas de instalación en todas las plataformas.
Archivo de ejemplo de Docker Compose (puede omitir `guacd` y la red si no planea usar las funciones de escritorio remoto): Ejemplo de archivo Docker Compose (puedes quitar `guacd` y la red si no piensas usar el escritorio remoto):
```yaml ```yaml
services: services:
@@ -305,11 +350,37 @@ networks:
driver: bridge driver: bridge
``` ```
### Línea de comandos
Termix también tiene un CLI, para que gestiones tus servidores desde un terminal y uses Termix en tus propios scripts.
```bash
npm install -g @termix-cli/cli
termix login --url https://termix.example.com
termix ssh 1
```
Puede abrir terminales, ejecutar un comando en un host o en una flota entera, mover archivos por SFTP y gestionar hosts, fragmentos y credenciales. La documentación completa está en [docs.termix.site/cli](https://docs.termix.site/cli).
### Alojamiento en la nube
Puedes ejecutar el servidor de Termix en un VPS en lugar de dentro de tu propia red. Si Termix corre en la red que gestiona, una caída se lo lleva por delante justo cuando lo necesitas para arreglar las cosas. Fuera se mantiene accesible, te da una IP fija y puedes entrar desde cualquier sitio sin VPN ni abrir puertos.
[GINERNET](https://docs.termix.site/install/ginernet) patrocina Termix, y la documentación tiene una guía paso a paso para desplegar en su plataforma de VPS.
<br />
## Telemetría
Termix envía una vez al día un pequeño aviso anónimo para que pueda ver cuántas instancias hay funcionando y qué funciones se usan. Contiene un identificador de instancia aleatorio, cuántos usuarios y hosts tienes, la versión de la aplicación y qué funciones (terminal, gestor de archivos, túneles, docker, etc.) se han usado en las últimas 24 horas. Nunca contiene nombres de usuario, nombres de host, direcciones IP, credenciales ni nada que te identifique a ti o a tus servidores.
Viene activado. Puedes desactivarlo en los ajustes de administración, en General, o poner `ENABLE_TELEMETRY=false` antes incluso de arrancar Termix.
<br /> <br />
## Donar ## Donar
Termix es gratuito y de codigo abierto, sin suscripciones ni planes de pago. Si lo encuentra util, considere donar para ayudar a cubrir los costos del servidor, los dominios y el tiempo de desarrollo. Las donaciones tambien ayudan a financiar el tiempo necesario para investigar y aprender lo que se necesita para construir funciones como soporte para SAML, Kubernetes y Agent. Siga el progreso y done a continuacion. Termix es gratuito y de código abierto, sin suscripciones ni planes de pago. Si te resulta útil, considera donar para ayudar con los servidores, los dominios y el tiempo de desarrollo. Las donaciones también financian el tiempo de investigar y aprender lo necesario para funciones como SAML, Kubernetes y el soporte de agentes. Sigue el progreso y dona abajo.
[Donar](https://donate.termix.site/) [Donar](https://donate.termix.site/)
@@ -317,7 +388,7 @@ Termix es gratuito y de codigo abierto, sin suscripciones ni planes de pago. Si
## Patrocinadores ## Patrocinadores
Interesado en un espacio patrocinado de pago para apoyar el desarrollo? Escriba a [mail@termix.site](mailto:mail@termix.site). ¿Te interesa un espacio de pago para apoyar el desarrollo? Escribe a [mail@termix.site](mailto:mail@termix.site).
<div align="center"> <div align="center">
@@ -339,10 +410,6 @@ Interesado en un espacio patrocinado de pago para apoyar el desarrollo? Escriba
<img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" /> <img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" />
</a> </a>
&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;
<a href="https://tailscale.com/">
<img src="https://drive.google.com/uc?export=view&id=1lIxkJuX6M23bW-2FElhT0rQieTrzaVSL" height="40" alt="Tailscale" />
</a>
&nbsp;&nbsp;&nbsp;
<a href="https://akamai.com/"> <a href="https://akamai.com/">
<img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" /> <img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" />
</a> </a>
@@ -354,18 +421,21 @@ Interesado en un espacio patrocinado de pago para apoyar el desarrollo? Escriba
<a href="https://rackgenius.com/"> <a href="https://rackgenius.com/">
<img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" /> <img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" />
</a> </a>
&nbsp;&nbsp;&nbsp;
<a href="https://ginernet.com/">
<img src="https://ginernet.com/img/logo-web.png" height="40" alt="Ginernet" />
</a>
</div> </div>
<br /> <br />
## Soporte ## Soporte
Si necesita ayuda o desea solicitar una funcion para Termix, visite la pagina de [Issues](https://github.com/Termix-SSH/Support/issues), inicie sesion y pulse `New Issue`. Por favor, sea lo mas detallado posible en su reporte, preferiblemente escrito en ingles. Tambien puede unirse al servidor de [Discord](https://discord.gg/jVQGdvHDrf) y visitar el canal de soporte, sin embargo, los tiempos de respuesta pueden ser mas largos. ¿Necesitas ayuda o quieres pedir una función? Abre una [nueva incidencia](https://github.com/Termix-SSH/Support/issues) y añade todo el detalle que puedas, en inglés si te es posible. También puedes preguntar en el canal de soporte de [Discord](https://discord.gg/jVQGdvHDrf), aunque allí las respuestas pueden tardar más.
<br /> <br />
## Capturas de Pantalla ## Capturas de pantalla
<div align="center"> <div align="center">
@@ -373,7 +443,7 @@ Si necesita ayuda o desea solicitar una funcion para Termix, visite la pagina de
[![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos) [![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos)
<sub>Ver resúmenes de actualizaciones en YouTube</sub> <sub>Mira los resúmenes de las actualizaciones en YouTube</sub>
<br /> <br />
<br /> <br />
@@ -413,18 +483,18 @@ Si necesita ayuda o desea solicitar una funcion para Termix, visite la pagina de
</tr> </tr>
</table> </table>
<sub>Algunos videos e imagenes pueden estar desactualizados o no mostrar perfectamente las caracteristicas.</sub> <sub>Algunos vídeos e imágenes pueden estar desactualizados o no mostrar del todo bien las funciones.</sub>
</div> </div>
<br /> <br />
## Caracteristicas Planeadas ## Características planeadas
Consulte [Proyectos](https://github.com/orgs/Termix-SSH/projects/5) para todas las caracteristicas planeadas. Si desea contribuir, consulte [Contribuir](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md). Todas las funciones planeadas están en [Projects](https://github.com/orgs/Termix-SSH/projects/5). Si quieres colaborar, consulta [Contributing](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md).
<br /> <br />
## Licencia ## Licencia
Distribuido bajo la Licencia Apache Version 2.0. Consulte `LICENSE` para mas informacion. Distribuido bajo la Licencia Apache versión 2.0. Consulta `LICENSE` para más información.
+159 -89
View File
@@ -4,7 +4,7 @@
<h1>Termix</h1> <h1>Termix</h1>
<p>Gestion SSH auto-hebergee et acces bureau a distance</p> <p>Gestion de serveurs auto-hébergée, du SSH au bureau à distance jusqu'aux automatisations</p>
<p> <p>
<a href="../README.md">English</a> · <a href="../README.md">English</a> ·
@@ -37,7 +37,7 @@
<br /> <br />
Termix est gratuit et open source. Si vous le trouvez utile, pensez à [faire un don](https://donate.termix.site/) pour aider à couvrir les coûts de serveur et le temps de développement. Termix est gratuit et open source. S'il vous est utile, pensez à [faire un don](https://donate.termix.site/) pour aider à payer les serveurs et le temps de développement.
<br /> <br />
@@ -56,152 +56,194 @@ Termix est gratuit et open source. Si vous le trouvez utile, pensez à [faire un
<br /> <br />
## Presentation ## Présentation
Termix est une plateforme de gestion de serveurs tout-en-un, open source, a jamais gratuite et auto-hebergee. Elle fournit une solution multiplateforme pour gerer vos serveurs et votre infrastructure a travers une interface unique et intuitive. Termix offre un acces terminal SSH, le controle de bureau a distance (RDP, VNC, Telnet), des capacites de tunneling SSH, la gestion de fichiers SSH a distance et de nombreux autres outils. Termix est l'alternative parfaite, gratuite et auto-hebergee a Termius, disponible sur toutes les plateformes. Termix est une plateforme gratuite, open source et auto-hébergée pour gérer vos serveurs. Elle réunit au même endroit les terminaux SSH, les bureaux à distance (RDP, VNC, Telnet), les transferts de fichiers, les tunnels, Docker, les métriques et les automatisations, sur le web, le bureau et le mobile. C'est une alternative auto-hébergée à Termius, gratuite pour toujours.
<br /> <br />
## Fonctionnalites ## Fonctionnalités
<table> <table>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Acces terminal SSH:** **Terminal SSH:**
Terminal complet avec support d'ecran partage (jusqu'a 4 panneaux) et un systeme d'onglets inspire des navigateurs. Inclut la personnalisation du terminal avec des themes courants, des polices et d'autres composants. Un vrai terminal avec des onglets façon navigateur et un écran divisé, jusqu'à 6 panneaux à la fois. Choisissez votre thème, votre police et vos couleurs. Une barre d'outils au-dessus de chaque session affiche le CPU, la mémoire et le disque en direct, avec des raccourcis vers les fichiers, Docker, les tunnels et les métriques de cet hôte.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Acces Bureau a Distance:** **Bureau à distance:**
Support RDP, VNC et Telnet via navigateur avec personnalisation complete et ecran partage. RDP, VNC et Telnet dans le navigateur, en onglets et en écran divisé comme n'importe quelle autre session. Comprend un explorateur de fichiers pour les lecteurs RDP et l'envoi par glisser-déposer. Sur le bureau Windows, vous pouvez aussi ouvrir un hôte dans le client RDP natif.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gestion des tunnels SSH:** **Tunnels SSH:**
Creez et gerez des tunnels SSH de serveur a serveur avec reconnexion automatique, surveillance de l'etat et transfert local, distant ou SOCKS dynamique. Les parametres de tunnel client-bureau-vers-serveur sont stockes localement par installation bureau ; des instantanes de prereglages C2S optionnels peuvent etre sauvegardes sur le serveur, renommes, charges ou supprimes pour deplacer une configuration de tunnel locale entre clients. Redirection locale, distante et SOCKS dynamique, avec reconnexion automatique et vérification de l'état. Les tunnels client vers serveur de l'application de bureau restent sur cette machine, et vous pouvez enregistrer des préréglages sur le serveur pour reprendre une configuration sur un autre poste.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gestionnaire de fichiers distant:** **Gestionnaire de fichiers:**
Gerez les fichiers directement sur les serveurs distants avec support de la visualisation et de l'edition de code, images, audio et video. Televersez, telechargez, renommez, supprimez et deplacez des fichiers de maniere fluide avec support sudo. Inclut la prise en charge du deplacement de fichiers de serveur a serveur. Parcourez, modifiez, envoyez, téléchargez, renommez, déplacez et supprimez des fichiers en SFTP, avec sudo. Affichez et modifiez du code, des images, de l'audio et de la vidéo. Copiez des fichiers directement d'un serveur à l'autre : le chemin le plus rapide est choisi pour vous et l'intégrité des transferts est vérifiée.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gestion Docker et Podman:** **Docker et Podman:**
Demarrez, arretez, mettez en pause, supprimez des conteneurs. Consultez les statistiques des conteneurs. Controlez les conteneurs via le terminal docker exec. Compatible avec Docker et Podman comme environnement d'execution de conteneurs. Non concu pour remplacer Portainer ou Dockge, mais plutot pour gerer simplement vos conteneurs plutot que de les creer. Démarrez, arrêtez, mettez en pause et supprimez des conteneurs, suivez leurs statistiques et ouvrez un shell à l'intérieur. Fonctionne avec Docker comme avec Podman. Le but n'est pas de remplacer Portainer ou Dockge, juste de gérer les conteneurs que vous avez déjà.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gestionnaire d'hotes SSH:** **Gestionnaire d'hôtes:**
Enregistrez, organisez et gerez vos connexions SSH avec des tags et des dossiers (personnalisation des dossiers et prise en charge des dossiers imbriques), et sauvegardez facilement les informations de connexion reutilisables tout en automatisant le deploiement des cles SSH. Rangez vos hôtes avec des étiquettes et des dossiers imbriqués que vous pouvez nommer et colorer. Réutilisez des identifiants enregistrés sur plusieurs hôtes, déployez des clés SSH automatiquement, regroupez des hôtes sous un hôte parent, modifiez et exportez en lot, et utilisez la connexion rapide pour les connexions ponctuelles que vous ne voulez pas garder.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Metriques d'hote:** **Métriques des hôtes:**
Visualisez l'utilisation du CPU, de la memoire, du disque, le reseau, le temps de fonctionnement, les informations systeme, le pare-feu, le moniteur de ports, le visualiseur de journaux, les utilisateurs/permissions, les certificats et bien plus encore sur la plupart des serveurs Linux. Inclut des graphiques d'historique en serie temporelle et des alertes basees sur des seuils avec support ntfy et webhook. CPU, mémoire, disque, seau, température, temps de fonctionnement, processus, ports, connexions et informations système sur la plupart des serveurs Linux, avec des graphiques d'historique. Les cartes de gestion vous permettent de gérer les services, les tâches cron, les paquets, les utilisateurs, les règles de pare-feu, WireGuard, Tailscale, les certificats SSL, les journaux et les vérifications d'état sans quitter Termix.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Authentification des utilisateurs:** **Automatisations:**
Gestion securisee des utilisateurs avec controles administrateur (peut modifier les informations des autres utilisateurs) et support OIDC/LDAP/SSO (avec controle d'acces), 2FA (TOTP), et support des passkeys (WebAuthn). Visualisez les sessions utilisateur actives sur toutes les plateformes et revoquez les permissions. Liez vos comptes OIDC/locaux ensemble. Consultez le journal d'audit des actions de tous les utilisateurs. Choisissez un déclencheur, puis dites ce qui doit se passer. Les déclencheurs peuvent être une métrique qui dépasse un seuil, un hôte qui tombe ou revient, une vérification d'état qui change, un horaire, un événement de conteneur ou un webhook entrant. Les étapes peuvent lancer des commandes et des extraits, piloter des conteneurs et des tunnels, réveiller un hôte, appeler une URL, attendre, se diviser selon une condition, lancer une autre automatisation et vous prévenir via ntfy, Discord ou un webhook. Les essais à blanc vous permettent de tester sans risque.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Integration Tailscale:** **Flottes:**
Listez les appareils de votre reseau Tailscale pour les ajouter rapidement comme hotes, et connectez-vous en utilisant Tailscale SSH comme methode d'authentification, laissant les ACL de votre reseau gerer l'autorisation sans stocker de credentials. Regroupez des hôtes dans une flotte en les choisissant ou avec des règles d'étiquettes, pour que les nouveaux hôtes s'ajoutent tout seuls. Lancez une commande sur tous les hôtes d'un coup, envoyez et récupérez des fichiers sur l'ensemble, installez des paquets et collectez un inventaire de l'OS, du noyau, de l'architecture et du temps de fonctionnement.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**RBAC/Partage:** **Assistant IA:**
Creez des roles et partagez des hotes entre utilisateurs/roles. Prend en charge tous les types d'authentification et tous les protocoles d'hote. Optionnel, et désactivé tant que vous ne l'activez pas. Connectez OpenAI, Anthropic, Gemini, Ollama ou n'importe quel point d'accès compatible OpenAI et posez des questions sur votre installation. Il lit les hôtes, les flottes, les extraits et les alertes, et propose des changements que vous validez au lieu de les appliquer lui-même. Il ne peut jamais toucher aux identifiants, aux utilisateurs ni aux réglages. Les administrateurs peuvent le laisser désactivé pour toute l'instance, et vous pouvez le masquer pendant la configuration.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Connexions Serie:** **Connexion et utilisateurs:**
Connectez-vous a des appareils serie (routeurs, commutateurs, microcontroleurs, etc.) directement depuis le navigateur ou l'application bureau. Configurez le debit en bauds, les bits de donnees, les bits d'arret et la parite. Utilise l'API Web Serial dans les navigateurs compatibles ou un backend natif dans l'application Electron. Comptes locaux ainsi que connexion OIDC, LDAP, GitHub et Google, avec double authentification (TOTP), clés d'accès (WebAuthn) et appareils de confiance. Les administrateurs peuvent gérer les utilisateurs, associer les groupes OIDC aux rôles, voir toutes les sessions actives sur toutes les plateformes et les révoquer. Reliez vos comptes local et OIDC, et consultez le journal d'audit de ce que chacun a fait.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Rôles et partage:**
Créez des rôles et partagez des hôtes avec des utilisateurs ou des rôles selon quatre niveaux : connexion, lecture, modification et gestion. Cela fonctionne avec tous les types d'authentification et tous les protocoles, et vous pouvez remplacer les identifiants utilisés pour un hôte partagé.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Alertes:** **Alertes:**
Definissez des regles d'alerte basees sur des seuils pour les metriques d'hote (CPU, memoire, disque, etc.) et recevez des notifications via ntfy ou webhooks lorsqu'elles se declenchent. Consultez les alertes actives et resolues dans un journal d'historique. Définissez des règles sur les métriques des hôtes comme le CPU, la mémoire et le disque, et recevez une notification via ntfy, Discord ou un webhook quand elles se déclenchent. Consultez les alertes en cours et résolues dans un historique, et écartez celles qui ne vous intéressent pas.
</td> </td>
</tr>
<tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Page d'accueil:** **Page d'accueil:**
Une page d'accueil entierement personnalisable avec une grille de widgets glisser-deposer. Ajoutez des widgets pour l'etat des hotes, les liens de services, les horloges, les notes, les flux RSS, la meteo, les conteneurs Docker, les graphiques de metriques d'hote, les terminaux integres, les iframes et plus encore. Une grille de widgets en glisser-déposer que vous construisez vous-même. Des widgets pour l'état des hôtes, les pings, les liens de services, les favoris, la recherche, les horloges, les calendriers, les comptes à rebours, les notes, les flux RSS, la météo, les images, les iframes, Docker, les tunnels, les graphiques de métriques, les API personnalisées et même un terminal en direct.
</td>
<td width="50%" valign="top">
**Chiffrement de la base de donnees:**
Le backend est stocke sous forme de fichiers de base de donnees SQLite chiffres. Consultez la [documentation](https://docs.termix.site) pour plus de details.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Graphe reseau:** **Extraits et outils:**
Personnalisez votre tableau de bord pour visualiser votre homelab base sur vos connexions SSH avec support des statuts. Enregistrez les commandes que vous lancez souvent et exécutez-les en un clic, avec des variables pour l'hôte et vos propres saisies. Lancez une même commande dans tous les terminaux ouverts, et cherchez dans votre historique avec la complétion automatique.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Outils SSH:** **Partage de session:**
Creez des extraits de commandes reutilisables executables en un seul clic. Executez une commande simultanement sur plusieurs terminaux ouverts. Partagez en direct une session terminal, RDP, VNC ou Telnet. Envoyez un lien que n'importe qui peut rejoindre sans compte, ou partagez avec un utilisateur Termix précis, en lecture seule ou en lecture-écriture. Les partages peuvent expirer d'eux-mêmes ou être révoqués, et se désactivent globalement ou hôte par hôte.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Onglets Persistants:** **Enregistrement et journaux de session:**
Les sessions SSH et les onglets restent ouverts sur tous les appareils/actualisations si active dans le profil utilisateur. Enregistrez les sessions terminal, RDP et VNC pour les revoir plus tard. Téléchargez les journaux d'une session en texte simple, et consultez le journal de connexion pour voir exactement ce qui s'est passé pendant une connexion.
</td>
<td width="50%" valign="top">
**Connexions série:**
Dialoguez avec des appareils série comme des routeurs, des commutateurs et des microcontrôleurs depuis le navigateur ou l'application de bureau. Réglez la vitesse, les bits de données, les bits d'arrêt et la parité. Utilise l'API Web Serial dans les navigateurs compatibles, ou un backend natif dans l'application de bureau.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Tailscale:**
Récupérez les appareils de votre tailnet pour les ajouter comme hôtes en quelques clics, et connectez-vous avec Tailscale SSH pour que les ACL de votre tailnet gèrent les accès, sans stocker d'identifiants. Headscale et les points d'accès personnalisés fonctionnent aussi.
</td>
<td width="50%" valign="top">
**Proxmox:**
Importez des hôtes directement depuis une instance Proxmox, et suivez les statistiques des nœuds et des invités, dont le CPU, la mémoire et le stockage, dans un onglet dédié.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Espaces de travail et onglets:**
Enregistrez un ensemble d'onglets avec leur disposition en écran divisé et rouvrez le tout en un clic. Termix retient aussi votre dernière session, donc vos onglets reviennent après un rafraîchissement ou sur un autre appareil.
</td>
<td width="50%" valign="top">
**Configuration guidée:**
Une courte configuration vous aide à choisir un préréglage d'interface, votre thème, les fonctionnalités que vous voulez et votre premier hôte. Le mode simple masque ce que vous n'utilisez pas, et vous pouvez relancer la configuration ou changer de préréglage quand vous voulez.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Application de bureau autonome et synchronisation:**
L'application de bureau fonctionne toute seule, avec son propre backend et sa base de données, sans serveur. Vous pouvez aussi la relier à un serveur Termix pour synchroniser dans les deux sens les hôtes, les identifiants, les extraits et le reste, et choisir si les connexions partent de votre machine ou passent par le serveur.
</td>
<td width="50%" valign="top">
**Ligne de commande:**
Un CLI `termix` pour votre shell et vos scripts. Ouvrez des terminaux, lancez une commande sur un hôte ou une flotte entière, déplacez des fichiers en SFTP et gérez hôtes, extraits et identifiants. Installez-le avec `npm install -g @termix-cli/cli` ou récupérez un binaire autonome. Voir la [documentation du CLI](https://docs.termix.site/cli).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Sécurité:**
Les mots de passe, les clés et les autres secrets sont chiffrés par utilisateur, et les fichiers de base de données eux-mêmes peuvent être chiffrés sur le disque. Voir la [documentation](https://docs.termix.site/security) pour le détail.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Langues:** **Langues:**
Support integre d'environ 30 langues (gere par [Crowdin](https://docs.termix.site/translations)). Une trentaine de langues intégrées, gérées via [Crowdin](https://docs.termix.site/translations).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Partage de session:**
Partagez une session de terminal, RDP, VNC ou Telnet en direct avec d'autres personnes en temps reel. Partagez via un lien (rejoint anonymement, sans compte necessaire) ou avec un utilisateur Termix specifique, et choisissez un acces en lecture seule ou en lecture-ecriture. Les partages peuvent expirer automatiquement ou etre revoques a tout moment, et le partage de session peut etre active globalement ou par hote.
</td>
<td width="50%" valign="top">
**Application de bureau autonome + synchronisation bidirectionnelle:**
L'application de bureau Electron fonctionne de maniere totalement autonome avec son propre backend et sa propre base de donnees locale, sans serveur requis. Connectez-la eventuellement a un serveur Termix distant pour une synchronisation bidirectionnelle automatique des hotes, des identifiants, des extraits de code et plus encore, et choisissez si les connexions SSH sont demarrees localement ou via le serveur distant.
</td> </td>
</tr> </tr>
@@ -210,26 +252,29 @@ L'application de bureau Electron fonctionne de maniere totalement autonome avec
<br /> <br />
<details> <details>
<summary><b>Plus de fonctionnalites</b></summary> <summary><b>Plus de fonctionnalités</b></summary>
<br /> <br />
- **Tableau de bord** - Consultez les informations de vos serveurs en un coup d'oeil depuis votre tableau de bord - **Tableau de bord** - Vos serveurs en un coup d'œil, avec des cartes que vous rangez vous-même
- **Cles API** - Creez des cles API a portee utilisateur avec des dates d'expiration pour une utilisation en automatisation/CI - **Graphe réseau** - Votre homelab dessiné à partir de vos hôtes, avec l'état en direct
- **Export/Import de donnees** - Exportez et importez les hotes SSH, les identifiants et les donnees du gestionnaire de fichiers - **Moniteur tmux** - Parcourez les sessions, fenêtres et panneaux tmux, avec aperçus et recherche
- **Configuration SSL automatique** - Generation et gestion integrees de certificats SSL avec redirections HTTPS - **Clés API** - Des clés par utilisateur avec date d'expiration, pour vos scripts et votre CI
- **Interface moderne** - Interface epuree compatible desktop/mobile construite avec React, Tailwind CSS et Shadcn. Choisissez parmi de nombreux themes d'interface utilisateur, notamment clair, sombre, Dracula, etc. Utilisez les routes URL pour ouvrir n'importe quelle connexion en plein ecran. - **Export et import** - Faites entrer et sortir hôtes, identifiants et données du gestionnaire de fichiers
- **Historique des commandes** - Auto-completion et consultation des commandes SSH precedemment executees - **SSL automatique** - Certificats générés et renouvelés pour vous, avec redirection HTTPS, ou apportez les vôtres
- **Connexion rapide** - Connectez-vous a un serveur sans avoir a sauvegarder les donnees de connexion - **Bases de données** - SQLite par défaut, PostgreSQL et MySQL également pris en charge
- **Palette de commandes** - Appuyez deux fois sur Shift gauche pour acceder rapidement aux connexions SSH avec votre clavier - **Interface moderne** - Une interface React soignée qui marche sur ordinateur et mobile, avec des thèmes clair, sombre et Dracula. Chaque connexion peut s'ouvrir en plein écran depuis une URL
- **Integration Proxmox** - Ajoutez automatiquement des hotes dans Termix depuis votre instance Proxmox - **Palette de commandes** - Double appui sur Maj gauche pour rejoindre un hôte au clavier
- **SSH riche en fonctionnalites** - Support des hotes de rebond, Warpgate, connexions basees sur TOTP, SOCKS5, verification des cles d'hote, remplissage automatique des mots de passe, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, journalisation du terminal, transfert d'agent SSH, agent SSH Bitwarden, signature SSH HashiCorp Vault, et plus encore. - **Raccourcis clavier** - Naviguer entre les onglets, les fermer et plus encore, tout est reconfigurable
- **Termix ID** - Un equivalent de sshid.io integre a Termix. Reservez un identifiant, publiez vos cles SSH publiques a une URL de resolution, et utilisez une autorite de certification integree pour emettre des certificats SSH. - **Wake-on-LAN** - Réveillez une machine depuis Termix ou depuis une étape d'automatisation
- **Authentification par proxy de confiance** - Laissez un reverse proxy gérer la connexion et transmettre l'utilisateur
- **SSH complet** - Hôtes de rebond, Warpgate, demandes TOTP, SOCKS5, vérification des clés d'hôte, remplissage automatique des mots de passe, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, journalisation du terminal, transfert d'agent, agent SSH Bitwarden, signature SSH HashiCorp Vault et plus encore
- **Termix ID** - Une version intégrée de sshid.io. Réservez un identifiant, publiez vos clés publiques sur une URL de résolution et émettez des certificats SSH depuis l'autorité intégrée
</details> </details>
<br /> <br />
## Support des plateformes ## Plateformes prises en charge
<table align="center"> <table align="center">
<tr> <tr>
@@ -238,11 +283,11 @@ L'application de bureau Electron fonctionne de maniere totalement autonome avec
</tr> </tr>
<tr> <tr>
<td align="center"><b>Web</b></td> <td align="center"><b>Web</b></td>
<td>Tout navigateur moderne (Chrome, Safari, Firefox) · Support PWA</td> <td>Tout navigateur récent (Chrome, Safari, Firefox) · Compatible PWA</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Windows</b> <sub>x64/ia32</sub></td> <td align="center"><b>Windows</b> <sub>x64/ia32</sub></td>
<td>Portable · MSI Installateur · Chocolatey</td> <td>Portable · Installeur MSI · Chocolatey</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Linux</b> <sub>x64/ia32</sub></td> <td align="center"><b>Linux</b> <sub>x64/ia32</sub></td>
@@ -266,9 +311,9 @@ L'application de bureau Electron fonctionne de maniere totalement autonome avec
## Installation ## Installation
Visitez la [documentation](https://docs.termix.site/install) de Termix pour des instructions d'installation completes sur toutes les plateformes. Consultez la [documentation Termix](https://docs.termix.site/install) pour les instructions d'installation complètes sur toutes les plateformes.
Voici un exemple de fichier Docker Compose (vous pouvez omettre guacd et le reseau si vous ne prevoyez pas d'utiliser les fonctionnalites de bureau a distance) : Exemple de fichier Docker Compose (vous pouvez retirer `guacd` et le réseau si vous ne comptez pas utiliser le bureau à distance) :
```yaml ```yaml
services: services:
@@ -305,11 +350,37 @@ networks:
driver: bridge driver: bridge
``` ```
### Ligne de commande
Termix propose aussi un CLI, pour gérer vos serveurs depuis un terminal et utiliser Termix dans vos propres scripts.
```bash
npm install -g @termix-cli/cli
termix login --url https://termix.example.com
termix ssh 1
```
Il peut ouvrir des terminaux, lancer une commande sur un hôte ou une flotte entière, déplacer des fichiers en SFTP et gérer hôtes, extraits et identifiants. La documentation complète est sur [docs.termix.site/cli](https://docs.termix.site/cli).
### Hébergement cloud
Vous pouvez faire tourner le serveur Termix sur un VPS plutôt que dans votre propre réseau. Si Termix tourne sur le réseau qu'il gère, une panne l'emporte avec elle, juste au moment où vous en avez besoin pour réparer. Ailleurs, il reste joignable, vous avez une IP fixe et vous pouvez y accéder de partout sans VPN ni redirection de port.
[GINERNET](https://docs.termix.site/install/ginernet) sponsorise Termix, et la documentation contient un guide pas à pas pour déployer sur leur plateforme VPS.
<br />
## Télémétrie
Termix envoie une fois par jour un petit signal anonyme, pour que je puisse voir combien d'instances tournent et quelles fonctionnalités servent vraiment. Il contient un identifiant d'instance aléatoire, le nombre d'utilisateurs et d'hôtes, la version de l'application et les fonctionnalités utilisées ces dernières 24 heures (terminal, gestionnaire de fichiers, tunnels, docker, etc.). Il ne contient jamais de noms d'utilisateur, de noms d'hôtes, d'adresses IP, d'identifiants ni quoi que ce soit qui puisse vous identifier, vous ou vos serveurs.
C'est activé par défaut. Désactivez-le dans les paramètres d'administration, section Général, ou définissez `ENABLE_TELEMETRY=false` avant même de démarrer Termix.
<br /> <br />
## Faire un don ## Faire un don
Termix est gratuit et open source, sans abonnement ni plan payant. Si vous le trouvez utile, pensez a faire un don pour aider a couvrir les couts de serveur, les domaines et le temps de developpement. Les dons contribuent egalement a financer le temps necessaire pour rechercher et apprendre ce qui est requis pour construire des fonctionnalites comme SAML, Kubernetes et le support des agents. Suivez la progression et faites un don ci-dessous. Termix est gratuit et open source, sans abonnement ni offre payante. S'il vous est utile, pensez à faire un don pour aider à couvrir les serveurs, les noms de domaine et le temps de développement. Les dons financent aussi le temps de recherche nécessaire pour construire des fonctionnalités comme SAML, Kubernetes et le support des agents. Suivez l'avancement et faites un don ci-dessous.
[Faire un don](https://donate.termix.site/) [Faire un don](https://donate.termix.site/)
@@ -317,7 +388,7 @@ Termix est gratuit et open source, sans abonnement ni plan payant. Si vous le tr
## Sponsors ## Sponsors
Interesse par un placement payant pour soutenir le developpement ? Envoyez un email a [mail@termix.site](mailto:mail@termix.site). Intéressé par un emplacement payant pour soutenir le développement ? Écrivez à [mail@termix.site](mailto:mail@termix.site).
<div align="center"> <div align="center">
@@ -339,10 +410,6 @@ Interesse par un placement payant pour soutenir le developpement ? Envoyez un em
<img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" /> <img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" />
</a> </a>
&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;
<a href="https://tailscale.com/">
<img src="https://drive.google.com/uc?export=view&id=1lIxkJuX6M23bW-2FElhT0rQieTrzaVSL" height="40" alt="Tailscale" />
</a>
&nbsp;&nbsp;&nbsp;
<a href="https://akamai.com/"> <a href="https://akamai.com/">
<img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" /> <img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" />
</a> </a>
@@ -354,18 +421,21 @@ Interesse par un placement payant pour soutenir le developpement ? Envoyez un em
<a href="https://rackgenius.com/"> <a href="https://rackgenius.com/">
<img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" /> <img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" />
</a> </a>
&nbsp;&nbsp;&nbsp;
<a href="https://ginernet.com/">
<img src="https://ginernet.com/img/logo-web.png" height="40" alt="Ginernet" />
</a>
</div> </div>
<br /> <br />
## Support ## Support
Si vous avez besoin d'aide ou souhaitez demander une fonctionnalite pour Termix, visitez la page [Issues](https://github.com/Termix-SSH/Support/issues), connectez-vous et appuyez sur `New Issue`. Veuillez etre aussi detaille que possible dans votre issue, de preference redigee en anglais. Vous pouvez egalement rejoindre le serveur [Discord](https://discord.gg/jVQGdvHDrf) et visiter le canal de support, cependant les temps de reponse peuvent etre plus longs. Besoin d'aide ou envie de proposer une fonctionnalité ? Ouvrez un [nouveau ticket](https://github.com/Termix-SSH/Support/issues) avec le plus de détails possible, en anglais si vous le pouvez. Vous pouvez aussi demander dans le canal support sur [Discord](https://discord.gg/jVQGdvHDrf), même si les réponses y prennent parfois plus de temps.
<br /> <br />
## Captures d'ecran ## Captures d'écran
<div align="center"> <div align="center">
@@ -373,7 +443,7 @@ Si vous avez besoin d'aide ou souhaitez demander une fonctionnalite pour Termix,
[![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos) [![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos)
<sub>Regarder les aperçus des mises a jour sur YouTube</sub> <sub>Regarder les présentations des mises à jour sur YouTube</sub>
<br /> <br />
<br /> <br />
@@ -413,18 +483,18 @@ Si vous avez besoin d'aide ou souhaitez demander une fonctionnalite pour Termix,
</tr> </tr>
</table> </table>
<sub>Certaines videos et images peuvent etre obsoletes ou ne pas presenter parfaitement les fonctionnalites.</sub> <sub>Certaines vidéos et images peuvent être dépassées ou ne pas montrer parfaitement les fonctionnalités.</sub>
</div> </div>
<br /> <br />
## Fonctionnalites prevues ## Fonctionnalités prévues
Consultez les [Projects](https://github.com/orgs/Termix-SSH/projects/5) pour toutes les fonctionnalites prevues. Si vous souhaitez contribuer, consultez [Contributing](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md). Toutes les fonctionnalités prévues sont dans [Projects](https://github.com/orgs/Termix-SSH/projects/5). Si vous souhaitez contribuer, voir [Contribuer](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md).
<br /> <br />
## Licence ## Licence
Distribue sous la licence Apache Version 2.0. Consultez `LICENSE` pour plus d'informations. Distribué sous licence Apache version 2.0. Voir `LICENSE` pour plus d'informations.
+152 -82
View File
@@ -4,7 +4,7 @@
<h1>Termix</h1> <h1>Termix</h1>
<p>स्व-होस्टेड SSH प्रबंधन और रिमोट डेस्कटॉप एक्सेस</p> <p>सेल्फ-होस्टेड सर्वर प्रबंधन, SSH और रिमोट डेस्कटॉप से लेकर ऑटोमेशन तक</p>
<p> <p>
<a href="../README.md">English</a> · <a href="../README.md">English</a> ·
@@ -37,7 +37,7 @@
<br /> <br />
Termix मुफ़्त और ओपन सोर्स है। यदि आपको यह उपयोगी लगता है, तो सर्वर लागत और विकास समय में मदद के लिए [दान करें](https://donate.termix.site/)। Termix मुफ़्त और ओपन सोर्स है। अगर यह आपके काम आता है, तो सर्वर की लागत और विकास के समय में मदद के लिए [दान](https://donate.termix.site/) करने पर विचार करें
<br /> <br />
@@ -49,7 +49,7 @@ Termix मुफ़्त और ओपन सोर्स है। यदि
<p> <p>
<img src="../repo-images/Repo of the Day.png" alt="Repo of the Day Achievement" width="280" /> <img src="../repo-images/Repo of the Day.png" alt="Repo of the Day Achievement" width="280" />
<br /> <br />
<sub>1 सितंबर, 2025 को प्राप्त</sub> <sub>1 सितंबर 2025 को हासिल किया गया</sub>
</p> </p>
</div> </div>
@@ -58,7 +58,7 @@ Termix मुफ़्त और ओपन सोर्स है। यदि
## अवलोकन ## अवलोकन
Termix एक ओपन-सोर्स, हमेशा के लिए मुफ़्त, सेल्फ-होस्टेड ऑल-इन-वन सर्वर प्रबंधन प्लेटफ़ॉर्म है। यह एक एकल, सहज इंटरफ़ेस के माध्यम से आपके सर्वर और बुनियादी ढाँचे के प्रबंधन के लिए एक मल्टी-प्लेटफ़ॉर्म समाधान प्रदान करता है। Termix SSH टर्मिनल एक्सेस, रिमोट डेस्कटॉप कंट्रोल (RDP, VNC, Telnet), SSH टनलिंग क्षमताएँ, रिमोट फ़ाइल ्रबंधन, और कई अन्य उपकरण प्रदान करता है। Termix सभी प्लेटफ़ॉर्म पर उपलब्ध Termius का सही मुफ़्त और सेल्फ-होस्टेड विकल्प है Termix आपके सर्वर संभालने के लिए एक मुफ़्त, ओपन सोर्स, सेल्फ-होस्टेड प्लेटफ़ॉर्म है। यह SSH टर्मिनल, रिमोट डेस्कटॉप (RDP, VNC, Telnet), फ़ाइल ्रांसफ़र, टनल, Docker, मेट्रिक्स और ऑटोमेशन को एक ही जगह लाता है, वेब, डेस्कटॉप और मोबाइल पर। यह Termius का सेल्फ-होस्टेड विकल्प है जो हमेशा मुफ़्त रहेगा
<br /> <br />
@@ -68,42 +68,42 @@ Termix एक ओपन-सोर्स, हमेशा के लिए मु
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH टर्मिनल एक्सेस:** **SSH टर्मिनल:**
ब्राउज़र जैस टैब प्रणाली के साथ स्प्लिट-स्क्रीन सपोर्ट (4 पैनल तक) वाला पूर्ण-विशेषता वाला टर्मिनल। इसमें लोकप्रिय टर्मिनल थीम, फ़ॉन्ट और अन्य कंपोनेंट सहित टर्मिनल को कस्टमाइज़ करने का सपोर्ट शामिल है ब्राउज़र जैस टैब और स्प्लिट स्क्रीन वाला पूरा टर्मिनल, एक साथ 6 पैनल तक। थीम, फ़ॉन्ट और रंग आप खुद चुनें। हर सत्र के ऊपर एक टूलबार रहता है जिसमें CPU, मेमोरी और डिस्क लाइव दिखते हैं, साथ ही उस होस्ट की फ़ाइलों, Docker, टनल और मेट्रिक्स तक जाने के शॉर्टकट भी
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**रिमोट डेस्कटॉप एक्सेस:** **रिमोट डेस्कटॉप:**
ब्राउज़र पर RDP, VNC और Telnet सपोर्ट, पूर्ण कस्टमाइज़ेशन और स्प्लिट स्क्रीन के साथ ब्राउज़र में RDP, VNC और Telnet, बाकी सत्रों की तरह टैब और स्प्लिट स्क्रीन में। इसमें RDP ड्राइव के लिए फ़ाइल ब्राउज़र और खींचकर छोड़ने वाला अपलोड भी है। Windows डेस्कटॉप पर आप होस्ट को सिस्टम के अपने RDP क्लाइंट में भी खोल सकते हैं
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH टनल प्रबंधन:** **SSH टनल:**
ऑटोमैटिक रीकनेक्शन, हेल्थ मॉनिटरिंग और लोकल, रिमोट या डायनमिक SOCKS फॉरवर्डिंग के साथ सर्वर-टु-सर्वर SSH टनल बनाएँ और प्रबंधित करें। डेस्कटॉप क्लाइंट-टु-सर्वर टनल सेटिंग्स प्रत्येक डेस्कटॉप इंस्टॉल में स्थानीय रूप से संग्रहीत होती हैं; वैकल्पिक C2S प्रीसेट स्नैपशॉट सर्वर पर सेव किए जा सकते हैं, तथा जब आप किसी लोकल टनल कॉन्फ़िगरेशन को क्लाइंट के बीच स्थानांतरित करना चाहें तो उन्हें रीनेम, लोड या डिलीट किया जा सकत है। लोकल, रिमोट और डायनमिक SOCKS फॉरवर्डिंग, अपने आप दोबारा जुड़ने और स्थिति जाँच के साथ। डेस्कटॉप ऐप के क्लाइंट से सर्वर वाले टनल उसी मशीन पर रहते हैं, और आप सेटिंग सर्वर पर सहेजकर उसे दूसरी मशीन पर ले जा सकत है
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**रिमोट फ़ाइल मैनेजर:** **फ़ाइल मैनेजर:**
कोड, इमेज, ऑडियो और वीडियो देखने और संपादित करने के सपोर्ट के साथ रिमोट सर्वर पर सीधे फ़ाइलें प्रबंधित करें। sudo सपोर्ट के साथ फ़ाइलें अपलोड, डाउनलोड, रीनेम, डिलीट और मूव करें। इसमें फ़ाइलको एक सर्वर से दूसरे सर्वर में स्थानांतरित करने का सपोर्ट भी शामिल है। SFTP से फ़ाइलें देखें, संपादित करें, अपलोड और डाउनलोड करें, नाम बदलें, हटाएँ और खिसकाएँ, sudo के साथ भी। कोड, तस्वीरें, डियो और वीडियो देखें और बदलें फ़ाइलसीधे एक सर्वर से दूसरे पर कॉपी करें,बसे तेज़ रास्ता अपने आप चुना जाता है और ट्रांसफ़र की जाँच भी होती है।
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Docker और Podman प्रबंधन:** **Docker और Podman:**
कंटेनर शुरू, बंद, पॉज़, हटाएँ। कंटेनर स्टैट्स देखें। docker exec टर्मिनल का उपयोग करके कंटेनर को नियंत्रित करें। Docker और Podman दोनों को कंटेनर रनटाइम के रूप में सपोर्ट करता है। इसे Portainer या Dockge की जगह लेने के लिए नहीं बनाया गया बल्कि कंटेनर बनाने की तुलना में उन्हें सरलता से प्रबंधित करने के लिए बनाया गया है। कंटेनर चालू करें, रोकें, थामें और हटाएँ, उनके आँकड़े देखें, और किसी एक के अंदर शेल खोलें। Docker और Podman दोनों के साथ चलता है। यह Portainer या Dockge की जगह लेने के लिए नहीं है, सिर्फ़ आपके पहले से मौजूद कंटेनर संभालने के लिए है।
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH होस्ट मैनेजर:** **होस्ट मैनेजर:**
टैग और फ़ोल्डर (फ़ोल्डर कस्टमाइज़ेशन और नेस्टेड फ़ोल्डर सपोर्ट के साथ) के साथ अपने SSH कनेक्शन सहेजें, व्यवस्थित करें और प्रबंधित करें, और SSH कुंजियों की तैनाती को स्वचालित करने की क्षमता के साथ पुन: उपयोग योग्य लॉगिन जानकारी आसानी से सहेजें। टैग और नाम व रंग वाले नेस्टेड फ़ोल्डर से होस्ट सहेजें और व्यवस्थित करें। सहेजे गए क्रेडेंशियल कई होस्ट पर दोबारा इस्तेमाल करें, SSH कुंजियाँ अपने आप भेजें, होस्ट को किसी मुख्य होस्ट के नीचे रखें, एक साथ कई में बदलाव करें और निर्यात करें, और जिन कनेक्शनों को सहेजना नहीं चाहते उनके लिए क्विक कनेक्ट इस्तेमाल करें।
</td> </td>
</tr> </tr>
@@ -111,97 +111,139 @@ Termix एक ओपन-सोर्स, हमेशा के लिए मु
<td width="50%" valign="top"> <td width="50%" valign="top">
**होस्ट मेट्रिक्स:** **होस्ट मेट्रिक्स:**
अधिकांश Linux आधारित सर्वर पर CPU, मेमोरी, डिस्क उपयोग, नेटवर्क, अपटाइम, सिस्टम जानकारी, फ़ायरवॉल, पोर्ट मॉनिटर, लॉग व्यूअर, उपयोगकर्ता/अनुमतियाँ, सर्टिफ़िकेट और भी बहुत कुछ देखें। इसमें टाइम-सीरीज़ हिस्ट्री ग्राफ़ और ntfy व webhook सपोर्ट के साथ थ्रेशोल्ड-आधारित अलर्ट शामिल हैं। ज़्यादातर Linux सर्वर पर CPU, मेमोरी, डिस्क, नेटवर्क, तापमान, अपटाइम, प्रोसेस, पोर्ट, लॉगिन और सिस्टम जानकारी, पुराने आँकड़ों के ग्राफ़ के साथ। मैनेजर कार्ड से आप सर्विस, cron कार्य, पैकेज, उपयोगकर्ता, फ़ायरवॉल नियम, WireGuard, Tailscale, SSL प्रमाणपत्र, लॉग और हेल्थ चेक Termix छोड़े बिना संभाल सकते हैं।
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**उपयोगकर्ता प्रमाणीकरण:** **ऑटोमेशन:**
व्यवस्थापक नियंत्रण (अन्य उपयोगकर्ताओं की जानकारी संपादित कर सकते हैं) और OIDC/LDAP/SSO (एक्सेस कंट्रोल के साथ), 2FA (TOTP), और पासकी (WebAuthn) सपोर्ट के साथ सुरक्षित उपयोगकर्ता प्रबंधन। सभी प्लेटफ़ॉर्म पर सक्रिय उपयोगकर्ता सत्र देखें और अनुमतियाँ रद्द करें। अपने OIDC/स्थानीय खातों को एक साथ जोड़ें। सभी उपयोगकर्ताओं की कार्रवाइयों का ऑडिट लॉग देखें। पहले एक ट्रिगर चुनें, फिर बताएँ कि क्या होना चाहिए। ट्रिगर में किसी मेट्रिक का तय सीमा पार करना, होस्ट का बंद होना या वापस आना, हेल्थ चेक का बदलना, कोई तय समय, कंटेनर की कोई घटना, या आने वाला webhook शामिल है। कदमों में कमांड और स्निपेट चलाना, कंटेनर और टनल संभालना, मशीन जगाना, कोई URL बुलाना, इंतज़ार करना, शर्त के हिसाब से रास्ता बदलना, दूसरा ऑटोमेशन चलाना, और ntfy, Discord या webhook से आपको बताना शामिल है। टेस्ट रन से आप पहले सुरक्षित तरीके से आज़मा सकते हैं।
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Tailscale एकीकरण:** **फ़्लीट:**
अपने Tailscale नेटवर्क के डिवाइस सूचीबद्ध करें ताकि उन्हें जल्दी से होस्ट के रूप में जोड़ जा सके, और Tailscale SSH को प्रमाणीकरण विधि के रूप में उपयोग करके कनेक्ट करें, जिससे आपके Tailscale ACL क्रेडेंशियल संग्रहीत किए बिना प्राधिकरण संभाल सकें। होस्ट चुनकर या टैग नियमों से एक फ़्लीट बनाएँ, ताकि नए होस्ट अपने आप जुड़ जाएँ। एक ही कमांड सभी होस्ट पर एक साथ चलाएँ, सब पर फ़ाइलें भेजें और उनसे लाएँ, पैकेज इंस्टॉल करें, और OS, कर्नेल, आर्किटेक्चर और अपटाइम की सूची इकट्ठा करें।
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**RBAC/शेयरिंग:** **AI सहायक:**
भूमिकाएँ बनाएँ और उपयोगकर्ताओं/भूमिकाओं में होस्ट साझा करें। सभी प्रमाणीकरण प्रकारों और सभी होस्ट प्रोटोकॉल का सपोर्ट करता है। यह वैकल्पिक है और जब तक आप खुद चालू न करें, बंद रहता है। OpenAI, Anthropic, Gemini, Ollama या OpenAI के अनुरूप कोई भी एंडपॉइंट जोड़ें और अपने सेटअप के बारे में पूछें। यह होस्ट, फ़्लीट, स्निपेट और अलर्ट पढ़ सकता है, और बदलाव खुद करने के बजाय आपकी मंज़ूरी के लिए सुझाता है। यह क्रेडेंशियल, उपयोगकर्ताओं या सेटिंग्स तक कभी नहीं पहुँच सकता। एडमिन इसे पूरे इंस्टेंस के लिए बंद रख सकते हैं, और आप इसे शुरुआती सेटअप में ही छिपा सकते है
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**सीरियल कनेक्शन:** **लॉगिन और उपयोगकर्ता:**
सीरियल डिवाइस (राउटर, स्विच, माइक्रोकंट्रोलर आदि) से सीधे ब्राउज़र या डेस्कटॉप ऐप से कनेक्ट करें। बॉड रेट, डेटा बिट्स, स्टॉप बिट्स और पैरिटी कॉन्फ़िगर करें। समर्थित ब्राउज़र में Web Serial API या Electron ऐप में नेटिव बैकएंड का उपयोग करता है लोकल खातों के साथ OIDC, LDAP, GitHub और Google से लॉगिन, और दो चरणों वाला सत्यापन (TOTP), पासकी (WebAuthn) तथा भरोसेमंद डिवाइस। एडमिन उपयोगकर्ताओं को संभाल सकते हैं, OIDC समूहों को भूमिकाओं से जोड़ सकते हैं, हर प्लेटफ़ॉर्म पर चालू सत्र देख और रद्द कर सकते हैं। अपने लोकल और OIDC खाते आपस में जोड़ें, और ऑडिट लॉग में देखें कि किसने क्या किया
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**भूमिकाएँ और साझाकरण:**
भूमिकाएँ बनाएँ और होस्ट को उपयोगकर्ताओं या भूमिकाओं के साथ चार स्तरों पर साझा करें: कनेक्ट, देखना, बदलना और प्रबंधन। यह हर तरह के प्रमाणीकरण और हर प्रोटोकॉल के साथ चलता है, और साझा होस्ट के लिए इस्तेमाल होने वाले क्रेडेंशियल आप बदल भी सकते हैं।
</td>
</tr>
<tr>
<td width="50%" valign="top">
**अलर्ट:** **अलर्ट:**
होस्ट मेट्रिक्स (CPU, मेमोरी, डिस्क आदि) पर थ्रेशोल्ड-आधारित अलर्ट नियम सेट करें और जब वे ट्रिगर हों तो ntfy या webhooks के माध्यम से सूचना पाएँ। इतिहास लॉग में सक्रिय और हल किए गए अलर्ट देखें। CPU, मेमोरी और डिस्क जैसी होस्ट मेट्रिक्स पर नियम लगाएँ, और उनके चलने पर ntfy, Discord या webhook से सूचना पाएँ। चल रहे और ठीक हो चुके अलर्ट इतिहास में देखें, और जो आपके काम के नहीं उन्हें हटा दें।
</td> </td>
</tr>
<tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**होमपेज:** **होमपेज:**
ड्रैग-एंड-ड्रॉप विजेट ग्रिड के साथ पूरी तरह से कस्टमाइज़ करने योग्य होमपेज। होस्ट स्टेटस, सर्विस लिंक, घड़ियाँ, नोट्स, RSS फ़ीड, मौसम, Docker कंटेनर, होस्ट मेट्रिक्स चार्ट, एम्बेडेड टर्मिनल, iframes और अन्य के लिए विजेट जोड़ें। खींचकर छोड़ने वाला विजेट ग्रिड जिसे आप खुद बनाते हैं। होस्ट की स्थिति, पिंग, सर्विस लिंक, बुकमार्क, खोज, घड़ियाँ, कैलेंडर, उलटी गिनती, नोट्स, RSS, मौसम, तस्वीरें, iframe, Docker, टनल, मेट्रिक्स के ग्राफ़, अपने API और यहाँ तक कि चालू टर्मिनल तक के विजेट मौजूद हैं।
</td>
<td width="50%" valign="top">
**डेटाबेस एन्क्रिप्शन:**
बैकएंड एन्क्रिप्टेड SQLite डेटाबेस फ़ाइलों के रूप में संग्रहीत। अधिक जानकारी के लिए [डॉक्स](https://docs.termix.site) देखें।
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**नेटवर्क ग्राफ़:** **स्निपेट और उपकरण:**
स्थिति सपोर्ट के साथ अपने SSH कनेक्शन के आधार पर अपने होमलैब को विज़ुअलाइज़ करने के लिए अपना डैशबोर्ड कस्टमाइज़ करें। जो कमांड आप बार-बार चलाते हैं उन्हें सहेजें और एक क्लिक में चलाएँ, होस्ट और अपने इनपुट के लिए वेरिएबल के साथ। एक ही कमांड सभी खुले टर्मिनलों पर चलाएँ, और अपने कमांड इतिहास में ऑटो-कंप्लीट के साथ खोजें।
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH टूल्स:** **सत्र साझा करना:**
एक क्लिक से निष्पादित होने वाले पुन: उपयोग योग्य कमांड स्निपेट बनाएँ। एक साथ कई खुले टर्मिनलों में एक कमांड चलाएँ चालू टर्मिनल, RDP, VNC या Telnet सत्र लाइव साझा करें। ऐसा लिभेजें जिससे कोई भी बिना खाते के जुड़ सके, या किसी खास Termix उपयोगकर्ता के साथ साझा करें, सिर्फ़ देखने या लिखने की अनुमति के साथ। साझाकरण अपने आप खत्म हो सकता है या कभी भी रद्द किया जा सकता है, और इसे पूरी तरह या हर होस्ट के लिए अलग से बंद किया जा सकता है
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**परसिस्टेंट टैब:** **सत्र रिकॉर्डिंग और लॉग:**
उपयोगकर्ता प्रोफ़ाइल में सक्षम होने पर SSH सेशन और टैब डिवाइस/रीफ्रेश के पार खुले रहते हैं टर्मिनल, RDP और VNC सत्र रिकॉर्ड करें और बाद में देखें। सत्र के सादे टेक्स्ट लॉग डाउनलोड करें, और कनेक्शन लॉग देखकर जानें कि जुड़ते समय असल में क्या हुआ
</td>
<td width="50%" valign="top">
**सीरियल कनेक्शन:**
राउटर, स्विच और माइक्रोकंट्रोलर जैसे सीरियल उपकरणों से ब्राउज़र या डेस्कटॉप ऐप से बात करें। बॉड रेट, डेटा बिट, स्टॉप बिट और पैरिटी सेट करें। सहयोगी ब्राउज़रों में Web Serial API और डेस्कटॉप ऐप में मूल बैकएंड इस्तेमाल होता है।
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Tailscale:**
अपने tailnet से डिवाइस लाकर कुछ ही क्लिक में होस्ट के रूप में जोड़ें, और Tailscale SSH से जुड़ें ताकि पहुँच का काम आपके tailnet के ACL संभालें और कोई क्रेडेंशियल सहेजना न पड़े। Headscale और अपने एंडपॉइंट भी चलते हैं।
</td>
<td width="50%" valign="top">
**Proxmox:**
होस्ट सीधे किसी Proxmox इंस्टेंस से लाएँ, और नोड तथा गेस्ट के आँकड़े, जिनमें CPU, मेमोरी और स्टोरेज शामिल हैं, अलग टैब में देखें।
</td>
</tr>
<tr>
<td width="50%" valign="top">
**वर्कस्पेस और टैब:**
टैब का एक सेट उनके स्प्लिट लेआउट के साथ सहेजें और पूरा का पूरा एक क्लिक में फिर खोलें। Termix आपका पिछला सत्र भी याद रखता है, इसलिए पेज रीफ़्रेश करने पर और दूसरे डिवाइस पर भी आपके टैब लौट आते हैं।
</td>
<td width="50%" valign="top">
**निर्देशित सेटअप:**
एक छोटा सा सेटअप आपको इंटरफ़ेस प्रीसेट, थीम, मनचाही सुविधाएँ और पहला होस्ट चुनने में मदद करता है। सरल मोड वह सब छिपा देता है जो आप इस्तेमाल नहीं करते, और आप सेटअप दोबारा चला सकते हैं या प्रीसेट कभी भी बदल सकते हैं।
</td>
</tr>
<tr>
<td width="50%" valign="top">
**स्वतंत्र डेस्कटॉप ऐप और सिंक:**
डेस्कटॉप ऐप अपने लोकल बैकएंड और डेटाबेस के साथ बिना किसी सर्वर के अकेले चलता है। आप इसे किसी Termix सर्वर से जोड़कर होस्ट, क्रेडेंशियल, स्निपेट वगैरह दोनों तरफ़ सिंक कर सकते हैं, और चुन सकते हैं कि कनेक्शन आपकी मशीन से शुरू हों या सर्वर के रास्ते।
</td>
<td width="50%" valign="top">
**कमांड लाइन:**
आपके शेल और स्क्रिप्ट के लिए `termix` CLI। टर्मिनल खोलें, किसी एक होस्ट या पूरे फ़्लीट पर कमांड चलाएँ, SFTP से फ़ाइलें भेजें, और होस्ट, स्निपेट व क्रेडेंशियल संभालें। `npm install -g @termix-cli/cli` से इंस्टॉल करें या अलग बाइनरी लें। [CLI दस्तावेज़](https://docs.termix.site/cli) देखें।
</td>
</tr>
<tr>
<td width="50%" valign="top">
**सुरक्षा:**
पासवर्ड, कुंजियाँ और बाकी गोपनीय जानकारी हर उपयोगकर्ता के लिए अलग से एन्क्रिप्ट होती है, और डेटाबेस फ़ाइलें भी डिस्क पर एन्क्रिप्ट की जा सकती हैं। यह कैसे काम करता है, यह [दस्तावेज़](https://docs.termix.site/security) में देखें।
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**भाषाएँ:** **भाषाएँ:**
लगभग 30 भाषाओं का बिल्ट-इन सपोर्ट ([Crowdin](https://docs.termix.site/translations) द्वारा प्रबंधित) लगभग 30 भाषाएँ पहले से मौजूद हैं, जिन्हें [Crowdin](https://docs.termix.site/translations) से संभाला जाता है
</td>
</tr>
<tr>
<td width="50%" valign="top">
**सेशन शेयरिंग:**
लाइव टर्मिनल, RDP, VNC, या Telnet सेशन को दूसरों के साथ रीयल टाइम में शेयर करें। लिंक के जरिए शेयर करें (गुमनाम रूप से जुड़ें, अकाउंट की जरूरत नहीं) या किसी खास Termix यूजर के साथ, और रीड-ओनली या रीड-राइट एक्सेस चुनें। शेयर अपने आप एक्सपायर हो सकते हैं या कभी भी रद्द किए जा सकते हैं, और सेशन शेयरिंग को ग्लोबली या प्रति होस्ट टॉगल किया जा सकता है।
</td>
<td width="50%" valign="top">
**डेस्कटॉप स्टैंडअलोन + 2-वे सिंक:**
Electron डेस्कटॉप ऐप अपने खुद के लोकल बैकएंड और डेटाबेस के साथ पूरी तरह से स्टैंडअलोन चलता है, किसी सर्वर की जरूरत नहीं। चाहें तो इसे किसी रिमोट Termix सर्वर से कनेक्ट करें ताकि होस्ट्स, क्रेडेंशियल्स, स्निपेट्स और अन्य चीज़ों का ऑटोमैटिक 2-वे सिंक हो सके, और चुनें कि SSH कनेक्शन लोकली शुरू हों या रिमोट सर्वर के जरिए।
</td> </td>
</tr> </tr>
@@ -210,20 +252,23 @@ Electron डेस्कटॉप ऐप अपने खुद के लोक
<br /> <br />
<details> <details>
<summary><b>अधिक विशेषताएँ</b></summary> <summary><b>और भी विशेषताएँ</b></summary>
<br /> <br />
- **डैशबोर्ड** - अपने डैशबोर्ड पर एक नज़र में सर्वर की जानकारी देखे - **डैशबोर्ड** - आपके सर्वर एक नज़र में, ऐसे कार्ड के साथ जिन्हें आप खुद जमाते है
- **API कुंजियाँ** - ऑटोमेशन/CI के लिए उपयोग हेतु समाप्ति तिथियों के साथ उपयोगकर्ता-स्कोप्ड API कुंजियाँ बनाएँ - **नेटवर्क ग्राफ़** - आपके होस्ट से बना आपका होमलैब का नक्शा, लाइव स्थिति के साथ
- **डेटा एक्सपोर्ट/इम्पोर्ट** - SSH होस्ट, क्रेडेंशियल और फ़ाइल मैनेजर डेटा एक्सपोर्ट और इम्पोर्ट करें - **tmux मॉनिटर** - tmux के सत्र, विंडो और पैन देखें, झलक और खोज के साथ
- **स्वचालित SSL सेटअप** - HTTPS रीडायरेक्ट के साथ बिल्ट-इन SSL सर्टिफ़िकेट जनरेशन और प्रबंधन - **API कुंजियाँ** - स्क्रिप्ट और CI के लिए, समाप्ति तिथि वाली उपयोगकर्ता-विशिष्ट कुंजियाँ
- **आधुनिक UI** - React, Tailwind CSS, और Shadcn से बना साफ़ डेस्कटॉप/मोबाइल-फ़्रेंडली इंटरफ़ेस। लाइट, डार्क, ड्रैकुला आदि सहित कई अलग-अलग UI थीम के बीच चुनें। किसी भी कनेक्शन को फ़ुल-स्क्रीन में खोलने के लिए URL रूट का उपयोग करें। - **निर्यात और आयात** - होस्ट, क्रेडेंशियल और फ़ाइल मैनेजर का डेटा अंदर-बाहर ले जाएँ
- **कमांड इतिहास** - पहले चलाए गए SSH कमांड का ऑटो-कम्प्लीट और दृश्य - **अपने आप SSL** - प्रमाणपत्र आपके लिए बनते और नवीनीकृत होते हैं, HTTPS रीडायरेक्ट के साथ, या अपने खुद के लगाएँ
- **क्विक कनेक्ट** - कनेक्शन डेटा सहेजे बिना सर्वर से कनेक्ट करें - **डेटाबेस** - डिफ़ॉल्ट रूप से SQLite, साथ में PostgreSQL और MySQL भी
- **कमांड पैलेट** - अपने कीबोर्ड से SSH कनेक्शन तक त्वरित पहुँच के लिए बाएँ Shift को दो बार टैप करें - **आधुनिक इंटरफ़ेस** - साफ़ सुथरा React इंटरफ़ेस जो डेस्कटॉप और मोबाइल दोनों पर चलता है, लाइट, डार्क और Dracula जैसी थीम के साथ। कोई भी कनेक्शन URL से पूरी स्क्रीन में खुल सकता है
- **Proxmox एकीकरण** - अपने Proxmox इंस्टेंस से Termix में होस्ट स्वचालित रूप से जोड़ें - **कमांड पैलेट** - बाईं Shift दो बार दबाकर कीबोर्ड से सीधे किसी होस्ट पर जाएँ
- **SSH सुविधाओं से भरपूर** - जम्प होस्ट, Warpgate, TOTP आधारित कनेक्शन, SOCKS5, होस्ट की वेरिफ़िकेशन, पासवर्ड ऑटोफ़िल, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, पोर्ट नॉकिंग, टर्मिनल लॉगिंग, SSH एजेंट फ़ॉरवर्डिंग, Bitwarden SSH एजेंट, HashiCorp Vault SSH सिग्निंग, और अन्य का सपोर्ट। - **कीबोर्ड शॉर्टकट** - टैब बदलना, बंद करना और बहुत कुछ, सब दोबारा तय किए जा सकते हैं
- **Termix ID** - Termix में बिल्ट-इन sshid.io के समकक्ष। एक हैंडल क्लेम करें, अपनी सार्वजनिक SSH कुंजियों को एक रिज़ॉल्वर URL पर प्रकाशित करें, और SSH सर्टिफ़िकेट जारी करने के लिए बिल्ट-इन CA का उपयोग करें। - **Wake-on-LAN** - किसी मशीन को Termix से या ऑटोमेशन के किसी कदम से जगाएँ
- **भरोसेमंद प्रॉक्सी से लॉगिन** - रिवर्स प्रॉक्सी को लॉगिन संभालने दें और उपयोगकर्ता की जानकारी आगे भेजने दें
- **भरपूर SSH सुविधाएँ** - जंप होस्ट, Warpgate, TOTP पूछना, SOCKS5, होस्ट कुंजी की जाँच, पासवर्ड अपने आप भरना, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, पोर्ट नॉकिंग, टर्मिनल लॉग, एजेंट फ़ॉरवर्डिंग, Bitwarden SSH एजेंट, HashiCorp Vault से SSH हस्ताक्षर और भी बहुत कुछ
- **Termix ID** - sshid.io जैसा अपना बना हुआ इंतज़ाम। एक नाम लें, अपनी सार्वजनिक कुंजियाँ एक रिज़ॉल्वर URL पर रखें, और अंदर मौजूद CA से SSH प्रमाणपत्र जारी करें
</details> </details>
@@ -266,9 +311,9 @@ Electron डेस्कटॉप ऐप अपने खुद के लोक
## इंस्टॉलेशन ## इंस्टॉलेशन
सभी प्लेटफ़ॉर्म पर पूर्ण इंस्टॉलेशन निर्देशों के लिए Termix [डॉक्स](https://docs.termix.site/install) पर जाएँ सभी प्लेटफ़ॉर्म पर पूर इंस्टॉलेशन जानकारी के लिए [Termix दस्तावेज़](https://docs.termix.site/install) देखें
नमूना Docker Compose फ़ाइल (यदि आप रिमोट डेस्कटॉप सुविधाओं का उपयोग करने की योजना नहीं बना रहे हैं तो आप `guacd` और नेटवर्क को हटा सकते हैं): Docker Compose फ़ाइल का नमूना (अगर आप रिमोट डेस्कटॉप इस्तेमाल नहीं करने वाले तो `guacd` और नेटवर्क वाला हिस्सा हटा सकते हैं):
```yaml ```yaml
services: services:
@@ -305,11 +350,37 @@ networks:
driver: bridge driver: bridge
``` ```
### कमांड लाइन
Termix में CLI भी है, ताकि आप टर्मिनल से अपने सर्वर संभाल सकें और Termix को अपनी स्क्रिप्ट में इस्तेमाल कर सकें।
```bash
npm install -g @termix-cli/cli
termix login --url https://termix.example.com
termix ssh 1
```
यह टर्मिनल खोल सकता है, एक होस्ट या पूरे फ़्लीट पर कमांड चला सकता है, SFTP से फ़ाइलें ले जा सकता है, और होस्ट, स्निपेट व क्रेडेंशियल संभाल सकता है। पूरा दस्तावेज़ [docs.termix.site/cli](https://docs.termix.site/cli) पर है।
### क्लाउड होस्टिंग
आप Termix सर्वर को अपने नेटवर्क के बजाय किसी VPS पर भी चला सकते हैं। अगर Termix उसी नेटवर्क पर चल रहा है जिसे वह संभालता है, तो गड़बड़ी होने पर वह भी साथ ही बंद हो जाएगा, ठीक उसी वक्त जब आपको उसे ठीक करने के लिए चाहिए। बाहर चलाने पर वह हमेशा पहुँच में रहता है, एक स्थिर IP देता है, और बिना VPN या पोर्ट फ़ॉरवर्ड के कहीं से भी पहुँच मिलती है।
[GINERNET](https://docs.termix.site/install/ginernet) Termix को प्रायोजित करता है, और दस्तावेज़ में उनके VPS प्लेटफ़ॉर्म पर तैनाती की कदम-दर-कदम गाइड मौजूद है।
<br />
## टेलीमेट्री
Termix दिन में एक बार एक छोटा सा गुमनाम संकेत भेजता है, ताकि मुझे पता चले कि कितने इंस्टेंस चल रहे हैं और कौन सी सुविधाएँ सच में इस्तेमाल होती हैं। इसमें एक बेतरतीब इंस्टेंस आईडी, आपके पास कितने उपयोगकर्ता और होस्ट हैं, ऐप का संस्करण, और पिछले 24 घंटे में इस्तेमाल हुई सुविधाएँ (टर्मिनल, फ़ाइल मैनेजर, टनल, docker आदि) होती हैं। इसमें कभी भी उपयोगकर्ता नाम, होस्ट नाम, IP पते, क्रेडेंशियल या ऐसी कोई चीज़ नहीं होती जो आपकी या आपके सर्वर की पहचान बताए।
यह डिफ़ॉल्ट रूप से चालू रहता है। इसे एडमिन सेटिंग्स में सामान्य के अंतर्गत बंद करें, या Termix शुरू करने से पहले ही `ENABLE_TELEMETRY=false` सेट कर दें।
<br /> <br />
## दान करें ## दान करें
Termix मुफ़्त और ओपन सोर्स है, बिना किसी सब्सक्रिप्शन या पेड प्लान के। यदि आपको यह उपयोगी लगता है, तो सर्वर लागत, डोमेन और विकास समय को कवर करने में मदद के लिए दान करने पर विचार करें। दान SAML, Kubernetes, और Agent सपोर्ट जैसी सुविधाओं के निर्माण के लिए आवश्यक शोध और सीखने में लगने वाले समय को वित्त पोषित करने में भी मदद करते है। नीचे प्रगति देखें और दान करें। Termix मुफ़्त और ओपन सोर्स है, न कोई सदस्यता है न कोई पेड प्लान। अगर यह आपके काम आता है, तो सर्वर, डोमेन और विकास के समय में मदद के लिए दान करने पर विचार करें। दान से SAML, Kubernetes और एजेंट सपोर्ट जैसी सुविधाएँ बनाने के लिए ज़रूरी शोध और सीखने का समय भी मिलता है। नीचे प्रगति देखें और दान करें।
[दान करें](https://donate.termix.site/) [दान करें](https://donate.termix.site/)
@@ -317,7 +388,7 @@ Termix मुफ़्त और ओपन सोर्स है, बिना
## प्रायोजक ## प्रायोजक
विकास को समर्थन देने के लिए पेड प्लेसमेंट में रुचि है? [mail@termix.site](mailto:mail@termix.site) पर ईमेल करें। विकास में सहयोग के लिए पेड प्लेसमेंट में रुचि है? [mail@termix.site](mailto:mail@termix.site) पर ईमेल करें।
<div align="center"> <div align="center">
@@ -339,10 +410,6 @@ Termix मुफ़्त और ओपन सोर्स है, बिना
<img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" /> <img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" />
</a> </a>
&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;
<a href="https://tailscale.com/">
<img src="https://drive.google.com/uc?export=view&id=1lIxkJuX6M23bW-2FElhT0rQieTrzaVSL" height="40" alt="Tailscale" />
</a>
&nbsp;&nbsp;&nbsp;
<a href="https://akamai.com/"> <a href="https://akamai.com/">
<img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" /> <img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" />
</a> </a>
@@ -354,14 +421,17 @@ Termix मुफ़्त और ओपन सोर्स है, बिना
<a href="https://rackgenius.com/"> <a href="https://rackgenius.com/">
<img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" /> <img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" />
</a> </a>
&nbsp;&nbsp;&nbsp;
<a href="https://ginernet.com/">
<img src="https://ginernet.com/img/logo-web.png" height="40" alt="Ginernet" />
</a>
</div> </div>
<br /> <br />
## सहायता ## सहायता
यदि आपको सहायता चाहिए या Termix के लिए किसी विशेषता का अनुरोध करना चाहते हैं, तो [इश्यूज़](https://github.com/Termix-SSH/Support/issues) पेज पर जाएँ, लॉग इन करें, और `New Issue` दबाएँ। कृपया अपने इश्यू में यथासंभव विस्तृत विवरण दें, अधिमानतः अंग्रेज़ी में लिखें। आप [Discord](https://discord.gg/jVQGdvHDrf) सर्वर में भी शामिल हो सकते हैं और सहायता चैनल पर जा सकते हैं, हालाँकि, प्रतिक्रिया समय अधिक हो सकता है। मदद चाहिए या कोई सुविधा माँगनी है? एक [नया issue](https://github.com/Termix-SSH/Support/issues) खोलें और जितना हो सके विस्तार से लिखें, हो सके तो अंग्रेज़ी में। आप [Discord](https://discord.gg/jVQGdvHDrf) के सपोर्ट चैनल में भी पूछ सकते हैं, हालाँकि वहाँ जवाब आने में ज़्यादा समय लग सकता है।
<br /> <br />
@@ -373,7 +443,7 @@ Termix मुफ़्त और ओपन सोर्स है, बिना
[![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos) [![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos)
<sub>YouTube पर अपडेट की समीक्षाएँ देखें</sub> <sub>YouTube पर अपडेट की जानकारी देखें</sub>
<br /> <br />
<br /> <br />
@@ -413,7 +483,7 @@ Termix मुफ़्त और ओपन सोर्स है, बिना
</tr> </tr>
</table> </table>
<sub>कुछ वीडियो और छवियाँ पुरानी हो सकती हैं या विशेषताओं को पूरी तरह से प्रदर्शित नहीं कर सकती हैं।</sub> <sub>कुछ वीडियो और तस्वीरें पुरानी हो सकती हैं या सुविधाओं को पूरी तरह नहीं दिखा पातीं।</sub>
</div> </div>
@@ -421,10 +491,10 @@ Termix मुफ़्त और ओपन सोर्स है, बिना
## नियोजित विशेषताएँ ## नियोजित विशेषताएँ
सभी नियोजित विशेषताओं के लिए [प्रोजेक्ट्स](https://github.com/orgs/Termix-SSH/projects/5) देखें। यदि आप योगदान देना चाहते हैं, तो [योगदान](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md) देखें। सभी नियोजित सुविधाएँ [Projects](https://github.com/orgs/Termix-SSH/projects/5) में हैं। अगर आप योगदान देना चाहते हैं, तो [Contributing](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md) देखें।
<br /> <br />
## लाइसेंस ## लाइसेंस
Apache License Version 2.0 के तहत वितरित। अधिक जानकारी के लिए `LICENSE` देखें। Apache License संस्करण 2.0 के तहत वितरित। अधिक जानकारी के लिए `LICENSE` देखें।
+151 -81
View File
@@ -4,7 +4,7 @@
<h1>Termix</h1> <h1>Termix</h1>
<p>Gestione SSH self-hosted e accesso al desktop remoto</p> <p>Gestione dei server self-hosted, da SSH e desktop remoto fino alle automazioni</p>
<p> <p>
<a href="../README.md">English</a> · <a href="../README.md">English</a> ·
@@ -32,12 +32,12 @@
</p> </p>
<p> <p>
<a href="https://donate.termix.site/"><img alt="Donazioni di questo mese" src="https://img.shields.io/badge/dynamic/json?style=for-the-badge&label=Donazioni%20di%20questo%20mese&query=%24.fiatTotal&prefix=%24&url=https%3A%2F%2Ftermix.site%2Fdonation-snapshot.json&color=F39044&labelColor=1a1a1a" /></a> <a href="https://donate.termix.site/"><img alt="Donations this month" src="https://img.shields.io/badge/dynamic/json?style=for-the-badge&label=Donations%20this%20month&query=%24.fiatTotal&prefix=%24&url=https%3A%2F%2Ftermix.site%2Fdonation-snapshot.json&color=F39044&labelColor=1a1a1a" /></a>
</p> </p>
<br /> <br />
Termix è gratuito e open source. Se lo trovi utile, considera di [donare](https://donate.termix.site/) per aiutare a coprire i costi del server e il tempo di sviluppo. Termix è gratuito e open source. Se ti è utile, valuta una [donazione](https://donate.termix.site/) per aiutare a coprire i costi dei server e il tempo di sviluppo.
<br /> <br />
@@ -58,7 +58,7 @@ Termix è gratuito e open source. Se lo trovi utile, considera di [donare](https
## Panoramica ## Panoramica
Termix è una piattaforma di gestione server tutto-in-uno, open-source, per sempre gratuita e self-hosted. Fornisce una soluzione multipiattaforma per gestire i tuoi server e la tua infrastruttura attraverso un'unica interfaccia intuitiva. Termix offre accesso al terminale SSH, controllo remoto del desktop (RDP, VNC, Telnet), funzionalità di tunneling SSH, gestione remota dei file e molti altri strumenti. Termix è la perfetta alternativa gratuita e self-hosted a Termius, disponibile per tutte le piattaforme. Termix è una piattaforma gratuita, open source e self-hosted per gestire i tuoi server. Mette in un unico posto terminali SSH, desktop remoti (RDP, VNC, Telnet), trasferimenti di file, tunnel, Docker, metriche e automazioni, su web, desktop e mobile. È un'alternativa self-hosted a Termius che resta gratuita per sempre.
<br /> <br />
@@ -68,140 +68,182 @@ Termix è una piattaforma di gestione server tutto-in-uno, open-source, per semp
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Accesso Terminale SSH:** **Terminale SSH:**
Terminale completo con supporto schermo diviso (fino a 4 pannelli) con un sistema di schede in stile browser. Include il supporto per la personalizzazione del terminale, inclusi temi, font e altri componenti comuni. Un terminale completo con schede come quelle del browser e schermo diviso, fino a 6 pannelli insieme. Scegli tema, carattere e colori. Sopra ogni sessione c'è una barra con CPU, memoria e disco in tempo reale, più scorciatoie ai file, a Docker, ai tunnel e alle metriche di quell'host.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Accesso Desktop Remoto:** **Desktop remoto:**
Supporto RDP, VNC e Telnet tramite browser con personalizzazione completa e schermo diviso. RDP, VNC e Telnet nel browser, in schede e schermo diviso come qualsiasi altra sessione. Include un browser dei file per le unità RDP e il caricamento trascinando i file. Sul desktop Windows puoi anche aprire un host nel client RDP nativo.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gestione Tunnel SSH:** **Tunnel SSH:**
Crea e gestisci tunnel SSH da server a server con riconnessione automatica, monitoraggio dello stato e inoltro locale, remoto o SOCKS dinamico. Le impostazioni del tunnel da client desktop a server sono archiviate localmente per ogni installazione desktop; gli snapshot di preset C2S opzionali possono essere salvati sul server, rinominati, caricati o eliminati per spostare una configurazione di tunnel locale tra i client. Inoltro locale, remoto e SOCKS dinamico, con riconnessione automatica e controlli di stato. I tunnel da client a server dell'app desktop restano su quella macchina, e puoi salvare delle preimpostazioni sul server per portare una configurazione su un altro computer.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gestore File Remoto:** **Gestore file:**
Gestisci i file direttamente sui server remoti con supporto per la visualizzazione e la modifica di codice, immagini, audio e video. Carica, scarica, rinomina, elimina e sposta file senza problemi con supporto sudo. Include il supporto per spostare file da server a server. Sfoglia, modifica, carica, scarica, rinomina, sposta ed elimina file via SFTP, anche con sudo. Guarda e modifica codice, immagini, audio e video. Copia i file direttamente da un server all'altro: il percorso più veloce viene scelto per te e i trasferimenti vengono verificati.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gestione Docker e Podman:** **Docker e Podman:**
Avvia, ferma, metti in pausa, rimuovi container. Visualizza le statistiche dei container. Controlla i container tramite terminale docker exec. Supporta sia Docker che Podman come runtime dei container. Non è stato creato per sostituire Portainer o Dockge, ma piuttosto per gestire semplicemente i tuoi container rispetto alla loro creazione. Avvia, ferma, metti in pausa ed elimina i container, guarda le loro statistiche e apri una shell dentro uno di essi. Funziona sia con Docker sia con Podman. Non vuole sostituire Portainer o Dockge, serve solo a gestire i container che hai già.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gestore Host SSH:** **Gestore host:**
Salva, organizza e gestisci le tue connessioni SSH con tag e cartelle (con personalizzazione delle cartelle e supporto per cartelle annidate), salva facilmente le informazioni di accesso riutilizzabili e automatizza il deployment delle chiavi SSH. Salva e organizza gli host con etichette e cartelle annidate a cui puoi dare nome e colore. Riutilizza le credenziali salvate su più host, distribuisci le chiavi SSH in automatico, raggruppa gli host sotto un host padre, modifica ed esporta in blocco, e usa la connessione rapida per i collegamenti una tantum che non vuoi salvare.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Metriche Host:** **Metriche host:**
Visualizza CPU, memoria, utilizzo del disco, rete, uptime, informazioni di sistema, firewall, monitoraggio porte, visualizzatore di log, utenti/permessi, certificati e molto altro, funzionanti sulla maggior parte dei server basati su Linux. Include grafici storici delle serie temporali e avvisi basati su soglie con supporto ntfy e webhook. CPU, memoria, disco, rete, temperatura, tempo di accensione, processi, porte, accessi e informazioni di sistema sulla maggior parte dei server Linux, con grafici storici. Le schede di gestione ti fanno seguire servizi, cron, pacchetti, utenti, regole del firewall, WireGuard, Tailscale, certificati SSL, log e controlli di stato senza uscire da Termix.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Autenticazione Utente:** **Automazioni:**
Gestione utenti sicura con controlli amministrativi (può modificare le informazioni di altri utenti) e OIDC/LDAP/SSO (con controllo degli accessi), 2FA (TOTP) e supporto passkey (WebAuthn). Visualizza le sessioni utente attive su tutte le piattaforme e revoca i permessi. Collega i tuoi account OIDC/Locali tra loro. Visualizza il log di controllo delle azioni di tutti gli utenti. Scegli un evento che fa partire tutto, poi decidi cosa deve succedere. Gli eventi possono essere una metrica che supera una soglia, un host che cade o torna su, un controllo di stato che cambia, una pianificazione, un evento di un container o un webhook in arrivo. I passaggi possono eseguire comandi e frammenti, gestire container e tunnel, accendere un host, chiamare un URL, aspettare, seguire una condizione, avviare un'altra automazione e avvisarti via ntfy, Discord o webhook. Le prove a vuoto ti permettono di provare senza rischi.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Integrazione Tailscale:** **Flotte:**
Elenca i dispositivi della tua rete Tailscale per aggiungerli rapidamente come host, e connettiti utilizzando Tailscale SSH come metodo di autenticazione, lasciando che le ACL della tua rete gestiscano l'autorizzazione senza memorizzare credenziali. Raggruppa gli host in una flotta scegliendoli o con regole sulle etichette, così i nuovi host entrano da soli. Esegui un comando su tutti gli host in una volta, invia e recupera file su tutti quanti, installa pacchetti e raccogli un inventario di sistema operativo, kernel, architettura e tempo di accensione.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**RBAC/Condivisione:** **Assistente IA:**
Crea ruoli e condividi host tra utenti/ruoli. Supporta tutti i tipi di autenticazione e tutti i protocolli host. È opzionale e resta spento finché non lo accendi tu. Collega OpenAI, Anthropic, Gemini, Ollama o qualsiasi endpoint compatibile con OpenAI e fai domande sulla tua installazione. Legge host, flotte, frammenti e avvisi, e propone modifiche da approvare invece di farle da solo. Non può mai toccare credenziali, utenti o impostazioni. Gli amministratori possono lasciarlo spento per tutta l'istanza, e tu puoi nasconderlo già durante la configurazione.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Connessioni Seriali:** **Accesso e utenti:**
Connettiti a dispositivi seriali (router, switch, microcontrollori, ecc.) direttamente dal browser o dall'app desktop. Configura baud rate, bit di dati, bit di stop e parità. Utilizza la Web Serial API nei browser supportati o un backend nativo nell'app Electron. Account locali più accesso con OIDC, LDAP, GitHub e Google, con doppia autenticazione (TOTP), passkey (WebAuthn) e dispositivi fidati. Gli amministratori possono gestire gli utenti, collegare i gruppi OIDC ai ruoli, vedere tutte le sessioni attive su ogni piattaforma e revocarle. Collega il tuo account locale a quello OIDC e consulta il registro di controllo di quello che ha fatto ognuno.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Ruoli e condivisione:**
Crea ruoli e condividi gli host con utenti o ruoli su quattro livelli: connessione, visualizzazione, modifica e gestione. Funziona con ogni tipo di autenticazione e ogni protocollo, e puoi cambiare le credenziali usate per un host condiviso.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Avvisi:** **Avvisi:**
Imposta regole di avviso basate su soglie per le metriche dell'host (CPU, memoria, disco, ecc.) e ricevi notifiche tramite ntfy o webhook quando si attivano. Visualizza gli avvisi attivi e risolti in un registro storico. Imposta regole sulle metriche degli host come CPU, memoria e disco, e ricevi una notifica via ntfy, Discord o webhook quando scattano. Guarda gli avvisi attivi e quelli rientrati in uno storico, e scarta quelli che non ti interessano.
</td>
<td width="50%" valign="top">
**Pagina iniziale:**
Una griglia di widget che costruisci tu trascinandoli. Ci sono widget per stato degli host, ping, collegamenti ai servizi, segnalibri, ricerca, orologi, calendari, conti alla rovescia, note, RSS, meteo, immagini, iframe, Docker, tunnel, grafici delle metriche, API personalizzate e perfino un terminale dal vivo.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Homepage:** **Frammenti e strumenti:**
Una homepage completamente personalizzabile con una griglia di widget drag-and-drop. Aggiungi widget per lo stato dell'host, link ai servizi, orologi, note, feed RSS, meteo, container Docker, grafici delle metriche dell'host, terminali incorporati, iframe e altro ancora. Salva i comandi che usi spesso e lanciali con un clic, con variabili per l'host e per quello che scrivi tu. Esegui uno stesso comando su tutti i terminali aperti e cerca nella cronologia con il completamento automatico.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Crittografia Database:** **Condivisione sessione:**
Il backend è archiviato come file di database SQLite crittografati. Consulta la [documentazione](https://docs.termix.site) per maggiori informazioni. Condividi dal vivo una sessione di terminale, RDP, VNC o Telnet. Manda un link a cui chiunque può accedere senza account, oppure condividi con un utente Termix preciso, in sola lettura o anche in scrittura. Le condivisioni possono scadere da sole o essere revocate, e si possono spegnere per tutti o per singolo host.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Grafico di Rete:** **Registrazione e log delle sessioni:**
Personalizza la tua Dashboard per visualizzare il tuo homelab basato sulle connessioni SSH con supporto dello stato. Registra le sessioni di terminale, RDP e VNC e riguardale dopo. Scarica i log di testo di una sessione e consulta il registro delle connessioni per vedere esattamente cosa è successo durante una connessione.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Strumenti SSH:** **Connessioni seriali:**
Crea snippet di comandi riutilizzabili che si eseguono con un singolo clic. Esegui un comando simultaneamente su più terminali aperti. Parla con dispositivi seriali come router, switch e microcontrollori dal browser o dall'app desktop. Imposta velocità, bit di dati, bit di stop e parità. Usa l'API Web Serial nei browser compatibili, oppure un backend nativo nell'app desktop.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Schede Persistenti:** **Tailscale:**
Le sessioni SSH e le schede rimangono aperte tra dispositivi/aggiornamenti se abilitato nel profilo utente. Prendi i dispositivi dalla tua tailnet per aggiungerli come host in pochi clic, e collegati con Tailscale SSH così gli ACL della tailnet gestiscono l'accesso senza salvare credenziali. Funzionano anche Headscale e gli endpoint personalizzati.
</td>
<td width="50%" valign="top">
**Proxmox:**
Importa gli host direttamente da un'istanza Proxmox e segui le statistiche di nodi e macchine ospiti, comprese CPU, memoria e spazio, in una scheda dedicata.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Spazi di lavoro e schede:**
Salva un insieme di schede con la loro disposizione divisa e riapri tutto con un clic. Termix ricorda anche l'ultima sessione, così le schede tornano dopo un ricaricamento e su altri dispositivi.
</td>
<td width="50%" valign="top">
**Configurazione guidata:**
Una breve configurazione ti accompagna nella scelta di una preimpostazione dell'interfaccia, del tema, delle funzionalità che vuoi e del primo host. La modalità semplice nasconde quello che non usi, e puoi rifare la configurazione o cambiare preimpostazione quando vuoi.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Desktop autonomo e sincronizzazione:**
L'app desktop funziona da sola, con backend e database locali, senza bisogno di un server. Puoi anche collegarla a un server Termix per sincronizzare nei due sensi host, credenziali, frammenti e altro, e scegliere se le connessioni partono dal tuo computer o passano dal server.
</td>
<td width="50%" valign="top">
**Riga di comando:**
Una CLI `termix` per la tua shell e i tuoi script. Apri terminali, esegui un comando su un host o su un'intera flotta, sposta file via SFTP e gestisci host, frammenti e credenziali. Installala con `npm install -g @termix-cli/cli` oppure prendi un binario autonomo. Vedi la [documentazione della CLI](https://docs.termix.site/cli).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Sicurezza:**
Password, chiavi e altri segreti sono cifrati per ogni utente, e gli stessi file del database possono essere cifrati su disco. Guarda la [documentazione](https://docs.termix.site/security) per capire come funziona.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Lingue:** **Lingue:**
Supporto integrato per circa 30 lingue (gestito da [Crowdin](https://docs.termix.site/translations)). Circa 30 lingue incluse, gestite tramite [Crowdin](https://docs.termix.site/translations).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Condivisione Sessione:**
Condividi una sessione di terminale, RDP, VNC o Telnet dal vivo con altri in tempo reale. Condividi tramite un link (accesso anonimo, nessun account necessario) o con un utente Termix specifico, e scegli l'accesso in sola lettura o lettura/scrittura. Le condivisioni possono scadere automaticamente o essere revocate in qualsiasi momento, e la condivisione della sessione puo essere attivata globalmente o per singolo host.
</td>
<td width="50%" valign="top">
**App Desktop Standalone + Sincronizzazione Bidirezionale:**
L'app desktop Electron funziona in modo completamente autonomo con il proprio backend e database locali, senza bisogno di un server. Facoltativamente, collegala a un server Termix remoto per la sincronizzazione bidirezionale automatica di host, credenziali, snippet e altro, scegliendo se le connessioni SSH vengono avviate localmente o tramite il server remoto.
</td> </td>
</tr> </tr>
@@ -213,23 +255,26 @@ L'app desktop Electron funziona in modo completamente autonomo con il proprio ba
<summary><b>Altre funzionalità</b></summary> <summary><b>Altre funzionalità</b></summary>
<br /> <br />
- **Dashboard** - Visualizza le informazioni del server a colpo d'occhio sulla tua dashboard - **Dashboard** - I tuoi server a colpo d'occhio, con schede che disponi tu
- **Chiavi API** - Crea chiavi API con ambito utente e date di scadenza da utilizzare per automazione/CI - **Grafico di rete** - Il tuo homelab disegnato a partire dagli host, con stato in tempo reale
- **Esportazione/Importazione Dati** - Esporta e importa host SSH, credenziali e dati del gestore file - **Monitor tmux** - Sfoglia sessioni, finestre e pannelli di tmux, con anteprime e ricerca
- **Configurazione SSL Automatica** - Generazione e gestione integrata dei certificati SSL con reindirizzamenti HTTPS - **Chiavi API** - Chiavi per singolo utente con scadenza, per script e CI
- **Interfaccia Moderna** - Interfaccia pulita e responsive per desktop/mobile costruita con React, Tailwind CSS e Shadcn. Scegli tra molti temi UI diversi, inclusi chiaro, scuro, Dracula, ecc. Usa i percorsi URL per aprire qualsiasi connessione a schermo intero. - **Esporta e importa** - Sposta host, credenziali e dati del gestore file dentro e fuori
- **Cronologia Comandi** - Autocompletamento e visualizzazione dei comandi SSH eseguiti in precedenza - **SSL automatico** - Certificati generati e rinnovati per te, con reindirizzamento a HTTPS, oppure usa i tuoi
- **Connessione Rapida** - Connettiti a un server senza dover salvare i dati di connessione - **Database** - SQLite di base, con supporto anche per PostgreSQL e MySQL
- **Palette Comandi** - Premi due volte shift sinistro per accedere rapidamente alle connessioni SSH con la tastiera - **Interfaccia moderna** - Interfaccia React pulita che funziona su desktop e mobile, con temi come chiaro, scuro e Dracula. Ogni connessione si può aprire a schermo intero da un URL
- **Integrazione Proxmox** - Aggiungi automaticamente host a Termix dalla tua istanza Proxmox - **Palette comandi** - Premi due volte Maiusc sinistro per saltare a un host da tastiera
- **SSH Ricco di Funzionalità** - Supporta jump host, Warpgate, connessioni basate su TOTP, SOCKS5, verifica chiave host, compilazione automatica password, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, registrazione terminale, SSH agent forwarding, Bitwarden SSH agent, firma SSH HashiCorp Vault e altro ancora - **Scorciatoie da tastiera** - Spostarsi tra le schede, chiuderle e altro, tutto riassegnabile
- **Termix ID** - L'equivalente di sshid.io integrato in Termix. Rivendica un handle, pubblica le tue chiavi SSH pubbliche su un URL resolver e utilizza una CA integrata per emettere certificati SSH - **Wake-on-LAN** - Accendi una macchina da Termix o da un passaggio di un'automazione
- **Autenticazione tramite proxy fidato** - Lascia che un reverse proxy gestisca l'accesso e passi l'utente
- **SSH molto completo** - Host di salto, Warpgate, richieste TOTP, SOCKS5, verifica delle chiavi host, riempimento automatico della password, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, log del terminale, inoltro dell'agente, agente SSH di Bitwarden, firma SSH con HashiCorp Vault e altro
- **Termix ID** - Una versione integrata di sshid.io. Prendi un identificativo, pubblica le tue chiavi pubbliche su un URL di risoluzione ed emetti certificati SSH dalla CA integrata
</details> </details>
<br /> <br />
## Supporto Piattaforme ## Piattaforme supportate
<table align="center"> <table align="center">
<tr> <tr>
@@ -238,15 +283,15 @@ L'app desktop Electron funziona in modo completamente autonomo con il proprio ba
</tr> </tr>
<tr> <tr>
<td align="center"><b>Web</b></td> <td align="center"><b>Web</b></td>
<td>Qualsiasi browser moderno (Chrome, Safari, Firefox) · Supporto PWA</td> <td>Qualsiasi browser recente (Chrome, Safari, Firefox) · Supporto PWA</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Windows</b> <sub>x64/ia32</sub></td> <td align="center"><b>Windows</b> <sub>x64/ia32</sub></td>
<td>Portable · Installer MSI · Chocolatey</td> <td>Portatile · Installer MSI · Chocolatey</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Linux</b> <sub>x64/ia32</sub></td> <td align="center"><b>Linux</b> <sub>x64/ia32</sub></td>
<td>Portable · AUR · AppImage · Deb · Flatpak</td> <td>Portatile · AUR · AppImage · Deb · Flatpak</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>macOS</b> <sub>x64/ia32, v12.0+</sub></td> <td align="center"><b>macOS</b> <sub>x64/ia32, v12.0+</sub></td>
@@ -266,9 +311,9 @@ L'app desktop Electron funziona in modo completamente autonomo con il proprio ba
## Installazione ## Installazione
Visita la [Documentazione Termix](https://docs.termix.site/install) per le istruzioni complete di installazione su tutte le piattaforme. Vai alla [documentazione di Termix](https://docs.termix.site/install) per le istruzioni complete di installazione su tutte le piattaforme.
File Docker Compose di esempio (puoi omettere `guacd` e la rete se non prevedi di utilizzare le funzioni di desktop remoto): Esempio di file Docker Compose (puoi togliere `guacd` e la rete se non pensi di usare il desktop remoto):
```yaml ```yaml
services: services:
@@ -305,11 +350,37 @@ networks:
driver: bridge driver: bridge
``` ```
### Riga di comando
Termix ha anche una CLI, così puoi gestire i tuoi server dal terminale e usare Termix nei tuoi script.
```bash
npm install -g @termix-cli/cli
termix login --url https://termix.example.com
termix ssh 1
```
Può aprire terminali, eseguire un comando su un host o su un'intera flotta, spostare file via SFTP e gestire host, frammenti e credenziali. La documentazione completa è su [docs.termix.site/cli](https://docs.termix.site/cli).
### Hosting in cloud
Puoi far girare il server Termix su un VPS invece che dentro la tua rete. Se Termix gira sulla rete che gestisce, un guasto se lo porta via proprio quando ti servirebbe per sistemare le cose. Fuori resta raggiungibile, ti dà un IP fisso e ci entri da ovunque senza VPN né porte aperte.
[GINERNET](https://docs.termix.site/install/ginernet) sponsorizza Termix, e nella documentazione c'è una guida passo passo per il rilascio sulla loro piattaforma VPS.
<br />
## Telemetria
Termix invia una volta al giorno un piccolo segnale anonimo, così posso vedere quante istanze sono attive e quali funzionalità vengono usate davvero. Contiene un ID istanza casuale, quanti utenti e host hai, la versione dell'app e quali funzionalità (terminale, gestore file, tunnel, docker, ecc.) sono state usate nelle ultime 24 ore. Non contiene mai nomi utente, nomi host, indirizzi IP, credenziali o qualsiasi altra cosa che identifichi te o i tuoi server.
È attivo di base. Puoi spegnerlo nelle impostazioni di amministrazione, sezione Generale, oppure impostare `ENABLE_TELEMETRY=false` prima ancora di avviare Termix.
<br /> <br />
## Dona ## Dona
Termix è gratuito e open source, senza abbonamenti o piani a pagamento. Se lo trovi utile, considera di donare per aiutare a coprire i costi del server, i domini e il tempo di sviluppo. Le donazioni aiutano anche a finanziare il tempo necessario per ricercare e imparare ciò che serve per costruire funzionalità come SAML, Kubernetes e supporto Agent. Segui i progressi e dona qui sotto. Termix è gratuito e open source, senza abbonamenti piani a pagamento. Se ti è utile, valuta una donazione per aiutare con server, domini e tempo di sviluppo. Le donazioni finanziano anche il tempo per studiare quello che serve a costruire funzionalità come SAML, Kubernetes e il supporto agli agenti. Segui i progressi e dona qui sotto.
[Dona](https://donate.termix.site/) [Dona](https://donate.termix.site/)
@@ -317,7 +388,7 @@ Termix è gratuito e open source, senza abbonamenti o piani a pagamento. Se lo t
## Sponsor ## Sponsor
Interessato a un posizionamento a pagamento per supportare lo sviluppo? Scrivi a [mail@termix.site](mailto:mail@termix.site). Ti interessa uno spazio a pagamento per sostenere lo sviluppo? Scrivi a [mail@termix.site](mailto:mail@termix.site).
<div align="center"> <div align="center">
@@ -339,10 +410,6 @@ Interessato a un posizionamento a pagamento per supportare lo sviluppo? Scrivi a
<img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" /> <img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" />
</a> </a>
&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;
<a href="https://tailscale.com/">
<img src="https://drive.google.com/uc?export=view&id=1lIxkJuX6M23bW-2FElhT0rQieTrzaVSL" height="40" alt="Tailscale" />
</a>
&nbsp;&nbsp;&nbsp;
<a href="https://akamai.com/"> <a href="https://akamai.com/">
<img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" /> <img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" />
</a> </a>
@@ -354,14 +421,17 @@ Interessato a un posizionamento a pagamento per supportare lo sviluppo? Scrivi a
<a href="https://rackgenius.com/"> <a href="https://rackgenius.com/">
<img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" /> <img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" />
</a> </a>
&nbsp;&nbsp;&nbsp;
<a href="https://ginernet.com/">
<img src="https://ginernet.com/img/logo-web.png" height="40" alt="Ginernet" />
</a>
</div> </div>
<br /> <br />
## Supporto ## Supporto
Se hai bisogno di aiuto o vuoi richiedere una funzionalità per Termix, visita la pagina [Issues](https://github.com/Termix-SSH/Support/issues), accedi e premi `New Issue`. Per favore, sii il più dettagliato possibile nella tua segnalazione, preferibilmente scritta in inglese. Puoi anche unirti al server [Discord](https://discord.gg/jVQGdvHDrf) e visitare il canale di supporto, tuttavia i tempi di risposta potrebbero essere più lunghi. Ti serve aiuto o vuoi proporre una funzionalità? Apri una [nuova issue](https://github.com/Termix-SSH/Support/issues) con più dettagli possibile, in inglese se ci riesci. Puoi anche chiedere nel canale di supporto su [Discord](https://discord.gg/jVQGdvHDrf), anche se lì le risposte possono richiedere più tempo.
<br /> <br />
@@ -413,18 +483,18 @@ Se hai bisogno di aiuto o vuoi richiedere una funzionalità per Termix, visita l
</tr> </tr>
</table> </table>
<sub>Alcuni video e immagini potrebbero non essere aggiornati o potrebbero non mostrare perfettamente le funzionalità.</sub> <sub>Alcuni video e immagini possono essere datati o non mostrare al meglio le funzionalità.</sub>
</div> </div>
<br /> <br />
## Funzionalità Pianificate ## Funzionalità pianificate
Consulta [Projects](https://github.com/orgs/Termix-SSH/projects/5) per tutte le funzionalità pianificate. Se desideri contribuire, consulta [Contributing](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md). Tutte le funzionalità pianificate sono su [Projects](https://github.com/orgs/Termix-SSH/projects/5). Se vuoi contribuire, guarda [Contributing](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md).
<br /> <br />
## Licenza ## Licenza
Distribuito sotto la Licenza Apache Versione 2.0. Consulta `LICENSE` per maggiori informazioni. Distribuito con licenza Apache versione 2.0. Vedi `LICENSE` per maggiori informazioni.
+154 -84
View File
@@ -4,7 +4,7 @@
<h1>Termix</h1> <h1>Termix</h1>
<p>セルフホスト型 SSH 管理とリモートデスクトップアクセス</p> <p>SSH リモートデスクトップから自動化まで、セルフホストのサーバー管理</p>
<p> <p>
<a href="../README.md">English</a> · <a href="../README.md">English</a> ·
@@ -37,7 +37,7 @@
<br /> <br />
Termix は無料オープンソースプロジェクトです。便利だと感じた場合は、サーバーコストと開発時間ために[寄付](https://donate.termix.site/)をご検討ください。 Termix は無料オープンソースです。役に立ったと感じた、サーバー費用と開発時間を支えるために[寄付](https://donate.termix.site/)をご検討ください。
<br /> <br />
@@ -49,7 +49,7 @@ Termix は無料のオープンソースプロジェクトです。便利だと
<p> <p>
<img src="../repo-images/Repo of the Day.png" alt="Repo of the Day Achievement" width="280" /> <img src="../repo-images/Repo of the Day.png" alt="Repo of the Day Achievement" width="280" />
<br /> <br />
<sub>2025年9月1日達成</sub> <sub>2025年9月1日 達成</sub>
</p> </p>
</div> </div>
@@ -58,7 +58,7 @@ Termix は無料のオープンソースプロジェクトです。便利だと
## 概要 ## 概要
Termixは、オープンソースで永久無料のセルフホスト型オールインワンサーバー管理プラットフォームです。単一の直感的なインターフェースを通じて、サーバーとインフラストラクチャを管理するマルチプラットフォームソリューションを提供します。Termixは、SSHターミナルアクセス、リモートデスクトップ制御RDP、VNC、Telnet)、SSHトンネリング機能、リモートファイル管理、およびその他多くのツールを提供します。Termixは、すべてのプラットフォームで利用可能なTermiusの完全無料でセルフホスト可能な代替ソリューションです。 Termix は無料でオープンソースのセルフホスト型サーバー管理プラットフォームです。SSH ターミナル、リモートデスクトップ(RDP、VNC、Telnet)、ファイル転送、トンネル、Docker、メトリクス、自動化をひとつにまとめ、ウェブ、デスクトップ、モバイルで使えます。ずっと無料で使える、セルフホスト版の Termius 代替です。
<br /> <br />
@@ -68,42 +68,42 @@ Termixは、オープンソースで永久無料のセルフホスト型オー
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSHターミナルアクセス:** **SSH ターミナル:**
ブラウザ風タブシステムによる分割画面対応(最大4パネル)のフル機能ターミナル。一般的なターミナルテーマ、フォント、その他のコンポーネントを含むターミナルカスタマイズに対応しています。 ブラウザのようなタブと分割画面を備えた本格的なターミナルで、最大 6 分割まで同時に表示できます。テーマ、フォント、配色は自由に選べます。各セッションの上のツールバーには CPU、メモリ、ディスクの状況がリアルタイムで表示され、そのホストのファイル、Docker、トンネル、メトリクスへすぐ移動できます。
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**リモートデスクトップアクセス:** **リモートデスクトップ:**
ブラウザ上でRDP、VNC、Telnetをサポート、完全なカスタマイズと分割画面に対応しています。 RDP、VNC、Telnet をブラウザから利用でき、他のセッションと同じようにタブや分割画面で扱えます。RDP ドライブ用のファイルブラウザとドラッグ&ドロップのアップロードも使えます。Windows のデスクトップ版では、ホストをネイティブの RDP クライアントで開くこともできます。
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSHトンネル管理:** **SSH トンネル:**
自動再接続とヘルスモニタリング、ローカルリモートダイナミックSOCKSフォワーディングを備えたサーバー間SSHトンネルの作成・管理が可能です。デスクトップクライアント対サーバーのトンネル設定はデスクトップインストールごとにローカルに保存され、オプションのC2Sプリセットスナップショットをサーバーに保存・名前変更・読み込み・削除してクライアント間でローカルトンネル設定を移動できます。 ローカルリモートダイナミック SOCKS の転送に対応し、自動再接続とヘルスチェックが付いています。デスクトップ版のクライアント間トンネルはその端末に保存され、プリセットをサーバーに保存しておけば別の端末に設定を移ます。
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**リモートファイルマネージャー:** **ファイルマネージャー:**
コード、画像、音声、動画の表示・編集に対応し、リモートサーバー上のファイルを直接管理できます。sudo対応でファイルのアップロード、ダウンロード、名前変更、削除、移動をシームレスに実行できます。サーバー間でファイル移動にも対応しています。 SFTP でファイルの閲覧、編集、アップロード、ダウンロード、名前変更、移動、削除ができ、sudo にも対応しています。コード、画像、音声、動画を表示・編集できます。サーバー間で直接ファイルをコピーでき、最速の経路が自動で選ばれ、転送の整合性も検証されます。
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**DockerおよびPodman管理:** **DockerPodman:**
コンテナの起動、停止、一時停止、削除。コンテナの統計情報を表示。docker execターミナルでコンテナを操作。DockerPodmanの両方をコンテナランタイムとしてサポートしています。PortainerDockgeの代替ではなく、コンテナの作成よりも簡易的な管理を目的としています。 コンテナの起動、停止、一時停止、削除ができ、状態を確認したり、中でシェルを開いたりできます。DockerPodman のどちらでも動きます。PortainerDockge を置き換えるためのものではなく、すでにあるコンテナを扱うためのものです。
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSHホストマネージャー:** **ホスト管理:**
タグやフォルダ(フォルダのカスタマイズとネストフォルダ対応)でSSH接続を保存、整理、管理し、再利用可能なログイン情報を簡単に保存しながらSSHキーのデプロイを自動化できます。 タグと、名前や色を付けられる入れ子のフォルダでホストを整理できます。保存した認証情報を複数のホストで使い回し、SSH 鍵を自動で配布し、ホストを親ホストの下にまとめ、一括編集やエクスポートができます。保存したくない一度きりの接続にはクイック接続が使えます。
</td> </td>
</tr> </tr>
@@ -111,97 +111,139 @@ Termixは、オープンソースで永久無料のセルフホスト型オー
<td width="50%" valign="top"> <td width="50%" valign="top">
**ホストメトリクス:** **ホストメトリクス:**
ほとんどのLinuxベースのサーバーでCPU、メモリ、ディスク使用量、ネットワーク、アップタイム、システム情報、ファイアウォール、ポートモニター、ログビューア、ユーザー/権限、証明書など、さらに多くの情報を表示できます。時系列の履歴グラフと、ntfyおよびwebhookに対応したしきい値ベースのアラートを含みます。 たいていの Linux サーバーで CPU、メモリ、ディスク、ネットワーク、温度、稼働時間、プロセス、ポート、ログイン、システム情報を履歴グラフ付きで確認できます。マネージャーカードを使えば、サービス、cron、パッケージ、ユーザー、ファイアウォール、WireGuard、Tailscale、SSL 証明書、ログ、ヘルスチェックを Termix から離れずに扱えます。
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**ユーザー認証:** **自動化:**
管理者コントロール(他のユーザー情報を編集可能)とOIDC/LDAP/SSO(アクセス制御付き)、2FATOTP)、パスキー(WebAuthn)対応による安全なユーザー管理。すべてのプラットフォームでアクティブなユーザーセッションを表示し、権限を取り消し可能。OIDC/ローカルアカウントの連携が可能です。すべてのユーザー操作の監査ログを表示できます。 きっかけを選んで、何をするかを決めるだけです。きっかけには、メトリクスがしきい値を超えたとき、ホストが上がったり落ちたりしたとき、ヘルスチェックの状態が変わったとき、スケジュール、コンテナのイベント、外部からの Webhook があります。ステップではコマンドやスニペットの実行、コンテナやトンネルの操作、ホストの起動、URL の呼び出し、待機、条件分岐、別の自動化の実行ができ、ntfy、Discord、Webhook で通知できます。テスト実行で安全に試せます。
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Tailscaleインテグレーション:** **フリート:**
Tailnetのデバイスをリストしてホストとしてすばやく追加し、Tailscale SSHを認証方法として使用して接続します。これにより、TailnetのACLが認証情報を保存せずに認可を処理します。 ホストを選ぶか、タグのルールを決めてフリートにまとめると、新しいホストは自動で入ります。すべてのホストで同じコマンドを一度に実行し、全台にファイルを配ったり集めたり、パッケージを入れたり、OS、カーネル、アーキテクチャ、稼働時間の一覧を集められます。
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**RBAC/共有:** **AI アシスタント:**
ロールを作成し、ユーザー/ロール間でホストを共有できます。すべての認証タイプとすべてのホストプロトコルに対応しています。 任意の機能で、自分で有効にするまでは動きません。OpenAI、Anthropic、Gemini、Ollama、または OpenAI 互換のエンドポイントにつないで、自分の環境について質問できます。ホスト、フリート、スニペット、アラートを読み取れますが、変更は自分で行わず、承認してもらうための提案として出します。認証情報、ユーザー、設定には決して触れられません。管理者はインスタンス全体で無効にでき、初期設定で非表示にすることもできます。
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**シリアル接続:** **ログインとユーザー:**
ブラウザまたはデスクトップアプリからシリアルデバイス(ルーター、スイッチ、マイクロコントローラーなど)に直接接続できます。ボーレート、データビット、ストップビット、パリティを設定できます。対応ブラウザではWeb Serial APIを使用し、Electronアプリではネイティブバックエンドを使用します。 ローカルアカウントに加えて OIDC、LDAP、GitHub、Google でのサインインに対応し、2 要素認証(TOTP)、パスキー(WebAuthn)、信頼済みデバイスも使えます。管理者はユーザーの管理、OIDC グループとロールの対応付け、全プラットフォームのアクティブなセッションの確認と失効ができます。ローカルと OIDC のアカウントを連携でき、誰が何をしたかは監査ログで確認できます。
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**ロールと共有:**
ロールを作り、接続、閲覧、編集、管理という 4 段階でホストをユーザーやロールに共有できます。すべての認証方式とすべてのプロトコルで使え、共有したホストで使う認証情報を上書きすることもできます。
</td>
</tr>
<tr>
<td width="50%" valign="top">
**アラート:** **アラート:**
ホストメトリクス(CPU、メモリ、ディスクなど)に対してしきい値ベースのアラートルールを設定し、発動時にntfyまたはwebhookで通知を受け取れます。発動中および解決済みのアラート履歴ログで確認できます。 CPU、メモリ、ディスクなどのホストメトリクスにルールを設定し、発報したら ntfy、Discord、Webhook で通知を受け取れます。発報中と解消済みのアラート履歴で確認でき、気にしないものは消しておけます。
</td> </td>
</tr>
<tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**ホームページ:** **ホームページ:**
ドラッグ&ドロップのウィジェットグリッドを備えた完全カスタマイズ可能なホームページ。ホストステータス、サービスリンク、時計、メモ、RSSフィード、天気、Dockerコンテナ、ホストメトリクスグラフ、埋め込みターミナル、iframeなどのウィジェットを追加できます。 自分で組み立てるドラッグ&ドロップのウィジェット画面です。ホストの状態、Ping、サービスリンク、ブックマーク、検索、時計、カレンダー、カウントダウン、メモ、RSS、天気、画像、iframe、Docker、トンネル、メトリクスグラフ、独自 API、さらにはライブのターミナルまでウィジェットとして置けます。
</td>
<td width="50%" valign="top">
**データベース暗号化:**
バックエンドは暗号化されたSQLiteデータベースファイルとして保存されます。詳細は[ドキュメント](https://docs.termix.site)をご覧ください。
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**ネットワークグラフ:** **スニペットとツール:**
ダッシュボードをカスタマイズして、SSH接続に基づくホームラボのネットワークをステータス表示付きで可視化できます。 よく使うコマンドを保存して、ワンクリックで実行できます。ホストの値や自分で入力する値を変数として使えます。開いているすべてのターミナルで同じコマンドをまとめて実行でき、コマンド履歴も補完付きで検索できます。
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSHツール:** **セッション共有:**
ワンクリックで実行できる再利用可能なコマンドスニペットの作成。複数の開いているターミナルに対して同時にコマンドを実行できます。 ターミナル、RDP、VNC、Telnet のセッションをリアルタイムで共有できます。アカウントなしで参加できるリンクを送るか、特定の Termix ユーザーと共有し、閲覧のみか操作可能かを選べます。共有は自動で期限切れにも、いつでも取り消しにもでき、全体またはホストごとにオフにできます。
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**永続タブ:** **セッション録画とログ:**
ユーザープロフィールで有効にすると、SSHセッションとタブがデバイス/更新をまたいで開いたまま保持されます。 ターミナル、RDP、VNC のセッションを録画して、あとから再生できます。セッションのテキストログをダウンロードでき、接続ログを見れば接続中に何が起きたかがそのまま分かります。
</td>
<td width="50%" valign="top">
**シリアル接続:**
ルーター、スイッチ、マイコンなどのシリアル機器に、ブラウザやデスクトップアプリから接続できます。ボーレート、データビット、ストップビット、パリティを設定できます。対応ブラウザでは Web Serial API を、デスクトップアプリではネイティブのバックエンドを使います。
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Tailscale:**
tailnet から端末を取り込んで数クリックでホストとして追加でき、Tailscale SSH で接続すればアクセス制御は tailnet の ACL に任せられ、認証情報を保存する必要がありません。Headscale や独自のエンドポイントにも対応しています。
</td>
<td width="50%" valign="top">
**Proxmox:**
Proxmox のインスタンスからそのままホストを取り込めます。ノードやゲストの CPU、メモリ、ストレージなどの状態を専用のタブで確認できます。
</td>
</tr>
<tr>
<td width="50%" valign="top">
**ワークスペースとタブ:**
タブと分割レイアウトのセットを保存して、ワンクリックでまるごと開き直せます。Termix は前回のセッションも覚えているので、再読み込みしても端末を変えてもタブは戻ってきます。
</td>
<td width="50%" valign="top">
**ガイド付きセットアップ:**
短いセットアップが、画面のプリセット、テーマ、使いたい機能、最初のホストの選択を案内します。シンプルモードは使わないものを隠してくれます。セットアップはいつでもやり直せますし、プリセットも切り替えられます。
</td>
</tr>
<tr>
<td width="50%" valign="top">
**デスクトップ単体利用と同期:**
デスクトップアプリはローカルのバックエンドとデータベースを持ち、サーバーなしで単体で動きます。Termix サーバーにつなげば、ホスト、認証情報、スニペットなどを双方向で同期でき、接続をローカルから始めるかサーバー経由にするかも選べます。
</td>
<td width="50%" valign="top">
**コマンドラインツール:**
シェルやスクリプトから使える `termix` CLI です。ターミナルを開き、ホスト 1 台またはフリート全体でコマンドを実行し、SFTP でファイルを移動し、ホストやスニペット、認証情報を管理できます。`npm install -g @termix-cli/cli` で入れるか、単体のバイナリを使ってください。詳しくは [CLI ドキュメント](https://docs.termix.site/cli)をご覧ください。
</td>
</tr>
<tr>
<td width="50%" valign="top">
**セキュリティ:**
パスワードや鍵などの秘密情報はユーザーごとに暗号化され、データベースのファイル自体もディスク上で暗号化できます。仕組みは[ドキュメント](https://docs.termix.site/security)をご覧ください。
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**多言語対応:** **多言語対応:**
約30言語の組み込みサポート([Crowdin](https://docs.termix.site/translations)で管理されています 30 言語に対応しており、[Crowdin](https://docs.termix.site/translations) で管理ています。
</td>
</tr>
<tr>
<td width="50%" valign="top">
**セッション共有:**
ターミナル、RDP、VNC、Telnetのライブセッションを他のユーザーとリアルタイムで共有できます。リンクで共有(匿名参加、アカウント不要)するか、特定のTermixユーザーと共有し、読み取り専用または読み取り/書き込みアクセスを選択できます。共有は自動的に期限切れになるか、いつでも取り消すことができ、セッション共有はグローバルまたはホストごとに切り替えられます。
</td>
<td width="50%" valign="top">
**デスクトップスタンドアロン + 双方向同期:**
Electronデスクトップアプリは、独自のローカルバックエンドとデータベースを使用して完全にスタンドアロンで動作し、サーバーは不要です。オプションでリモートのTermixサーバーに接続し、ホスト、認証情報、スニペットなどの自動双方向同期を行い、SSH接続をローカルで開始するかリモートサーバー経由で開始するかを選択できます。
</td> </td>
</tr> </tr>
@@ -213,17 +255,20 @@ Electronデスクトップアプリは、独自のローカルバックエンド
<summary><b>その他の機能</b></summary> <summary><b>その他の機能</b></summary>
<br /> <br />
- **ダッシュボード** - ダッシュボードでサーバー情報を一目で確認できます - **ダッシュボード** - 自分で並べたカードでサーバーの状況をひと目で把握
- **APIキー** - 自動化/CI用に有効期限付きのユーザースコープAPIキーを作成できます - **ネットワーク図** - ホストからホームラボを図にして、状態をリアルタイム表示
- **データのエクスポート/インポート** - SSHホスト、認証情報、ファイルマネージャーデータのエクスポートとインポートが可能です - **tmux モニター** - tmux のセッション、ウィンドウ、ペインをプレビューと検索付きで一覧
- **自動SSL設定** - HTTPSリダイレクト付きの組み込みSSL証明書生成・管理が可能です - **API キー** - スクリプトや CI 用の、有効期限付きユーザー単位のキー
- **モダンUI** - React、Tailwind CSS、Shadcnで構築された、デスクトップ/モバイル対応のクリーンなインターフェース。ライト、ダーク、Draculaなど、多くの異なるUIテーマから選択可能。URLルートで任意の接続をフルスクリーンで開くことができます。 - **エクスポートとインポート** - ホスト、認証情報、ファイルマネージャーのデータを出し入れ
- **コマンド履歴** - 過去に実行したSSHコマンドの自動補完と表示が可能で - **自動 SSL** - 証明書の発行と更新、HTTPS へのリダイレクトを自動で。自前の証明書も使えま
- **クイック接続** - 接続データを保存せずにサーバーに接続できます - **データベース** - 標準は SQLite、PostgreSQL と MySQL にも対応
- **コマンドパレット** - 左Shiftキーを2回押すことで、キーボードからSSH接続に素早くアクセスできます - **モダンな UI** - デスクトップでもモバイルでも使える React の画面。ライト、ダーク、Dracula などのテーマ付き。どの接続も URL からフルスクリーンで開けます
- **Proxmox統合** - Proxmoxインスタンスからホストを自動的にTermixに追加できます - **コマンドパレット** - 左 Shift の 2 回押しで、キーボードからホストへ移動
- **SSH機能充実** - ジャンプホスト、Warpgate、TOTPベースの接続、SOCKS5、ホストキー検証、パスワード自動入力、[OPKSSH](https://github.com/openpubkey/opkssh)、tmux、ポート敲き(port knocking)、ターミナルログ記録、SSHエージェントフォワーディング、Bitwarden SSHエージェント、HashiCorp Vault SSH署名などに対応しています - **キーボードショートカット** - タブの移動や閉じる操作など、すべて割り当て変更可能
- **Termix ID** - Termixに組み込まれたsshid.io相当の機能です。ハンドルを取得し、リゾルバーURLで公開SSHキーを公開し、組み込みCAを使用してSSH証明書を発行できます。 - **Wake-on-LAN** - Termix からでも自動化のステップからでもマシンを起動
- **信頼済みプロキシ認証** - リバースプロキシにサインインを任せ、ユーザー情報を引き継ぎ
- **充実した SSH 機能** - 踏み台ホスト、Warpgate、TOTP の入力、SOCKS5、ホスト鍵の検証、パスワードの自動入力、[OPKSSH](https://github.com/openpubkey/opkssh)、tmux、ポートノッキング、ターミナルのログ、エージェント転送、Bitwarden SSH エージェント、HashiCorp Vault の SSH 署名など
- **Termix ID** - sshid.io のような仕組みを内蔵。ハンドルを取得し、公開鍵をリゾルバー URL で公開し、内蔵 CA から SSH 証明書を発行できます
</details> </details>
@@ -238,15 +283,15 @@ Electronデスクトップアプリは、独自のローカルバックエンド
</tr> </tr>
<tr> <tr>
<td align="center"><b>Web</b></td> <td align="center"><b>Web</b></td>
<td>あらゆる最新ブラウザ(Chrome、Safari、Firefox)· PWA対応</td> <td>最近のブラウザ全般Chrome、Safari、Firefox)· PWA 対応</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Windows</b> <sub>x64/ia32</sub></td> <td align="center"><b>Windows</b> <sub>x64/ia32</sub></td>
<td>ポータブル · MSIインストーラー · Chocolatey</td> <td>ポータブル · MSI インストーラー · Chocolatey</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Linux</b> <sub>x64/ia32</sub></td> <td align="center"><b>Linux</b> <sub>x64/ia32</sub></td>
<td>ポータブル · AUR · AppImage · Deb · Flatpak</td> <td>ポータブル · AUR · AppImage · Deb · Flatpak</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>macOS</b> <sub>x64/ia32, v12.0+</sub></td> <td align="center"><b>macOS</b> <sub>x64/ia32, v12.0+</sub></td>
@@ -266,9 +311,9 @@ Electronデスクトップアプリは、独自のローカルバックエンド
## インストール ## インストール
すべてのプラットフォームへのTermixのインストール方法については、[Termixドキュメント](https://docs.termix.site/install)をご覧ください。 すべてのプラットフォーム向けの詳しいインストール手順は [Termix ドキュメント](https://docs.termix.site/install)をご覧ください。
サンプルDocker Composeファイル(リモートデスクトップ機能を使用する予定がない場合は、`guacd`とネットワークの設定を省略できます) Docker Compose の例です(リモートデスクトップ機能を使わないなら `guacd` とネットワークの部分は省略できます):
```yaml ```yaml
services: services:
@@ -305,11 +350,37 @@ networks:
driver: bridge driver: bridge
``` ```
### コマンドラインツール
Termix には CLI もあるので、ターミナルからサーバーを管理したり、自分のスクリプトに組み込んだりできます。
```bash
npm install -g @termix-cli/cli
termix login --url https://termix.example.com
termix ssh 1
```
ターミナルを開き、ホスト 1 台またはフリート全体でコマンドを実行し、SFTP でファイルを移動し、ホストやスニペット、認証情報を管理できます。詳しい説明は [docs.termix.site/cli](https://docs.termix.site/cli) にあります。
### クラウドでの運用
Termix のサーバーは自分のネットワーク内ではなく、VPS で動かすこともできます。管理対象のネットワーク上で動かしていると、障害が起きたときに Termix も一緒に落ちてしまい、直したいときに限って使えなくなります。外で動かしておけばいつでも届きますし、固定 IP も手に入り、VPN やポート開放なしでどこからでも入れます。
[GINERNET](https://docs.termix.site/install/ginernet) は Termix のスポンサーで、同社の VPS へデプロイする手順はドキュメントに詳しく載っています。
<br />
## テレメトリー
Termix は 1 日 1 回、匿名の小さなデータを送ります。どれくらいのインスタンスが動いていて、どの機能が使われているかを把握するためのものです。含まれるのはランダムなインスタンス ID、ユーザーとホストの数、アプリのバージョン、直近 24 時間に使われた機能(ターミナル、ファイルマネージャー、トンネル、Docker など)だけです。ユーザー名、ホスト名、IP アドレス、認証情報など、あなたやサーバーを特定できるものは一切含まれません。
初期状態では有効です。管理設定の「一般」から止められますし、Termix を起動する前に `ENABLE_TELEMETRY=false` を設定しておくこともできます。
<br /> <br />
## 寄付 ## 寄付
Termixは無料オープンソースプロジェクトであり、サブスクリプション有料プランありません。便利だと感じた場合は、サーバーコスト、ドメイン、開発時間を賄うための寄付をご検討ください。寄付はSAML、Kubernetes、Agentサポートなどの機能を構築するために必要な調査学習の時間を確保することにも役立ちます。以下で進捗を確認し、寄付できます Termix は無料オープンソース、サブスクリプション有料プランありません。役に立っていると感じた、サーバー、ドメイン、開発時間を支えるための寄付をご検討ください。寄付は SAML、Kubernetes、エージェント対応といった機能を作るための調査学習の時間にもあてられます。進み具合の確認と寄付は下記からどうぞ
[寄付する](https://donate.termix.site/) [寄付する](https://donate.termix.site/)
@@ -317,7 +388,7 @@ Termixは無料のオープンソースプロジェクトであり、サブス
## スポンサー ## スポンサー
開発を支援するための有料掲載にご興味がありますか[mail@termix.site](mailto:mail@termix.site)までメールをお送りください。 有料掲載で開発を支援することにご興味がありますか[mail@termix.site](mailto:mail@termix.site) までご連絡ください。
<div align="center"> <div align="center">
@@ -339,10 +410,6 @@ Termixは無料のオープンソースプロジェクトであり、サブス
<img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" /> <img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" />
</a> </a>
&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;
<a href="https://tailscale.com/">
<img src="https://drive.google.com/uc?export=view&id=1lIxkJuX6M23bW-2FElhT0rQieTrzaVSL" height="40" alt="Tailscale" />
</a>
&nbsp;&nbsp;&nbsp;
<a href="https://akamai.com/"> <a href="https://akamai.com/">
<img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" /> <img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" />
</a> </a>
@@ -354,14 +421,17 @@ Termixは無料のオープンソースプロジェクトであり、サブス
<a href="https://rackgenius.com/"> <a href="https://rackgenius.com/">
<img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" /> <img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" />
</a> </a>
&nbsp;&nbsp;&nbsp;
<a href="https://ginernet.com/">
<img src="https://ginernet.com/img/logo-web.png" height="40" alt="Ginernet" />
</a>
</div> </div>
<br /> <br />
## サポート ## サポート
Termixに関するヘルプや機能リクエストが必要な場合は、[Issues](https://github.com/Termix-SSH/Support/issues)ページにアクセスし、ログインして`New Issue`を押してください。Issueはできるだけ詳細に記述し、英語での記述が望ましいです。また、[Discord](https://discord.gg/jVQGdvHDrf)サーバーに参加してサポートチャンネルを利用することもできますが、応答時間が長くなる場合があります。 困ったときや機能の要望があるときは、[新しい issue](https://github.com/Termix-SSH/Support/issues) を作って、できるだけ詳しく、できれば英語で書いてください。[Discord](https://discord.gg/jVQGdvHDrf) のサポートチャンネルでも質問できますが、返信には時間がかかることがあります。
<br /> <br />
@@ -373,7 +443,7 @@ Termixに関するヘルプや機能リクエストが必要な場合は、[Issu
[![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos) [![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos)
<sub>YouTubeでアップデートの概要を視聴する</sub> <sub>YouTube でアップデートの紹介を見る</sub>
<br /> <br />
<br /> <br />
@@ -413,7 +483,7 @@ Termixに関するヘルプや機能リクエストが必要な場合は、[Issu
</tr> </tr>
</table> </table>
<sub>動画や画像の一部は最新ではない場合や、機能を完全に紹介できていない場合があります。</sub> <sub>動画や画像は古くなっていたり、機能を十分に伝えられていない場合があります。</sub>
</div> </div>
@@ -421,10 +491,10 @@ Termixに関するヘルプや機能リクエストが必要な場合は、[Issu
## 予定されている機能 ## 予定されている機能
すべての予定機能については[Projects](https://github.com/orgs/Termix-SSH/projects/5)をご覧ください。コントリビュートをご希望の方は[Contributing](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md)をご覧ください。 予定されている機能はすべて [Projects](https://github.com/orgs/Termix-SSH/projects/5) にあります。貢献をお考えの方は[コントリビューションガイド](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md)をご覧ください。
<br /> <br />
## ライセンス ## ライセンス
Apache License Version 2.0のもとで配布されています。詳細は`LICENSE`をご覧ください。 Apache License 2.0 のもとで配布ています。詳しくは `LICENSE` をご覧ください。
+160 -90
View File
@@ -4,7 +4,7 @@
<h1>Termix</h1> <h1>Termix</h1>
<p>셀프 호스팅 SSH 관리 및 원격 데스크톱 액세스</p> <p>SSH와 원격 데스크톱부터 자동화까지, 셀프 호스팅 서버 관리</p>
<p> <p>
<a href="../README.md">English</a> · <a href="../README.md">English</a> ·
@@ -37,7 +37,7 @@
<br /> <br />
Termix는 무료 오픈소스 프로젝트입니다. 유용하게 사용하고 있다면 서버 비용과 개발 시간을 위해 [후원](https://donate.termix.site/)을 고려해 주세요. Termix는 무료이며 오픈 소스입니다. 유용하게 쓰고 계시다면 서버 비용과 개발 시간에 보탬이 되도록 [후원](https://donate.termix.site/)을 고려해 주세요.
<br /> <br />
@@ -58,7 +58,7 @@ Termix는 무료 오픈소스 프로젝트입니다. 유용하게 사용하고
## 개요 ## 개요
Termix는 오픈 소스이며 영구 무료인 셀프 호스팅 올인원 서버 관리 플랫폼입니다. 단일 직관적인 인터페이스를 통해 서버와 인프라를 관리할 수 있는 멀티 플랫폼 솔루션을 제공합니다. Termix는 SSH 터미널 접속, 원격 데스크톱 제어(RDP, VNC, Telnet), SSH 터널링 기능, 원격 SSH 파일 관리 및 기타 다양한 도구를 제공합니다. Termix는 모든 플랫폼에서 사용 가능한 Termius의 완벽한 무료 셀프 호스팅 대안입니다. Termix는 무료 오픈 소스 셀프 호스팅 서버 관리 플랫폼입니다. SSH 터미널, 원격 데스크톱(RDP, VNC, Telnet), 파일 전송, 터널, Docker, 지표, 자동화를 한곳에 모아 웹과 데스크톱, 모바일에서 쓸 수 있습니다. 계속 무료로 쓸 수 있는 셀프 호스팅 Termius 대안입니다.
<br /> <br />
@@ -68,140 +68,182 @@ Termix는 오픈 소스이며 영구 무료인 셀프 호스팅 올인원 서버
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH 터미널 접속:** **SSH 터미널:**
브라우저 스타일 탭 시스템과 분할 화면 지원(최대 4개 패널)을 갖춘 완전한 기능의 터미널. 일반 터미널 테마, 글꼴 및 기타 구성 요소를 포함한 터미널 사용자 정의 지원. 브라우저 같은 탭과 분할 화면을 갖춘 제대로 된 터미널로, 한 번에 최대 6개 패널까지 띄울 수 있습니다. 테마 글꼴, 색을 골라 쓸 수 있습니다. 각 세션 위의 툴바에는 CPU, 메모리, 디스크가 실시간으로 표시되고, 해당 호스트의 파일과 Docker, 터널, 지표로 바로 갈 수 있습니다.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**원격 데스크톱 접속:** **원격 데스크톱:**
완전한 사용자 정의와 분할 화면을 지원하는 브라우저 기반 RDP, VNC, Telnet 지원. 브라우저에서 RDP와 VNC, Telnet을 쓸 수 있고 다른 세션과 똑같이 탭과 분할 화면으로 다룰 수 있습니다. RDP 드라이브용 파일 브라우저와 끌어다 놓기 업로드도 있습니다. Windows 데스크톱에서는 호스트를 기본 RDP 클라이언트로 열 수도 있습니다.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH 터널 관리:** **SSH 터널:**
자동 재연결, 상태 모니터링, 로컬·원격·동적 SOCKS 포워딩을 지원하는 서버 간 SSH 터널 생성 및 관리. 데스크톱 클라이언트-서버 터널 설정은 데스크톱 설치별로 로컬에 저장되, 선택적 C2S 사전 설정 스냅샷을 서버에 저장·이름 변경·불러오기·삭제하여 클라이언트 간 로컬 터널 구성을 이동할 수 있습니다. 로컬과 원격, 동적 SOCKS 포워딩을 지원하며 자동 재연결과 상태 확인이 붙어 있습니다. 데스크톱 앱의 클라이언트서버 터널은 그 컴퓨터에 저장되, 프리셋을 서버에 저장해 두면 다른 컴퓨터로 설정을 옮길 수 있습니다.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**원격 파일 관리자:** **파일 관리자:**
코드, 이미지, 오디오, 비디오기 및 편집을 지원하여 원격 서버에서 파일을 직접 관리. sudo 지원으로 파일 업로드, 다운로드, 이름 변경, 삭제, 이동을 원활하게 수행. 서버 간 파일 이동도 지원합니다. SFTP로 파일을 살펴보고 편집하고 올리고 내려받고 이름을 바꾸고 옮기고 지울 수 있으며 sudo도 됩니다. 코드 이미지, 오디오, 비디오고 편집할 수 있습니다. 서버에서 서버로 파일을 바로 복사할 수 있는데, 가장 빠른 경로가 자동으로 선택되고 전송 무결성도 확인합니다.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Docker Podman 관리:** **Docker Podman:**
컨테이너 시작, 중지, 일시 정지, 제거. 컨테이너 통계 보기. docker exec 터미널로 컨테이너 제어. Docker와 Podman 모두 컨테이너 런타임으로 지원. Portainer나 Dockge를 대체하기 위한 것이 아니라 컨테이너 생성보다는 간편한 관리를 목적으로 합니다. 컨테이너 시작하고 멈추고 일시 정지하고 지울 수 있으며, 상태를 보거나 안에서 셸을 열 수 있습니다. Docker와 Podman 모두에서 동작합니다. Portainer나 Dockge를 대신하려는 것이 아니라, 이미 있는 컨테이너를 다루기 위한 것입니다.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH 호스트 관리:** **호스트 관리:**
태그와 폴더(폴더 사용자 지정 및 중첩 폴더 지원)로 SSH 연결을 저장, 정리, 관리하고, 재사용 가능한 로그인 정보를 쉽게 저장하면서 SSH 키 배포를 자동화. 태그와, 이름과 색을 붙일 수 있는 중첩 폴더로 호스트를 정리합니다. 저장한 자격 증명을 여러 호스트에서 다시 쓰고, SSH 키를 자동으로 배포하고, 호스트를 상위 호스트 아래로 묶고, 한꺼번에 편집하거나 내보낼 수 있습니다. 저장하고 싶지 않은 일회성 연결에는 빠른 연결을 쓰면 됩니다.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**호스트 메트릭:** **호스트 지표:**
대부분의 Linux 기반 서버에서 CPU, 메모리, 디스크 사용량, 네트워크, 업타임, 시스템 정보, 방화벽, 포트 모니터, 로그 뷰어, 사용자/권한, 인증서 등 다양한 정보를 표시. 시계열 히스토리 그래프와 ntfy 및 웹훅을 지원하는 임계값 기반 알림을 포함합니다. 대부분의 리눅스 서버에서 CPU, 메모리, 디스크, 네트워크, 온도, 가동 시간, 프로세스, 포트, 로그인, 시스템 정보를 기록 그래프와 함께 볼 수 있습니다. 관리 카드로 서비스와 cron 작업, 패키지, 사용자, 방화벽 규칙, WireGuard, Tailscale, SSL 인증서, 로그, 상태 확인을 Termix 안에서 처리할 수 있습니다.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**사용자 인증:** **자동화:**
관리자 제어(다른 사용자 정보 편집 가능)와 OIDC/LDAP/SSO(액세스 제어 포함), 2FA(TOTP), 패스키(WebAuthn) 지원을 통한 안전한 사용자 관리. 모든 플랫폼에서 활성 사용자 세션을 보고 권한을 취소 가능. OIDC/로컬 계정 연동. 모든 사용자 작업의 감사 로그 조회. 먼저 조건을 고르고, 무슨 일이 일어날지 정하면 됩니다. 조건에는 지표가 기준을 넘을 때, 호스트가 올라오거나 내려갈 때, 상태 확인 결과가 바뀔 때, 정해진 일정, 컨테이너 이벤트, 들어오는 웹훅이 있습니다. 각 단계에서 명령과 스니펫을 실행하고, 컨테이너와 터널을 조작하고, 호스트를 깨우고, URL을 호출하고, 기다리고, 조건에 따라 갈라지고, 다른 자동화를 실행하고, ntfy나 Discord, 웹훅으로 알릴 수 있습니다. 테스트 실행으로 먼저 안전하게 시험해 볼 수 있습니다.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Tailscale 통합:** **플릿:**
Tailscale 네트워크의 기기를 나열하여 호스트로 빠르게 추가하고, Tailscale SSH를 인증 방법으로 사용하여 연결함으로써 자격 증명을 저장하지 않고도 네트워크 ACL이 권한 부여를 처리하도록 합니다. 호스트를 직접 고르거나 태그 규칙으로 플릿에 묶으면 새 호스트는 알아서 들어옵니다. 모든 호스트에서 같은 명령을 한 번에 실행하고, 전부에 파일을 보내고 가져오고, 패키지를 설치하고, OS와 커널, 아키텍처, 가동 시간 목록을 모을 수 있습니다.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**RBAC/공유:** **AI 어시스턴트:**
역할을 생성하고 사용자/역할 간에 호스트를 공유합니다. 모든 인증 유형과 모든 호스트 프로토콜을 지원합니다. 선택 기능이며 직접 켜기 전까지는 꺼져 있습니다. OpenAI, Anthropic, Gemini, Ollama 또는 OpenAI 호환 엔드포인트를 연결해 내 환경에 대해 물어볼 수 있습니다. 호스트와 플릿, 스니펫, 알림을 읽을 수 있지만 직접 바꾸지 않고 승인받을 제안으로 내놓습니다. 자격 증명과 사용자, 설정에는 절대 접근할 수 없습니다. 관리자는 인스턴스 전체에서 꺼 둘 수 있고, 초기 설정에서 아예 숨길 수도 있습니다.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**시리얼 연결:** **로그인과 사용자:**
브라우저 또는 데스크톱 앱에서 직접 시리얼 장치(라우터, 스위치, 마이크로컨트롤러 등)에 연결. 보드레이트, 데이터 비트, 스톱 비트, 패리티 구성. 지원 브라우저에서는 Web Serial API를, Electron 앱에서는 네이티브 백엔드를 사용합니다. 로컬 계정과 함께 OIDC, LDAP, GitHub, Google 로그인을 지원하고 2단계 인증(TOTP), 패스키(WebAuthn), 신뢰할 수 있는 기기도 쓸 수 있습니다. 관리자는 사용자를 관리하고, OIDC 그룹을 역할에 연결하고, 모든 플랫폼의 활성 세션을 보고 해지할 수 있습니다. 로컬 계정과 OIDC 계정을 연결할 수 있고, 누가 무엇을 했는지는 감사 로그에서 확인합니다.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**역할과 공유:**
역할을 만들고 연결, 보기, 편집, 관리라는 네 단계로 호스트를 사용자나 역할에 공유할 수 있습니다. 모든 인증 방식과 모든 프로토콜에서 동작하며, 공유한 호스트에 쓸 자격 증명을 따로 지정할 수도 있습니다.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**알림:** **알림:**
호스트 메트릭(CPU, 메모리, 디스크 등)에 대한 임계값 기반 알림 규칙을 설정하고 트리거될 때 ntfy 또는 웹훅을 통해 알림 수신. 기록 로그에서 발생 중인 알림과 해된 알림 확인. CPU 메모리, 디스크 같은 호스트 지표에 규칙을 걸어 두고 조건이 걸리면 ntfy나 Discord, 웹훅으로 알림을 받습니다. 발생 중인 알림과 해된 알림을 기록에서 보고, 신경 쓰지 않을 것은 지워 둘 수 있습니다.
</td> </td>
</tr>
<tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**홈페이지:** **홈페이지:**
드래그 앤 드롭 위젯 그리드를 갖춘 완전 맞춤형 홈페이지. 호스트 상태, 서비스 링크, 시계, 메모, RSS 피드, 날씨, Docker 컨테이너, 호스트 메트릭 차트, 임베디드 터미널, iframe 등의 위젯 추가 가능. 직접 꾸미는 끌어다 놓기 위젯 화면입니다. 호스트 상태, 핑, 서비스 링크, 북마크, 검색, 시계, 달력, 카운트다운, 메모, RSS, 날씨, 이미지, iframe, Docker, 터널, 지표 차트, 사용자 API, 심지어 살아 있는 터미널까지 위젯으로 놓을 수 있습니다.
</td>
<td width="50%" valign="top">
**데이터베이스 암호화:**
백엔드가 암호화된 SQLite 데이터베이스 파일로 저장됨. 자세한 내용은 [문서](https://docs.termix.site)를 참조하세요.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**네트워크 그래프:** **스니펫과 도구:**
대시보드를 사용자 정의하여 SSH 연결 기반의 홈랩 네트워크를 상태 표시와 함께 시각화. 자주 쓰는 명령을 저장해 두고 한 번에 실행할 수 있으며, 호스트 값이나 직접 넣는 값을 변수로 쓸 수 있습니다. 열려 있는 모든 터미널에서 같은 명령을 한꺼번에 실행할 수 있고, 명령 기록도 자동 완성으로 찾을 수 있습니다.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH 도구:**
한 번의 클릭으로 실행 가능한 재사용 가능 명령어 스니펫 생성. 여러 열린 터미널에서 동시에 하나의 명령어 실행.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**지속 탭:**
사용자 프로필에서 활성화된 경우 SSH 세션 및 탭이 기기/새로 고침 간에 열린 상태 유지.
</td>
<td width="50%" valign="top">
**다국어 지원:**
약 30개 언어 내장 지원([Crowdin](https://docs.termix.site/translations)으로 관리).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**세션 공유:** **세션 공유:**
터미널, RDP, VNC, Telnet 세션을 다른 사람과 실시간으로 공유하세요. 링크를 통해 공유(계정 없이 익명으로 참여)하거나 특정 Termix 사용자와 공유할 수 있으며, 읽기 전용 또는 읽기/쓰기 권한을 선택할 수 있습니다. 공유는 자동으로 만료되거나 언제든 취소 수 있으며, 세션 공유는 전역 또는 호스트별로 전환할 수 있습니다. 터미널 RDP, VNC, Telnet 세션을 실시간으로 공유합니다. 계정 없이 들어올 수 있는 링크를 보내거나 특정 Termix 사용자와 공유할 수 있고, 보기만 할지 조작까지 할지 고를 수 있습니다. 공유는 알아서 만료되게 하거나 언제든 취소 수 있고, 전체 또는 호스트별로 꺼 둘 수 있습니다.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**세션 녹화와 로그:**
터미널과 RDP, VNC 세션을 녹화해 두었다가 나중에 다시 볼 수 있습니다. 세션의 텍스트 로그를 내려받을 수 있고, 연결 로그를 보면 연결하는 동안 무슨 일이 있었는지 그대로 알 수 있습니다.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**데스크톱 독립 실행 + 양방향 동기화:** **시리얼 연결:**
Electron 데스크톱 앱은 자체 로컬 백엔드와 데이터베이스를 사용하여 서버 없이 완전히 독립적으로 실행됩니다. 선택적으로 원격 Termix 서버에 연결하여 호스트, 자격 증명, 스니펫 등을 자동으로 양방향 동기화하고, SSH 연결을 로컬에서 시작할지 원격 서버를 통해 시작할지 선택할 수 있습니다. 라우터와 스위치, 마이크로컨트롤러 같은 시리얼 장치에 브라우저나 데스크톱 앱에서 접속할 수 있습니다. 보드레이트와 데이터 비트, 스톱 비트, 패리티를 설정할 수 있습니다. 지원되는 브라우저에서는 Web Serial API를, 데스크톱 앱에서는 네이티브 백엔드를 씁니다.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Tailscale:**
tailnet에서 기기를 가져와 몇 번의 클릭으로 호스트로 추가하고, Tailscale SSH로 접속하면 접근 권한은 tailnet ACL이 처리하므로 자격 증명을 저장할 필요가 없습니다. Headscale과 사용자 지정 엔드포인트도 됩니다.
</td>
<td width="50%" valign="top">
**Proxmox:**
Proxmox 인스턴스에서 호스트를 바로 가져오고, 노드와 게스트의 CPU와 메모리, 스토리지 상태를 전용 탭에서 볼 수 있습니다.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**워크스페이스와 탭:**
탭과 분할 배치를 통째로 저장해 두고 한 번에 다시 열 수 있습니다. Termix는 마지막 세션도 기억하기 때문에 새로 고침을 하거나 기기를 바꿔도 탭이 그대로 돌아옵니다.
</td>
<td width="50%" valign="top">
**설치 안내:**
짧은 설정 과정이 화면 프리셋과 테마, 쓰고 싶은 기능, 첫 호스트를 고르도록 안내합니다. 간단 모드는 쓰지 않는 것을 숨겨 주고, 설정은 언제든 다시 하거나 프리셋을 바꿀 수 있습니다.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**데스크톱 단독 실행과 동기화:**
데스크톱 앱은 자체 백엔드와 데이터베이스로 서버 없이 혼자 돌아갑니다. Termix 서버에 연결하면 호스트와 자격 증명, 스니펫 등을 양방향으로 동기화할 수 있고, 연결을 로컬에서 시작할지 서버를 거칠지도 고를 수 있습니다.
</td>
<td width="50%" valign="top">
**명령줄 도구:**
셸과 스크립트에서 쓰는 `termix` CLI입니다. 터미널을 열고, 호스트 하나나 플릿 전체에서 명령을 실행하고, SFTP로 파일을 옮기고, 호스트와 스니펫, 자격 증명을 관리할 수 있습니다. `npm install -g @termix-cli/cli`로 설치하거나 단독 실행 파일을 받으면 됩니다. [CLI 문서](https://docs.termix.site/cli)를 참고하세요.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**보안:**
비밀번호와 키를 비롯한 비밀 정보는 사용자별로 암호화되고, 데이터베이스 파일 자체도 디스크에서 암호화할 수 있습니다. 어떻게 동작하는지는 [문서](https://docs.termix.site/security)에서 볼 수 있습니다.
</td>
<td width="50%" valign="top">
**언어:**
약 30개 언어가 기본으로 들어 있으며 [Crowdin](https://docs.termix.site/translations)으로 관리합니다.
</td> </td>
</tr> </tr>
@@ -213,17 +255,20 @@ Electron 데스크톱 앱은 자체 로컬 백엔드와 데이터베이스를
<summary><b>더 많은 기능</b></summary> <summary><b>더 많은 기능</b></summary>
<br /> <br />
- **대시보드** - 대시보드에서 서버 정보를 한눈에 확인 - **대시보드** - 직접 배치한 카드로 서버 상태를 한눈에
- **API 키** - 자동화/CI에 사용할 만료일이 있는 사용자 범위 API 키 생성 - **네트워크 그래프** - 호스트를 바탕으로 홈랩을 그려 주고 상태를 실시간 표시
- **데이터 내보내기/가져오기** - SSH 호스트, 자격 증명, 파일 관리자 데이터의 내보내기 및 가져오 - **tmux 모니터** - tmux 세션과 창, 페인을 미리보기와 검색으로 살펴보
- **자동 SSL 설정** - HTTPS 리디렉션을 포함한 내장 SSL 인증서 생성 및 관리 - **API 키** - 스크립트와 CI용, 만료일이 있는 사용자별 키
- **모던 UI** - React, Tailwind CSS, Shadcn으로 구축된 깔끔한 데스크톱/모바일 친화적 인터페이스. 라이트, 다크, 드라큘라 등 다양한 UI 테마 선택 가능. URL 라우트를 사용하여 모든 연결을 전체 화면으로 열기 가능. - **내보내기와 가져오기** - 호스트와 자격 증명, 파일 관리자 데이터를 옮기기
- **명령어 기록** - 이전에 실행한 SSH 명령어의 자동 완성 및 조회 - **자동 SSL** - 인증서 발급과 갱신, HTTPS 리다이렉트를 알아서. 직접 만든 인증서도 쓸 수 있습니다
- **빠른 연결** - 연결 데이터를 저장하지 않고 서버에 접속 - **데이터베이스** - 기본은 SQLite, PostgreSQL과 MySQL도 지원
- **명령어 팔레트** - 왼쪽 Shift 키를 두 번 눌러 키보드로 SSH 연결에 빠르게 접근 - **현대적인 UI** - 데스크톱과 모바일에서 모두 쓸 수 있는 깔끔한 React 화면. 라이트와 다크, Dracula 같은 테마 제공. 어떤 연결이든 URL로 전체 화면에서 열 수 있습니다
- **Proxmox 통합** - Proxmox 인스턴스에서 Termix로 호스트를 자동 추가 - **명령 팔레트** - 왼쪽 Shift를 두 번 눌러 키보드로 호스트로 이동
- **풍부한 SSH 기능** - 점프 호스트, Warpgate, TOTP 기반 연결, SOCKS5, 호스트 키 검증, 비밀번호 자동 입력, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, 포트 노킹, 터미널 로깅, SSH 에이전트 포워딩, Bitwarden SSH 에이전트, HashiCorp Vault SSH 서명 등 지원. - **키보드 단축키** - 탭 이동과 닫기 등, 모두 다시 지정할 수 있습니다
- **Termix ID** - Termix에 내장된 sshid.io와 동등한 기능. 핸들을 등록하고, 리졸버 URL에 공개 SSH 키를 게시하며, 내장 CA를 사용하여 SSH 인증서를 발급할 수 있습니다. - **Wake-on-LAN** - Termix에서도, 자동화 단계에서도 컴퓨터를 켜기
- **신뢰할 수 있는 프록시 인증** - 리버스 프록시가 로그인을 처리하고 사용자 정보를 넘겨주기
- **풍부한 SSH 기능** - 점프 호스트, Warpgate, TOTP 입력, SOCKS5, 호스트 키 확인, 비밀번호 자동 입력, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, 포트 노킹, 터미널 로그, 에이전트 포워딩, Bitwarden SSH 에이전트, HashiCorp Vault SSH 서명 등
- **Termix ID** - sshid.io 같은 기능을 내장했습니다. 핸들을 등록하고 리졸버 URL에 공개 키를 올리고 내장 CA에서 SSH 인증서를 발급할 수 있습니다
</details> </details>
@@ -234,15 +279,15 @@ Electron 데스크톱 앱은 자체 로컬 백엔드와 데이터베이스를
<table align="center"> <table align="center">
<tr> <tr>
<th align="center">플랫폼</th> <th align="center">플랫폼</th>
<th align="center">배포</th> <th align="center">배포 형태</th>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Web</b></td> <td align="center"><b>Web</b></td>
<td>모든 최신 브라우저(Chrome, Safari, Firefox) · PWA 지원</td> <td>최신 브라우저 전반(Chrome, Safari, Firefox) · PWA 지원</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Windows</b> <sub>x64/ia32</sub></td> <td align="center"><b>Windows</b> <sub>x64/ia32</sub></td>
<td>포터블 · MSI 설치 프로그램 · Chocolatey</td> <td>포터블 · MSI 설치 파일 · Chocolatey</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Linux</b> <sub>x64/ia32</sub></td> <td align="center"><b>Linux</b> <sub>x64/ia32</sub></td>
@@ -266,9 +311,9 @@ Electron 데스크톱 앱은 자체 로컬 백엔드와 데이터베이스를
## 설치 ## 설치
모든 플랫폼에 Termix를 설치하는 방법에 대한 자세한 내용은 Termix [문서](https://docs.termix.site/install)를 방문하세요. 모든 플랫폼의 자세한 설치 방법은 [Termix 문서](https://docs.termix.site/install)를 참고하세요.
다음은 Docker Compose 파일 예시입니다(원격 데스크톱 기능을 사용할 계획이 없다면 guacd와 네트워크를 생략할 수 있습니다): Docker Compose 예시입니다(원격 데스크톱 기능을 쓰지 않는다면 `guacd`와 네트워크 부분은 빼도 됩니다):
```yaml ```yaml
services: services:
@@ -305,11 +350,37 @@ networks:
driver: bridge driver: bridge
``` ```
### 명령줄 도구
Termix에는 CLI도 있어서 터미널에서 서버를 관리하거나 Termix를 자기 스크립트에 넣어 쓸 수 있습니다.
```bash
npm install -g @termix-cli/cli
termix login --url https://termix.example.com
termix ssh 1
```
터미널을 열고, 호스트 하나나 플릿 전체에서 명령을 실행하고, SFTP로 파일을 옮기고, 호스트와 스니펫, 자격 증명을 관리할 수 있습니다. 전체 문서는 [docs.termix.site/cli](https://docs.termix.site/cli)에 있습니다.
### 클라우드 호스팅
Termix 서버는 집 안 네트워크가 아니라 VPS에서 돌릴 수도 있습니다. 관리 대상 네트워크 위에서 돌아가면 장애가 났을 때 Termix도 같이 멈춰서, 정작 고쳐야 할 때 쓸 수 없게 됩니다. 밖에서 돌리면 언제든 접속할 수 있고 고정 IP도 생기며, VPN이나 포트 포워딩 없이 어디서나 들어갈 수 있습니다.
[GINERNET](https://docs.termix.site/install/ginernet)은 Termix를 후원하고 있으며, 문서에 이 회사 VPS에 배포하는 단계별 안내가 있습니다.
<br />
## 텔레메트리
Termix는 하루에 한 번 익명의 작은 데이터를 보냅니다. 인스턴스가 얼마나 돌아가는지, 어떤 기능이 쓰이는지 파악하기 위한 것입니다. 여기에는 무작위 인스턴스 ID, 사용자와 호스트 수, 앱 버전, 최근 24시간 동안 쓴 기능(터미널, 파일 관리자, 터널, Docker 등)만 들어갑니다. 사용자 이름과 호스트 이름, IP 주소, 자격 증명처럼 나나 내 서버를 알아볼 수 있는 것은 전혀 담기지 않습니다.
기본으로 켜져 있습니다. 관리 설정의 일반에서 끄거나, Termix를 시작하기 전에 `ENABLE_TELEMETRY=false`를 지정하면 됩니다.
<br /> <br />
## 후원 ## 후원
Termix는 구독이나 유료 요금제가 없는 무료 오픈소스 프로젝트입니다. 유용하게 사용하고 있다면 서버 비용, 도메인, 개발 시간을 위해 후원을 고려해 주세요. 후원은 SAML, Kubernetes, 에이전트 지원 같은 기능을 구축하는 데 필요한 사항을 연구하고 학습하는 시간에도 사용됩니다. 아래에서 진행 상황을 확인하고 후원할 수 있습니다. Termix는 무료 오픈 소스이고 구독이나 유료 요금제가 없니다. 유용하게 쓰고 계시다면 서버 비용 도메인, 개발 시간에 보탬이 되도록 후원을 고려해 주세요. 후원은 SAML Kubernetes, 에이전트 지원 같은 기능을 만들기 위해 알아보고 배우는 시간에도 쓰입니다. 진행 상황을 고 후원하시려면 아래를 눌러 주세요.
[후원하기](https://donate.termix.site/) [후원하기](https://donate.termix.site/)
@@ -317,7 +388,7 @@ Termix는 구독이나 유료 요금제가 없는 무료 오픈소스 프로젝
## 스폰서 ## 스폰서
개발 지원을 위한 유료 광고에 관심이 있으신가요? [mail@termix.site](mailto:mail@termix.site)로 메일을 보내주세요. 유료 게재로 개발 지원하고 싶으신가요? [mail@termix.site](mailto:mail@termix.site)로 메일을 보내 주세요.
<div align="center"> <div align="center">
@@ -339,10 +410,6 @@ Termix는 구독이나 유료 요금제가 없는 무료 오픈소스 프로젝
<img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" /> <img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" />
</a> </a>
&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;
<a href="https://tailscale.com/">
<img src="https://drive.google.com/uc?export=view&id=1lIxkJuX6M23bW-2FElhT0rQieTrzaVSL" height="40" alt="Tailscale" />
</a>
&nbsp;&nbsp;&nbsp;
<a href="https://akamai.com/"> <a href="https://akamai.com/">
<img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" /> <img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" />
</a> </a>
@@ -354,14 +421,17 @@ Termix는 구독이나 유료 요금제가 없는 무료 오픈소스 프로젝
<a href="https://rackgenius.com/"> <a href="https://rackgenius.com/">
<img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" /> <img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" />
</a> </a>
&nbsp;&nbsp;&nbsp;
<a href="https://ginernet.com/">
<img src="https://ginernet.com/img/logo-web.png" height="40" alt="Ginernet" />
</a>
</div> </div>
<br /> <br />
## 지원 ## 지원
Termix에 대한 도움이 필요하거나 기능을 요청하려면 [Issues](https://github.com/Termix-SSH/Support/issues) 페이지를 방문하여 로그인하고 `New Issue`를 누르세요. 이슈는 가능한 한 상세하게 작성하고, 영어로 작성하는 것이 좋습니다. [Discord](https://discord.gg/jVQGdvHDrf) 서버에 참여하여 지원 채널을 이용할 수지만, 응답 시간이 더 길 수 있습니다. 도움이 필요하거나 기능을 제안하고 싶으신가요? [새 이슈](https://github.com/Termix-SSH/Support/issues)를 올리면서 되도록 자세히, 가능하면 영어로 적어 주세요. [Discord](https://discord.gg/jVQGdvHDrf) 지원 채널에서 물어봐지만 답변이 늦을 수 있습니다.
<br /> <br />
@@ -373,7 +443,7 @@ Termix에 대한 도움이 필요하거나 기능을 요청하려면 [Issues](ht
[![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos) [![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos)
<sub>YouTube에서 업데이트 개요 시청하기</sub> <sub>YouTube에서 업데이트 소개 보기</sub>
<br /> <br />
<br /> <br />
@@ -413,7 +483,7 @@ Termix에 대한 도움이 필요하거나 기능을 요청하려면 [Issues](ht
</tr> </tr>
</table> </table>
<sub>일부 비디오 및 이미지는 최신이 아니거나 기능을 완벽하게 보여주지 않을 수 있습니다.</sub> <sub>일부 영상과 이미지는 오래되었거나 기능을 제대로 보여 주지 못할 수 있습니다.</sub>
</div> </div>
@@ -421,10 +491,10 @@ Termix에 대한 도움이 필요하거나 기능을 요청하려면 [Issues](ht
## 계획된 기능 ## 계획된 기능
모든 계획된 기능은 [Projects](https://github.com/orgs/Termix-SSH/projects/5)를 참조하세요. 기여를 원하시면 [Contributing](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md)을 참조하세요. 계획된 기능은 모두 [Projects](https://github.com/orgs/Termix-SSH/projects/5)에 있습니다. 기여하고 싶다면 [기여 안내](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md)를 봐 주세요.
<br /> <br />
## 라이선스 ## 라이선스
Apache License Version 2.0에 따라 배포니다. 자세한 내용은 `LICENSE`를 참하세요. Apache License 2.0에 따라 배포니다. 자세한 내용은 `LICENSE`를 참하세요.
+156 -86
View File
@@ -4,7 +4,7 @@
<h1>Termix</h1> <h1>Termix</h1>
<p>Gerenciamento SSH auto-hospedado e acesso a area de trabalho remota</p> <p>Gestão de servidores auto-hospedada, do SSH e do desktop remoto às automações</p>
<p> <p>
<a href="../README.md">English</a> · <a href="../README.md">English</a> ·
@@ -37,7 +37,7 @@
<br /> <br />
Termix é gratuito e de código aberto. Se o achar útil, considere [doar](https://donate.termix.site/) para ajudar a cobrir os custos de servidor e o tempo de desenvolvimento. O Termix é gratuito e de código aberto. Se ele te ajuda, considera [doar](https://donate.termix.site/) para ajudar a cobrir os custos de servidor e o tempo de desenvolvimento.
<br /> <br />
@@ -56,9 +56,9 @@ Termix é gratuito e de código aberto. Se o achar útil, considere [doar](https
<br /> <br />
## Visao Geral ## Visão geral
Termix e uma plataforma de gerenciamento de servidores tudo-em-um, de codigo aberto, sempre gratuita e auto-hospedada. Ela fornece uma solucao multiplataforma para gerenciar seus servidores e infraestrutura atraves de uma interface unica e intuitiva. Termix oferece acesso a terminal SSH, controle de desktop remoto (RDP, VNC, Telnet), capacidades de tunelamento SSH, gerenciamento remoto de arquivos SSH e muitas outras ferramentas. Termix e a alternativa perfeita, gratuita e auto-hospedada ao Termius, disponivel para todas as plataformas. O Termix é uma plataforma gratuita, de código aberto e auto-hospedada para gerenciar os teus servidores. Ele junta num só lugar terminais SSH, desktops remotos (RDP, VNC, Telnet), transferência de arquivos, túneis, Docker, métricas e automações, na web, no desktop e no celular. É uma alternativa auto-hospedada ao Termius que continua gratuita para sempre.
<br /> <br />
@@ -68,140 +68,182 @@ Termix e uma plataforma de gerenciamento de servidores tudo-em-um, de codigo abe
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Acesso ao Terminal SSH:** **Terminal SSH:**
Terminal completo com suporte a tela dividida (ate 4 paineis) com um sistema de abas similar ao navegador. Inclui suporte para personalizacao do terminal incluindo temas comuns de terminal, fontes e outros componentes. Um terminal completo com abas como as do navegador e tela dividida, até 6 painéis ao mesmo tempo. Escolhe o teu tema, a fonte e as cores. Acima de cada sessão há uma barra com CPU, memória e disco ao vivo, além de atalhos para os arquivos, o Docker, os túneis e as métricas daquele host.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Acesso a Area de Trabalho Remota:** **Desktop remoto:**
Suporte a RDP, VNC e Telnet pelo navegador com personalizacao completa e tela dividida. RDP, VNC e Telnet no navegador, em abas e tela dividida como qualquer outra sessão. Inclui um navegador de arquivos para as unidades RDP e envio arrastando e soltando. No desktop Windows também dá para abrir um host no cliente RDP nativo.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gerenciamento de Tuneis SSH:** **neis SSH:**
Crie e gerencie tuneis SSH de servidor para servidor com reconexao automatica, monitoramento de saude e encaminhamento local, remoto ou SOCKS dinamico. As configuracoes de tunel de cliente desktop para servidor sao armazenadas localmente por instalacao de desktop, snapshots de predefinicoes C2S opcionais podem ser salvos no servidor, renomeados, carregados ou excluidos quando voce quiser mover uma configuracao de tunel local entre clientes. Encaminhamento local, remoto e SOCKS dinâmico, com reconexão automática e verificação de estado. Os túneis de cliente para servidor do aplicativo de desktop ficam naquela máquina, e dá para salvar predefinições no servidor para levar uma configuração para outro computador.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gerenciador Remoto de Arquivos:** **Gerenciador de arquivos:**
Gerencie arquivos diretamente em servidores remotos com suporte para visualizar e editar codigo, imagens, audio e video. Faca upload, download, renomeie, exclua e mova arquivos facilmente com suporte sudo. Inclui suporte para mover arquivos de servidor para servidor. Navega, edita, envia, baixa, renomeia, move e apaga arquivos por SFTP, com suporte a sudo. Vê e edita código, imagens, áudio e vídeo. Copia arquivos direto de um servidor para outro, com o caminho mais rápido escolhido para ti e a integridade das transferências verificada.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gerenciamento de Docker e Podman:** **Docker e Podman:**
Inicie, pare, pause, remova conteineres. Visualize estatisticas de conteineres. Controle conteineres usando o terminal Docker Exec. Suporta Docker e Podman como ambiente de execucao de conteineres. Nao foi feito para substituir Portainer ou Dockge, mas sim para simplesmente gerenciar seus conteineres em vez de cria-los. Inicia, para, pausa e remove containers, acompanha as estatísticas e abre um shell dentro de um deles. Funciona tanto com Docker quanto com Podman. Não é para substituir o Portainer ou o Dockge, só para gerenciar os containers que já tens.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Gerenciador de Hosts SSH:** **Gerenciador de hosts:**
Salve, organize e gerencie suas conexoes SSH com tags e pastas (com personalizacao de pastas e suporte a pastas aninhadas), e salve facilmente informacoes de login reutilizaveis com a capacidade de automatizar a implantacao de chaves SSH. Salva e organiza hosts com etiquetas e pastas aninhadas que podes nomear e colorir. Reaproveita credenciais salvas entre hosts, distribui chaves SSH automaticamente, agrupa hosts sob um host pai, edita e exporta em lote, e usa a conexão rápida para conexões pontuais que não queres guardar.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Metricas do Host:** **Métricas de host:**
Visualize o uso de CPU, memoria e disco, rede, tempo de atividade, informacoes do sistema, firewall, monitor de portas, visualizador de logs, usuarios/permissoes, certificados e muito mais na maioria dos servidores baseados em Linux. Inclui graficos de historico em serie temporal e alertas baseados em limites com suporte a ntfy e webhook. CPU, memória, disco, rede, temperatura, tempo ligado, processos, portas, logins e informações do sistema na maioria dos servidores Linux, com gráficos de histórico. Os cartões de gerenciamento deixam cuidar de serviços, tarefas cron, pacotes, usuários, regras de firewall, WireGuard, Tailscale, certificados SSL, logs e verificações de saúde sem sair do Termix.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Autenticacao de Usuarios:** **Automações:**
Gerenciamento seguro de usuarios com controles de administrador (podem editar informacoes de outros usuarios) e suporte para OIDC/LDAP/SSO (com controle de acesso), 2FA (TOTP) e passkey (WebAuthn). Visualize sessoes ativas de usuarios em todas as plataformas e revogue permissoes. Vincule suas contas OIDC/Locais entre si. Visualize o log de auditoria de todas as acoes dos usuarios. Escolhe um gatilho e depois diz o que deve acontecer. Os gatilhos incluem uma métrica passando de um limite, um host caindo ou voltando, uma verificação de saúde mudando, um agendamento, um evento de container ou um webhook recebido. Os passos podem rodar comandos e trechos, controlar containers e túneis, acordar um host, chamar uma URL, esperar, seguir por uma condição, rodar outra automação e te avisar por ntfy, Discord ou webhook. As execuções de teste deixam experimentar com segurança primeiro.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Integracao com Tailscale:** **Frotas:**
Liste dispositivos da sua rede Tailscale para adicioná-los rapidamente como hosts, e conecte-se usando Tailscale SSH como metodo de autenticacao, deixando as ACLs da sua rede gerenciar a autorizacao sem armazenar credenciais. Junta hosts numa frota escolhendo um a um ou com regras de etiquetas, para que os novos entrem sozinhos. Roda um comando em todos os hosts de uma vez, envia e busca arquivos em todos eles, instala pacotes e reúne um inventário do sistema, do kernel, da arquitetura e do tempo ligado.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**RBAC/Compartilhamento:** **Assistente de IA:**
Crie funcoes e compartilhe hosts entre usuarios/funcoes. Suporta todos os tipos de autenticacao e todos os protocolos de host. É opcional e fica desligado até tu ligares. Conecta OpenAI, Anthropic, Gemini, Ollama ou qualquer endpoint compatível com OpenAI e pergunta sobre a tua instalação. Ele lê hosts, frotas, trechos e alertas, e propõe mudanças para tu aprovares em vez de fazer sozinho. Nunca consegue mexer em credenciais, usuários ou configurações. Os administradores podem deixar desligado para toda a instância, e dá para escondê-lo já na configuração inicial.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Conexoes Seriais:** **Login e usuários:**
Conecte-se a dispositivos seriais (roteadores, switches, microcontroladores, etc.) diretamente do navegador ou do aplicativo desktop. Configure taxa de baud, bits de dados, bits de parada e paridade. Usa a Web Serial API em navegadores suportados ou um backend nativo no aplicativo Electron. Contas locais além de login por OIDC, LDAP, GitHub e Google, com dois fatores (TOTP), chaves de acesso (WebAuthn) e dispositivos confiáveis. Os administradores podem gerenciar usuários, ligar grupos do OIDC a papéis, ver todas as sessões ativas em qualquer plataforma e encerrá-las. Liga a tua conta local com a do OIDC e consulta o registro de auditoria do que cada um fez.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Papéis e compartilhamento:**
Cria papéis e compartilha hosts com usuários ou papéis em quatro níveis: conectar, ver, editar e gerenciar. Funciona com todos os tipos de autenticação e todos os protocolos, e dá para trocar as credenciais usadas num host compartilhado.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Alertas:** **Alertas:**
Defina regras de alerta baseadas em limites para metricas do host (CPU, memoria, disco, etc.) e receba notificacoes via ntfy ou webhooks quando forem ativadas. Visualize alertas ativos e resolvidos em um historico de registros. Define regras em métricas de host como CPU, memória e disco, e recebe aviso por ntfy, Discord ou webhook quando elas disparam. Vê os alertas ativos e resolvidos num histórico e dispensa os que não te interessam.
</td>
<td width="50%" valign="top">
**Página inicial:**
Uma grade de widgets que tu mesmo montas arrastando e soltando. Tem widget para status de host, ping, links de serviços, favoritos, busca, relógios, calendários, contagens regressivas, notas, RSS, previsão do tempo, imagens, iframes, Docker, túneis, gráficos de métricas, APIs próprias e até um terminal ao vivo.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Pagina Inicial:** **Trechos e ferramentas:**
Uma pagina inicial totalmente personalizavel com uma grade de widgets de arrastar e soltar. Adicione widgets para status do host, links de servicos, relogios, notas, feeds RSS, clima, conteineres Docker, graficos de metricas do host, terminais incorporados, iframes e mais. Salva os comandos que usas sempre e dispara com um clique, com variáveis para o host e para o que tu digitares. Roda um mesmo comando em todos os terminais abertos e pesquisa o teu histórico com preenchimento automático.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Criptografia de Banco de Dados:** **Compartilhar sessão:**
Backend armazenado como arquivos de banco de dados SQLite criptografados. Consulte a [documentacao](https://docs.termix.site) para mais informacoes. Compartilha ao vivo uma sessão de terminal, RDP, VNC ou Telnet. Manda um link que qualquer um entra sem conta, ou compartilha com um usuário específico do Termix, em somente leitura ou com escrita. Os compartilhamentos podem expirar sozinhos ou ser revogados, e dá para desligar tudo de uma vez ou por host.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Grafico de Rede:** **Gravação e registros de sessão:**
Personalize seu Dashboard para visualizar seu homelab baseado nas suas conexoes SSH com suporte de status. Grava sessões de terminal, RDP e VNC e reproduz depois. Baixa registros de texto de uma sessão e olha o registro de conexão para ver exatamente o que aconteceu durante ela.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Ferramentas SSH:** **Conexões seriais:**
Crie trechos de comandos reutilizaveis que sao executados com um unico clique. Execute um comando simultaneamente em multiplos terminais abertos. Fala com dispositivos seriais como roteadores, switches e microcontroladores pelo navegador ou pelo aplicativo de desktop. Define taxa de transmissão, bits de dados, bits de parada e paridade. Usa a API Web Serial nos navegadores compatíveis, ou um backend nativo no aplicativo de desktop.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Abas Persistentes:** **Tailscale:**
Sessoes SSH e abas permanecem abertas entre dispositivos/atualizacoes se habilitado no perfil do usuario. Traz dispositivos da tua tailnet para adicionar como hosts em poucos cliques, e conecta com Tailscale SSH para que as ACLs da tailnet cuidem do acesso sem guardar credenciais. Headscale e endpoints personalizados também funcionam.
</td>
<td width="50%" valign="top">
**Proxmox:**
Importa hosts direto de uma instância Proxmox e acompanha as estatísticas de nós e convidados, incluindo CPU, memória e armazenamento, numa aba própria.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Áreas de trabalho e abas:**
Salva um conjunto de abas com a divisão da tela e reabre tudo com um clique. O Termix também lembra da tua última sessão, então as abas voltam depois de recarregar e em outros dispositivos.
</td>
<td width="50%" valign="top">
**Configuração guiada:**
Uma configuração curta te leva por escolher uma predefinição de interface, o tema, as funcionalidades que queres e o teu primeiro host. O modo simples esconde o que não usas, e dá para refazer a configuração ou trocar de predefinição quando quiseres.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Desktop independente e sincronização:**
O aplicativo de desktop roda sozinho, com backend e banco de dados locais, sem servidor. Também dá para ligar num servidor Termix e sincronizar nos dois sentidos hosts, credenciais, trechos e mais, e escolher se as conexões saem da tua máquina ou passam pelo servidor.
</td>
<td width="50%" valign="top">
**Linha de comando:**
Um CLI `termix` para o teu shell e os teus scripts. Abre terminais, roda um comando num host ou numa frota inteira, move arquivos por SFTP e gerencia hosts, trechos e credenciais. Instala com `npm install -g @termix-cli/cli` ou pega um binário independente. Vê a [documentação do CLI](https://docs.termix.site/cli).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Segurança:**
Senhas, chaves e outros segredos são criptografados por usuário, e os próprios arquivos do banco de dados podem ser criptografados em disco. Vê a [documentação](https://docs.termix.site/security) para entender como funciona.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Idiomas:** **Idiomas:**
Suporte integrado para aproximadamente 30 idiomas (gerenciado pelo [Crowdin](https://docs.termix.site/translations)). Cerca de 30 idiomas incluídos, gerenciados pelo [Crowdin](https://docs.termix.site/translations).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Compartilhamento de sessao:**
Compartilhe uma sessao de terminal, RDP, VNC ou Telnet ao vivo com outras pessoas em tempo real. Compartilhe por meio de um link (entrada anonima, sem necessidade de conta) ou com um usuario especifico do Termix, e escolha acesso somente leitura ou leitura/gravacao. Os compartilhamentos podem expirar automaticamente ou ser revogados a qualquer momento, e o compartilhamento de sessao pode ser ativado globalmente ou por host.
</td>
<td width="50%" valign="top">
**Aplicativo de desktop autonomo + sincronizacao bidirecional:**
O aplicativo de desktop Electron funciona de forma totalmente autonoma com seu proprio backend e banco de dados locais, sem necessidade de servidor. Opcionalmente, conecte-o a um servidor Termix remoto para sincronizacao bidirecional automatica de hosts, credenciais, snippets e muito mais, e escolha se as conexoes SSH sao iniciadas localmente ou por meio do servidor remoto.
</td> </td>
</tr> </tr>
@@ -213,40 +255,43 @@ O aplicativo de desktop Electron funciona de forma totalmente autonoma com seu p
<summary><b>Mais funcionalidades</b></summary> <summary><b>Mais funcionalidades</b></summary>
<br /> <br />
- **Dashboard** - Visualize informacoes do servidor de relance no seu dashboard - **Painel** - Os teus servidores num relance, com cartões que tu mesmo organizas
- **Chaves de API** - Crie chaves de API com escopo de usuario e datas de expiracao para uso em automacao/CI - **Gráfico de rede** - O teu homelab desenhado a partir dos teus hosts, com status ao vivo
- **Exportacao/Importacao de Dados** - Exporte e importe hosts SSH, credenciais e dados do gerenciador de arquivos - **Monitor tmux** - Percorre sessões, janelas e painéis do tmux, com prévia e busca
- **Configuracao Automatica de SSL** - Geracao e gerenciamento integrado de certificados SSL com redirecionamentos HTTPS - **Chaves de API** - Chaves por usuário com data de validade para scripts e CI
- **Interface Moderna** - Interface limpa compativel com desktop/mobile construida com React, Tailwind CSS e Shadcn. Escolha entre muitos temas de interface diferentes, incluindo claro, escuro, Dracula, etc. Use rotas de URL para abrir qualquer conexao em tela cheia. - **Exportar e importar** - Leva e traz hosts, credenciais e dados do gerenciador de arquivos
- **Historico de Comandos** - Autocompletar e visualizar comandos SSH executados anteriormente - **SSL automático** - Certificados gerados e renovados para ti, com redirecionamento para HTTPS, ou usa os teus
- **Conexao Rapida** - Conecte-se a um servidor sem precisar salvar os dados de conexao - **Bancos de dados** - SQLite por padrão, com PostgreSQL e MySQL também suportados
- **Paleta de Comandos** - Pressione duas vezes a tecla Shift esquerda para acessar rapidamente as conexoes SSH com seu teclado - **Interface moderna** - Interface React limpa que funciona no desktop e no celular, com temas como claro, escuro e Dracula. Qualquer conexão abre em tela cheia por uma URL
- **Integracao com Proxmox** - Adicione automaticamente hosts ao Termix a partir da sua instancia Proxmox - **Paleta de comandos** - Toca duas vezes no Shift esquerdo para ir a um host pelo teclado
- **SSH Rico em Funcionalidades** - Suporta jump hosts, Warpgate, conexoes baseadas em TOTP, SOCKS5, verificacao de chave do host, preenchimento automatico de senhas, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, registro de terminal, encaminhamento de agente SSH, agente SSH do Bitwarden, assinatura SSH do HashiCorp Vault, e mais. - **Atalhos de teclado** - Trocar de aba, fechar abas e mais, tudo remapeável
- **Termix ID** - Um equivalente ao sshid.io integrado ao Termix. Reivindique um identificador, publique suas chaves SSH publicas em uma URL de resolucao e use uma CA integrada para emitir certificados SSH. - **Wake-on-LAN** - Liga uma máquina pelo Termix ou por um passo de automação
- **Autenticação por proxy confiável** - Deixa um proxy reverso cuidar do login e repassar o usuário
- **SSH bem completo** - Hosts de salto, Warpgate, pedidos de TOTP, SOCKS5, verificação de chave de host, preenchimento automático de senha, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, registro do terminal, encaminhamento de agente, agente SSH do Bitwarden, assinatura SSH com HashiCorp Vault e mais
- **Termix ID** - Uma versão embutida do sshid.io. Registra um identificador, publica as tuas chaves públicas numa URL de resolução e emite certificados SSH pela CA embutida
</details> </details>
<br /> <br />
## Suporte a Plataformas ## Plataformas suportadas
<table align="center"> <table align="center">
<tr> <tr>
<th align="center">Plataforma</th> <th align="center">Plataforma</th>
<th align="center">Distribuicao</th> <th align="center">Distribuição</th>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Web</b></td> <td align="center"><b>Web</b></td>
<td>Qualquer navegador moderno (Chrome, Safari, Firefox) · Suporte PWA</td> <td>Qualquer navegador moderno (Chrome, Safari, Firefox) · Suporte a PWA</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Windows</b> <sub>x64/ia32</sub></td> <td align="center"><b>Windows</b> <sub>x64/ia32</sub></td>
<td>Portatil · Instalador MSI · Chocolatey</td> <td>Portátil · Instalador MSI · Chocolatey</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Linux</b> <sub>x64/ia32</sub></td> <td align="center"><b>Linux</b> <sub>x64/ia32</sub></td>
<td>Portatil · AUR · AppImage · Deb · Flatpak</td> <td>Portátil · AUR · AppImage · Deb · Flatpak</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>macOS</b> <sub>x64/ia32, v12.0+</sub></td> <td align="center"><b>macOS</b> <sub>x64/ia32, v12.0+</sub></td>
@@ -264,11 +309,11 @@ O aplicativo de desktop Electron funciona de forma totalmente autonoma com seu p
<br /> <br />
## Instalacao ## Instalação
Visite a [documentacao](https://docs.termix.site/install) do Termix para instrucoes completas de instalacao em todas as plataformas. Vê a [documentação do Termix](https://docs.termix.site/install) para as instruções completas de instalação em todas as plataformas.
Arquivo Docker Compose de exemplo (voce pode omitir o `guacd` e a rede se nao planeja usar recursos de area de trabalho remota): Exemplo de arquivo Docker Compose (dá para tirar o `guacd` e a rede se não pretendes usar o desktop remoto):
```yaml ```yaml
services: services:
@@ -305,11 +350,37 @@ networks:
driver: bridge driver: bridge
``` ```
### Linha de comando
O Termix também tem um CLI, para gerenciares os teus servidores pelo terminal e usares o Termix nos teus próprios scripts.
```bash
npm install -g @termix-cli/cli
termix login --url https://termix.example.com
termix ssh 1
```
Ele abre terminais, roda um comando num host ou numa frota inteira, move arquivos por SFTP e gerencia hosts, trechos e credenciais. A documentação completa está em [docs.termix.site/cli](https://docs.termix.site/cli).
### Hospedagem na nuvem
Dá para rodar o servidor do Termix num VPS em vez de dentro da tua própria rede. Se o Termix roda na rede que ele gerencia, uma queda leva ele junto, bem na hora em que precisas dele para resolver. Rodando fora ele continua acessível, te dá um IP fixo e dá para entrar de qualquer lugar sem VPN nem abrir portas.
A [GINERNET](https://docs.termix.site/install/ginernet) patrocina o Termix, e a documentação tem um guia passo a passo para publicar na plataforma de VPS deles.
<br />
## Telemetria
O Termix manda uma vez por dia um pequeno sinal anônimo, para eu saber quantas instâncias estão rodando e quais funcionalidades são usadas. Ele contém um ID de instância aleatório, quantos usuários e hosts tu tens, a versão do aplicativo e quais funcionalidades (terminal, gerenciador de arquivos, túneis, docker, etc.) foram usadas nas últimas 24 horas. Nunca contém nomes de usuário, nomes de host, endereços IP, credenciais ou qualquer coisa que identifique ti ou os teus servidores.
Vem ligado por padrão. Podes desligar nas configurações de administração, em Geral, ou definir `ENABLE_TELEMETRY=false` antes mesmo de iniciar o Termix.
<br /> <br />
## Doar ## Doar
Termix e gratuito e de codigo aberto, sem assinaturas ou planos pagos. Se o achar util, considere doar para ajudar a cobrir custos de servidor, dominios e tempo de desenvolvimento. As doacoes tambem ajudam a financiar o tempo de pesquisa e aprendizado necessario para construir funcionalidades como suporte a SAML, Kubernetes e Agent. Acompanhe o progresso e doe abaixo. O Termix é gratuito e de código aberto, sem assinaturas nem planos pagos. Se ele te ajuda, considera doar para ajudar com servidores, domínios e tempo de desenvolvimento. As doações também custeiam o tempo de pesquisar e aprender o necessário para funcionalidades como SAML, Kubernetes e suporte a agentes. Acompanha o progresso e doa abaixo.
[Doar](https://donate.termix.site/) [Doar](https://donate.termix.site/)
@@ -317,7 +388,7 @@ Termix e gratuito e de codigo aberto, sem assinaturas ou planos pagos. Se o acha
## Patrocinadores ## Patrocinadores
Interessado em um espaco pago para apoiar o desenvolvimento? Envie um email para [mail@termix.site](mailto:mail@termix.site). Tens interesse num espaço pago para apoiar o desenvolvimento? Escreve para [mail@termix.site](mailto:mail@termix.site).
<div align="center"> <div align="center">
@@ -339,10 +410,6 @@ Interessado em um espaco pago para apoiar o desenvolvimento? Envie um email para
<img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" /> <img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" />
</a> </a>
&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;
<a href="https://tailscale.com/">
<img src="https://drive.google.com/uc?export=view&id=1lIxkJuX6M23bW-2FElhT0rQieTrzaVSL" height="40" alt="Tailscale" />
</a>
&nbsp;&nbsp;&nbsp;
<a href="https://akamai.com/"> <a href="https://akamai.com/">
<img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" /> <img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" />
</a> </a>
@@ -354,18 +421,21 @@ Interessado em um espaco pago para apoiar o desenvolvimento? Envie um email para
<a href="https://rackgenius.com/"> <a href="https://rackgenius.com/">
<img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" /> <img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" />
</a> </a>
&nbsp;&nbsp;&nbsp;
<a href="https://ginernet.com/">
<img src="https://ginernet.com/img/logo-web.png" height="40" alt="Ginernet" />
</a>
</div> </div>
<br /> <br />
## Suporte ## Suporte
Se voce precisa de ajuda ou deseja solicitar uma funcionalidade para o Termix, visite a pagina de [Issues](https://github.com/Termix-SSH/Support/issues), faca login e clique em `New Issue`. Por favor, seja o mais detalhado possivel no seu relato, preferencialmente escrito em ingles. Voce tambem pode entrar no servidor do [Discord](https://discord.gg/jVQGdvHDrf) e visitar o canal de suporte, porem, os tempos de resposta podem ser mais longos. Precisas de ajuda ou queres pedir uma funcionalidade? Abre uma [nova issue](https://github.com/Termix-SSH/Support/issues) com o máximo de detalhes possível, em inglês se der. Também podes perguntar no canal de suporte do [Discord](https://discord.gg/jVQGdvHDrf), embora as respostas por lá possam demorar mais.
<br /> <br />
## Capturas de Tela ## Capturas de tela
<div align="center"> <div align="center">
@@ -373,7 +443,7 @@ Se voce precisa de ajuda ou deseja solicitar uma funcionalidade para o Termix, v
[![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos) [![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos)
<sub>Assista resumos de atualizacoes no YouTube</sub> <sub>Vê as apresentações das atualizações no YouTube</sub>
<br /> <br />
<br /> <br />
@@ -413,18 +483,18 @@ Se voce precisa de ajuda ou deseja solicitar uma funcionalidade para o Termix, v
</tr> </tr>
</table> </table>
<sub>Alguns videos e imagens podem estar desatualizados ou podem nao mostrar perfeitamente as funcionalidades.</sub> <sub>Alguns vídeos e imagens podem estar desatualizados ou o mostrar as funcionalidades perfeitamente.</sub>
</div> </div>
<br /> <br />
## Funcionalidades Planejadas ## Funcionalidades planejadas
Consulte [Projetos](https://github.com/orgs/Termix-SSH/projects/5) para todas as funcionalidades planejadas. Se voce deseja contribuir, consulte [Contribuir](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md). Todas as funcionalidades planejadas estão em [Projects](https://github.com/orgs/Termix-SSH/projects/5). Se queres contribuir, [Contributing](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md).
<br /> <br />
## Licenca ## Licença
Distribuido sob a Licenca Apache Versao 2.0. Consulte `LICENSE` para mais informacoes. Distribuído sob a Licença Apache versão 2.0. `LICENSE` para mais informações.
+155 -85
View File
@@ -4,7 +4,7 @@
<h1>Termix</h1> <h1>Termix</h1>
<p>Самостоятельно размещаемое управление SSH и доступ к удалённому рабочему столу</p> <p>Управление серверами на своём хостинге, от SSH и удалённого рабочего стола до автоматизаций</p>
<p> <p>
<a href="../README.md">English</a> · <a href="../README.md">English</a> ·
@@ -37,7 +37,7 @@
<br /> <br />
Termix бесплатный проект с открытым исходным кодом. Если он вам полезен, рассмотрите возможность [пожертвования](https://donate.termix.site/) для покрытия расходов на серверы и время разработки. Termix бесплатен и с открытым исходным кодом. Если он вам пригодился, подумайте о [пожертвовании](https://donate.termix.site/), чтобы помочь покрыть расходы на серверы и время на разработку.
<br /> <br />
@@ -49,7 +49,7 @@ Termix — бесплатный проект с открытым исходны
<p> <p>
<img src="../repo-images/Repo of the Day.png" alt="Repo of the Day Achievement" width="280" /> <img src="../repo-images/Repo of the Day.png" alt="Repo of the Day Achievement" width="280" />
<br /> <br />
<sub>Достигнуто 1 сентября 2025 года</sub> <sub>Получено 1 сентября 2025 года</sub>
</p> </p>
</div> </div>
@@ -58,7 +58,7 @@ Termix — бесплатный проект с открытым исходны
## Обзор ## Обзор
Termix - это платформа для управления серверами с открытым исходным кодом, навсегда бесплатная и размещаемая на собственном сервере. Она предоставляет мультиплатформенное решение для управления вашими серверами и инфраструктурой через единый интуитивно понятный интерфейс. Termix предлагает доступ к SSH-терминалу, управление удаленным рабочим столом (RDP, VNC, Telnet), возможности SSH-туннелирования, удаленное управление файлами SSH и множество других инструментов. Termix - это идеальная бесплатная альтернатива Termius с возможностью размещения на собственном сервере, доступная для всех платформ. Termix это бесплатная платформа с открытым исходным кодом для управления серверами на своём хостинге. Она собирает в одном месте SSH-терминалы, удалённые рабочие столы (RDP, VNC, Telnet), передачу файлов, туннели, Docker, метрики и автоматизации, в браузере, на компьютере и на телефоне. Это self-hosted замена Termius, которая остаётся бесплатной навсегда.
<br /> <br />
@@ -68,140 +68,182 @@ Termix - это платформа для управления серверам
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Доступ к SSH-терминалу:** **SSH-терминал:**
Полнофункциональный терминал с поддержкой разделения экрана (до 4 панелей) и системой вкладок, как в браузере. Включает поддержку настройки терминала, включая популярные темы, шрифты и другие компоненты. Полноценный терминал с вкладками как в браузере и разделением экрана, до 6 панелей одновременно. Тему, шрифт и цвета выбираете вы. Над каждой сессией есть панель с текущей загрузкой процессора, памяти и диска, а также быстрые ссылки на файлы, Docker, туннели и метрики этого хоста.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Доступ к удалённому рабочему столу:** **Удалённый рабочий стол:**
Поддержка RDP, VNC и Telnet через браузер с полной настройкой и разделением экрана. RDP, VNC и Telnet прямо в браузере, во вкладках и с разделением экрана, как и любая другая сессия. Есть просмотр файлов на дисках RDP и загрузка перетаскиванием. В версии для Windows хост можно открыть и в обычном клиенте RDP.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Управление SSH-туннелями:** **SSH-туннели:**
Создание и управление межсерверными SSH-туннелями с автоматическим переподключением, мониторингом состояния и локальной, удалённой или динамической SOCKS-переадресацией. Настройки туннелей «десктопный клиент - сервер» хранятся локально для каждой установки; опциональные снимки C2S-пресетов можно сохранять на сервере, переименовывать, загружать или удалять, когда вы хотите перенести локальную конфигурацию туннеля между клиентами. Локальная, удалённая и динамическая переадресация SOCKS с автоматическим переподключением и проверкой состояния. Туннели от клиента к серверу в настольном приложении хранятся на этом компьютере, а наборы настроек можно сохранить на сервере, чтобы перенести конфигурацию на другую машину.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Удалённый файловый менеджер:** **Файловый менеджер:**
Управление файлами непосредственно на удалённых серверах с поддержкой просмотра и редактирования кода, изображений, аудио и видео. Загрузка, скачивание, переименование, удаление и перемещение файлов с поддержкой sudo. Включает поддержку перемещения файлов с сервера на сервер. Просматривайте, редактируйте, загружайте, скачивайте, переименовывайте, перемещайте и удаляйте файлы по SFTP, в том числе через sudo. Смотрите и правьте код, изображения, аудио и видео. Копируйте файлы напрямую с одного сервера на другой: самый быстрый маршрут подбирается сам, а целостность передачи проверяется.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Управление Docker и Podman:** **Docker и Podman:**
Запуск, остановка, приостановка, удаление контейнеров. Просмотр статистики контейнеров. Управление контейнером через терминал docker exec. Поддерживает как Docker, так и Podman в качестве среды выполнения контейнеров. Не предназначен для замены Portainer или Dockge, а скорее для простого управления контейнерами по сравнению с их созданием. Запускайте, останавливайте, ставьте на паузу и удаляйте контейнеры, смотрите их нагрузку и открывайте оболочку внутри. Работает и с Docker, и с Podman. Это не замена Portainer или Dockge, а способ управлять теми контейнерами, что у вас уже есть.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Менеджер SSH-хостов:** **Менеджер хостов:**
Сохранение, организация и управление SSH-подключениями с помощью тегов и папок (с настройкой папок и поддержкой вложенных папок), с возможностью сохранения данных для повторного входа и автоматизации развёртывания SSH-ключей. Храните и упорядочивайте хосты с помощью меток и вложенных папок, которым можно задать имя и цвет. Используйте сохранённые учётные данные на нескольких хостах, разворачивайте SSH-ключи автоматически, группируйте хосты под родительским, редактируйте и выгружайте пакетно, а для разовых подключений, которые не хочется сохранять, есть быстрое подключение.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Метрики хоста:** **Метрики хостов:**
Просмотр использования CPU, памяти и диска, сети, времени работы, информации о системе, файрвола, монитора портов, просмотрщика логов, пользователей/прав доступа, сертификатов и многого другого на большинстве серверов на базе Linux. Включает графики истории временных рядов и оповещения на основе пороговых значений с поддержкой ntfy и вебхуков. Процессор, память, диск, сеть, температура, время работы, процессы, порты, входы в систему и сведения о системе на большинстве серверов Linux, с графиками за прошлые периоды. Карточки управления позволяют работать со службами, задачами cron, пакетами, пользователями, правилами брандмауэра, WireGuard, Tailscale, сертификатами SSL, журналами и проверками состояния, не выходя из Termix.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Аутентификация пользователей:** **Автоматизации:**
Безопасное управление пользователями с административным контролем (может редактировать информацию других пользователей) и поддержкой OIDC/LDAP/SSO (с контролем доступа), 2FA (TOTP) и поддержкой ключей доступа (WebAuthn). Просмотр активных сессий пользователей на всех платформах и отзыв прав доступа. Связывание аккаунтов OIDC/локальных аккаунтов. Просмотр журнала аудита действий всех пользователей. Выберите событие, а затем опишите, что должно произойти. Событием может быть превышение порога метрикой, хост, который упал или вернулся, изменение проверки состояния, расписание, событие контейнера или входящий webhook. Шаги умеют выполнять команды и сниппеты, управлять контейнерами и туннелями, будить хост, обращаться по адресу, ждать, ветвиться по условию, запускать другую автоматизацию и присылать уведомления через ntfy, Discord или webhook. Тестовый запуск позволяет всё безопасно проверить.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Интеграция с Tailscale:** **Флоты:**
Список устройств вашей сети Tailscale для быстрого добавления их в качестве хостов и подключение через Tailscale SSH в качестве метода аутентификации, позволяя ACL вашей сети управлять авторизацией без хранения учётных данных. Объединяйте хосты во флот вручную или по правилам меток, чтобы новые хосты попадали туда сами. Выполняйте одну команду сразу на всех хостах, отправляйте и забирайте файлы со всех, устанавливайте пакеты и собирайте сводку по системе, ядру, архитектуре и времени работы.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**RBAC/Общий доступ:** **ИИ-помощник:**
Создание ролей и предоставление общего доступа к хостам для пользователей/ролей. Поддерживает все типы аутентификации и все протоколы хостов. Необязательная возможность, выключенная до тех пор, пока вы сами её не включите. Подключите OpenAI, Anthropic, Gemini, Ollama или любой совместимый с OpenAI адрес и спрашивайте о своей системе. Он читает хосты, флоты, сниппеты и оповещения и предлагает изменения на ваше утверждение, а не вносит их сам. До учётных данных, пользователей и настроек он не доберётся никогда. Администраторы могут оставить его выключенным для всей установки, а вы можете скрыть его ещё при первичной настройке.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Последовательные подключения:** **Вход и пользователи:**
Подключение к последовательным устройствам (маршрутизаторы, коммутаторы, микроконтроллеры и т. д.) напрямую из браузера или приложения для рабочего стола. Настройка скорости передачи данных, битов данных, стоп-битов и чётности. Использует Web Serial API в поддерживаемых браузерах или нативный бэкенд в приложении Electron. Локальные учётные записи, а также вход через OIDC, LDAP, GitHub и Google, с двухфакторной проверкой (TOTP), ключами доступа (WebAuthn) и доверенными устройствами. Администраторы могут управлять пользователями, сопоставлять группы OIDC с ролями, видеть все активные сессии на всех платформах и завершать их. Свяжите локальную учётную запись с OIDC и смотрите журнал аудита действий каждого.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Роли и общий доступ:**
Создавайте роли и делитесь хостами с пользователями или ролями на четырёх уровнях: подключение, просмотр, изменение и управление. Работает со всеми способами аутентификации и всеми протоколами, а учётные данные для общего хоста можно переопределить.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Оповещения:** **Оповещения:**
Настройте правила оповещений на основе пороговых значений для метрик хоста (CPU, память, диск и т. д.) и получайте уведомления через ntfy или вебхуки при их срабатывании. Просматривайте активные и разрешённые оповещения в журнале истории. Задайте правила по метрикам хостов, например процессору, памяти и диску, и получайте уведомления через ntfy, Discord или webhook, когда они срабатывают. Смотрите активные и уже снятые оповещения в журнале и убирайте те, что вам не нужны.
</td> </td>
</tr>
<tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Домашняя страница:** **Домашняя страница:**
Полностью настраиваемая домашняя страница с сеткой виджетов с перетаскиванием. Добавляйте виджеты для статуса хоста, ссылок на сервисы, часов, заметок, RSS-лент, погоды, контейнеров Docker, графиков метрик хоста, встроенных терминалов, iframe и многого другого. Сетка виджетов, которую вы собираете сами перетаскиванием. Есть виджеты для состояния хостов, пингов, ссылок на сервисы, закладок, поиска, часов, календарей, обратного отсчёта, заметок, RSS, погоды, изображений, встроенных страниц, Docker, туннелей, графиков метрик, своих API и даже живого терминала.
</td>
<td width="50%" valign="top">
**Шифрование базы данных:**
Бэкенд хранится в виде зашифрованных файлов базы данных SQLite. Подробнее в [документации](https://docs.termix.site).
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Сетевой граф:** **Сниппеты и инструменты:**
Настройте панель управления для визуализации вашей домашней лаборатории на основе SSH-подключений с поддержкой статусов. Сохраняйте команды, которые часто набираете, и запускайте их одним нажатием, с переменными для хоста и для собственного ввода. Выполняйте одну команду сразу во всех открытых терминалах и ищите по истории команд с автодополнением.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Инструменты SSH:** **Общий доступ к сессии:**
Создание переиспользуемых фрагментов команд, выполняемых одним нажатием. Запуск одной команды одновременно в нескольких открытых терминалах. Делитесь живой сессией терминала, RDP, VNC или Telnet. Отправьте ссылку, по которой можно подключиться без учётной записи, или поделитесь с конкретным пользователем Termix, только для просмотра или с правом ввода. Доступ может истекать сам или отзываться в любой момент, и его можно отключить полностью или для отдельного хоста.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Постоянные вкладки:** **Запись сессий и журналы:**
SSH-сессии и вкладки остаются открытыми на всех устройствах/при обновлении страницы, если включено в профиле пользователя. Записывайте сессии терминала, RDP и VNC и просматривайте их позже. Скачивайте текстовые журналы сессии и заглядывайте в журнал подключения, чтобы увидеть, что именно происходило во время соединения.
</td>
<td width="50%" valign="top">
**Последовательные подключения:**
Общайтесь с последовательными устройствами вроде маршрутизаторов, коммутаторов и микроконтроллеров из браузера или настольного приложения. Настраивайте скорость, биты данных, стоповые биты и чётность. В подходящих браузерах используется Web Serial API, а в настольном приложении собственный бэкенд.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Tailscale:**
Подтягивайте устройства из своей tailnet, чтобы добавить их как хосты в пару нажатий, и подключайтесь через Tailscale SSH: доступом займутся правила tailnet, а учётные данные хранить не придётся. Headscale и свои адреса тоже работают.
</td>
<td width="50%" valign="top">
**Proxmox:**
Импортируйте хосты прямо из установки Proxmox и следите за показателями узлов и гостевых машин, включая процессор, память и хранилище, на отдельной вкладке.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Рабочие пространства и вкладки:**
Сохраните набор вкладок вместе с разделением экрана и откройте всё это одним нажатием. Termix помнит и последнюю сессию, поэтому вкладки возвращаются после обновления страницы и на других устройствах.
</td>
<td width="50%" valign="top">
**Пошаговая настройка:**
Короткая настройка поможет выбрать шаблон интерфейса, тему, нужные возможности и первый хост. Простой режим скрывает то, чем вы не пользуетесь, а настройку можно пройти заново или сменить шаблон в любой момент.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Автономный клиент и синхронизация:**
Настольное приложение работает само по себе, со своим бэкендом и базой данных, без сервера. Его можно подключить к серверу Termix, чтобы в обе стороны синхронизировать хосты, учётные данные, сниппеты и остальное, и выбрать, откуда идут подключения: с вашего компьютера или через сервер.
</td>
<td width="50%" valign="top">
**Командная строка:**
CLI `termix` для вашей оболочки и ваших скриптов. Открывайте терминалы, выполняйте команду на одном хосте или на целом флоте, перемещайте файлы по SFTP и управляйте хостами, сниппетами и учётными данными. Установите через `npm install -g @termix-cli/cli` или возьмите отдельный исполняемый файл. Смотрите [документацию CLI](https://docs.termix.site/cli).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Безопасность:**
Пароли, ключи и другие секреты шифруются для каждого пользователя, а сами файлы базы данных можно зашифровать на диске. Как это устроено, описано в [документации](https://docs.termix.site/security).
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Языки:** **Языки:**
Встроенная поддержка около 30 языков (управляется через [Crowdin](https://docs.termix.site/translations)). Около 30 встроенных языков, которые ведутся через [Crowdin](https://docs.termix.site/translations).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Общий доступ к сеансу:**
Делитесь сеансом терминала, RDP, VNC или Telnet с другими в режиме реального времени. Делитесь по ссылке (анонимное присоединение, учетная запись не требуется) или с конкретным пользователем Termix, выбирая доступ только для чтения или для чтения и записи. Общий доступ может автоматически истекать или быть отозван в любое время, а общий доступ к сеансам можно включать глобально или для отдельного хоста.
</td>
<td width="50%" valign="top">
**Автономное настольное приложение + двусторонняя синхронизация:**
Настольное приложение на Electron полностью автономно, с собственным локальным бэкендом и базой данных, сервер не требуется. При желании подключите его к удаленному серверу Termix для автоматической двусторонней синхронизации хостов, учетных данных, сниппетов и прочего, и выберите, запускаются ли SSH-соединения локально или через удаленный сервер.
</td> </td>
</tr> </tr>
@@ -210,20 +252,23 @@ SSH-сессии и вкладки остаются открытыми на вс
<br /> <br />
<details> <details>
<summary><b>Больше возможностей</b></summary> <summary><b>Другие возможности</b></summary>
<br /> <br />
- **Панель управления** - Просмотр информации о сервере на панели управления одним взглядом - **Панель** - Ваши серверы одним взглядом, карточки расставляете вы сами
- **API-ключи** - Создание API-ключей с областью видимости пользователя и сроками действия для использования в автоматизации/CI - **Схема сети** - Ваша домашняя лаборатория, нарисованная по хостам, с состоянием в реальном времени
- **Экспорт/импорт данных** - Экспорт и импорт SSH-хостов, учётных данных и данных файлового менеджера - **Монитор tmux** - Просмотр сессий, окон и панелей tmux с предпросмотром и поиском
- **Автоматическая настройка SSL** - Встроенная генерация и управление SSL-сертификатами с перенаправлением на HTTPS - **Ключи API** - Ключи для конкретного пользователя со сроком действия, для скриптов и CI
- **Современный интерфейс** - Чистый интерфейс для десктопа и мобильных устройств, построенный на React, Tailwind CSS и Shadcn. Выбор между множеством различных тем интерфейса, включая светлую, тёмную, Dracula и т. д. Использование URL-маршрутов для открытия любого подключения в полноэкранном режиме. - **Экспорт и импорт** - Перенос хостов, учётных данных и данных файлового менеджера
- **История команд** - Автодополнение и просмотр ранее выполненных SSH-команд - **Автоматический SSL** - Сертификаты выпускаются и обновляются за вас, с переходом на HTTPS, либо используйте свои
- **Быстрое подключение** - Подключение к серверу без необходимости сохранения данных подключения - **Базы данных** - По умолчанию SQLite, поддерживаются также PostgreSQL и MySQL
- **Командная палитра** - Двойное нажатие левого Shift для быстрого доступа к SSH-подключениям с клавиатуры - **Современный интерфейс** - Аккуратный интерфейс на React для компьютера и телефона, с темами вроде светлой, тёмной и Dracula. Любое подключение открывается на весь экран по ссылке
- **Интеграция с Proxmox** - Автоматическое добавление хостов в Termix из вашего экземпляра Proxmox - **Палитра команд** - Двойное нажатие левого Shift, чтобы перейти к хосту с клавиатуры
- **Богатый функционал SSH** - Поддержка jump-хостов, Warpgate, подключений на основе TOTP, SOCKS5, верификации ключей хоста, автозаполнения паролей, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, логирования терминала, переадресации SSH-агента, SSH-агента Bitwarden, подписи SSH через HashiCorp Vault и многого другого. - **Сочетания клавиш** - Переход между вкладками, их закрытие и другое, всё можно переназначить
- **Termix ID** - Аналог sshid.io, встроенный в Termix. Зарегистрируйте имя пользователя, опубликуйте свои публичные SSH-ключи по URL резолвера и используйте встроенный ЦС для выдачи SSH-сертификатов. - **Wake-on-LAN** - Разбудите машину из Termix или из шага автоматизации
- **Доверенный прокси** - Пусть обратный прокси возьмёт вход на себя и передаст пользователя
- **Богатые возможности SSH** - Промежуточные хосты, Warpgate, запросы TOTP, SOCKS5, проверка ключей хоста, автозаполнение паролей, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, журналы терминала, проброс агента, SSH-агент Bitwarden, подпись SSH через HashiCorp Vault и другое
- **Termix ID** - Встроенный аналог sshid.io. Займите имя, опубликуйте открытые ключи по адресу распознавателя и выпускайте SSH-сертификаты через встроенный центр сертификации
</details> </details>
@@ -234,7 +279,7 @@ SSH-сессии и вкладки остаются открытыми на вс
<table align="center"> <table align="center">
<tr> <tr>
<th align="center">Платформа</th> <th align="center">Платформа</th>
<th align="center">Дистрибутив</th> <th align="center">Способ установки</th>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Web</b></td> <td align="center"><b>Web</b></td>
@@ -266,9 +311,9 @@ SSH-сессии и вкладки остаются открытыми на вс
## Установка ## Установка
Посетите [документацию](https://docs.termix.site/install) Termix для получения полных инструкций по установке на всех платформах. Полные инструкции по установке для всех платформ смотрите в [документации Termix](https://docs.termix.site/install).
Пример файла Docker Compose (вы можете опустить `guacd` и сеть, если не планируете использовать функции удаленного рабочего стола): Пример файла Docker Compose (`guacd` и сеть можно убрать, если удалённый рабочий стол вам не нужен):
```yaml ```yaml
services: services:
@@ -305,19 +350,45 @@ networks:
driver: bridge driver: bridge
``` ```
### Командная строка
У Termix есть и CLI, так что серверами можно управлять из терминала и использовать Termix в своих скриптах.
```bash
npm install -g @termix-cli/cli
termix login --url https://termix.example.com
termix ssh 1
```
Он умеет открывать терминалы, выполнять команду на одном хосте или на целом флоте, перемещать файлы по SFTP и управлять хостами, сниппетами и учётными данными. Полная документация есть на [docs.termix.site/cli](https://docs.termix.site/cli).
### Размещение в облаке
Сервер Termix можно держать на VPS, а не внутри своей сети. Если Termix работает в той же сети, которой управляет, при сбое он упадёт вместе с ней, как раз тогда, когда нужен для починки. Снаружи он остаётся доступным, даёт постоянный IP и позволяет зайти откуда угодно без VPN и проброса портов.
[GINERNET](https://docs.termix.site/install/ginernet) спонсирует Termix, и в документации есть пошаговое руководство по развёртыванию на их площадке VPS.
<br /> <br />
## Пожертвование ## Телеметрия
Termix бесплатен и имеет открытый исходный код, без подписок или платных тарифов. Если он вам полезен, рассмотрите возможность пожертвования, чтобы помочь покрыть расходы на серверы, домены и время разработки. Пожертвования также помогают финансировать время на исследование и изучение того, что необходимо для создания таких функций, как поддержка SAML, Kubernetes и Agent. Отслеживайте прогресс и делайте пожертвования ниже. Termix раз в сутки отправляет небольшой анонимный сигнал, чтобы я понимал, сколько установок работает и какими возможностями действительно пользуются. В нём есть случайный идентификатор установки, число пользователей и хостов, версия приложения и то, какие возможности (терминал, файловый менеджер, туннели, docker и прочее) использовались за последние 24 часа. В нём никогда нет имён пользователей, имён хостов, IP-адресов, учётных данных и ничего другого, что указывало бы на вас или ваши серверы.
[Пожертвовать](https://donate.termix.site/) По умолчанию он включён. Выключить можно в настройках администратора в разделе «Общие» или задать `ENABLE_TELEMETRY=false` ещё до первого запуска Termix.
<br />
## Пожертвования
Termix бесплатен и открыт, без подписок и платных тарифов. Если он вам полезен, подумайте о пожертвовании: оно помогает с серверами, доменами и временем на разработку. Пожертвования также оплачивают время на изучение того, что нужно для таких возможностей, как SAML, Kubernetes и поддержка агентов. Следить за ходом работ и поддержать можно по ссылке ниже.
[Поддержать](https://donate.termix.site/)
<br /> <br />
## Спонсоры ## Спонсоры
Заинтересованы в платном размещении для поддержки разработки? Напишите на [mail@termix.site](mailto:mail@termix.site). Интересует платное размещение в поддержку разработки? Напишите на [mail@termix.site](mailto:mail@termix.site).
<div align="center"> <div align="center">
@@ -339,10 +410,6 @@ Termix бесплатен и имеет открытый исходный код
<img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" /> <img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" />
</a> </a>
&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;
<a href="https://tailscale.com/">
<img src="https://drive.google.com/uc?export=view&id=1lIxkJuX6M23bW-2FElhT0rQieTrzaVSL" height="40" alt="Tailscale" />
</a>
&nbsp;&nbsp;&nbsp;
<a href="https://akamai.com/"> <a href="https://akamai.com/">
<img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" /> <img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" />
</a> </a>
@@ -354,14 +421,17 @@ Termix бесплатен и имеет открытый исходный код
<a href="https://rackgenius.com/"> <a href="https://rackgenius.com/">
<img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" /> <img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" />
</a> </a>
&nbsp;&nbsp;&nbsp;
<a href="https://ginernet.com/">
<img src="https://ginernet.com/img/logo-web.png" height="40" alt="Ginernet" />
</a>
</div> </div>
<br /> <br />
## Поддержка ## Поддержка
Если вам нужна помощь или вы хотите запросить новую функцию для Termix, посетите страницу [Проблемы](https://github.com/Termix-SSH/Support/issues), войдите в систему и нажмите `New Issue`. Пожалуйста, опишите вашу проблему как можно подробнее, предпочтительно на английском языке. Вы также можете присоединиться к серверу [Discord](https://discord.gg/jVQGdvHDrf) и обратиться в канал поддержки, однако время ответа может быть дольше. Нужна помощь или хотите предложить функцию? Создайте [новое обращение](https://github.com/Termix-SSH/Support/issues) и опишите всё как можно подробнее, по возможности на английском. Ещё можно спросить в канале поддержки в [Discord](https://discord.gg/jVQGdvHDrf), хотя там ответа иногда приходится ждать дольше.
<br /> <br />
@@ -413,7 +483,7 @@ Termix бесплатен и имеет открытый исходный код
</tr> </tr>
</table> </table>
<sub>Некоторые видео и изображения могут быть устаревшими или не полностью отражать функциональность.</sub> <sub>Некоторые видео и изображения могут устареть или не полностью показывать возможности.</sub>
</div> </div>
@@ -421,10 +491,10 @@ Termix бесплатен и имеет открытый исходный код
## Запланированные функции ## Запланированные функции
Смотрите [Проекты](https://github.com/orgs/Termix-SSH/projects/5) для просмотра всех запланированных функций. Если вы хотите внести вклад, смотрите [Участие в разработке](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md). Все запланированные функции собраны в [Projects](https://github.com/orgs/Termix-SSH/projects/5). Если хотите поучаствовать, посмотрите [Contributing](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md).
<br /> <br />
## Лицензия ## Лицензия
Распространяется по лицензии Apache License Version 2.0. Подробнее см. в файле `LICENSE`. Распространяется по лицензии Apache версии 2.0. Подробности в файле `LICENSE`.
+160 -90
View File
@@ -4,7 +4,7 @@
<h1>Termix</h1> <h1>Termix</h1>
<p>Kendi sunucunuzda barindirilan SSH yonetimi ve uzak masaustu erisimi</p> <p>Kendi sunucunuzda çalışan sunucu yönetimi, SSH ve uzak masaüstünden otomasyonlara kadar</p>
<p> <p>
<a href="../README.md">English</a> · <a href="../README.md">English</a> ·
@@ -37,7 +37,7 @@
<br /> <br />
Termix ücretsiz ve açık kaynaklıdır. Faydalı buluyorsanız, sunucu maliyetleri ve geliştirme süresine katkıda bulunmak için [bağış yapmayı](https://donate.termix.site/) düşünebilirsiniz. Termix ücretsiz ve açık kaynaklıdır. İşinize yarıyorsa, sunucu masraflarına ve geliştirme süresine katkı için [bağış yapmayı](https://donate.termix.site/) düşünün.
<br /> <br />
@@ -49,159 +49,201 @@ Termix ücretsiz ve açık kaynaklıdır. Faydalı buluyorsanız, sunucu maliyet
<p> <p>
<img src="../repo-images/Repo of the Day.png" alt="Repo of the Day Achievement" width="280" /> <img src="../repo-images/Repo of the Day.png" alt="Repo of the Day Achievement" width="280" />
<br /> <br />
<sub>1 Eylül 2025'te kazanildi</sub> <sub>1 Eylül 2025 tarihinde kazanıldı</sub>
</p> </p>
</div> </div>
<br /> <br />
## Genel Bakis ## Genel bakış
Termix, acik kaynakli, sonsuza kadar ucretsiz, kendi sunucunuzda barindirabileceginez hepsi bir arada sunucu yonetim platformudur. Sunucularinizi ve altyapinizi tek bir sezgisel arayuz uzerinden yonetmek icin cok platformlu bir cozum sunar. Termix, SSH terminal erisimi, uzak masaustu kontrolu (RDP, VNC, Telnet), SSH tunelleme yetenekleri, uzak dosya yonetimi ve daha bircok arac saglar. Termix, tum platformlarda kullanilabilen Termius'un mukemmel ucretsiz ve kendi barindirmali alternatifidir. Termix, sunucularınızı yönetmek için ücretsiz, açık kaynaklı ve kendi sunucunuzda çalışan bir platformdur. SSH terminallerini, uzak masaüstlerini (RDP, VNC, Telnet), dosya aktarımlarını, tünelleri, Docker'ı, ölçümleri ve otomasyonları tek yerde toplar; web, masaüstü ve mobilde çalışır. Sonsuza dek ücretsiz kalan, kendi sunucunuzda çalışan bir Termius alternatifidir.
<br /> <br />
## Ozellikler ## Özellikler
<table> <table>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH Terminal Erisimi:** **SSH terminali:**
Tarayici benzeri sekme sistemiyle bolunmus ekran destegine sahip (4 panele kadar) tam ozellikli terminal. Yaygin terminal temalari, yazi tipleri ve diger bilesenleri iceren terminal ozellestirme destegi. Tarayıcı gibi sekmeleri ve bölünmüş ekranı olan tam donanımlı bir terminal, aynı anda 6 panele kadar. Temanızı, yazı tipinizi ve renklerinizi seçin. Her oturumun üstünde anlık CPU, bellek ve disk bilgisi gösteren bir araç çubuğu ile o sunucunun dosyalarına, Docker'ına, tünellerine ve ölçümlerine giden kısayollar bulunur.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Uzak Masaustu Erisimi:** **Uzak masaüstü:**
Tam ozellestirme ve bolunmus ekran ile tarayici uzerinden RDP, VNC ve Telnet destegi. Tarayıcıda RDP, VNC ve Telnet; diğer oturumlar gibi sekmelerde ve bölünmüş ekranda. RDP sürücüleri için dosya tarayıcısı ve sürükle bırak yükleme içerir. Windows masaüstünde bir sunucuyu yerel RDP istemcisinde de açabilirsiniz.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH Tunel Yonetimi:** **SSH nelleri:**
Otomatik yeniden baglanti, saglik izleme ve yerel, uzak veya dinamik SOCKS yonlendirme ile sunucular arasi SSH tunelleri olusturun ve yonetin. Masaustu istemci-sunucu tunel ayarlari her masaustu kurulumu icin yerel olarak depolanir; istege bagli C2S hazir ayar anlik goruntuleri, yerel bir tunel yapilandirmasini istemciler arasinda tasimak istediginizde sunucuya kaydedilebilir, yeniden adlandirilabilir, yuklenebilir veya silinebilir. Yerel, uzak ve dinamik SOCKS yönlendirmesi; otomatik yeniden bağlanma ve durum kontrolleriyle. Masaüstü uygulamasındaki istemciden sunucuya tüneller o makinede saklanır, ayarları sunucuya kaydederek bir kurulumu başka bir makineye taşıyabilirsiniz.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Uzak Dosya Yoneticisi:** **Dosya neticisi:**
Uzak sunuculardaki dosyalari dogrudan yonetin; kod, goruntu, ses ve video goruntuleme ve duzenleme destegi ile. Sudo destegi ile dosyalari sorunsuzca yukleyin, indirin, yeniden adlandirin, silin ve tasiyin. Dosyalari sunucudan sunucuya tasima destegini de icerir. SFTP üzerinden dosyalara göz atın, düzenleyin, yükleyin, indirin, yeniden adlandırın, taşıyın ve silin; sudo da kullanılabilir. Kod, görsel, ses ve videoyu görüntüleyip düzenleyin. Dosyaları doğrudan bir sunucudan diğerine kopyalayın; en hızlı yol sizin için seçilir ve aktarımların bütünlüğü doğrulanır.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Docker ve Podman Yonetimi:** **Docker ve Podman:**
Konteynerleri baslatın, durdurun, duraklatın, kaldirin. Konteyner istatistiklerini goruntuleyin. Docker exec terminali kullanarak konteyneri kontrol edin. Docker ve Podman'i konteyner calisma ortami olarak destekler. Portainer veya Dockge'nin yerini almak icin degil, konteynerlerinizi olusturmak yerine basitce yonetmek icin tasarlanmistir. Kapsayıcıları başlatın, durdurun, duraklatın ve silin, durumlarını izleyin ve içlerinde bir kabuk açın. Hem Docker hem Podman ile çalışır. Portainer ya da Dockge'nin yerini almak için değil, hâlihazırdaki kapsayıcılarınızı yönetmek için tasarlandı.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH Ana Bilgisayar Yoneticisi:** **Sunucu yöneticisi:**
SSH baglantilarinizi etiketler ve klasorlerle (klasor ozellestirme ve ic ice klasor destegi ile) kaydedin, duzenleyin ve yonetin; yeniden kullanilabilir giris bilgilerini kolayca kaydedin ve SSH anahtarlarinin dagitimini otomatiklestirin. Sunucularınızı etiketlerle ve isim ve renk verebileceğiniz iç içe klasörlerle düzenleyin. Kayıtlı kimlik bilgilerini birden çok sunucuda kullanın, SSH anahtarlarını otomatik dağıtın, sunucuları bir üst sunucunun altında toplayın, toplu düzenleyip dışa aktarın ve kaydetmek istemediğiniz tek seferlik bağlantılar için hızlı bağlantıyı kullanın.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Ana Bilgisayar Metrikleri:** **Sunucu ölçümleri:**
Cogu Linux tabanli sunucularda calisan CPU, bellek, disk kullanimi, ag, calisma suresi, sistem bilgisi, guvenlik duvari, port izleme, gunluk goruntuleyici, kullanicilar/izinler, sertifikalar ve daha fazlasini goruntuleyin. Zaman serisi gecmis grafiklerini ve ntfy ile webhook destekli esik tabanli uyarilari icerir. Çoğu Linux sunucusunda CPU, bellek, disk, ağ, sıcaklık, çalışma süresi, süreçler, portlar, oturum açmalar ve sistem bilgisi; geçmiş grafikleriyle birlikte. Yönetim kartları sayesinde servisleri, cron görevlerini, paketleri, kullanıcıları, güvenlik duvarı kurallarını, WireGuard'ı, Tailscale'i, SSL sertifikalarını, günlükleri ve sağlık kontrollerini Termix'ten çıkmadan yönetirsiniz.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Kullanici Kimlik Dogrulama:** **Otomasyonlar:**
Yonetici kontrolleri (diger kullanicilarin bilgilerini duzenleyebilir), OIDC/LDAP/SSO (erisim kontrollu), 2FA (TOTP) ve passkey (WebAuthn) destegi ile guvenli kullanici yonetimi. Tum platformlardaki aktif kullanici oturumlarini goruntuleyin ve izinleri iptal edin. OIDC/Yerel hesaplarinizi birbirine baglayin. Tum kullanicilarin islemlerinin denetim gunlugunu goruntuleyin. Bir tetikleyici seçin, sonra ne olacağını söyleyin. Tetikleyiciler arasında bir ölçümün eşiği aşması, bir sunucunun düşmesi veya geri gelmesi, sağlık kontrolünün değişmesi, bir zamanlama, bir kapsayıcı olayı ya da gelen bir webhook var. Adımlar komut ve parçacık çalıştırabilir, kapsayıcı ve tünelleri yönetebilir, bir makineyi uyandırabilir, bir adrese istek atabilir, bekleyebilir, koşula göre dallanabilir, başka bir otomasyonu çalıştırabilir ve ntfy, Discord ya da webhook ile size haber verebilir. Deneme çalıştırmaları ile önce güvenle test edersiniz.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Tailscale Entegrasyonu:** **Filolar:**
Tailscale aginizdaki cihazlari listeleyerek hizlica ana bilgisayar olarak ekleyin ve kimlik dogrulama yontemi olarak Tailscale SSH kullanarak baglanin; bu sayede ag ACL'leriniz kimlik bilgileri depolamadan yetkilendirmeyi yonetir. Sunucuları tek tek seçerek ya da etiket kurallarıyla bir filoda toplayın; yeni sunucular kendiliğinden katılsın. Tek bir komutu tüm sunucularda aynı anda çalıştırın, hepsine dosya gönderip hepsinden dosya alın, paket kurun ve işletim sistemi, çekirdek, mimari ve çalışma süresi dökümünü toplayın.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**RBAC/Paylasim:** **Yapay zekâ asistanı:**
Roller olusturun ve ana bilgisayarlari kullanicilar/roller arasinda paylasin. Tum kimlik dogrulama turlerini ve tum ana bilgisayar protokollerini destekler. İsteğe bağlıdır ve siz açana kadar kapalıdır. OpenAI, Anthropic, Gemini, Ollama ya da OpenAI uyumlu herhangi bir uç noktayı bağlayın ve kurulumunuz hakkında sorular sorun. Sunucuları, filoları, parçacıkları ve uyarıları okuyabilir; değişiklikleri kendisi yapmak yerine onayınıza sunar. Kimlik bilgilerine, kullanıcılara ve ayarlara asla erişemez. Yöneticiler tüm kurulum için kapalı bırakabilir, siz de kurulum sırasında gizleyebilirsiniz.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Seri Baglantilar:** **Giriş ve kullanıcılar:**
Seri cihazlara (router, switch, mikrodenetleyici vb.) dogrudan tarayici veya masaustu uygulamasindan baglanin. Baud hizi, veri bitleri, durdurma bitleri ve parite yapilandirin. Desteklenen tarayicilarda Web Serial API, Electron uygulamasinda yerel arka ucu kullanir. Yerel hesapların yanında OIDC, LDAP, GitHub ve Google ile giriş; iki adımlı doğrulama (TOTP), geçiş anahtarları (WebAuthn) ve güvenilir cihazlar. Yöneticiler kullanıcıları yönetebilir, OIDC gruplarını rollerle eşleştirebilir, tüm platformlardaki etkin oturumları görüp sonlandırabilir. Yerel ve OIDC hesaplarınızı birbirine bağlayın ve herkesin ne yaptığını denetim günlüğünden okuyun.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Uyarilar:** **Roller ve paylaşım:**
Ana bilgisayar metrikleri (CPU, bellek, disk vb.) icin esik tabanli uyari kurallari belirleyin ve tetiklendiklerinde ntfy veya webhook araciligiyla bildirim alin. Gecmis gunlugunde tetiklenen ve cozulen uyarilari goruntuleyin. Roller oluşturun ve sunucuları kullanıcılar veya rollerle dört düzeyde paylaşın: bağlanma, görüntüleme, düzenleme ve yönetme. Tüm kimlik doğrulama türleri ve tüm protokollerle çalışır, paylaşılan bir sunucuda kullanılan kimlik bilgilerini değiştirebilirsiniz.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Ana Sayfa:** **Uyarılar:**
Surukleme ve birakma widget izgarasina sahip tamamen ozellestirilebilir bir ana sayfa. Ana bilgisayar durumu, hizmet baglantilari, saatler, notlar, RSS besleme, hava durumu, Docker konteynerleri, ana bilgisayar metrik grafikleri, gomulu terminaller, iframe ve daha fazlasi icin widget ekleyin. CPU, bellek ve disk gibi sunucu ölçümlerine kurallar koyun ve tetiklendiklerinde ntfy, Discord veya webhook ile haberdar olun. Devam eden ve çözülen uyarıları geçmişte görün, ilgilenmediklerinizi kapatın.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Veritabani Sifreleme:** **Ana sayfa:**
Arka uc, sifrelenmis SQLite veritabani dosyalari olarak depolanir. Daha fazla bilgi icin [belgelere](https://docs.termix.site) bakin. Kendi kurduğunuz, sürükle bırak çalışan bir bileşen ızgarası. Sunucu durumu, ping, servis bağlantıları, yer imleri, arama, saatler, takvimler, geri sayımlar, notlar, RSS, hava durumu, görseller, gömülü sayfalar, Docker, tüneller, ölçüm grafikleri, kendi API'leriniz ve hatta canlı bir terminal için bileşenler var.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Ag Grafigi:** **Parçacıklar ve araçlar:**
Kontrol panelinizi, SSH baglantilariniza dayali olarak ev laboratuvarinizi durum destegi ile gorselletirmek icin ozellestirin. Sık kullandığınız komutları kaydedin ve tek tıkla çalıştırın; sunucu için ve kendi girdileriniz için değişkenler kullanabilirsiniz. Aynı komutu açık olan tüm terminallerde çalıştırın, komut geçmişinizde tamamlamayla arama yapın.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**SSH Araclari:** **Oturum paylaşımı:**
Tek tiklamayla calistirilan yeniden kullanilabilir komut parcaciklari olusturun. Birden fazla acik terminalde ayni anda tek bir komut calistirin. Canlı bir terminal, RDP, VNC veya Telnet oturumunu paylaşın. Hesap gerekmeden katılınabilen bir bağlantı gönderin ya da belirli bir Termix kullanıcısıyla, salt okunur veya yazma yetkili olarak paylaşın. Paylaşımlar kendiliğinden sona erebilir veya istediğiniz an iptal edilebilir; tümüyle ya da sunucu bazında kapatılabilir.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Kalici Sekmeler:** **Oturum kaydı ve günlükler:**
Kullanici profilinde etkinlestirilmisse SSH oturumlari ve sekmeler cihazlar/yenilemeler arasinda acik kalir. Terminal, RDP ve VNC oturumlarını kaydedin ve sonra izleyin. Bir oturumun düz metin günlüğünü indirin, bağlantı günlüğüne bakarak bağlantı sırasında tam olarak ne olduğunu görün.
</td>
<td width="50%" valign="top">
**Seri bağlantılar:**
Yönlendirici, anahtar ve mikrodenetleyici gibi seri cihazlarla tarayıcıdan veya masaüstü uygulamasından konuşun. Baud hızını, veri bitlerini, dur bitlerini ve pariteyi ayarlayın. Destekleyen tarayıcılarda Web Serial API'yi, masaüstü uygulamasında yerel bir arka ucu kullanır.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Tailscale:**
Tailnet'inizdeki cihazları çekip birkaç tıkla sunucu olarak ekleyin ve Tailscale SSH ile bağlanın; erişimi tailnet kurallarınız yönetsin, kimlik bilgisi saklamanız gerekmesin. Headscale ve özel uç noktalar da çalışır.
</td>
<td width="50%" valign="top">
**Proxmox:**
Sunucuları doğrudan bir Proxmox kurulumundan içe aktarın; düğüm ve misafir makinelerin CPU, bellek ve depolama dahil durumlarını kendi sekmesinde izleyin.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Çalışma alanları ve sekmeler:**
Bir sekme grubunu bölünmüş düzeniyle birlikte kaydedin ve hepsini tek tıkla yeniden açın. Termix son oturumunuzu da hatırlar, böylece sayfayı yenileseniz de başka cihaza geçseniz de sekmeleriniz geri gelir.
</td>
<td width="50%" valign="top">
**Rehberli kurulum:**
Kısa bir kurulum, arayüz ön ayarını, temanızı, istediğiniz özellikleri ve ilk sunucunuzu seçmenizde size yol gösterir. Basit kip kullanmadığınız şeyleri gizler; kurulumu istediğiniz zaman yeniden çalıştırabilir veya ön ayarı değiştirebilirsiniz.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Bağımsız masaüstü ve eşitleme:**
Masaüstü uygulaması kendi arka ucu ve veritabanıyla tek başına, sunucusuz çalışır. İsterseniz bir Termix sunucusuna bağlayıp sunucuları, kimlik bilgilerini, parçacıkları ve fazlasını iki yönlü eşitleyebilir, bağlantıların kendi makinenizden mi yoksa sunucu üzerinden mi kurulacağını seçebilirsiniz.
</td>
<td width="50%" valign="top">
**Komut satırı:**
Kabuğunuz ve betikleriniz için bir `termix` CLI'ı. Terminal açın, tek bir sunucuda veya tüm filoda komut çalıştırın, SFTP ile dosya taşıyın ve sunucuları, parçacıkları ve kimlik bilgilerini yönetin. `npm install -g @termix-cli/cli` ile kurun ya da bağımsız bir çalıştırılabilir dosya edinin. [CLI belgelerine](https://docs.termix.site/cli) bakın.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Güvenlik:**
Parolalar, anahtarlar ve diğer gizli bilgiler kullanıcı bazında şifrelenir, veritabanı dosyalarının kendisi de diskte şifrelenebilir. Nasıl çalıştığı için [belgelere](https://docs.termix.site/security) bakın.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Diller:** **Diller:**
Yaklasik 30 dil icin yerlesik destek ([Crowdin](https://docs.termix.site/translations) tarafindan yonetilir). Yaklaşık 30 dil yerleşik olarak gelir, [Crowdin](https://docs.termix.site/translations) üzerinden yönetilir.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Oturum Paylasimi:**
Canli bir terminal, RDP, VNC veya Telnet oturumunu baskalariyla gercek zamanli olarak paylasin. Bir baglanti uzerinden (anonim olarak katilir, hesap gerekmez) veya belirli bir Termix kullanicisiyla paylasin ve salt okunur veya okuma/yazma erisimi secin. Paylasimlar otomatik olarak sona erebilir veya istediginiz zaman iptal edilebilir; oturum paylasimi genel olarak veya sunucu bazinda acilip kapatilabilir.
</td>
<td width="50%" valign="top">
**Bagimsiz Masaustu + Cift Yonlu Senkronizasyon:**
Electron masaustu uygulamasi, kendi yerel arka ucu ve veritabaniyla tamamen bagimsiz calisir, sunucu gerekmez. Istege bagli olarak sunucular, kimlik bilgileri, kod parcaciklari ve daha fazlasinin otomatik cift yonlu senkronizasyonu icin uzak bir Termix sunucusuna baglayin ve SSH baglantilarinin yerel olarak mi yoksa uzak sunucu uzerinden mi baslatilacagini secin.
</td> </td>
</tr> </tr>
@@ -210,43 +252,46 @@ Electron masaustu uygulamasi, kendi yerel arka ucu ve veritabaniyla tamamen bagi
<br /> <br />
<details> <details>
<summary><b>Daha fazla ozellik</b></summary> <summary><b>Daha fazla özellik</b></summary>
<br /> <br />
- **Kontrol Paneli** - Kontrol panelinizde sunucu bilgilerini bir bakista goruntuleyin - **Kontrol paneli** - Kendi dizdiğiniz kartlarla sunucularınıza tek bakışta göz atın
- **API Anahtarlari** - Otomasyon/CI icin kullanilmak uzere son kullanma tarihleriyle kullanici kapsamli API anahtarlari olusturun - **Ağ grafiği** - Ev laboratuvarınız sunucularınızdan çizilir, durum anlık gösterilir
- **Veri Disa/Ice Aktarma** - SSH ana bilgisayarlarini, kimlik bilgilerini ve dosya yoneticisi verilerini disa ve ice aktarin - **Tmux izleyici** - tmux oturumlarına, pencerelerine ve panellerine önizleme ve aramayla göz atın
- **Otomatik SSL Kurulumu** - HTTPS yonlendirmeleriyle yerlesik SSL sertifika olusturma ve yonetimi - **API anahtarları** - Betikler ve CI için, son kullanma tarihli kullanıcıya özel anahtarlar
- **Modern Arayuz** - React, Tailwind CSS ve Shadcn ile olusturulmus temiz masaustu/mobil uyumlu arayuz. Isik, karanlik, Dracula vb. dahil olmak uzere bircok farkli UI temasi arasından secim yapin. Herhangi bir baglantıyı tam ekranda acmak icin URL yollarini kullanin. - **Dışa ve içe aktarma** - Sunucuları, kimlik bilgilerini ve dosya yöneticisi verilerini taşıyın
- **Komut Gecmisi** - Daha once calistirilan SSH komutlarini otomatik tamamlayin ve goruntuleyin - **Otomatik SSL** - Sertifikalar sizin için oluşturulur ve yenilenir, HTTPS yönlendirmesiyle birlikte; ya da kendi sertifikanızı kullanın
- **Hizli Baglanti** - Baglanti verilerini kaydetmeden bir sunucuya baglanin - **Veritabanları** - Varsayılan SQLite, ayrıca PostgreSQL ve MySQL desteklenir
- **Komut Paleti** - Sol shift tusuna iki kez basarak SSH baglantilariniza klavyenizle hizlica erisin - **Modern arayüz** - Masaüstü ve mobilde çalışan sade bir React arayüzü; açık, koyu ve Dracula gibi temalarla. Her bağlantı bir adresten tam ekran açılabilir
- **Proxmox Entegrasyonu** - Proxmox ornekinizden Termix'e otomatik olarak ana bilgisayar ekleyin - **Komut paleti** - Sol Shift'e iki kez basarak klavyeden bir sunucuya atlayın
- **SSH Zengin Ozellikler** - Atlama ana bilgisayarlari, Warpgate, TOTP tabanli baglantilar, SOCKS5, ana bilgisayar anahtar dogrulama, otomatik sifre doldurma, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, terminal gunlukleme, SSH agent forwarding, Bitwarden SSH agent, HashiCorp Vault SSH imzalama ve dahasini destekler. - **Klavye kısayolları** - Sekmeler arasında geçiş, sekme kapatma ve dahası, hepsi yeniden atanabilir
- **Termix ID** - Termix'e entegre edilmis bir sshid.io esdegeri. Bir kullanici adi edinin, genel SSH anahtarlarinizi bir cozumleyici URL'sinde yayinlayin ve SSH sertifikalari vermek icin yerlesik bir CA kullanin. - **Wake-on-LAN** - Bir makineyi Termix'ten ya da bir otomasyon adımından uyandırın
- **Güvenilir vekil doğrulaması** - Girişi ters vekil sunucu halletsin ve kullanıcıyı aktarsın
- **Zengin SSH desteği** - Atlama sunucuları, Warpgate, TOTP istekleri, SOCKS5, sunucu anahtarı doğrulama, parola otomatik doldurma, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, terminal günlüğü, aracı yönlendirme, Bitwarden SSH aracısı, HashiCorp Vault ile SSH imzalama ve dahası
- **Termix ID** - sshid.io'nun yerleşik hali. Bir kullanıcı adı alın, açık anahtarlarınızı bir çözümleyici adresinde yayımlayın ve yerleşik CA ile SSH sertifikaları çıkarın
</details> </details>
<br /> <br />
## Platform Destegi ## Platform desteği
<table align="center"> <table align="center">
<tr> <tr>
<th align="center">Platform</th> <th align="center">Platform</th>
<th align="center">Dagitim</th> <th align="center">Dağıtım</th>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Web</b></td> <td align="center"><b>Web</b></td>
<td>Herhangi bir modern tarayici (Chrome, Safari, Firefox) · PWA destegi</td> <td>Güncel her tarayıcı (Chrome, Safari, Firefox) · PWA desteği</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Windows</b> <sub>x64/ia32</sub></td> <td align="center"><b>Windows</b> <sub>x64/ia32</sub></td>
<td>Tasınabilir · MSI Yukleyici · Chocolatey</td> <td>Taşınabilir · MSI kurulumu · Chocolatey</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Linux</b> <sub>x64/ia32</sub></td> <td align="center"><b>Linux</b> <sub>x64/ia32</sub></td>
<td>Tasınabilir · AUR · AppImage · Deb · Flatpak</td> <td>Taşınabilir · AUR · AppImage · Deb · Flatpak</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>macOS</b> <sub>x64/ia32, v12.0+</sub></td> <td align="center"><b>macOS</b> <sub>x64/ia32, v12.0+</sub></td>
@@ -266,9 +311,9 @@ Electron masaustu uygulamasi, kendi yerel arka ucu ve veritabaniyla tamamen bagi
## Kurulum ## Kurulum
Termix'i tum platformlara nasil kuracaginiz hakkinda daha fazla bilgi icin Termix [Belgelerine](https://docs.termix.site/install) bakin. Tüm platformlar için ayrıntılı kurulum yönergelerini [Termix belgelerinde](https://docs.termix.site/install) bulabilirsiniz.
Ornek bir Docker Compose dosyasi (uzak masaustu ozelliklerini kullanmayi planlamiyorsaniz `guacd` ve agi cikarabilirsiniz): Örnek Docker Compose dosyası (uzak masaüstünü kullanmayacaksanız `guacd` ve ağ kısmını çıkarabilirsiniz):
```yaml ```yaml
services: services:
@@ -305,19 +350,45 @@ networks:
driver: bridge driver: bridge
``` ```
### Komut satırı
Termix'in bir CLI'ı da var; sunucularınızı terminalden yönetebilir ve Termix'i kendi betiklerinizde kullanabilirsiniz.
```bash
npm install -g @termix-cli/cli
termix login --url https://termix.example.com
termix ssh 1
```
Terminal açabilir, tek bir sunucuda veya tüm filoda komut çalıştırabilir, SFTP ile dosya taşıyabilir ve sunucuları, parçacıkları ve kimlik bilgilerini yönetebilir. Belgelerin tamamı [docs.termix.site/cli](https://docs.termix.site/cli) adresinde.
### Bulutta barındırma
Termix sunucusunu kendi ağınız yerine bir VPS üzerinde de çalıştırabilirsiniz. Termix yönettiği ağın içinde çalışıyorsa, bir kesinti onu da beraberinde götürür; hem de tam onu tamir için kullanmanız gereken anda. Dışarıda çalıştırmak erişilebilir kalmasını sağlar, sabit bir IP verir ve VPN ya da port yönlendirme olmadan her yerden girmenize izin verir.
[GINERNET](https://docs.termix.site/install/ginernet) Termix'e sponsor oluyor ve belgelerde onların VPS platformuna kurulum için adım adım bir rehber var.
<br /> <br />
## Bağış Yapın ## Telemetri
Termix ücretsiz ve açık kaynaklıdır, abonelik veya ücretli plan yoktur. Faydalı buluyorsaniz, sunucu maliyetleri, alan adlari ve gelistirme suresine katkida bulunmak icin bagis yapmayi dusunebilirsiniz. Bagislar ayrica SAML, Kubernetes ve Agent destegi gibi ozellikleri gelistirmek icin gereken arastirma ve ogrenme suresini finanse etmeye yardimci olur. Ilerlemeyi takip edin ve asagidan bagis yapin. Termix günde bir kez küçük ve anonim bir sinyal gönderir; böylece kaç kurulumun çalıştığını ve hangi özelliklerin kullanıldığını görebiliyorum. İçinde rastgele bir kurulum kimliği, kaç kullanıcı ve sunucunuz olduğu, uygulama sürümü ve son 24 saatte hangi özelliklerin (terminal, dosya yöneticisi, tüneller, docker vb.) kullanıldığı yer alır. İçinde asla kullanıcı adları, sunucu adları, IP adresleri, kimlik bilgileri ya da sizi veya sunucularınızı tanımlayan başka bir şey bulunmaz.
[Bağış Yapın](https://donate.termix.site/) Varsayılan olarak açıktır. Yönetici ayarlarında Genel bölümünden kapatabilir ya da Termix'i hiç başlatmadan önce `ENABLE_TELEMETRY=false` tanımlayabilirsiniz.
<br />
## Bağış
Termix ücretsiz ve açık kaynaklıdır; abonelik ya da ücretli plan yoktur. İşinize yarıyorsa, sunucu, alan adı ve geliştirme süresi masraflarına katkı için bağış yapmayı düşünün. Bağışlar ayrıca SAML, Kubernetes ve aracı desteği gibi özellikler için gereken araştırma ve öğrenme süresini karşılar. İlerlemeyi aşağıdan izleyip bağış yapabilirsiniz.
[Bağış yap](https://donate.termix.site/)
<br /> <br />
## Sponsorlar ## Sponsorlar
Gelistirmeyi desteklemek icin ucretli bir yerlesim ile ilgileniyor musunuz? [mail@termix.site](mailto:mail@termix.site) adresine e-posta gonderin. Geliştirmeyi desteklemek için ücretli bir yerleşim ilginizi çeker mi? [mail@termix.site](mailto:mail@termix.site) adresine yazın.
<div align="center"> <div align="center">
@@ -339,10 +410,6 @@ Gelistirmeyi desteklemek icin ucretli bir yerlesim ile ilgileniyor musunuz? [mai
<img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" /> <img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" />
</a> </a>
&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;
<a href="https://tailscale.com/">
<img src="https://drive.google.com/uc?export=view&id=1lIxkJuX6M23bW-2FElhT0rQieTrzaVSL" height="40" alt="Tailscale" />
</a>
&nbsp;&nbsp;&nbsp;
<a href="https://akamai.com/"> <a href="https://akamai.com/">
<img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" /> <img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" />
</a> </a>
@@ -354,18 +421,21 @@ Gelistirmeyi desteklemek icin ucretli bir yerlesim ile ilgileniyor musunuz? [mai
<a href="https://rackgenius.com/"> <a href="https://rackgenius.com/">
<img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" /> <img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" />
</a> </a>
&nbsp;&nbsp;&nbsp;
<a href="https://ginernet.com/">
<img src="https://ginernet.com/img/logo-web.png" height="40" alt="Ginernet" />
</a>
</div> </div>
<br /> <br />
## Destek ## Destek
Termix ile ilgili yardima ihtiyaciniz varsa veya bir ozellik talep etmek istiyorsaniz, [Sorunlar](https://github.com/Termix-SSH/Support/issues) sayfasini ziyaret edin, giris yapin ve `New Issue` butonuna basin. Lutfen sorununuzu mumkun oldugunca ayrintili yazin, tercihen Ingilizce olarak. Ayrica [Discord](https://discord.gg/jVQGdvHDrf) sunucusuna katilabilir ve destek kanalini ziyaret edebilirsiniz, ancak yanit sureleri daha uzun olabilir. Yardıma mı ihtiyacınız var ya da bir özellik mi istiyorsunuz? [Yeni bir konu](https://github.com/Termix-SSH/Support/issues) açın ve olabildiğince ayrıntı ekleyin, mümkünse İngilizce yazın. [Discord](https://discord.gg/jVQGdvHDrf) üzerindeki destek kanalında da sorabilirsiniz, ancak oradaki yanıtlar daha uzun sürebilir.
<br /> <br />
## Ekran Goruntuleri ## Ekran görüntüleri
<div align="center"> <div align="center">
@@ -373,7 +443,7 @@ Termix ile ilgili yardima ihtiyaciniz varsa veya bir ozellik talep etmek istiyor
[![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos) [![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos)
<sub>YouTube'da guncelleme ozetlerini izleyin</sub> <sub>Güncelleme tanıtımlarını YouTube'da izleyin</sub>
<br /> <br />
<br /> <br />
@@ -413,18 +483,18 @@ Termix ile ilgili yardima ihtiyaciniz varsa veya bir ozellik talep etmek istiyor
</tr> </tr>
</table> </table>
<sub>Bazi videolar ve gorseller guncel olmayabilir veya ozellikleri tam olarak yansitmayabilir.</sub> <sub>Bazı videolar ve görseller güncelliğini yitirmiş ya da özellikleri tam olarak göstermiyor olabilir.</sub>
</div> </div>
<br /> <br />
## Planlanan Ozellikler ## Planlanan özellikler
Tum planlanan ozellikler icin [Projeler](https://github.com/orgs/Termix-SSH/projects/5) sayfasina bakin. Katkida bulunmak istiyorsaniz, [Katkida Bulunma](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md) sayfasina bakin. Planlanan tüm özellikler [Projects](https://github.com/orgs/Termix-SSH/projects/5) sayfasında. Katkıda bulunmak isterseniz [Contributing](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md) dosyasına bakın.
<br /> <br />
## Lisans ## Lisans
Apache Lisansi Surumu 2.0 altinda dagitilmaktadir. Daha fazla bilgi icin `LICENSE` dosyasina bakin. Apache Lisansı Sürüm 2.0 ile dağıtılır. Ayrıntılar için `LICENSE` dosyasına bakın.
+154 -84
View File
@@ -4,7 +4,7 @@
<h1>Termix</h1> <h1>Termix</h1>
<p>Quan ly SSH tu luu tru va truy cap may tinh tu xa</p> <p>Qun lý máy chủ t lưu trữ, từ SSH và máy tính t xa cho đến tự động hoá</p>
<p> <p>
<a href="../README.md">English</a> · <a href="../README.md">English</a> ·
@@ -37,7 +37,7 @@
<br /> <br />
Termix là dự án miễn phí và mã nguồn mở. Nếu bạn thấy hữu ích, hãy cân nhắc [quyên góp](https://donate.termix.site/) để giúp trang trải chi phí máy chủ và thời gian phát triển. Termix miễn phí và mã nguồn mở. Nếu bạn thấy hữu ích, hãy cân nhắc [quyên góp](https://donate.termix.site/) để giúp trang trải chi phí máy chủ và thời gian phát triển.
<br /> <br />
@@ -49,159 +49,201 @@ Termix là dự án miễn phí và mã nguồn mở. Nếu bạn thấy hữu
<p> <p>
<img src="../repo-images/Repo of the Day.png" alt="Repo of the Day Achievement" width="280" /> <img src="../repo-images/Repo of the Day.png" alt="Repo of the Day Achievement" width="280" />
<br /> <br />
<sub>Dat duoc vao ngay 1 thang 9 nam 2025</sub> <sub>Đạt được vào ngày 1 tháng 9 năm 2025</sub>
</p> </p>
</div> </div>
<br /> <br />
## Tong Quan ## Tng quan
Termix la nen tang quan ly may chu tat ca trong mot, ma nguon mo, mien phi vinh vien, tu luu tru. No cung cap giai phap da nen tang de quan ly may chu va co so ha tang cua ban thong qua mot giao dien truc quan duy nhat. Termix cung cap quyen truy cap terminal SSH, dieu khien may tinh tu xa (RDP, VNC, Telnet), kha nang tao duong ham SSH, quan ly tep tu xa va nhieu cong cu khac. Termix la giai phap thay the mien phi va tu luu tru hoan hao cho Termius, kha dung tren tat ca cac nen tang. Termix là nn tng miễn phí, mã ngun m, t lưu trữ để qun lý máy ch ca bạn. Nó gom vào một chỗ terminal SSH, y tính t xa (RDP, VNC, Telnet), truyền tệp, tunnel, Docker, số liệu và tự động hoá, trên web, máy tính và điện thoại. Đây là bản thay thế t lưu tr cho Termius và sẽ miễn phí mãi mãi.
<br /> <br />
## Tinh Nang ## Tính ng
<table> <table>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Truy Cap Terminal SSH:** **Terminal SSH:**
Terminal day du tinh nang voi ho tro chia man hinh (len den 4 bang) voi he thong tab kieu trinh duyet. Bao gom ho tro tuy chinh terminal bao gom cac chu de terminal pho bien, phong chu va cac thanh phan khac. Một terminal đầy đủ với các thẻ giống trình duyệt và chia đôi màn hình, tối đa 6 khung cùng lúc. Bạn tự chọn giao diện, phông chữ và màu sắc. Phía trên mỗi phiên có một thanh công cụ hiện CPU, bộ nhớ và ổ đĩa theo thời gian thực, kèm lối tắt tới tệp, Docker, tunnel và số liệu của máy chủ đó.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Truy Cap Man Hinh Tu Xa:** **Máy tính từ xa:**
Ho tro RDP, VNC va Telnet qua trinh duyet voi day du tuy chinh va chia man hinh. RDP, VNC và Telnet ngay trong trình duyệt, dùng thẻ và chia đôi màn hình như mọi phiên khác. Có trình duyệt tệp cho ổ đĩa RDP và tải lên bằng cách kéo thả. Trên máy tính Windows, bạn còn có thể mở máy chủ bằng ứng dụng RDP của hệ điều hành.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Quan Ly Duong Ham SSH:** **Tunnel SSH:**
Tao va quan ly duong ham SSH giua cac may chu voi tu dong ket noi lai, giam sat suc khoe va chuyen tiep cuc bo, tu xa hoac SOCKS dong. Cai dat duong ham tu may khach desktop den may chu duoc luu tru cuc bo cho moi ban cai dat desktop; cac snapshot C2S preset tuy chon co the duoc luu tren may chu, doi ten, tai hoac xoa khi ban muon di chuyen mot cau hinh duong ham cuc bo giua cac may khach. Chuyển tiếp cc bộ, từ xa và SOCKS động, có tự kết ni lại và kiểm tra tình trạng. Tunnel t máy khách tới máy chủ trong ứng dụng máy tính được lưu ngay trên máy đó, và bạn có thể lưu cấu hình sẵn lên máy chủ để mang sang máy khác.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Trinh Quan Ly Tep Tu Xa:** **Trình quản lý tệp:**
Quan ly tep truc tiep tren may chu tu xa voi ho tro xem va chinh sua ma, hinh anh, am thanh va video. Tai len, tai xuong, doi ten, xoa va di chuyen tep lien mach voi ho tro sudo. Bao gom ho tro di chuyen tep tu may chu nay sang may chu khac. Duyệt, sửa, tải lên, tải xuống, đổi tên, di chuyển và xoá tệp qua SFTP, có h trợ sudo. Xem và sa mã nguồn, hình nh, âm thanh và video. Sao chép tệp thẳng từ máy chủ này sang máy chủ khác, h thống tự chọn đường nhanh nhất và kiểm tra tính toàn vẹn khi truyền.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Quan Ly Docker va Podman:** **Docker và Podman:**
Khoi dong, dung, tam dung, xoa container. Xem thong ke container. Dieu khien container bang terminal docker exec. Ho tro ca Docker va Podman lam moi truong chay container. Khong duoc tao ra de thay the Portainer hay Dockge ma don gian la de quan ly container cua ban thay vi tao moi chung. Khi động, dng, tm dng xoá container, xem thông số của chúng và mở một shell bên trong. Chạy được với c Docker lẫn Podman. Nó không nhằm thay thế Portainer hay Dockge, chỉ để qun lý những container bạn đã có.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Trinh Quan Ly May Chu SSH:** **Qun lý máy chủ:**
Luu, sap xep va quan ly cac ket noi SSH cua ban voi the va thu muc (ho tro tuy chinh thu muc va thu muc long nhau), de dang luu thong tin dang nhap co the tai su dung dong thoi co the tu dong hoa viec trien khai khoa SSH. Lưu và sp xếp máy chủ bằng th và thư mc lồng nhau mà bạn có thể đặt tên và tô màu. Dùng lại thông tin đăng nhp đã lưu cho nhiều máy chủ, tự động triển khai khoá SSH, gom máy chủ dưới một máy chủ cha, sửa và xuất hàng loạt, và dùng kết nối nhanh cho những lần kết nối một lần mà bạn không muốn lưu.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Chi So May Chu:** **Số liệu máy chủ:**
Xem muc su dung CPU, bo nho, o dia, mang, thoi gian hoat dong, thong tin he thong, tuong lua, giam sat cong, trinh xem nhat ky, nguoi dung/quyen, chung chi va nhieu hon nua tren hau het cac may chu chay Linux. Bao gom bieu do lich su theo chuoi thoi gian va canh bao dua tren nguong voi ho tro ntfy va webhook. CPU, b nh, ổ đĩa, mng, nhiệt độ, thi gian hot động, tiến trình, cổng, lượt đăng nhập và thông tin hệ thống trên hu hết máy chủ Linux, kèm biu đồ lch sử. Các thẻ quản lý cho phép bạn xử lý dịch vụ, tác vụ cron, gói phần mềm, người dùng, luật tường lửa, WireGuard, Tailscale, chứng chỉ SSL, nhật ký và kiểm tra tình trạng mà không cần rời Termix.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Xac Thuc Nguoi Dung:** **Tự động hoá:**
Quan ly nguoi dung an toan voi quyen quan tri (co the chinh sua thong tin cua nguoi dung khac) va ho tro OIDC/LDAP/SSO (co kiem soat truy cap), 2FA (TOTP) va passkey (WebAuthn). Xem phien hoat dong cua nguoi dung tren tat ca cac nen tang va thu hoi quyen. Lien ket tai khoan OIDC/Noi bo cua ban voi nhau. Xem nhat ky kiem toan cac hanh dong cua tat ca nguoi dung. Chọn một điều kiện kích hoạt, rồi nói bạn muốn điều gì xảy ra. Điều kiện gồm một số liệu vượt ngưỡng, một máy chủ sập hoặc sống lại, kim tra tình trạng thay đổi, một lịch định sẵn, một sự kiện container, hoặc một webhook gửi đến. Các bước có thể chạy lệnh và đoạn lệnh, điều khiển container và tunnel, đánh thức máy chủ, gọi một địa chỉ, chờ, rẽ nhánh theo điều kiện, chạy một tự động hoá khác, và báo cho bạn qua ntfy, Discord hoặc webhook. Chạy thử giúp bạn kim tra an toàn trước.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Tich Hop Tailscale:** **Nhóm máy chủ:**
Liet ke cac thiet bi trong mang Tailscale de nhanh chong them vao lam may chu, va ket noi bang Tailscale SSH lam phuong thuc xac thuc, de cac ACL mang xu ly uy quyen ma khong can luu tru thong tin xac thuc. Gom máy chủ vào một nhóm bằng cách tự chọn hoặc theo luật thẻ, để máy chủ mới tự vào nhóm. Chạy một lệnh trên mọi máy chủ cùng lúc, đẩy và lấy tệp trên tất cả, cài gói phần mềm, và thu thập danh sách hệ điều hành, nhân, kiến trúc và thời gian hoạt động.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**RBAC/Chia Se:** **Trợ lý AI:**
Tao vai tro va chia se may chu giua nguoi dung/vai tro. Ho tro tat ca cac loai xac thuc va tat ca cac giao thuc may chu. Là tuỳ chọn, và tắt cho đến khi bạn tự bật. Kết nối OpenAI, Anthropic, Gemini, Ollama hoặc bất kỳ endpoint tương thích OpenAI nào rồi hỏi về hệ thống của bạn. Nó đọc được máy chủ, nhóm máy chủ, đoạn lệnh và cảnh báo, và đề xuất thay đổi để bạn duyệt chứ không tự làm. Nó không bao giờ chạm được vào thông tin đăng nhập, người dùng hay thiết lập. Quản trị viên có thể tắt hẳn cho cả hệ thống, còn bạn có thể ẩn nó ngay khi cài đặt ban đầu.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Ket Noi Noi Tiep:** **Đăng nhập và người dùng:**
Ket noi voi cac thiet bi noi tiep (router, switch, vi dieu khien, v.v.) truc tiep tu trinh duyet hoac ung dung may tinh. Cau hinh toc do baud, bit du lieu, bit dung va chan le. Su dung Web Serial API tren trinh duyet duoc ho tro hoac backend ban dia trong ung dung Electron. Tài khoản cc bộ cùng với đăng nhập qua OIDC, LDAP, GitHub và Google, kèm xác thực hai bước (TOTP), passkey (WebAuthn) và thiết bị tin cậy. Quản trị viên có thể quản lý người dùng, ánh xạ nhóm OIDC sang vai trò, xem mọi phiên đang hoạt động trên mọi nền tảng và thu hồi chúng. Bạn có thể liên kết tài khoản cục bộ với tài khoản OIDC, và xem nhật ký kiểm toán về những gì mọi người đã làm.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Canh Bao:** **Vai trò và chia sẻ:**
Dat cac quy tac canh bao dua tren nguong cho chi so may chu (CPU, bo nho, o dia, v.v.) va nhan thong bao qua ntfy hoac webhook khi chung kich hoat. Xem canh bao dang kich hoat va da giai quyet trong nhat ky lich su. Tạo vai trò và chia s máy chủ với người dùng hoặc vai trò theo bốn mức: kết nối, xem, sửa và quản lý. Hoạt động với mọi kiểu xác thực và mọi giao thức, và bạn có thể thay thông tin đăng nhập dùng cho một máy chủ được chia s.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Trang Chu:** **Cảnh báo:**
Trang chu co the tuy chinh hoan toan voi luoi widget keo va tha. Them widget cho trang thai may chu, lien ket dich vu, dong ho, ghi chu, feed RSS, thoi tiet, container Docker, bieu do chi so may chu, terminal nhung, iframe va nhieu hon nua. Đặt luật cho các số liệu máy chủ như CPU, bộ nhớ và ổ đĩa, rồi nhận thông báo qua ntfy, Discord hoặc webhook khi chúng kích hoạt. Xem cảnh báo đang bật và đã hết trong nhật ký, và bỏ qua nhng cái bạn không quan tâm.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Ma Hoa Co So Du Lieu:** **Trang chủ:**
Backend duoc luu tru duoi dang tep co so du lieu SQLite duoc ma hoa. Xem [tai lieu](https://docs.termix.site) de biet them. Một lưới tiện ích kéo thả do bạn tự dng. Có tiện ích cho tình trạng máy chủ, ping, liên kết dịch vụ, dấu trang, tìm kiếm, đồng hồ, lịch, đếm ngược, ghi chú, RSS, thời tiết, hình ảnh, iframe, Docker, tunnel, biểu đồ số liệu, API riêng, và cả một terminal đang chạy.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Bieu Do Mang:** **Đoạn lệnh và công cụ:**
Tuy chinh Bang Dieu Khien de truc quan hoa homelab cua ban dua tren cac ket noi SSH voi ho tro trang thai. Lưu những lệnh bạn hay dùng và chạy chỉ với một cú nhấp, có biến cho máy chủ và cho phần bn tự nhập. Chạy một lệnh trên tất cả terminal đang mở, và tìm trong lịch sử lệnh với gợi ý tự động.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Cong Cu SSH:** **Chia sẻ phiên:**
Tao doan lenh co the tai su dung, thuc thi chi voi mot cu nhap chuot. Chay mot lenh dong thoi tren nhieu terminal dang mo. Chia sẻ trực tiếp một phiên terminal, RDP, VNC hoặc Telnet. Gửi một liên kết mà ai cũng vào được không cần tài khoản, hoặc chia sẻ với một người dùng Termix cụ thể, ở chế độ chỉ xem hoặc cho phép thao tác. Chia sẻ có thể tự hết hạn hoặc bị thu hồi bất cứ lúc nào, và có thể tắt toàn bộ hoặc theo từng máy chủ.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Tab Lien Tuc:** **Ghi phiên và nhật ký:**
Cac phien SSH va tab van mo tren cac thiet bi/lan lam moi neu duoc bat trong ho so nguoi dung. Ghi lại phiên terminal, RDP và VNC rồi xem lại sau. Tải nhật ký dạng văn bản của một phiên, và xem nhật ký kết nối để biết chính xác chuyện gì đã xảy ra trong lúc kết nối.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Ngon Ngu:** **Kết nối serial:**
Ho tro tich hop khoang 30 ngon ngu (duoc quan ly boi [Crowdin](https://docs.termix.site/translations)). Làm việc với thiết bị serial như router, switch và vi điều khiển từ trình duyệt hoặc ứng dụng máy tính. Đặt tốc độ baud, bit dữ liệu, bit dừng và bit chẵn lẻ. Dùng Web Serial API trên các trình duyệt hỗ trợ, hoặc backend gốc trong ứng dụng máy tính.
</td> </td>
</tr> </tr>
<tr> <tr>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Chia Se Phien:** **Tailscale:**
Chia se mot phien terminal, RDP, VNC, hoac Telnet truc tiep voi nguoi khac theo thoi gian thuc. Chia se qua lien ket (tham gia an danh, khong can tai khoan) hoac voi mot nguoi dung Termix cu the, va chon quyen truy cap chi doc hoac doc/ghi. Cac lien ket chia se co the tu dong het han hoac bi thu hoi bat cu luc nao, va tinh nang chia se phien co the duoc bat/tat toan cuc hoac theo tung host. Lấy thiết bị từ tailnet của bạn để thêm làm máy chủ chỉ với vài cú nhấp, và kết nối bằng Tailscale SSH để ACL của tailnet lo phần quyn truy cập, không cần lưu thông tin đăng nhập. Headscale và endpoint tuỳ chỉnh cũng dùng được.
</td> </td>
<td width="50%" valign="top"> <td width="50%" valign="top">
**Ung Dung Desktop Doc Lap + Dong Bo 2 Chieu:** **Proxmox:**
Ung dung desktop Electron chay hoan toan doc lap voi backend va co so du lieu cuc bo rieng, khong can may chu. Tuy chon ket noi voi may chu Termix tu xa de tu dong dong bo 2 chieu cac host, thong tin dang nhap, doan ma va nhieu hon nua, va chon xem cac ket noi SSH duoc khoi tao cuc bo hay thong qua may chu tu xa. Nhập máy chủ thẳng từ một hệ thống Proxmox, và theo dõi số liu của node và máy ảo, gồm CPU, bộ nhớ và dung lượng, trong một thẻ riêng.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Không gian làm việc và thẻ:**
Lưu một bộ thẻ cùng cách chia màn hình rồi mở lại toàn bộ chỉ với một cú nhấp. Termix cũng nhớ phiên gần nhất, nên các thẻ của bạn quay lại sau khi tải lại trang và trên thiết bị khác.
</td>
<td width="50%" valign="top">
**Cài đặt có hướng dẫn:**
Một phần cài đặt ngắn sẽ hướng bạn chọn kiểu giao diện, chủ đề, những tính năng bạn muốn và máy chủ đầu tiên. Chế độ đơn giản ẩn bớt những gì bạn không dùng, và bạn có thể chạy lại phần cài đặt hoặc đổi kiểu bất cứ lúc nào.
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Ứng dụng máy tính độc lập và đồng bộ:**
Ứng dụng máy tính chạy độc lập với backend và cơ sở dữ liệu riêng, không cần máy chủ. Bạn cũng có thể nối nó với một máy chủ Termix để đồng bộ hai chiều máy chủ, thông tin đăng nhập, đoạn lệnh và nhiều thứ khác, và chọn kết nối xuất phát từ máy của bạn hay đi qua máy chủ.
</td>
<td width="50%" valign="top">
**Dòng lệnh:**
Công cụ `termix` cho shell và các script của bạn. Mở terminal, chạy một lệnh trên một máy chủ hoặc cả một nhóm, chuyển tệp qua SFTP, và quản lý máy chủ, đoạn lệnh và thông tin đăng nhập. Cài bằng `npm install -g @termix-cli/cli` hoặc tải bản chạy độc lập. Xem [tài liệu CLI](https://docs.termix.site/cli).
</td>
</tr>
<tr>
<td width="50%" valign="top">
**Bảo mật:**
Mật khẩu, khoá và các thông tin bí mật khác được mã hoá theo từng người dùng, và bản thân các tệp cơ sở dữ liệu cũng có thể mã hoá trên ổ đĩa. Xem [tài liệu](https://docs.termix.site/security) để biết cách hoạt động.
</td>
<td width="50%" valign="top">
**Ngôn ngữ:**
Có sẵn khoảng 30 ngôn ngữ, quản lý qua [Crowdin](https://docs.termix.site/translations).
</td> </td>
</tr> </tr>
@@ -210,43 +252,46 @@ Ung dung desktop Electron chay hoan toan doc lap voi backend va co so du lieu cu
<br /> <br />
<details> <details>
<summary><b>Them tinh nang</b></summary> <summary><b>Thêm tính năng khác</b></summary>
<br /> <br />
- **Bang Dieu Khien** - Xem thong tin may chu trong nháy mat tren bang dieu khien cua ban - **Bng điều khin** - Nhìn nhanh toàn bộ máy chủ, với các thẻ do bạn tự sắp xếp
- **Khoa API** - Tao khoa API theo pham vi nguoi dung voi ngay het han de su dung cho tu dong hoa/CI - **Sơ đồ mạng** - Vẽ homelab của bạn từ danh sách máy chủ, kèm trạng thái theo thời gian thực
- **Xuat/Nhap Du Lieu** - Xuat va nhap may chu SSH, thong tin xac thuc va du lieu trinh quan ly tep - **Theo dõi tmux** - Xem các phiên, cửa sổ và khung tmux, có xem trước và tìm kiếm
- **Thiet Lap SSL Tu Dong** - Tao va quan ly chung chi SSL tich hop voi chuyen huong HTTPS - **Khoá API** - Khoá theo từng người dùng có ngày hết hạn, dùng cho script và CI
- **Giao Dien Hien Dai** - Giao dien sach se, than thien voi may tinh/di dong duoc xay dung bang React, Tailwind CSS va Shadcn. Chon giua nhieu chu de UI khac nhau bao gom sang, toi, Dracula, v.v. Su dung duong dan URL de mo bat ky ket noi nao o che do toan man hinh. - **Xuất và nhập** - Chuyển máy chủ, thông tin đăng nhập và dữ liệu trình quản lý tệp ra vào
- **Lich Su Lenh** - Tu dong hoan thanh va xem cac lenh SSH da chay truoc do - **SSL tự động** - Chứng chỉ được tạo và gia hạn giúp bạn, kèm chuyển hướng HTTPS, hoặc dùng chứng chỉ của riêng bạn
- **Ket Noi Nhanh** - Ket noi den may chu ma khong can luu du lieu ket noi - **Cơ sở dữ liệu** - Mặc định là SQLite, đồng thời hỗ trợ PostgreSQL và MySQL
- **Bang Lenh** - Nhan dup phim shift trai de truy cap nhanh cac ket noi SSH bang ban phim - **Giao diện hiện đại** - Giao diện React gọn gàng chạy tốt trên máy tính và điện thoại, với các chủ đề như sáng, tối và Dracula. Mọi kết ni đều mở toàn màn hình được từ một địa chỉ
- **Tich Hop Proxmox** - Tu dong them may chu vao Termix tu instance Proxmox cua ban - **Bảng lệnh** - Nhấn hai lần phím Shift trái để nhảy tới một máy chủ bằng bàn phím
- **SSH Giau Tinh Nang** - Ho tro jump host, Warpgate, ket noi dua tren TOTP, SOCKS5, xac minh khoa may chu, tu dong dien mat khau, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, ghi nhat ky terminal, chuyen tiep SSH agent, Bitwarden SSH agent, ky SSH bang HashiCorp Vault va nhieu hon nua. - **Phím tắt** - Chuyển giữa các thẻ, đóng thẻ và nhiều thao tác khác, đều gán lại được
- **Termix ID** - Mot tuong duong cua sshid.io duoc tich hop san trong Termix. Dang ky mot ten dinh danh, cong bo khoa SSH cong khai cua ban tai mot URL phan giai va su dung CA tich hop san de cap chung chi SSH. - **Wake-on-LAN** - Đánh thức một máy từ Termix hoặc từ mt bước tự động hoá
- **Xác thực qua proxy tin cậy** - Để reverse proxy lo phần đăng nhập rồi chuyển thông tin người dùng vào
- **SSH nhiều tính năng** - Máy chủ trung gian, Warpgate, hỏi mã TOTP, SOCKS5, kiểm tra khoá máy chủ, tự điền mật khẩu, [OPKSSH](https://github.com/openpubkey/opkssh), tmux, port knocking, ghi nhật ký terminal, chuyển tiếp agent, SSH agent của Bitwarden, ký SSH bằng HashiCorp Vault và nhiều thứ khác
- **Termix ID** - Bản dựng sẵn theo kiểu sshid.io. Đăng ký một tên, công bố khoá công khai của bạn tại một địa chỉ phân giải, và cấp chứng chỉ SSH từ CA tích hợp
</details> </details>
<br /> <br />
## Ho Tro Nen Tang ## Nền tảng hỗ trợ
<table align="center"> <table align="center">
<tr> <tr>
<th align="center">Nen tang</th> <th align="center">Nn tng</th>
<th align="center">Phan phoi</th> <th align="center">Bản phân phi</th>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Web</b></td> <td align="center"><b>Web</b></td>
<td>Bat ky trinh duyet hien dai nao (Chrome, Safari, Firefox) · Ho tro PWA</td> <td>Mọi trình duyt hin đại (Chrome, Safari, Firefox) · H tr PWA</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Windows</b> <sub>x64/ia32</sub></td> <td align="center"><b>Windows</b> <sub>x64/ia32</sub></td>
<td>Portable · MSI Installer · Chocolatey</td> <td>Bản chạy ngay · Bộ cài MSI · Chocolatey</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>Linux</b> <sub>x64/ia32</sub></td> <td align="center"><b>Linux</b> <sub>x64/ia32</sub></td>
<td>Portable · AUR · AppImage · Deb · Flatpak</td> <td>Bản chạy ngay · AUR · AppImage · Deb · Flatpak</td>
</tr> </tr>
<tr> <tr>
<td align="center"><b>macOS</b> <sub>x64/ia32, v12.0+</sub></td> <td align="center"><b>macOS</b> <sub>x64/ia32, v12.0+</sub></td>
@@ -264,11 +309,11 @@ Ung dung desktop Electron chay hoan toan doc lap voi backend va co so du lieu cu
<br /> <br />
## Cai Dat ## Cài đặt
Truy cap [Tai Lieu](https://docs.termix.site/install) Termix de biet them thong tin ve cach cai dat Termix tren tat ca cac nen tang. Xem [tài liệu Termix](https://docs.termix.site/install) để có hướng dẫn cài đặt đầy đủ trên mọi nn tng.
Tep Docker Compose mau (ban co the bo qua `guacd` va mang neu khong co y dinh su dung cac tinh nang dieu khien may tinh tu xa): Tp Docker Compose mu (bn có th b `guacd` và phần mng nếu không định dùng máy tính t xa):
```yaml ```yaml
services: services:
@@ -305,19 +350,45 @@ networks:
driver: bridge driver: bridge
``` ```
### Dòng lệnh
Termix cũng có CLI, để bạn quản lý máy chủ từ terminal và dùng Termix trong script của mình.
```bash
npm install -g @termix-cli/cli
termix login --url https://termix.example.com
termix ssh 1
```
Nó mở được terminal, chạy lệnh trên một máy chủ hoặc cả một nhóm, chuyển tệp qua SFTP, và quản lý máy chủ, đoạn lệnh và thông tin đăng nhập. Tài liệu đầy đủ ở [docs.termix.site/cli](https://docs.termix.site/cli).
### Chạy trên cloud
Bạn có thể chạy máy chủ Termix trên VPS thay vì trong mạng của mình. Nếu Termix chạy ngay trong mạng mà nó quản lý, một sự cố sẽ kéo nó sập theo, đúng lúc bạn cần nó để sửa. Chạy ở ngoài thì nó luôn truy cập được, cho bạn một IP cố định và vào được từ bất cứ đâu mà không cần VPN hay mở cổng.
[GINERNET](https://docs.termix.site/install/ginernet) là nhà tài trợ của Termix, và tài liệu có hướng dẫn từng bước để triển khai trên nền tảng VPS của họ.
<br />
## Dữ liệu sử dụng
Termix gửi một tín hiệu nhỏ ẩn danh mỗi ngày một lần, để tôi biết có bao nhiêu bản đang chạy và tính năng nào thực sự được dùng. Nó gồm một mã bản cài ngẫu nhiên, số người dùng và máy chủ bạn có, phiên bản ứng dụng, và những tính năng (terminal, trình quản lý tệp, tunnel, docker, v.v.) đã dùng trong 24 giờ qua. Nó không bao giờ chứa tên người dùng, tên máy chủ, địa chỉ IP, thông tin đăng nhập hay bất cứ thứ gì nhận dạng bạn hoặc máy chủ của bạn.
Mặc định là bật. Bạn tắt nó trong phần Cài đặt quản trị, mục Chung, hoặc đặt `ENABLE_TELEMETRY=false` trước cả khi khởi động Termix.
<br /> <br />
## Quyên góp ## Quyên góp
Termix là dự án miễn phí và mã nguồn mở, không có gói đăng ký hay trả phí. Nếu bạn thấy hữu ích, hãy cân nhắc quyên góp để giúp trang trải chi phí máy chủ, tên miền và thời gian phát triển. Các khoản quyên góp cũng giúp tài trợ thời gian nghiên cứu và tìm hiểu những cần thiết để xây dựng các tính năng như SAML, Kubernetes và hỗ trợ Agent. Theo dõi tiến độ và quyên góp bên dưới. Termix miễn phí và mã nguồn mở, không có gói thuê bao hay bản trả phí. Nếu bạn thấy hữu ích, hãy cân nhắc quyên góp để giúp trang trải máy chủ, tên miền và thời gian phát triển. Quyên góp cũng giúp thời gian tìm hiểu những thứ cần thiết cho các tính năng như SAML, Kubernetes và hỗ trợ agent. Theo dõi tiến độ và quyên góp bên dưới.
[Quyên góp](https://donate.termix.site/) [Quyên góp](https://donate.termix.site/)
<br /> <br />
## Nha Tai Tro ## Nhà tài trợ
Ban quan tam den viec dat quang cao tra phi de ho tro phat trien? Gui email toi [mail@termix.site](mailto:mail@termix.site). Bạn muốn đặt qung cáo tr phí để ủng hộ việc phát trin? Gi thư ti [mail@termix.site](mailto:mail@termix.site).
<div align="center"> <div align="center">
@@ -339,10 +410,6 @@ Ban quan tam den viec dat quang cao tra phi de ho tro phat trien? Gui email toi
<img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" /> <img src="https://sirv.sirv.com/website/screenshots/cloudflare/cloudflare-logo.png?w=300" height="40" alt="Cloudflare" />
</a> </a>
&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;
<a href="https://tailscale.com/">
<img src="https://drive.google.com/uc?export=view&id=1lIxkJuX6M23bW-2FElhT0rQieTrzaVSL" height="40" alt="Tailscale" />
</a>
&nbsp;&nbsp;&nbsp;
<a href="https://akamai.com/"> <a href="https://akamai.com/">
<img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" /> <img src="https://upload.wikimedia.org/wikipedia/commons/8/8b/Akamai_logo.svg" height="40" alt="Akamai" />
</a> </a>
@@ -354,18 +421,21 @@ Ban quan tam den viec dat quang cao tra phi de ho tro phat trien? Gui email toi
<a href="https://rackgenius.com/"> <a href="https://rackgenius.com/">
<img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" /> <img src="https://rackgenius.com/rackgenius-logo.png" height="40" alt="Rack Genius" />
</a> </a>
&nbsp;&nbsp;&nbsp;
<a href="https://ginernet.com/">
<img src="https://ginernet.com/img/logo-web.png" height="40" alt="Ginernet" />
</a>
</div> </div>
<br /> <br />
## Ho Tro ## Hỗ trợ
Neu ban can tro giup hoac muon yeu cau tinh nang voi Termix, hay truy cap trang [Van De](https://github.com/Termix-SSH/Support/issues), dang nhap va nhan `New Issue`. Vui long mo ta van de cang chi tiet cang tot, uu tien viet bang tieng Anh. Ban cung co the tham gia may chu [Discord](https://discord.gg/jVQGdvHDrf) va truy cap kenh ho tro, tuy nhien thoi gian phan hoi co the lau hon. Cần giúp đỡ hoc mun đề xuất tính năng? Hãy mở một [issue mới](https://github.com/Termix-SSH/Support/issues) mô t càng chi tiết càng tt, bằng tiếng Anh nếu được. Bn cũng có thể hỏi trong kênh hỗ trợ trên [Discord](https://discord.gg/jVQGdvHDrf), tuy nhiên ở đó có thể lâu được trả lời hơn.
<br /> <br />
## Anh Chup Man Hinh ## nh chụp màn hình
<div align="center"> <div align="center">
@@ -373,7 +443,7 @@ Neu ban can tro giup hoac muon yeu cau tinh nang voi Termix, hay truy cap trang
[![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos) [![YouTube](../repo-images/YouTube.png)](https://www.youtube.com/@TermixSSH/videos)
<sub>Xem tong quan cap nhat tren YouTube</sub> <sub>Xem giới thiệu các bản cp nht trên YouTube</sub>
<br /> <br />
<br /> <br />
@@ -413,18 +483,18 @@ Neu ban can tro giup hoac muon yeu cau tinh nang voi Termix, hay truy cap trang
</tr> </tr>
</table> </table>
<sub>Mot so video va hinh anh co the da loi thoi hoac khong the hien chinh xac hoan toan cac tinh nang.</sub> <sub>Mt s video và hình nh có thể đã cũ hoc chưa th hiện đầy đủ tính năng.</sub>
</div> </div>
<br /> <br />
## Tinh Nang Du Kien ## Tính ng dự kiến
Xem [Du An](https://github.com/orgs/Termix-SSH/projects/5) de biet tat ca cac tinh nang du kien. Neu ban muon dong gop, xem [Dong Gop](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md). Toàn bộ tính năng dự kiến nằm ở [Projects](https://github.com/orgs/Termix-SSH/projects/5). Nếu bn mun đóng góp, xem [Contributing](https://github.com/Termix-SSH/Termix/blob/main/CONTRIBUTING.md).
<br /> <br />
## Giay Phep ## Giy phép
Duoc phan phoi theo Giay Phep Apache Phien Ban 2.0. Xem `LICENSE` de biet them thong tin. Phát hành theo Giy phép Apache phiên bản 2.0. Xem `LICENSE` để biết thêm chi tiết.
+10
View File
@@ -0,0 +1,10 @@
CREATE TABLE `host_sidebar_preferences` (
`user_id` varchar(255) NOT NULL,
`data` text NOT NULL,
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
CONSTRAINT `host_sidebar_preferences_user_id` PRIMARY KEY(`user_id`)
);
--> statement-breakpoint
ALTER TABLE `ssh_data` ADD `sort_order` int;--> statement-breakpoint
ALTER TABLE `ssh_folders` ADD `sort_order` int;--> statement-breakpoint
ALTER TABLE `host_sidebar_preferences` ADD CONSTRAINT `host_sidebar_preferences_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;
+10
View File
@@ -0,0 +1,10 @@
CREATE TABLE `credential_sidebar_preferences` (
`user_id` varchar(255) NOT NULL,
`data` text NOT NULL,
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
CONSTRAINT `credential_sidebar_preferences_user_id` PRIMARY KEY(`user_id`)
);
--> statement-breakpoint
ALTER TABLE `ssh_credentials` ADD `pin` boolean DEFAULT false NOT NULL;--> statement-breakpoint
ALTER TABLE `ssh_credentials` ADD `sort_order` int;--> statement-breakpoint
ALTER TABLE `credential_sidebar_preferences` ADD CONSTRAINT `credential_sidebar_preferences_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;
+1
View File
@@ -0,0 +1 @@
ALTER TABLE `snippets` ADD `is_note` boolean DEFAULT false NOT NULL;
@@ -0,0 +1,28 @@
CREATE TABLE `proxmox_node_history` (
`id` int AUTO_INCREMENT NOT NULL,
`host_id` int NOT NULL,
`ts` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
`cpu_percent` double,
`mem_percent` double,
`disk_percent` double,
`net_rx_bytes` int,
`net_tx_bytes` int,
CONSTRAINT `proxmox_node_history_id` PRIMARY KEY(`id`)
);
--> statement-breakpoint
CREATE TABLE `proxmox_stats_preferences` (
`id` int AUTO_INCREMENT NOT NULL,
`user_id` varchar(255) NOT NULL,
`host_id` int NOT NULL,
`layout` text NOT NULL,
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
CONSTRAINT `proxmox_stats_preferences_id` PRIMARY KEY(`id`),
CONSTRAINT `idx_proxmox_stats_prefs_user_host` UNIQUE(`user_id`,`host_id`)
);
--> statement-breakpoint
ALTER TABLE `ssh_data` ADD `enable_proxmox_stats` boolean DEFAULT false NOT NULL;--> statement-breakpoint
ALTER TABLE `ssh_data` ADD `proxmox_stats_config` text;--> statement-breakpoint
ALTER TABLE `proxmox_node_history` ADD CONSTRAINT `proxmox_node_history_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `proxmox_stats_preferences` ADD CONSTRAINT `proxmox_stats_preferences_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `proxmox_stats_preferences` ADD CONSTRAINT `proxmox_stats_preferences_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;
+1
View File
@@ -0,0 +1 @@
ALTER TABLE `ssh_data` ADD `enable_terminal_toolbar` boolean DEFAULT true NOT NULL;
@@ -0,0 +1,45 @@
CREATE TABLE `fleet_inventory` (
`id` int AUTO_INCREMENT NOT NULL,
`host_id` int NOT NULL,
`user_id` varchar(255) NOT NULL,
`os_pretty_name` text,
`kernel` text,
`architecture` text,
`hostname` text,
`uptime_seconds` int,
`ip` text,
`package_manager` text,
`collected_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
CONSTRAINT `fleet_inventory_id` PRIMARY KEY(`id`),
CONSTRAINT `idx_fleet_inventory_host` UNIQUE(`host_id`,`user_id`)
);
--> statement-breakpoint
CREATE TABLE `fleet_members` (
`id` int AUTO_INCREMENT NOT NULL,
`fleet_id` int NOT NULL,
`host_id` int NOT NULL,
`added_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
CONSTRAINT `fleet_members_id` PRIMARY KEY(`id`),
CONSTRAINT `idx_fleet_members_fleet_host` UNIQUE(`fleet_id`,`host_id`)
);
--> statement-breakpoint
CREATE TABLE `fleets` (
`id` int AUTO_INCREMENT NOT NULL,
`user_id` varchar(255) NOT NULL,
`name` varchar(255) NOT NULL,
`description` text,
`color` text,
`icon` text,
`tag_rules` text,
`sync_id` varchar(255),
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
CONSTRAINT `fleets_id` PRIMARY KEY(`id`),
CONSTRAINT `fleets_sync_id_unique` UNIQUE(`sync_id`)
);
--> statement-breakpoint
ALTER TABLE `fleet_inventory` ADD CONSTRAINT `fleet_inventory_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `fleet_inventory` ADD CONSTRAINT `fleet_inventory_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `fleet_members` ADD CONSTRAINT `fleet_members_fleet_id_fleets_id_fk` FOREIGN KEY (`fleet_id`) REFERENCES `fleets`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `fleet_members` ADD CONSTRAINT `fleet_members_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `fleets` ADD CONSTRAINT `fleets_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;
+2
View File
@@ -0,0 +1,2 @@
ALTER TABLE `ssh_data` ADD `parent_host_id` int;--> statement-breakpoint
ALTER TABLE `ssh_data` ADD CONSTRAINT `ssh_data_parent_host_id_ssh_data_id_fk` FOREIGN KEY (`parent_host_id`) REFERENCES `ssh_data`(`id`) ON DELETE set null ON UPDATE no action;
+18
View File
@@ -0,0 +1,18 @@
CREATE TABLE `user_workspaces` (
`id` int AUTO_INCREMENT NOT NULL,
`user_id` varchar(255) NOT NULL,
`name` varchar(255) NOT NULL,
`color` text,
`icon` text,
`kind` text NOT NULL DEFAULT ('manual'),
`is_default` boolean NOT NULL DEFAULT false,
`payload` text NOT NULL DEFAULT ('{}'),
`sync_id` varchar(255),
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
`last_used_at` text,
CONSTRAINT `user_workspaces_id` PRIMARY KEY(`id`),
CONSTRAINT `user_workspaces_sync_id_unique` UNIQUE(`sync_id`)
);
--> statement-breakpoint
ALTER TABLE `user_workspaces` ADD CONSTRAINT `user_workspaces_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;
+26
View File
@@ -0,0 +1,26 @@
ALTER TABLE `api_keys` MODIFY COLUMN `expires_at` varchar(255);--> statement-breakpoint
ALTER TABLE `audit_logs` MODIFY COLUMN `action` varchar(255) NOT NULL;--> statement-breakpoint
ALTER TABLE `audit_logs` MODIFY COLUMN `resource_type` varchar(255) NOT NULL;--> statement-breakpoint
ALTER TABLE `audit_logs` MODIFY COLUMN `timestamp` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `host_access` MODIFY COLUMN `expires_at` varchar(255);--> statement-breakpoint
ALTER TABLE `opkssh_tokens` MODIFY COLUMN `expires_at` varchar(255) NOT NULL;--> statement-breakpoint
ALTER TABLE `recent_activity` MODIFY COLUMN `timestamp` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `session_shares` MODIFY COLUMN `expires_at` varchar(255) NOT NULL;--> statement-breakpoint
ALTER TABLE `sessions` MODIFY COLUMN `expires_at` varchar(255) NOT NULL;--> statement-breakpoint
ALTER TABLE `snippet_access` MODIFY COLUMN `expires_at` varchar(255);--> statement-breakpoint
ALTER TABLE `trusted_devices` MODIFY COLUMN `expires_at` varchar(255) NOT NULL;--> statement-breakpoint
ALTER TABLE `vault_tokens` MODIFY COLUMN `expires_at` varchar(255) NOT NULL;--> statement-breakpoint
ALTER TABLE `webauthn_credentials` MODIFY COLUMN `credential_id` varchar(255) NOT NULL;--> statement-breakpoint
CREATE INDEX `idx_audit_logs_timestamp` ON `audit_logs` (`timestamp`);--> statement-breakpoint
CREATE INDEX `idx_audit_logs_user_ts` ON `audit_logs` (`user_id`,`timestamp`);--> statement-breakpoint
CREATE INDEX `idx_audit_logs_action_ts` ON `audit_logs` (`action`,`timestamp`);--> statement-breakpoint
CREATE INDEX `idx_audit_logs_resource_ts` ON `audit_logs` (`resource_type`,`timestamp`);--> statement-breakpoint
CREATE INDEX `idx_host_access_user_id` ON `host_access` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_host_access_role_id` ON `host_access` (`role_id`);--> statement-breakpoint
CREATE INDEX `idx_host_access_host_id` ON `host_access` (`host_id`);--> statement-breakpoint
CREATE INDEX `idx_host_access_expires_at` ON `host_access` (`expires_at`);--> statement-breakpoint
CREATE INDEX `idx_ssh_data_user_id` ON `ssh_data` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_ssh_data_parent_host` ON `ssh_data` (`parent_host_id`);--> statement-breakpoint
CREATE INDEX `idx_ssh_data_credential` ON `ssh_data` (`credential_id`);--> statement-breakpoint
CREATE INDEX `idx_sessions_user_id` ON `sessions` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_sessions_expires_at` ON `sessions` (`expires_at`);
@@ -0,0 +1,8 @@
CREATE TABLE `ui_preferences` (
`user_id` varchar(255) NOT NULL,
`data` text NOT NULL,
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
CONSTRAINT `ui_preferences_user_id` PRIMARY KEY(`user_id`)
);
--> statement-breakpoint
ALTER TABLE `ui_preferences` ADD CONSTRAINT `ui_preferences_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;
+32
View File
@@ -0,0 +1,32 @@
ALTER TABLE `alert_firings` MODIFY COLUMN `fired_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `session_recordings` MODIFY COLUMN `started_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `session_shares` MODIFY COLUMN `session_id` varchar(255) NOT NULL;--> statement-breakpoint
CREATE INDEX `idx_alert_firings_rule` ON `alert_firings` (`rule_id`,`fired_at`);--> statement-breakpoint
CREATE INDEX `idx_alert_firings_host` ON `alert_firings` (`host_id`);--> statement-breakpoint
CREATE INDEX `idx_api_keys_user_id` ON `api_keys` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_command_history_user_host` ON `command_history` (`user_id`,`host_id`);--> statement-breakpoint
CREATE INDEX `idx_dismissed_alerts_user_id` ON `dismissed_alerts` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_file_manager_pinned_user` ON `file_manager_pinned` (`user_id`,`host_id`);--> statement-breakpoint
CREATE INDEX `idx_file_manager_recent_user` ON `file_manager_recent` (`user_id`,`host_id`);--> statement-breakpoint
CREATE INDEX `idx_file_manager_shortcuts_user` ON `file_manager_shortcuts` (`user_id`,`host_id`);--> statement-breakpoint
CREATE INDEX `idx_fleet_inventory_user` ON `fleet_inventory` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_fleet_members_host` ON `fleet_members` (`host_id`);--> statement-breakpoint
CREATE INDEX `idx_homepage_items_user_id` ON `homepage_items` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_recent_activity_user_ts` ON `recent_activity` (`user_id`,`timestamp`);--> statement-breakpoint
CREATE INDEX `idx_session_recordings_user_started` ON `session_recordings` (`user_id`,`started_at`);--> statement-breakpoint
CREATE INDEX `idx_session_recordings_host` ON `session_recordings` (`host_id`);--> statement-breakpoint
CREATE INDEX `idx_session_shares_session_id` ON `session_shares` (`session_id`);--> statement-breakpoint
CREATE INDEX `idx_session_shares_host_id` ON `session_shares` (`host_id`);--> statement-breakpoint
CREATE INDEX `idx_snippet_access_user_id` ON `snippet_access` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_snippet_access_snippet_id` ON `snippet_access` (`snippet_id`);--> statement-breakpoint
CREATE INDEX `idx_snippet_access_role_id` ON `snippet_access` (`role_id`);--> statement-breakpoint
CREATE INDEX `idx_snippets_user_id` ON `snippets` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_ssh_credential_usage_credential` ON `ssh_credential_usage` (`credential_id`);--> statement-breakpoint
CREATE INDEX `idx_ssh_credential_usage_user` ON `ssh_credential_usage` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_ssh_credentials_user_id` ON `ssh_credentials` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_ssh_folders_user_id` ON `ssh_folders` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_transfer_recent_user` ON `transfer_recent` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_trusted_devices_user_id` ON `trusted_devices` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_user_open_tabs_user_id` ON `user_open_tabs` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_user_roles_role_id` ON `user_roles` (`role_id`);--> statement-breakpoint
CREATE INDEX `idx_user_workspaces_user_id` ON `user_workspaces` (`user_id`);
+224
View File
@@ -0,0 +1,224 @@
CREATE TABLE `ai_conversations` (
`id` int AUTO_INCREMENT NOT NULL,
`user_id` varchar(255) NOT NULL,
`title` text,
`provider_id` int,
`model` text,
`created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP),
`updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP),
CONSTRAINT `ai_conversations_id` PRIMARY KEY(`id`)
);
--> statement-breakpoint
CREATE TABLE `ai_messages` (
`id` int AUTO_INCREMENT NOT NULL,
`conversation_id` int NOT NULL,
`role` text NOT NULL,
`content` text NOT NULL DEFAULT (''),
`tool_calls` text,
`created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP),
CONSTRAINT `ai_messages_id` PRIMARY KEY(`id`)
);
--> statement-breakpoint
CREATE TABLE `ai_proposals` (
`id` int AUTO_INCREMENT NOT NULL,
`conversation_id` int NOT NULL,
`user_id` varchar(255) NOT NULL,
`kind` text NOT NULL,
`summary` text,
`payload` text NOT NULL DEFAULT ('{}'),
`status` varchar(255) NOT NULL DEFAULT 'pending',
`applied_at` text,
`result_summary` text,
`created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP),
CONSTRAINT `ai_proposals_id` PRIMARY KEY(`id`)
);
--> statement-breakpoint
CREATE TABLE `ai_providers` (
`id` int AUTO_INCREMENT NOT NULL,
`user_id` varchar(255) NOT NULL,
`provider_type` text NOT NULL,
`label` varchar(255) NOT NULL,
`base_url` text,
`api_key` text,
`api_key_prefix` text,
`default_model` text,
`enabled` boolean NOT NULL DEFAULT true,
`created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP),
`updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP),
CONSTRAINT `ai_providers_id` PRIMARY KEY(`id`),
CONSTRAINT `idx_ai_providers_user_label` UNIQUE(`user_id`,`label`)
);
--> statement-breakpoint
CREATE TABLE `automation_channels` (
`id` int AUTO_INCREMENT NOT NULL,
`automation_id` int NOT NULL,
`channel_id` int NOT NULL,
CONSTRAINT `automation_channels_id` PRIMARY KEY(`id`),
CONSTRAINT `idx_automation_channels_pair` UNIQUE(`automation_id`,`channel_id`)
);
--> statement-breakpoint
CREATE TABLE `automation_run_steps` (
`id` int AUTO_INCREMENT NOT NULL,
`run_id` int NOT NULL,
`step_index` int NOT NULL,
`step_id` text NOT NULL,
`step_type` text NOT NULL,
`status` varchar(255) NOT NULL,
`started_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP),
`finished_at` text,
`output` text,
`error` text,
`truncated` boolean NOT NULL DEFAULT false,
CONSTRAINT `automation_run_steps_id` PRIMARY KEY(`id`)
);
--> statement-breakpoint
CREATE TABLE `automation_runs` (
`id` int AUTO_INCREMENT NOT NULL,
`automation_id` int NOT NULL,
`user_id` varchar(255) NOT NULL,
`trigger_type` text NOT NULL,
`trigger_context` text,
`status` varchar(255) NOT NULL,
`started_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP),
`finished_at` text,
`duration_ms` int,
`error` text,
`dry_run` boolean NOT NULL DEFAULT false,
`parent_run_id` int,
CONSTRAINT `automation_runs_id` PRIMARY KEY(`id`)
);
--> statement-breakpoint
CREATE TABLE `automation_schedules` (
`id` int AUTO_INCREMENT NOT NULL,
`automation_id` int NOT NULL,
`cron` text,
`interval_seconds` int,
`timezone` text,
`next_due_at` varchar(255),
`last_tick_at` text,
CONSTRAINT `automation_schedules_id` PRIMARY KEY(`id`),
CONSTRAINT `idx_automation_schedules_automation` UNIQUE(`automation_id`)
);
--> statement-breakpoint
CREATE TABLE `automation_trigger_state` (
`id` int AUTO_INCREMENT NOT NULL,
`automation_id` int NOT NULL,
`state_key` varchar(255) NOT NULL,
`breach_started_at` text,
`last_fired_at` text,
`last_value` double,
`last_observed_state` text,
`updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP),
CONSTRAINT `automation_trigger_state_id` PRIMARY KEY(`id`),
CONSTRAINT `idx_automation_trigger_state_key` UNIQUE(`automation_id`,`state_key`)
);
--> statement-breakpoint
CREATE TABLE `automations` (
`id` int AUTO_INCREMENT NOT NULL,
`user_id` varchar(255) NOT NULL,
`name` varchar(255) NOT NULL,
`description` text,
`enabled` boolean NOT NULL DEFAULT true,
`definition` text NOT NULL,
`definition_version` int NOT NULL DEFAULT 1,
`concurrency_policy` text NOT NULL DEFAULT ('skip'),
`max_run_seconds` int NOT NULL DEFAULT 300,
`dry_run` boolean NOT NULL DEFAULT false,
`last_run_at` text,
`last_run_status` text,
`created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP),
`updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP),
CONSTRAINT `automations_id` PRIMARY KEY(`id`)
);
--> statement-breakpoint
ALTER TABLE `alert_rules` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `alert_rules` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `api_keys` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `c2s_tunnel_presets` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `c2s_tunnel_presets` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `credential_sidebar_preferences` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `dashboard_service_links` MODIFY COLUMN `label` varchar(255) NOT NULL;--> statement-breakpoint
ALTER TABLE `dashboard_service_links` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `dashboard_service_links` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `file_manager_shortcuts` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `fleets` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `fleets` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `homepage_items` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `homepage_items` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `homepage_layouts` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `host_access` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `host_health_checks` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `host_health_checks` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `host_metrics_preferences` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `host_metrics_preferences` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `host_sidebar_preferences` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `ssh_data` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `ssh_data` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `network_topology` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `network_topology` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `notification_channels` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `opkssh_tokens` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `proxmox_stats_preferences` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `proxmox_stats_preferences` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `roles` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `roles` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `session_shares` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `sessions` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `shared_host_auth_overrides` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `shared_host_auth_overrides` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `shared_host_secrets` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `shared_host_secrets` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `snippet_access` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `snippet_folders` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `snippet_folders` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `snippets` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `snippets` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `ssh_credentials` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `ssh_credentials` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `ssh_folders` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `ssh_folders` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `sso_providers` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `sso_providers` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `termix_identities` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `termix_identities` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `termix_identity_ca` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `termix_identity_ca` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `termix_identity_keys` MODIFY COLUMN `label` varchar(255);--> statement-breakpoint
ALTER TABLE `termix_identity_keys` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `tmux_session_tags` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `trusted_devices` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `ui_preferences` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `user_open_tabs` MODIFY COLUMN `label` varchar(255) NOT NULL;--> statement-breakpoint
ALTER TABLE `user_open_tabs` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `user_open_tabs` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `user_preferences` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `user_workspaces` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `user_workspaces` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `vault_profiles` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `vault_profiles` MODIFY COLUMN `updated_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `vault_tokens` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `webauthn_credentials` MODIFY COLUMN `created_at` varchar(255) NOT NULL DEFAULT (CURRENT_TIMESTAMP);--> statement-breakpoint
ALTER TABLE `user_preferences` ADD `ai_assistant_enabled` boolean;--> statement-breakpoint
ALTER TABLE `user_preferences` ADD `ai_read_only_commands` boolean;--> statement-breakpoint
ALTER TABLE `ai_conversations` ADD CONSTRAINT `ai_conversations_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `ai_messages` ADD CONSTRAINT `ai_messages_conversation_id_ai_conversations_id_fk` FOREIGN KEY (`conversation_id`) REFERENCES `ai_conversations`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `ai_proposals` ADD CONSTRAINT `ai_proposals_conversation_id_ai_conversations_id_fk` FOREIGN KEY (`conversation_id`) REFERENCES `ai_conversations`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `ai_proposals` ADD CONSTRAINT `ai_proposals_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `ai_providers` ADD CONSTRAINT `ai_providers_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `automation_channels` ADD CONSTRAINT `automation_channels_automation_id_automations_id_fk` FOREIGN KEY (`automation_id`) REFERENCES `automations`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `automation_channels` ADD CONSTRAINT `automation_channels_channel_id_notification_channels_id_fk` FOREIGN KEY (`channel_id`) REFERENCES `notification_channels`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `automation_run_steps` ADD CONSTRAINT `automation_run_steps_run_id_automation_runs_id_fk` FOREIGN KEY (`run_id`) REFERENCES `automation_runs`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `automation_runs` ADD CONSTRAINT `automation_runs_automation_id_automations_id_fk` FOREIGN KEY (`automation_id`) REFERENCES `automations`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `automation_runs` ADD CONSTRAINT `automation_runs_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `automation_schedules` ADD CONSTRAINT `automation_schedules_automation_id_automations_id_fk` FOREIGN KEY (`automation_id`) REFERENCES `automations`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `automation_trigger_state` ADD CONSTRAINT `automation_trigger_state_automation_id_automations_id_fk` FOREIGN KEY (`automation_id`) REFERENCES `automations`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE `automations` ADD CONSTRAINT `automations_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
CREATE INDEX `idx_ai_conversations_user` ON `ai_conversations` (`user_id`,`updated_at`);--> statement-breakpoint
CREATE INDEX `idx_ai_messages_conversation` ON `ai_messages` (`conversation_id`,`created_at`);--> statement-breakpoint
CREATE INDEX `idx_ai_proposals_user` ON `ai_proposals` (`user_id`,`status`);--> statement-breakpoint
CREATE INDEX `idx_ai_proposals_conversation` ON `ai_proposals` (`conversation_id`);--> statement-breakpoint
CREATE INDEX `idx_automation_run_steps_run` ON `automation_run_steps` (`run_id`,`step_index`);--> statement-breakpoint
CREATE INDEX `idx_automation_runs_automation` ON `automation_runs` (`automation_id`,`started_at`);--> statement-breakpoint
CREATE INDEX `idx_automation_runs_user` ON `automation_runs` (`user_id`,`started_at`);--> statement-breakpoint
CREATE INDEX `idx_automation_schedules_due` ON `automation_schedules` (`next_due_at`);--> statement-breakpoint
CREATE INDEX `idx_automations_user` ON `automations` (`user_id`,`enabled`);
+2
View File
@@ -0,0 +1,2 @@
ALTER TABLE `user_preferences` ADD `terminal_defaults` text;--> statement-breakpoint
ALTER TABLE `user_preferences` ADD `rdp_defaults` text;
+1
View File
@@ -0,0 +1 @@
ALTER TABLE `user_preferences` ADD `terminal_macros` text;
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+98
View File
@@ -8,6 +8,104 @@
"when": 1785738871436, "when": 1785738871436,
"tag": "0000_clean_pretty_boy", "tag": "0000_clean_pretty_boy",
"breakpoints": true "breakpoints": true
},
{
"idx": 1,
"version": "5",
"when": 1786132418625,
"tag": "0001_puzzling_aqueduct",
"breakpoints": true
},
{
"idx": 2,
"version": "5",
"when": 1786147319261,
"tag": "0002_bumpy_korg",
"breakpoints": true
},
{
"idx": 3,
"version": "5",
"when": 1786258964346,
"tag": "0003_dry_human_robot",
"breakpoints": true
},
{
"idx": 4,
"version": "5",
"when": 1786423595505,
"tag": "0004_fancy_spencer_smythe",
"breakpoints": true
},
{
"idx": 5,
"version": "5",
"when": 1786428085301,
"tag": "0005_tearful_mindworm",
"breakpoints": true
},
{
"idx": 6,
"version": "5",
"when": 1786482021452,
"tag": "0006_last_fantastic_four",
"breakpoints": true
},
{
"idx": 7,
"version": "5",
"when": 1786487754919,
"tag": "0007_aspiring_turbo",
"breakpoints": true
},
{
"idx": 8,
"version": "5",
"when": 1786498680274,
"tag": "0008_lame_nighthawk",
"breakpoints": true
},
{
"idx": 9,
"version": "5",
"when": 1786509736628,
"tag": "0009_tan_skaar",
"breakpoints": true
},
{
"idx": 10,
"version": "5",
"when": 1786515117582,
"tag": "0010_small_infant_terrible",
"breakpoints": true
},
{
"idx": 11,
"version": "5",
"when": 1786519424221,
"tag": "0011_easy_the_order",
"breakpoints": true
},
{
"idx": 12,
"version": "5",
"when": 1786598522577,
"tag": "0012_outgoing_ultron",
"breakpoints": true
},
{
"idx": 13,
"version": "5",
"when": 1786737725732,
"tag": "0013_third_wraith",
"breakpoints": true
},
{
"idx": 14,
"version": "5",
"when": 1786757023790,
"tag": "0014_bitter_nextwave",
"breakpoints": true
} }
] ]
} }
@@ -0,0 +1,9 @@
CREATE TABLE "host_sidebar_preferences" (
"user_id" varchar(255) PRIMARY KEY NOT NULL,
"data" text NOT NULL,
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
);
--> statement-breakpoint
ALTER TABLE "ssh_data" ADD COLUMN "sort_order" integer;--> statement-breakpoint
ALTER TABLE "ssh_folders" ADD COLUMN "sort_order" integer;--> statement-breakpoint
ALTER TABLE "host_sidebar_preferences" ADD CONSTRAINT "host_sidebar_preferences_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;
+9
View File
@@ -0,0 +1,9 @@
CREATE TABLE "credential_sidebar_preferences" (
"user_id" varchar(255) PRIMARY KEY NOT NULL,
"data" text NOT NULL,
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
);
--> statement-breakpoint
ALTER TABLE "ssh_credentials" ADD COLUMN "pin" boolean DEFAULT false NOT NULL;--> statement-breakpoint
ALTER TABLE "ssh_credentials" ADD COLUMN "sort_order" integer;--> statement-breakpoint
ALTER TABLE "credential_sidebar_preferences" ADD CONSTRAINT "credential_sidebar_preferences_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;
+1
View File
@@ -0,0 +1 @@
ALTER TABLE "snippets" ADD COLUMN "is_note" boolean DEFAULT false NOT NULL;
@@ -0,0 +1,26 @@
CREATE TABLE "proxmox_node_history" (
"id" serial PRIMARY KEY NOT NULL,
"host_id" integer NOT NULL,
"ts" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
"cpu_percent" double precision,
"mem_percent" double precision,
"disk_percent" double precision,
"net_rx_bytes" integer,
"net_tx_bytes" integer
);
--> statement-breakpoint
CREATE TABLE "proxmox_stats_preferences" (
"id" serial PRIMARY KEY NOT NULL,
"user_id" varchar(255) NOT NULL,
"host_id" integer NOT NULL,
"layout" text NOT NULL,
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
);
--> statement-breakpoint
ALTER TABLE "ssh_data" ADD COLUMN "enable_proxmox_stats" boolean DEFAULT false NOT NULL;--> statement-breakpoint
ALTER TABLE "ssh_data" ADD COLUMN "proxmox_stats_config" text;--> statement-breakpoint
ALTER TABLE "proxmox_node_history" ADD CONSTRAINT "proxmox_node_history_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "proxmox_stats_preferences" ADD CONSTRAINT "proxmox_stats_preferences_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "proxmox_stats_preferences" ADD CONSTRAINT "proxmox_stats_preferences_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
CREATE UNIQUE INDEX "idx_proxmox_stats_prefs_user_host" ON "proxmox_stats_preferences" USING btree ("user_id","host_id");
@@ -0,0 +1 @@
ALTER TABLE "ssh_data" ADD COLUMN "enable_terminal_toolbar" boolean DEFAULT true NOT NULL;
@@ -0,0 +1,42 @@
CREATE TABLE "fleet_inventory" (
"id" serial PRIMARY KEY NOT NULL,
"host_id" integer NOT NULL,
"user_id" varchar(255) NOT NULL,
"os_pretty_name" text,
"kernel" text,
"architecture" text,
"hostname" text,
"uptime_seconds" integer,
"ip" text,
"package_manager" text,
"collected_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
);
--> statement-breakpoint
CREATE TABLE "fleet_members" (
"id" serial PRIMARY KEY NOT NULL,
"fleet_id" integer NOT NULL,
"host_id" integer NOT NULL,
"added_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
);
--> statement-breakpoint
CREATE TABLE "fleets" (
"id" serial PRIMARY KEY NOT NULL,
"user_id" varchar(255) NOT NULL,
"name" varchar(255) NOT NULL,
"description" text,
"color" text,
"icon" text,
"tag_rules" text,
"sync_id" varchar(255),
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
CONSTRAINT "fleets_sync_id_unique" UNIQUE("sync_id")
);
--> statement-breakpoint
ALTER TABLE "fleet_inventory" ADD CONSTRAINT "fleet_inventory_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "fleet_inventory" ADD CONSTRAINT "fleet_inventory_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "fleet_members" ADD CONSTRAINT "fleet_members_fleet_id_fleets_id_fk" FOREIGN KEY ("fleet_id") REFERENCES "public"."fleets"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "fleet_members" ADD CONSTRAINT "fleet_members_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "fleets" ADD CONSTRAINT "fleets_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
CREATE UNIQUE INDEX "idx_fleet_inventory_host" ON "fleet_inventory" USING btree ("host_id","user_id");--> statement-breakpoint
CREATE UNIQUE INDEX "idx_fleet_members_fleet_host" ON "fleet_members" USING btree ("fleet_id","host_id");
@@ -0,0 +1,2 @@
ALTER TABLE "ssh_data" ADD COLUMN "parent_host_id" integer;--> statement-breakpoint
ALTER TABLE "ssh_data" ADD CONSTRAINT "ssh_data_parent_host_id_ssh_data_id_fk" FOREIGN KEY ("parent_host_id") REFERENCES "public"."ssh_data"("id") ON DELETE set null ON UPDATE no action;
@@ -0,0 +1,17 @@
CREATE TABLE "user_workspaces" (
"id" serial PRIMARY KEY NOT NULL,
"user_id" varchar(255) NOT NULL,
"name" varchar(255) NOT NULL,
"color" text,
"icon" text,
"kind" text DEFAULT 'manual' NOT NULL,
"is_default" boolean DEFAULT false NOT NULL,
"payload" text DEFAULT '{}' NOT NULL,
"sync_id" varchar(255),
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
"last_used_at" text,
CONSTRAINT "user_workspaces_sync_id_unique" UNIQUE("sync_id")
);
--> statement-breakpoint
ALTER TABLE "user_workspaces" ADD CONSTRAINT "user_workspaces_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;
@@ -0,0 +1,28 @@
ALTER TABLE "api_keys" ALTER COLUMN "expires_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "audit_logs" ALTER COLUMN "action" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "audit_logs" ALTER COLUMN "resource_type" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "audit_logs" ALTER COLUMN "timestamp" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "audit_logs" ALTER COLUMN "timestamp" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "host_access" ALTER COLUMN "expires_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "opkssh_tokens" ALTER COLUMN "expires_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "recent_activity" ALTER COLUMN "timestamp" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "recent_activity" ALTER COLUMN "timestamp" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "session_shares" ALTER COLUMN "expires_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "sessions" ALTER COLUMN "expires_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "snippet_access" ALTER COLUMN "expires_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "trusted_devices" ALTER COLUMN "expires_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "vault_tokens" ALTER COLUMN "expires_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "webauthn_credentials" ALTER COLUMN "credential_id" SET DATA TYPE varchar(255);--> statement-breakpoint
CREATE INDEX "idx_audit_logs_timestamp" ON "audit_logs" USING btree ("timestamp");--> statement-breakpoint
CREATE INDEX "idx_audit_logs_user_ts" ON "audit_logs" USING btree ("user_id","timestamp");--> statement-breakpoint
CREATE INDEX "idx_audit_logs_action_ts" ON "audit_logs" USING btree ("action","timestamp");--> statement-breakpoint
CREATE INDEX "idx_audit_logs_resource_ts" ON "audit_logs" USING btree ("resource_type","timestamp");--> statement-breakpoint
CREATE INDEX "idx_host_access_user_id" ON "host_access" USING btree ("user_id");--> statement-breakpoint
CREATE INDEX "idx_host_access_role_id" ON "host_access" USING btree ("role_id");--> statement-breakpoint
CREATE INDEX "idx_host_access_host_id" ON "host_access" USING btree ("host_id");--> statement-breakpoint
CREATE INDEX "idx_host_access_expires_at" ON "host_access" USING btree ("expires_at");--> statement-breakpoint
CREATE INDEX "idx_ssh_data_user_id" ON "ssh_data" USING btree ("user_id");--> statement-breakpoint
CREATE INDEX "idx_ssh_data_parent_host" ON "ssh_data" USING btree ("parent_host_id");--> statement-breakpoint
CREATE INDEX "idx_ssh_data_credential" ON "ssh_data" USING btree ("credential_id");--> statement-breakpoint
CREATE INDEX "idx_sessions_user_id" ON "sessions" USING btree ("user_id");--> statement-breakpoint
CREATE INDEX "idx_sessions_expires_at" ON "sessions" USING btree ("expires_at");
+7
View File
@@ -0,0 +1,7 @@
CREATE TABLE "ui_preferences" (
"user_id" varchar(255) PRIMARY KEY NOT NULL,
"data" text NOT NULL,
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
);
--> statement-breakpoint
ALTER TABLE "ui_preferences" ADD CONSTRAINT "ui_preferences_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;
@@ -0,0 +1,34 @@
ALTER TABLE "alert_firings" ALTER COLUMN "fired_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "alert_firings" ALTER COLUMN "fired_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "session_recordings" ALTER COLUMN "started_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "session_recordings" ALTER COLUMN "started_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "session_shares" ALTER COLUMN "session_id" SET DATA TYPE varchar(255);--> statement-breakpoint
CREATE INDEX "idx_alert_firings_rule" ON "alert_firings" USING btree ("rule_id","fired_at");--> statement-breakpoint
CREATE INDEX "idx_alert_firings_host" ON "alert_firings" USING btree ("host_id");--> statement-breakpoint
CREATE INDEX "idx_api_keys_user_id" ON "api_keys" USING btree ("user_id");--> statement-breakpoint
CREATE INDEX "idx_command_history_user_host" ON "command_history" USING btree ("user_id","host_id");--> statement-breakpoint
CREATE INDEX "idx_dismissed_alerts_user_id" ON "dismissed_alerts" USING btree ("user_id");--> statement-breakpoint
CREATE INDEX "idx_file_manager_pinned_user" ON "file_manager_pinned" USING btree ("user_id","host_id");--> statement-breakpoint
CREATE INDEX "idx_file_manager_recent_user" ON "file_manager_recent" USING btree ("user_id","host_id");--> statement-breakpoint
CREATE INDEX "idx_file_manager_shortcuts_user" ON "file_manager_shortcuts" USING btree ("user_id","host_id");--> statement-breakpoint
CREATE INDEX "idx_fleet_inventory_user" ON "fleet_inventory" USING btree ("user_id");--> statement-breakpoint
CREATE INDEX "idx_fleet_members_host" ON "fleet_members" USING btree ("host_id");--> statement-breakpoint
CREATE INDEX "idx_homepage_items_user_id" ON "homepage_items" USING btree ("user_id");--> statement-breakpoint
CREATE INDEX "idx_recent_activity_user_ts" ON "recent_activity" USING btree ("user_id","timestamp");--> statement-breakpoint
CREATE INDEX "idx_session_recordings_user_started" ON "session_recordings" USING btree ("user_id","started_at");--> statement-breakpoint
CREATE INDEX "idx_session_recordings_host" ON "session_recordings" USING btree ("host_id");--> statement-breakpoint
CREATE INDEX "idx_session_shares_session_id" ON "session_shares" USING btree ("session_id");--> statement-breakpoint
CREATE INDEX "idx_session_shares_host_id" ON "session_shares" USING btree ("host_id");--> statement-breakpoint
CREATE INDEX "idx_snippet_access_user_id" ON "snippet_access" USING btree ("user_id");--> statement-breakpoint
CREATE INDEX "idx_snippet_access_snippet_id" ON "snippet_access" USING btree ("snippet_id");--> statement-breakpoint
CREATE INDEX "idx_snippet_access_role_id" ON "snippet_access" USING btree ("role_id");--> statement-breakpoint
CREATE INDEX "idx_snippets_user_id" ON "snippets" USING btree ("user_id");--> statement-breakpoint
CREATE INDEX "idx_ssh_credential_usage_credential" ON "ssh_credential_usage" USING btree ("credential_id");--> statement-breakpoint
CREATE INDEX "idx_ssh_credential_usage_user" ON "ssh_credential_usage" USING btree ("user_id");--> statement-breakpoint
CREATE INDEX "idx_ssh_credentials_user_id" ON "ssh_credentials" USING btree ("user_id");--> statement-breakpoint
CREATE INDEX "idx_ssh_folders_user_id" ON "ssh_folders" USING btree ("user_id");--> statement-breakpoint
CREATE INDEX "idx_transfer_recent_user" ON "transfer_recent" USING btree ("user_id");--> statement-breakpoint
CREATE INDEX "idx_trusted_devices_user_id" ON "trusted_devices" USING btree ("user_id");--> statement-breakpoint
CREATE INDEX "idx_user_open_tabs_user_id" ON "user_open_tabs" USING btree ("user_id");--> statement-breakpoint
CREATE INDEX "idx_user_roles_role_id" ON "user_roles" USING btree ("role_id");--> statement-breakpoint
CREATE INDEX "idx_user_workspaces_user_id" ON "user_workspaces" USING btree ("user_id");
+278
View File
@@ -0,0 +1,278 @@
CREATE TABLE "ai_conversations" (
"id" serial PRIMARY KEY NOT NULL,
"user_id" varchar(255) NOT NULL,
"title" text,
"provider_id" integer,
"model" text,
"created_at" varchar(255) DEFAULT CURRENT_TIMESTAMP NOT NULL,
"updated_at" varchar(255) DEFAULT CURRENT_TIMESTAMP NOT NULL
);
--> statement-breakpoint
CREATE TABLE "ai_messages" (
"id" serial PRIMARY KEY NOT NULL,
"conversation_id" integer NOT NULL,
"role" text NOT NULL,
"content" text DEFAULT '' NOT NULL,
"tool_calls" text,
"created_at" varchar(255) DEFAULT CURRENT_TIMESTAMP NOT NULL
);
--> statement-breakpoint
CREATE TABLE "ai_proposals" (
"id" serial PRIMARY KEY NOT NULL,
"conversation_id" integer NOT NULL,
"user_id" varchar(255) NOT NULL,
"kind" text NOT NULL,
"summary" text,
"payload" text DEFAULT '{}' NOT NULL,
"status" varchar(255) DEFAULT 'pending' NOT NULL,
"applied_at" text,
"result_summary" text,
"created_at" varchar(255) DEFAULT CURRENT_TIMESTAMP NOT NULL
);
--> statement-breakpoint
CREATE TABLE "ai_providers" (
"id" serial PRIMARY KEY NOT NULL,
"user_id" varchar(255) NOT NULL,
"provider_type" text NOT NULL,
"label" varchar(255) NOT NULL,
"base_url" text,
"api_key" text,
"api_key_prefix" text,
"default_model" text,
"enabled" boolean DEFAULT true NOT NULL,
"created_at" varchar(255) DEFAULT CURRENT_TIMESTAMP NOT NULL,
"updated_at" varchar(255) DEFAULT CURRENT_TIMESTAMP NOT NULL
);
--> statement-breakpoint
CREATE TABLE "automation_channels" (
"id" serial PRIMARY KEY NOT NULL,
"automation_id" integer NOT NULL,
"channel_id" integer NOT NULL
);
--> statement-breakpoint
CREATE TABLE "automation_run_steps" (
"id" serial PRIMARY KEY NOT NULL,
"run_id" integer NOT NULL,
"step_index" integer NOT NULL,
"step_id" text NOT NULL,
"step_type" text NOT NULL,
"status" varchar(255) NOT NULL,
"started_at" varchar(255) DEFAULT CURRENT_TIMESTAMP NOT NULL,
"finished_at" text,
"output" text,
"error" text,
"truncated" boolean DEFAULT false NOT NULL
);
--> statement-breakpoint
CREATE TABLE "automation_runs" (
"id" serial PRIMARY KEY NOT NULL,
"automation_id" integer NOT NULL,
"user_id" varchar(255) NOT NULL,
"trigger_type" text NOT NULL,
"trigger_context" text,
"status" varchar(255) NOT NULL,
"started_at" varchar(255) DEFAULT CURRENT_TIMESTAMP NOT NULL,
"finished_at" text,
"duration_ms" integer,
"error" text,
"dry_run" boolean DEFAULT false NOT NULL,
"parent_run_id" integer
);
--> statement-breakpoint
CREATE TABLE "automation_schedules" (
"id" serial PRIMARY KEY NOT NULL,
"automation_id" integer NOT NULL,
"cron" text,
"interval_seconds" integer,
"timezone" text,
"next_due_at" varchar(255),
"last_tick_at" text
);
--> statement-breakpoint
CREATE TABLE "automation_trigger_state" (
"id" serial PRIMARY KEY NOT NULL,
"automation_id" integer NOT NULL,
"state_key" varchar(255) NOT NULL,
"breach_started_at" text,
"last_fired_at" text,
"last_value" double precision,
"last_observed_state" text,
"updated_at" varchar(255) DEFAULT CURRENT_TIMESTAMP NOT NULL
);
--> statement-breakpoint
CREATE TABLE "automations" (
"id" serial PRIMARY KEY NOT NULL,
"user_id" varchar(255) NOT NULL,
"name" varchar(255) NOT NULL,
"description" text,
"enabled" boolean DEFAULT true NOT NULL,
"definition" text NOT NULL,
"definition_version" integer DEFAULT 1 NOT NULL,
"concurrency_policy" text DEFAULT 'skip' NOT NULL,
"max_run_seconds" integer DEFAULT 300 NOT NULL,
"dry_run" boolean DEFAULT false NOT NULL,
"last_run_at" text,
"last_run_status" text,
"created_at" varchar(255) DEFAULT CURRENT_TIMESTAMP NOT NULL,
"updated_at" varchar(255) DEFAULT CURRENT_TIMESTAMP NOT NULL
);
--> statement-breakpoint
ALTER TABLE "alert_rules" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "alert_rules" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "alert_rules" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "alert_rules" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "api_keys" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "api_keys" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "c2s_tunnel_presets" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "c2s_tunnel_presets" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "c2s_tunnel_presets" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "c2s_tunnel_presets" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "credential_sidebar_preferences" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "credential_sidebar_preferences" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "dashboard_service_links" ALTER COLUMN "label" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "dashboard_service_links" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "dashboard_service_links" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "dashboard_service_links" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "dashboard_service_links" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "file_manager_shortcuts" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "file_manager_shortcuts" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "fleets" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "fleets" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "fleets" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "fleets" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "homepage_items" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "homepage_items" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "homepage_items" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "homepage_items" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "homepage_layouts" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "homepage_layouts" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "host_access" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "host_access" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "host_health_checks" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "host_health_checks" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "host_health_checks" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "host_health_checks" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "host_metrics_preferences" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "host_metrics_preferences" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "host_metrics_preferences" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "host_metrics_preferences" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "host_sidebar_preferences" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "host_sidebar_preferences" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "ssh_data" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "ssh_data" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "ssh_data" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "ssh_data" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "network_topology" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "network_topology" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "network_topology" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "network_topology" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "notification_channels" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "notification_channels" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "opkssh_tokens" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "opkssh_tokens" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "proxmox_stats_preferences" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "proxmox_stats_preferences" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "proxmox_stats_preferences" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "proxmox_stats_preferences" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "roles" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "roles" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "roles" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "roles" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "session_shares" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "session_shares" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "sessions" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "sessions" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "shared_host_auth_overrides" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "shared_host_auth_overrides" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "shared_host_auth_overrides" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "shared_host_auth_overrides" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "shared_host_secrets" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "shared_host_secrets" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "shared_host_secrets" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "shared_host_secrets" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "snippet_access" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "snippet_access" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "snippet_folders" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "snippet_folders" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "snippet_folders" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "snippet_folders" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "snippets" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "snippets" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "snippets" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "snippets" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "ssh_credentials" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "ssh_credentials" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "ssh_credentials" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "ssh_credentials" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "ssh_folders" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "ssh_folders" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "ssh_folders" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "ssh_folders" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "sso_providers" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "sso_providers" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "sso_providers" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "sso_providers" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "termix_identities" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "termix_identities" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "termix_identities" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "termix_identities" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "termix_identity_ca" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "termix_identity_ca" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "termix_identity_ca" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "termix_identity_ca" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "termix_identity_keys" ALTER COLUMN "label" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "termix_identity_keys" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "termix_identity_keys" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "tmux_session_tags" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "tmux_session_tags" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "trusted_devices" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "trusted_devices" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "ui_preferences" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "ui_preferences" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "user_open_tabs" ALTER COLUMN "label" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "user_open_tabs" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "user_open_tabs" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "user_open_tabs" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "user_open_tabs" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "user_preferences" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "user_preferences" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "user_workspaces" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "user_workspaces" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "user_workspaces" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "user_workspaces" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "vault_profiles" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "vault_profiles" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "vault_profiles" ALTER COLUMN "updated_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "vault_profiles" ALTER COLUMN "updated_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "vault_tokens" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "vault_tokens" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "webauthn_credentials" ALTER COLUMN "created_at" SET DATA TYPE varchar(255);--> statement-breakpoint
ALTER TABLE "webauthn_credentials" ALTER COLUMN "created_at" SET DEFAULT CURRENT_TIMESTAMP;--> statement-breakpoint
ALTER TABLE "user_preferences" ADD COLUMN "ai_assistant_enabled" boolean;--> statement-breakpoint
ALTER TABLE "user_preferences" ADD COLUMN "ai_read_only_commands" boolean;--> statement-breakpoint
ALTER TABLE "ai_conversations" ADD CONSTRAINT "ai_conversations_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "ai_messages" ADD CONSTRAINT "ai_messages_conversation_id_ai_conversations_id_fk" FOREIGN KEY ("conversation_id") REFERENCES "public"."ai_conversations"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "ai_proposals" ADD CONSTRAINT "ai_proposals_conversation_id_ai_conversations_id_fk" FOREIGN KEY ("conversation_id") REFERENCES "public"."ai_conversations"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "ai_proposals" ADD CONSTRAINT "ai_proposals_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "ai_providers" ADD CONSTRAINT "ai_providers_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "automation_channels" ADD CONSTRAINT "automation_channels_automation_id_automations_id_fk" FOREIGN KEY ("automation_id") REFERENCES "public"."automations"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "automation_channels" ADD CONSTRAINT "automation_channels_channel_id_notification_channels_id_fk" FOREIGN KEY ("channel_id") REFERENCES "public"."notification_channels"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "automation_run_steps" ADD CONSTRAINT "automation_run_steps_run_id_automation_runs_id_fk" FOREIGN KEY ("run_id") REFERENCES "public"."automation_runs"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "automation_runs" ADD CONSTRAINT "automation_runs_automation_id_automations_id_fk" FOREIGN KEY ("automation_id") REFERENCES "public"."automations"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "automation_runs" ADD CONSTRAINT "automation_runs_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "automation_schedules" ADD CONSTRAINT "automation_schedules_automation_id_automations_id_fk" FOREIGN KEY ("automation_id") REFERENCES "public"."automations"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "automation_trigger_state" ADD CONSTRAINT "automation_trigger_state_automation_id_automations_id_fk" FOREIGN KEY ("automation_id") REFERENCES "public"."automations"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
ALTER TABLE "automations" ADD CONSTRAINT "automations_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
CREATE INDEX "idx_ai_conversations_user" ON "ai_conversations" USING btree ("user_id","updated_at");--> statement-breakpoint
CREATE INDEX "idx_ai_messages_conversation" ON "ai_messages" USING btree ("conversation_id","created_at");--> statement-breakpoint
CREATE INDEX "idx_ai_proposals_user" ON "ai_proposals" USING btree ("user_id","status");--> statement-breakpoint
CREATE INDEX "idx_ai_proposals_conversation" ON "ai_proposals" USING btree ("conversation_id");--> statement-breakpoint
CREATE UNIQUE INDEX "idx_ai_providers_user_label" ON "ai_providers" USING btree ("user_id","label");--> statement-breakpoint
CREATE UNIQUE INDEX "idx_automation_channels_pair" ON "automation_channels" USING btree ("automation_id","channel_id");--> statement-breakpoint
CREATE INDEX "idx_automation_run_steps_run" ON "automation_run_steps" USING btree ("run_id","step_index");--> statement-breakpoint
CREATE INDEX "idx_automation_runs_automation" ON "automation_runs" USING btree ("automation_id","started_at");--> statement-breakpoint
CREATE INDEX "idx_automation_runs_user" ON "automation_runs" USING btree ("user_id","started_at");--> statement-breakpoint
CREATE UNIQUE INDEX "idx_automation_schedules_automation" ON "automation_schedules" USING btree ("automation_id");--> statement-breakpoint
CREATE INDEX "idx_automation_schedules_due" ON "automation_schedules" USING btree ("next_due_at");--> statement-breakpoint
CREATE UNIQUE INDEX "idx_automation_trigger_state_key" ON "automation_trigger_state" USING btree ("automation_id","state_key");--> statement-breakpoint
CREATE INDEX "idx_automations_user" ON "automations" USING btree ("user_id","enabled");
+2
View File
@@ -0,0 +1,2 @@
ALTER TABLE "user_preferences" ADD COLUMN "terminal_defaults" text;--> statement-breakpoint
ALTER TABLE "user_preferences" ADD COLUMN "rdp_defaults" text;
@@ -0,0 +1 @@
ALTER TABLE "user_preferences" ADD COLUMN "terminal_macros" text;
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+98
View File
@@ -8,6 +8,104 @@
"when": 1785738871078, "when": 1785738871078,
"tag": "0000_jazzy_infant_terrible", "tag": "0000_jazzy_infant_terrible",
"breakpoints": true "breakpoints": true
},
{
"idx": 1,
"version": "7",
"when": 1786132418140,
"tag": "0001_worried_silvermane",
"breakpoints": true
},
{
"idx": 2,
"version": "7",
"when": 1786147318741,
"tag": "0002_clear_cerebro",
"breakpoints": true
},
{
"idx": 3,
"version": "7",
"when": 1786258963173,
"tag": "0003_harsh_gravity",
"breakpoints": true
},
{
"idx": 4,
"version": "7",
"when": 1786423595034,
"tag": "0004_great_victor_mancha",
"breakpoints": true
},
{
"idx": 5,
"version": "7",
"when": 1786428084849,
"tag": "0005_loose_captain_marvel",
"breakpoints": true
},
{
"idx": 6,
"version": "7",
"when": 1786482020978,
"tag": "0006_gigantic_thor_girl",
"breakpoints": true
},
{
"idx": 7,
"version": "7",
"when": 1786487750371,
"tag": "0007_orange_mandrill",
"breakpoints": true
},
{
"idx": 8,
"version": "7",
"when": 1786498679719,
"tag": "0008_bright_miss_america",
"breakpoints": true
},
{
"idx": 9,
"version": "7",
"when": 1786509724258,
"tag": "0009_spicy_the_leader",
"breakpoints": true
},
{
"idx": 10,
"version": "7",
"when": 1786515117043,
"tag": "0010_nasty_mordo",
"breakpoints": true
},
{
"idx": 11,
"version": "7",
"when": 1786519423735,
"tag": "0011_unique_sleepwalker",
"breakpoints": true
},
{
"idx": 12,
"version": "7",
"when": 1786598522041,
"tag": "0012_dashing_mandroid",
"breakpoints": true
},
{
"idx": 13,
"version": "7",
"when": 1786737723263,
"tag": "0013_open_swarm",
"breakpoints": true
},
{
"idx": 14,
"version": "7",
"when": 1786757021444,
"tag": "0014_unusual_maelstrom",
"breakpoints": true
} }
] ]
} }
@@ -90,6 +90,13 @@ CREATE TABLE `command_history` (
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
); );
--> statement-breakpoint --> statement-breakpoint
CREATE TABLE `credential_sidebar_preferences` (
`user_id` text PRIMARY KEY NOT NULL,
`data` text NOT NULL,
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE TABLE `dashboard_service_links` ( CREATE TABLE `dashboard_service_links` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL, `id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`user_id` text NOT NULL, `user_id` text NOT NULL,
@@ -234,6 +241,13 @@ CREATE TABLE `host_metrics_preferences` (
); );
--> statement-breakpoint --> statement-breakpoint
CREATE UNIQUE INDEX `idx_host_metrics_prefs_user_host` ON `host_metrics_preferences` (`user_id`,`host_id`);--> statement-breakpoint CREATE UNIQUE INDEX `idx_host_metrics_prefs_user_host` ON `host_metrics_preferences` (`user_id`,`host_id`);--> statement-breakpoint
CREATE TABLE `host_sidebar_preferences` (
`user_id` text PRIMARY KEY NOT NULL,
`data` text NOT NULL,
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE TABLE `ssh_data` ( CREATE TABLE `ssh_data` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL, `id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`user_id` text NOT NULL, `user_id` text NOT NULL,
@@ -245,6 +259,7 @@ CREATE TABLE `ssh_data` (
`folder` text, `folder` text,
`tags` text, `tags` text,
`pin` integer DEFAULT false NOT NULL, `pin` integer DEFAULT false NOT NULL,
`sort_order` integer,
`auth_type` text NOT NULL, `auth_type` text NOT NULL,
`use_warpgate` integer DEFAULT false NOT NULL, `use_warpgate` integer DEFAULT false NOT NULL,
`share_ssh_auth` integer DEFAULT false NOT NULL, `share_ssh_auth` integer DEFAULT false NOT NULL,
@@ -550,6 +565,7 @@ CREATE TABLE `snippets` (
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL, `created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL, `updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
`host_filter` text, `host_filter` text,
`is_note` integer DEFAULT false NOT NULL,
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
); );
--> statement-breakpoint --> statement-breakpoint
@@ -572,6 +588,8 @@ CREATE TABLE `ssh_credentials` (
`description` text, `description` text,
`folder` text, `folder` text,
`tags` text, `tags` text,
`pin` integer DEFAULT false NOT NULL,
`sort_order` integer,
`auth_type` text NOT NULL, `auth_type` text NOT NULL,
`username` text, `username` text,
`password` text, `password` text,
@@ -598,6 +616,7 @@ CREATE TABLE `ssh_folders` (
`color` text, `color` text,
`icon` text, `icon` text,
`credential_id` integer, `credential_id` integer,
`sort_order` integer,
`sync_id` text, `sync_id` text,
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL, `created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL, `updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
+26
View File
@@ -0,0 +1,26 @@
CREATE TABLE `proxmox_node_history` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`host_id` integer NOT NULL,
`ts` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
`cpu_percent` real,
`mem_percent` real,
`disk_percent` real,
`net_rx_bytes` integer,
`net_tx_bytes` integer,
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE TABLE `proxmox_stats_preferences` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`user_id` text NOT NULL,
`host_id` integer NOT NULL,
`layout` text NOT NULL,
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE UNIQUE INDEX `idx_proxmox_stats_prefs_user_host` ON `proxmox_stats_preferences` (`user_id`,`host_id`);--> statement-breakpoint
ALTER TABLE `ssh_data` ADD `enable_proxmox_stats` integer DEFAULT false NOT NULL;--> statement-breakpoint
ALTER TABLE `ssh_data` ADD `proxmox_stats_config` text;
+1
View File
@@ -0,0 +1 @@
ALTER TABLE `ssh_data` ADD `enable_terminal_toolbar` integer DEFAULT true NOT NULL;
+42
View File
@@ -0,0 +1,42 @@
CREATE TABLE `fleet_inventory` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`host_id` integer NOT NULL,
`user_id` text NOT NULL,
`os_pretty_name` text,
`kernel` text,
`architecture` text,
`hostname` text,
`uptime_seconds` integer,
`ip` text,
`package_manager` text,
`collected_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade,
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE UNIQUE INDEX `idx_fleet_inventory_host` ON `fleet_inventory` (`host_id`,`user_id`);--> statement-breakpoint
CREATE TABLE `fleet_members` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`fleet_id` integer NOT NULL,
`host_id` integer NOT NULL,
`added_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
FOREIGN KEY (`fleet_id`) REFERENCES `fleets`(`id`) ON UPDATE no action ON DELETE cascade,
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE UNIQUE INDEX `idx_fleet_members_fleet_host` ON `fleet_members` (`fleet_id`,`host_id`);--> statement-breakpoint
CREATE TABLE `fleets` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`user_id` text NOT NULL,
`name` text NOT NULL,
`description` text,
`color` text,
`icon` text,
`tag_rules` text,
`sync_id` text,
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE UNIQUE INDEX `fleets_sync_id_unique` ON `fleets` (`sync_id`);
+1
View File
@@ -0,0 +1 @@
ALTER TABLE `ssh_data` ADD `parent_host_id` integer REFERENCES ssh_data(id) ON DELETE SET NULL;
+17
View File
@@ -0,0 +1,17 @@
CREATE TABLE `user_workspaces` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`user_id` text NOT NULL,
`name` text NOT NULL,
`color` text,
`icon` text,
`kind` text DEFAULT 'manual' NOT NULL,
`is_default` integer DEFAULT false NOT NULL,
`payload` text DEFAULT '{}' NOT NULL,
`sync_id` text,
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
`last_used_at` text,
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE UNIQUE INDEX `user_workspaces_sync_id_unique` ON `user_workspaces` (`sync_id`);
@@ -0,0 +1,6 @@
CREATE TABLE `ui_preferences` (
`user_id` text PRIMARY KEY NOT NULL,
`data` text NOT NULL,
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
);
+42
View File
@@ -0,0 +1,42 @@
CREATE INDEX `idx_alert_firings_rule` ON `alert_firings` (`rule_id`,`fired_at`);--> statement-breakpoint
CREATE INDEX `idx_alert_firings_host` ON `alert_firings` (`host_id`);--> statement-breakpoint
CREATE INDEX `idx_api_keys_user_id` ON `api_keys` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_audit_logs_timestamp` ON `audit_logs` (`timestamp`);--> statement-breakpoint
CREATE INDEX `idx_audit_logs_user_ts` ON `audit_logs` (`user_id`,`timestamp`);--> statement-breakpoint
CREATE INDEX `idx_audit_logs_action_ts` ON `audit_logs` (`action`,`timestamp`);--> statement-breakpoint
CREATE INDEX `idx_audit_logs_resource_ts` ON `audit_logs` (`resource_type`,`timestamp`);--> statement-breakpoint
CREATE INDEX `idx_command_history_user_host` ON `command_history` (`user_id`,`host_id`);--> statement-breakpoint
CREATE INDEX `idx_dismissed_alerts_user_id` ON `dismissed_alerts` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_file_manager_pinned_user` ON `file_manager_pinned` (`user_id`,`host_id`);--> statement-breakpoint
CREATE INDEX `idx_file_manager_recent_user` ON `file_manager_recent` (`user_id`,`host_id`);--> statement-breakpoint
CREATE INDEX `idx_file_manager_shortcuts_user` ON `file_manager_shortcuts` (`user_id`,`host_id`);--> statement-breakpoint
CREATE INDEX `idx_fleet_inventory_user` ON `fleet_inventory` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_fleet_members_host` ON `fleet_members` (`host_id`);--> statement-breakpoint
CREATE INDEX `idx_homepage_items_user_id` ON `homepage_items` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_host_access_user_id` ON `host_access` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_host_access_role_id` ON `host_access` (`role_id`);--> statement-breakpoint
CREATE INDEX `idx_host_access_host_id` ON `host_access` (`host_id`);--> statement-breakpoint
CREATE INDEX `idx_host_access_expires_at` ON `host_access` (`expires_at`);--> statement-breakpoint
CREATE INDEX `idx_ssh_data_user_id` ON `ssh_data` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_ssh_data_parent_host` ON `ssh_data` (`parent_host_id`);--> statement-breakpoint
CREATE INDEX `idx_ssh_data_credential` ON `ssh_data` (`credential_id`);--> statement-breakpoint
CREATE INDEX `idx_recent_activity_user_ts` ON `recent_activity` (`user_id`,`timestamp`);--> statement-breakpoint
CREATE INDEX `idx_session_recordings_user_started` ON `session_recordings` (`user_id`,`started_at`);--> statement-breakpoint
CREATE INDEX `idx_session_recordings_host` ON `session_recordings` (`host_id`);--> statement-breakpoint
CREATE INDEX `idx_session_shares_session_id` ON `session_shares` (`session_id`);--> statement-breakpoint
CREATE INDEX `idx_session_shares_host_id` ON `session_shares` (`host_id`);--> statement-breakpoint
CREATE INDEX `idx_sessions_user_id` ON `sessions` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_sessions_expires_at` ON `sessions` (`expires_at`);--> statement-breakpoint
CREATE INDEX `idx_snippet_access_user_id` ON `snippet_access` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_snippet_access_snippet_id` ON `snippet_access` (`snippet_id`);--> statement-breakpoint
CREATE INDEX `idx_snippet_access_role_id` ON `snippet_access` (`role_id`);--> statement-breakpoint
CREATE INDEX `idx_snippets_user_id` ON `snippets` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_ssh_credential_usage_credential` ON `ssh_credential_usage` (`credential_id`);--> statement-breakpoint
CREATE INDEX `idx_ssh_credential_usage_user` ON `ssh_credential_usage` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_ssh_credentials_user_id` ON `ssh_credentials` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_ssh_folders_user_id` ON `ssh_folders` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_transfer_recent_user` ON `transfer_recent` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_trusted_devices_user_id` ON `trusted_devices` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_user_open_tabs_user_id` ON `user_open_tabs` (`user_id`);--> statement-breakpoint
CREATE INDEX `idx_user_roles_role_id` ON `user_roles` (`role_id`);--> statement-breakpoint
CREATE INDEX `idx_user_workspaces_user_id` ON `user_workspaces` (`user_id`);
+147
View File
@@ -0,0 +1,147 @@
CREATE TABLE `ai_conversations` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`user_id` text NOT NULL,
`title` text,
`provider_id` integer,
`model` text,
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE INDEX `idx_ai_conversations_user` ON `ai_conversations` (`user_id`,`updated_at`);--> statement-breakpoint
CREATE TABLE `ai_messages` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`conversation_id` integer NOT NULL,
`role` text NOT NULL,
`content` text DEFAULT '' NOT NULL,
`tool_calls` text,
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
FOREIGN KEY (`conversation_id`) REFERENCES `ai_conversations`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE INDEX `idx_ai_messages_conversation` ON `ai_messages` (`conversation_id`,`created_at`);--> statement-breakpoint
CREATE TABLE `ai_proposals` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`conversation_id` integer NOT NULL,
`user_id` text NOT NULL,
`kind` text NOT NULL,
`summary` text,
`payload` text DEFAULT '{}' NOT NULL,
`status` text DEFAULT 'pending' NOT NULL,
`applied_at` text,
`result_summary` text,
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
FOREIGN KEY (`conversation_id`) REFERENCES `ai_conversations`(`id`) ON UPDATE no action ON DELETE cascade,
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE INDEX `idx_ai_proposals_user` ON `ai_proposals` (`user_id`,`status`);--> statement-breakpoint
CREATE INDEX `idx_ai_proposals_conversation` ON `ai_proposals` (`conversation_id`);--> statement-breakpoint
CREATE TABLE `ai_providers` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`user_id` text NOT NULL,
`provider_type` text NOT NULL,
`label` text NOT NULL,
`base_url` text,
`api_key` text(8192),
`api_key_prefix` text,
`default_model` text,
`enabled` integer DEFAULT true NOT NULL,
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE UNIQUE INDEX `idx_ai_providers_user_label` ON `ai_providers` (`user_id`,`label`);--> statement-breakpoint
CREATE TABLE `automation_channels` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`automation_id` integer NOT NULL,
`channel_id` integer NOT NULL,
FOREIGN KEY (`automation_id`) REFERENCES `automations`(`id`) ON UPDATE no action ON DELETE cascade,
FOREIGN KEY (`channel_id`) REFERENCES `notification_channels`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE UNIQUE INDEX `idx_automation_channels_pair` ON `automation_channels` (`automation_id`,`channel_id`);--> statement-breakpoint
CREATE TABLE `automation_run_steps` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`run_id` integer NOT NULL,
`step_index` integer NOT NULL,
`step_id` text NOT NULL,
`step_type` text NOT NULL,
`status` text NOT NULL,
`started_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
`finished_at` text,
`output` text,
`error` text,
`truncated` integer DEFAULT false NOT NULL,
FOREIGN KEY (`run_id`) REFERENCES `automation_runs`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE INDEX `idx_automation_run_steps_run` ON `automation_run_steps` (`run_id`,`step_index`);--> statement-breakpoint
CREATE TABLE `automation_runs` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`automation_id` integer NOT NULL,
`user_id` text NOT NULL,
`trigger_type` text NOT NULL,
`trigger_context` text,
`status` text NOT NULL,
`started_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
`finished_at` text,
`duration_ms` integer,
`error` text,
`dry_run` integer DEFAULT false NOT NULL,
`parent_run_id` integer,
FOREIGN KEY (`automation_id`) REFERENCES `automations`(`id`) ON UPDATE no action ON DELETE cascade,
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE INDEX `idx_automation_runs_automation` ON `automation_runs` (`automation_id`,`started_at`);--> statement-breakpoint
CREATE INDEX `idx_automation_runs_user` ON `automation_runs` (`user_id`,`started_at`);--> statement-breakpoint
CREATE TABLE `automation_schedules` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`automation_id` integer NOT NULL,
`cron` text,
`interval_seconds` integer,
`timezone` text,
`next_due_at` text,
`last_tick_at` text,
FOREIGN KEY (`automation_id`) REFERENCES `automations`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE UNIQUE INDEX `idx_automation_schedules_automation` ON `automation_schedules` (`automation_id`);--> statement-breakpoint
CREATE INDEX `idx_automation_schedules_due` ON `automation_schedules` (`next_due_at`);--> statement-breakpoint
CREATE TABLE `automation_trigger_state` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`automation_id` integer NOT NULL,
`state_key` text NOT NULL,
`breach_started_at` text,
`last_fired_at` text,
`last_value` real,
`last_observed_state` text,
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
FOREIGN KEY (`automation_id`) REFERENCES `automations`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE UNIQUE INDEX `idx_automation_trigger_state_key` ON `automation_trigger_state` (`automation_id`,`state_key`);--> statement-breakpoint
CREATE TABLE `automations` (
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
`user_id` text NOT NULL,
`name` text NOT NULL,
`description` text,
`enabled` integer DEFAULT true NOT NULL,
`definition` text NOT NULL,
`definition_version` integer DEFAULT 1 NOT NULL,
`concurrency_policy` text DEFAULT 'skip' NOT NULL,
`max_run_seconds` integer DEFAULT 300 NOT NULL,
`dry_run` integer DEFAULT false NOT NULL,
`last_run_at` text,
`last_run_status` text,
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
);
--> statement-breakpoint
CREATE INDEX `idx_automations_user` ON `automations` (`user_id`,`enabled`);--> statement-breakpoint
ALTER TABLE `user_preferences` ADD `ai_assistant_enabled` integer;--> statement-breakpoint
ALTER TABLE `user_preferences` ADD `ai_read_only_commands` integer;
@@ -0,0 +1,2 @@
ALTER TABLE `user_preferences` ADD `terminal_defaults` text;--> statement-breakpoint
ALTER TABLE `user_preferences` ADD `rdp_defaults` text;
+1
View File
@@ -0,0 +1 @@
ALTER TABLE `user_preferences` ADD `terminal_macros` text;
+131 -2
View File
@@ -1,7 +1,7 @@
{ {
"version": "6", "version": "6",
"dialect": "sqlite", "dialect": "sqlite",
"id": "426410c9-f34a-47bc-9df6-17748689ad0d", "id": "818cd7d9-d223-494f-ac73-f98708c72dc2",
"prevId": "00000000-0000-0000-0000-000000000000", "prevId": "00000000-0000-0000-0000-000000000000",
"tables": { "tables": {
"alert_firings": { "alert_firings": {
@@ -657,6 +657,52 @@
"uniqueConstraints": {}, "uniqueConstraints": {},
"checkConstraints": {} "checkConstraints": {}
}, },
"credential_sidebar_preferences": {
"name": "credential_sidebar_preferences",
"columns": {
"user_id": {
"name": "user_id",
"type": "text",
"primaryKey": true,
"notNull": true,
"autoincrement": false
},
"data": {
"name": "data",
"type": "text",
"primaryKey": false,
"notNull": true,
"autoincrement": false
},
"updated_at": {
"name": "updated_at",
"type": "text",
"primaryKey": false,
"notNull": true,
"autoincrement": false,
"default": "CURRENT_TIMESTAMP"
}
},
"indexes": {},
"foreignKeys": {
"credential_sidebar_preferences_user_id_users_id_fk": {
"name": "credential_sidebar_preferences_user_id_users_id_fk",
"tableFrom": "credential_sidebar_preferences",
"tableTo": "users",
"columnsFrom": [
"user_id"
],
"columnsTo": [
"id"
],
"onDelete": "cascade",
"onUpdate": "no action"
}
},
"compositePrimaryKeys": {},
"uniqueConstraints": {},
"checkConstraints": {}
},
"dashboard_service_links": { "dashboard_service_links": {
"name": "dashboard_service_links", "name": "dashboard_service_links",
"columns": { "columns": {
@@ -1700,6 +1746,52 @@
"uniqueConstraints": {}, "uniqueConstraints": {},
"checkConstraints": {} "checkConstraints": {}
}, },
"host_sidebar_preferences": {
"name": "host_sidebar_preferences",
"columns": {
"user_id": {
"name": "user_id",
"type": "text",
"primaryKey": true,
"notNull": true,
"autoincrement": false
},
"data": {
"name": "data",
"type": "text",
"primaryKey": false,
"notNull": true,
"autoincrement": false
},
"updated_at": {
"name": "updated_at",
"type": "text",
"primaryKey": false,
"notNull": true,
"autoincrement": false,
"default": "CURRENT_TIMESTAMP"
}
},
"indexes": {},
"foreignKeys": {
"host_sidebar_preferences_user_id_users_id_fk": {
"name": "host_sidebar_preferences_user_id_users_id_fk",
"tableFrom": "host_sidebar_preferences",
"tableTo": "users",
"columnsFrom": [
"user_id"
],
"columnsTo": [
"id"
],
"onDelete": "cascade",
"onUpdate": "no action"
}
},
"compositePrimaryKeys": {},
"uniqueConstraints": {},
"checkConstraints": {}
},
"ssh_data": { "ssh_data": {
"name": "ssh_data", "name": "ssh_data",
"columns": { "columns": {
@@ -1775,6 +1867,13 @@
"autoincrement": false, "autoincrement": false,
"default": false "default": false
}, },
"sort_order": {
"name": "sort_order",
"type": "integer",
"primaryKey": false,
"notNull": false,
"autoincrement": false
},
"auth_type": { "auth_type": {
"name": "auth_type", "name": "auth_type",
"type": "text", "type": "text",
@@ -4025,6 +4124,14 @@
"primaryKey": false, "primaryKey": false,
"notNull": false, "notNull": false,
"autoincrement": false "autoincrement": false
},
"is_note": {
"name": "is_note",
"type": "integer",
"primaryKey": false,
"notNull": true,
"autoincrement": false,
"default": false
} }
}, },
"indexes": { "indexes": {
@@ -4186,6 +4293,21 @@
"notNull": false, "notNull": false,
"autoincrement": false "autoincrement": false
}, },
"pin": {
"name": "pin",
"type": "integer",
"primaryKey": false,
"notNull": true,
"autoincrement": false,
"default": false
},
"sort_order": {
"name": "sort_order",
"type": "integer",
"primaryKey": false,
"notNull": false,
"autoincrement": false
},
"auth_type": { "auth_type": {
"name": "auth_type", "name": "auth_type",
"type": "text", "type": "text",
@@ -4368,6 +4490,13 @@
"notNull": false, "notNull": false,
"autoincrement": false "autoincrement": false
}, },
"sort_order": {
"name": "sort_order",
"type": "integer",
"primaryKey": false,
"notNull": false,
"autoincrement": false
},
"sync_id": { "sync_id": {
"name": "sync_id", "name": "sync_id",
"type": "text", "type": "text",
@@ -6077,4 +6206,4 @@
"internal": { "internal": {
"indexes": {} "indexes": {}
} }
} }
File diff suppressed because it is too large Load Diff

Some files were not shown because too many files have changed in this diff Show More