A read-only window onto the machine. Not a remote control.
Host vitals, containers, processes, packages, logs and verified backups, with no way to change any of them.
SystemGate lets a dashboard or an agent see how the machine is doing without ever receiving write access to it. By design there is no write, exec, restart, install or file-read endpoint. Part of Conker, and usable on its own.
flowchart LR
Pi[Conker's Pi<br/>or any dashboard] -->|admin key, server-side| SG[SystemGate]
SG -.->|read-only mounts| Host["/proc · Docker socket · disk · backups"]
classDef focus fill:#e36b2c,color:#fff,stroke:#b4521f
class SG focus
| Route | What it reports |
|---|---|
GET /health |
Real probes of procfs, the Docker socket and the key store. No key. |
GET /vitals |
CPU, memory, disk and uptime, and whether they describe the host or the container. |
GET /containers |
Docker containers and their state. |
GET /processes · GET /services |
Processes, and listening services (metadata only). |
GET /packages · GET /logs/errors |
Installed packages and recent errors. |
GET /backups |
Snapshots whose manifest, hashes and archives verify. Details |
GET /runtime |
Processes, containers and ports in one bounded inventory. Details |
Every route except /health needs X-SystemGate-Key. Every response is bounded.
Requires Docker with Compose.
cp .env.example .env # then set SYSTEMGATE_ADMIN_KEY to a long random value
docker compose up -d --build
curl -H "X-SystemGate-Key: $KEY" http://127.0.0.1:8040/vitalsThe API listens on 127.0.0.1:8040 only. Backups are read from ~/systemgate-backups by default;
set SYSTEMGATE_BACKUP_ROOT to use another host directory.
- Read-only by construction. Package and log collection use a fixed command set; no caller input reaches a shell.
- Read-only mounts. The Docker socket,
/proc, the host root and backups are mounted:ro. - Stated trade-off. Host disk figures need the host root visible inside the container. Drop the
mount for container-only figures, and
/vitalswill say so. - Keys are stored as PBKDF2 hashes. Use it from a server-side proxy so browsers never hold one.
Full model: security.
pip install -r requirements.txt pytest httpx
python -m pytest tests -q