Projects

systemd Service Management System

Source code

A system for centralized management of systemd services on a group of servers. Every server runs an agent that itself establishes an outgoing gRPC connection to the control node, so the servers need no open ports, and machines behind NAT connect the same way as a VPS with a public IP. The connection is protected by mutual TLS authentication; the control node maintains its own certificate authority and issues and revokes agent certificates. Users, access policies, API tokens and the audit log are stored in PostgreSQL, and permissions are granted down to the server, service and action. Services can be managed through a web panel or the REST API, for example from a Telegram bot. On the servers themselves the agent runs as an unprivileged user and calls systemctl through sudo only from a whitelist.

Contact me

A question, an offer or just hello