Omahub
← All plugins
R

Server Status

by ryuhzk

Agentless server and Docker monitoring over read-only SSH. Nothing is installed on the servers.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
60aac11
Scanned
3 weeks ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
60aac11
Reviewed
3 weeks ago

The plugin is a read-only SSH-based monitoring widget. It runs a fixed, non-destructive remote script on user-configured hosts, uses BatchMode and a timeout, and deliberately avoids leaking container environment variables. No obfuscation, persistence, or credential theft was found; the only risk is that it executes remote commands on hosts the user explicitly configures, which is the intended functionality.

  • The remote script invokes `sudo -n docker` when available, which could have unintended effects if the user's sudo policy is misconfigured, but the commands are read-only (ps/stats/inspect).
  • The plugin can open SSH terminals and run btop/htop over SSH via keyboard shortcuts, but these are user-initiated actions.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/ryuhzk/omarchy-server-status --enable
System #bar #quickshell #system

Omarchy Server Status

A glanceable ops panel for your servers, living in the Omarchy bar. If you run a couple of VPSes, a homelab box, or a small Docker-based product, this widget answers "is everything OK over there?" without opening a browser dashboard or SSHing around: host load, memory, disk, network, and every Docker container's health and resource usage — one click away, with desktop notifications when something crosses a threshold. It complements (not replaces) full monitoring stacks: no history, no server-side storage, just the current truth on demand.

Agentless by design: every refresh is one read-only SSH round trip — nothing is installed, written, or left running on your servers. Hosts without Docker simply show host metrics; the containers column appears only when containers exist.

panel → bun backend → ssh <host> '<read-only script>' → JSON snapshot → panel

The remote script reads /proc, free, and df for host metrics, and docker ps / stats / inspect for containers. docker inspect deliberately uses a narrow format string: full inspect output would leak container environment variables (secrets) into the snapshot.

Features

  • Host metrics — CPU load, memory, per-disk usage, network rate, uptime, with traffic-light thresholds (memory warns at 75%, red at 85%; disk warns at 70%, red at 80%; load per core warns at 0.7, red at 1.0)
  • Containers — one row per container: health, CPU%, memory versus its limit, restart count; unhealthy, restarting, or OOM-killed turns red
  • Multiple servers — chips to switch between hosts, worst state on the bar dot
  • Desktop notifications — notify-send on threshold breaches, container failures, unreachable hosts, and recoveries
  • Zero server footprint — works with any Linux host you can SSH into

Requirements

  • Omarchy Shell with third-party plugin support
  • Bun 1.2 or newer on the desktop (only long-stable Bun.spawn / bun test APIs are used)
  • Passwordless SSH to each server (key-based; the backend runs with BatchMode=yes, so password prompts fail closed)
  • For container metrics, the remote account needs either sudo -n docker or membership in the docker group; host metrics work without either

Install

omarchy plugin add https://github.com/ryuhzk/omarchy-server-status --enable --yes

Or from a local clone:

omarchy plugin validate ~/path/to/omarchy-server-status
omarchy plugin add file://$HOME/path/to/omarchy-server-status --enable --yes

Remove

omarchy plugin remove ryuhzk.server-status

This unregisters the plugin and deletes its installed files. Your per-widget settings (the sshHosts list and thresholds) live in ~/.config/omarchy/shell.json; remove the widget's entry there if you want a fully clean slate. Nothing was ever installed on the monitored servers, so there is nothing to clean up remotely.

Adding servers

  1. Give each server an alias in ~/.ssh/config with key authentication:

    Host web-1
        HostName 203.0.113.10
        User ops
        IdentityFile ~/.ssh/id_ed25519
        IdentitiesOnly yes
    
  2. Open the widget's settings in the bar and set SSH hosts to a colon-separated list of aliases:

    web-1:db-1:home-nas
    
  3. Switch between servers with the chips at the top of the panel, or press 1–9. The bar dot always shows the worst state across every host.

The focused host refreshes at refreshIntervalSec while the panel is open; all hosts are swept on a slow background cycle (10× the interval, at least 5 minutes) to keep the bar dot, chips, and notifications alive without constant SSH traffic.

Shortcuts

Key Action
r Refresh the focused host
R Refresh every host
T Open an SSH terminal
B Open btop/htop/top over SSH
E Edit settings (shell.json) in your editor
1–9 Switch host
Esc Close the panel

Bar icon: middle-click refreshes all hosts, right-click opens an SSH terminal to the focused host.

Settings

Key Default Description
sshHosts (empty) Colon-separated ssh host aliases to monitor
refreshIntervalSec 30 Focused-host refresh while the panel is open
panelWidth 1000 Popup width in layout units

Diagnosing

Run the collector outside Omarchy to inspect the raw snapshot:

bun run backend/server-status.ts status --host <ssh-alias>

Development

bun run check              # tests + build
omarchy plugin validate .

Security notes

  • The remote script is read-only; the plugin never mutates server state.
  • Snapshots exclude container environment variables by design.
  • Use a dedicated, restricted SSH identity if you want the panel's key to be unable to do anything beyond reading status.

License

MIT