About
The Swiss-army-knife control plane for your Linux fleet — or your homelab. Monitoring, alerting, a CMDB, CVE scanning, patching, and remote management, all self-hosted in one place — with optional AI woven through it. Push-based agents, zero inbound ports. Up and running in five minutes.
Most teams stitch together a monitor, a CMDB, a wiki, a vulnerability scanner, a patch tool and an SSH jump box. RemotePower is one self-hosted tool that does all of it — monitoring & alerting, an asset CMDB, documentation with RAG search over your own fleet, CVE scanning, patching, and remote management — with AI as an entirely optional layer on top (bring your own local or cloud model, or leave it off). RemotePower is extremely feature-rich.
Each host runs a small Python agent that polls the server over outbound HTTPS only — nothing opens on the client, ever. Enrolment is a 6-digit PIN, like pairing a controller.
Deliberately small and readable: nginx + Python (gunicorn/Flask) on the server, plain vanilla JS in the browser — no React/Vue, no build step, no Node.js, no Redis, no Kubernetes. install-server.sh or docker compose up provisions the full stack — PostgreSQL, the app server, a maintenance scheduler, a scanner satellite — with no flags required. A single small box handles a couple hundred devices out of the box, no tuning needed — and the same box carries several thousand agents with just the poll-interval and worker-count knobs turned, before you'd ever reach for load-balanced app nodes, read replicas or relay satellites.
What you can do with it
Monitor & alert — live metrics, a CheckMK-style Checks page, active monitors (HTTP/DNS/ICMP/TCP), an Alerts inbox with ack/auto-resolve/mute.
See every signal — SMART/hardware health, GPU, power/UPS, disk-fill forecasting, a per-host timeline, log search.
Manage remotely — shell + Custom Scripts, a browser SSH terminal and VNC, a file manager, cron/systemd-timer control, Proxmox/VMware/OpenShift guest lifecycle — all with zero inbound ports.
Lock it down — passkeys/WebAuthn, SAML/OIDC/LDAP, TOTP, per-role MFA, a tamper-evident audit log, strict CSP.
Scan for CVEs — OSV.dev-backed, CISA KEV + EPSS prioritized, SBOM export (CycloneDX/SPDX).
Pentest what you own — authorized nuclei/nikto/nmap/ZAP/wapiti/lynis scans on a hardened scanner satellite.
CMDB + RAG search — assets, an encrypted credentials vault, a Knowledge Base, and an AI assistant that cites your fleet's own data.
Stay compliant — OpenSCAP CIS/STIG/PCI scans, PCI/HIPAA/SOC 2 mapping.
Integrate — 40 homelab-app connectors, a code-free custom-HTTP-probe plugin, Prometheus/Grafana endpoints, webhooks, syslog, and an MCP server.
Deploy & automate — a one-click app catalog, auto-patch policies, drift detection, ACME, backups, and a Terraform/Ansible provisioning catalog.
