Dashboard
Add serverNo servers monitored yet
Add a Hetzner project token in Settings → Integrations, then register a server and install its agent.
Servers
| Server | Location | Primary IPv4 | Status | Monitoring | Actions |
|---|---|---|---|---|---|
provider ID |
not monitored monitored controller host | ||||
| No servers discovered yet. | |||||
Servers are identified by their immutable provider ID (plus creation time), never by name or IP. The server that runs this controller cannot be recovered by it and is monitored only.
· · provider ID
Live traffic
No samples in this window yet. Unknown is shown as a gap, never as zero.
Now
- RX
- TX
- TOTAL
- Detection metric
- Threshold
- State
- Last sample
Quiet but legitimate workloads can trigger the rule: choose a threshold that real traffic exceeds. Equality with the threshold never counts as low.
Recovery alert
Any sample strictly above the threshold cancels this immediately. Deadline changed by .
Blocked:
Re-checked while traffic stays low. Nothing is forced.
Replacement dispatched. Traffic recovered: cancel is honoured only until the first shutdown.
Auto-recovery readiness
ACTIVE All gates satisfied. No manual switch is needed.
BLOCKED Incomplete setup never operates silently.
Recent alerts
| Raised | State | Metric / threshold | Policy rev | Outcome |
|---|---|---|---|---|
| < | operation |
Per-server overrides. Leave a value empty to inherit the global default shown under each field.
Effective: required range
Revision history
| Rev | When | By | Change |
|---|---|---|---|
| No changes yet — defaults are in effect. | |||
Agent
No agent is enrolled. The agent is a small Go binary installed manually with a one-time token. It sends RX/TX counters to the controller over HTTPS; it never receives provider tokens or shell commands.
- State
- Agent ID
- Version
- Enrolled
- Last seen
- Credential
Public interface(s)
Enroll an agent first; it reports its physical interfaces. Loopback, bridges, tunnels, veth and docker interfaces are never offered, so traffic is not double-counted.
Choose the interface(s) that carry the server's public traffic. Detection sums only these.
Guest network (DHCP check)
After a Primary IPv4 swap the guest must obtain the new address by itself (DHCP from the interface's lease). Only DHCP-managed networking is supported; static or unknown configurations keep recovery BLOCKED. This tool does not edit guest network files and does not rely on cloud-init to fix it.
Reported by the agent after enrollment.
Dependency coverage
Required before recovery can be enabled. It tells cleanup whether a clean scan of the configured zones is enough to release an old IP, or whether the IP must be held.
Approved records (updated during recovery)
| Record | Zone | Content | Preserved | Approved | |
|---|---|---|---|---|---|
| · TTL | |||||
| No records approved. Without any, only the Primary IPv4 changes (use this if the server has no DNS names managed here). | |||||
Discover candidates
Finds A records in the configured zones whose content equals . Discovery only suggests; nothing is changed unless you approve a record. AAAA, CNAME, MX, TXT and other types are never edited.
| Record | Zone | Proxy / TTL | Notes | |
|---|---|---|---|---|
| · | approvedprotected |
No matching A records in the configured zones.
| Started | Kind | State | Phase | IP change | Result |
|---|---|---|---|---|---|
| → | |||||
| No operations yet. | |||||
| IP | Kind | State | Release due | Last check / reason | |
|---|---|---|---|---|---|
| No cleanup jobs. A job is created after each successful replacement. | |||||
Advanced
TEST RESOURCE The release interlock is bypassed for this server only.
Operations
Every IP replacement is journaled step by step. Only one infrastructure operation runs at a time; the original IP is kept through every incomplete or failed run.
| Started | Server | Kind | State | Phase | IP change | Policy rev |
|---|---|---|---|---|---|---|
| → | ||||||
| No operations have run. | ||||||
IP cleanup
The only resource this tool can ever delete is one journaled, unassigned retired Primary IPv4, and only after every guard passes twice: exact ID/address/creation time match, unassigned, not used by any server, no provider protection or hold, no active operation, DNS success still consistent, and a complete scan of the configured zones that finds no reference. Anything uncertain stays BLOCKED and the IP is kept.
| Server | IP | Kind | State | Release due | Status / reason | |
|---|---|---|---|---|---|---|
due time changed by |
||||||
| No cleanup jobs. | ||||||
Notifications
Push on this device
Settings
Effective: required range
Revision history
| Rev | When | By | Change |
|---|---|---|---|
| No changes yet — defaults are in effect. | |||
Provider credentials
| Label | Provider | Fingerprint | Scope | Validated | |
|---|---|---|---|---|---|
| No credentials. Tokens are encrypted at rest with a key stored outside the database and never sent to the browser. | |||||
Hetzner: use a dedicated project so the project boundary adds to the application's own exact-ID checks (it does not replace them). Cloudflare: a zone-scoped token with only Zone Read + DNS Edit. The app has no code path to delete servers, volumes, networks, firewalls, snapshots, DNS records or zones.
DNS zones in scope
| Zone | Zone ID | Account | |
|---|---|---|---|
| No zones. Zones in scope are read in full for candidate discovery and for the cleanup dependency scan. | |||
- in scope
Protect a DNS name
Protected names are excluded from discovery and can never be bound or edited (the panel's own domain is protected automatically).
Recovery codes
Unused codes: / 10
If you lose both the authenticator and the codes, run sudo hng-controller reset-mfa on the server (offline recovery; revokes all sessions).
Active sessions
| Started | Last active | IP | Browser | |
|---|---|---|---|---|
| this device |
Encrypted (AES-256-GCM) SQLite snapshots in a dedicated directory, taken automatically at the configured interval. The encryption key is the controller's master key file: back it up separately (/etc/hng/master.key), or backups cannot be restored on a new host. Pruning only touches files in the backup directory named hng-*.db.enc.
| File | Created | Size | |
|---|---|---|---|
| No backups yet. | |||
Restore (offline)
sudo systemctl stop hng-controller sudo -u hng hng-controller restore --from /var/lib/hng/backups/hng-YYYYMMDDTHHMMSSZ.db.enc sudo systemctl start hng-controller
| Gate | Critical | Status | Evidence | Updated | |
|---|---|---|---|---|---|
PASS = executed evidence · FAIL = criteria unmet · BLOCKED = missing real prerequisites · DEFERRED / NOT RUN are tracked separately and are never counted as passed.
| When | Actor | Action | Target | Result | Details |
|---|---|---|---|---|---|
- Version
- Go runtime
- Uptime
- Heap in use
- Memory from OS
- Goroutines
- Database size
- Raw samples / rollups
- Monitored / agents
- Schema
- Master key fingerprint
Record idle and load measurements from this page (and systemctl status) in the packaging gate. Retention budgets are tunable under Policy → Retention.