Cockpit – Integrated, glanceable, web-based interface for servers
cockpit-project.org
cockpit-project.org
It worked "ok". It required pulling in a bunch of dependencies I wouldn't have normally installed. I had it set up behind an HAproxy LB, with ssl terminated at the LB. When I was using it ~1 year ago, it was pretty buggy, and certain components would crash and I would have to restart the web page.
Overall it was a mediocre experience, but I suppose better than having to ssh into every server. The main pain point was that I still had to go in to every server, and install cockpit.
In the end, I ended up just moving on to Proxmox. But I suppose cockpit is nice if you don't want a centrally managed cluster, but still want a web interface.
I think its definitely a valid opinion to have. And I would stand by not recommending Cockpit until it becomes more polished.
Cockpit – Administer Linux servers via a web browser - https://news.ycombinator.com/item?id=16445612 - Feb 2018 (148 comments)
I suppose having a GUI can be nice for a health overview of your infrastructure, but in general I dislike GUIs for actual administrative work, since using them is a practice that steers you away from automation.
Most GUI tools don't provide you very good ways to make "atomic" changes, which is made very easy if you run your automation from a git repository, since the final review before hitting go is just "git diff".
I would never use it to actually change machines though. Definitely Ansible over SSH is the way to go there.
I've mixed feelings about controlling the machines through cockpit. In theory there shouldn't be any difference between SSH and HTTPS on the security of the protocol side, but it definitely feels iffy to have a python (I think?) web app execute administration commands on a server.
I wonder what the security professionals think of it.
GUIs are great for discoverability and observation, but they always make my life harder when I actually need to manage change in a system.
As simple as it is, there's so far nothing that beats plain old text as the source of truth for how things should be; even if you have a fancy API to actually make changes into a system, you'd still want the desired state of that system to be stored as plain old text, so that changes may be tracked and reviewed easily.
use cases: server management and monitoring, log viewer, ssh terminals, parallel execution of commands, vnc, sftp, secure storage of credentials and keys.
it's still far, far away from being useful.
i am trying to figure out if there is a business case for a desktop app. there is plenty of open source and commercial systems more or less similar to cockpit, and it's hard to compete with free
I'd rather have a client-only app that connect through ssh and get its data from standard binaries installed on the server.
So, yes. I'd give that a try.
I think I'd like some kind of alerts on some specific events (disk space, some logs, IDK), systemctl management and status/reporting, some instantaneous “update as I type” filtering/searching in logs, cron and/or systemctl timer management, space usage graphics, booting reports, etc. ... maybe these are just things I usually do and think a GUI would be nice to have if I had to do it for multiple servers. Not enough experience with that in a professional setting though so take it all with a grain of salt.
But as-is, I think I could justify asking for 50 bucks for the product if I needed it.
Looking at the logs is how this tool was started. This in itself is a failrly involved chunk of functionality. It'll be a year, probably, before I can release even that.
If you're looking for pretty, single host, read-only monitoring dashboards though, checkout Netdata: https://www.netdata.cloud/
Webmin is pretty useful.
I even use it in production for monitoring small sites/apps. The graphs for CPU/Mem/Network/Disk are really great, and I can leave them open in a tab on my browser. I run one fairly popular blog that as a web machine and a db machine, and it's great for that.
That said I don't use it for "serious production" where I have more than a couple of machines simply because at that scale I prefer cattle to pets and I prefer aggregation.
I also find myself strongly preferring SSH and the CLI, likely because I'm very familiar with all that and have been doing that for decades.
I've never heard of security issues with Cockpit, but I do firewall it off from everyone but my own IP (or a few others if they are involved). It's pretty easy to do:
# Get your IP address from home or work: curl -s 'https://api.ipify.org'
MY_IP=<ip>
firewall-cmd --zone-public --permanent --remove-service=cockpit
firewall-cmd --zone=public --permanent \
--add-rich-rule="rule family=\"ipv4\" source address=\"${MY_IP}\" port protocol=\"tcp\" port=\"9090\" accept"
firewall-cmd --reload
Here's a gist of it: https://gist.github.com/FreedomBen/0aabe5493ba02d1c9bb33fea2..."You cannot (IP) right now because the website sent scrambled credentials that Google Chrome cannot process."
Is this because I run a NGINX server from that box?
If it's just Chrome not trusting the certificate, you can usually override the error by clicking "details" and then continuing by clicking a link. If the override isn't there (because of HSTS or similar), you can type "thisisunsafe" into the web page to override any non-technical certificate errors (there's no input field but it'll work)
I don't think it needs to be this way. Someone needs to figure out server software for consumers.
Just like PCs became more accessible, so should servers!
Edit: Brainstorming here: specifically, I'd like a more accessible UI, automatic updates, sensible defaults on all apps, an easier way to get started and so on.
Just today I set up a postgres and ms sql server for testing - pretty much identically, running out of their own named docker containers (for those not aware, it's even more similar than it sounds, ms sql runs on Linux now).
Running any rdbms in production in docker isn't a great idea. But for dev and test it can be great.
For my use case, we deploy mostly to traditional setup (dedicated sql server) - but I could also see it useful for prototyping deployment to mssql in azure cloud.
Actually, it would appear ms is quite serious about sql server on Linux:
https://docs.microsoft.com/en-us/troubleshoot/sql/linux/choo...
So I guess, similar to running sql server on windows?
Similarly for the "accessible UI" bits, particularly if your managing more than a single server and you want to say upgrade a few thousand of them at the same time.
In both cases its pretty "easy" to configure a more server mgmt related tool to do those operations (hence cockpit! or anisible GUIs/etc). If you looking for a more android level of software mgmt then its pretty easy to install the desktop tooling on something like fedora server that comes with fedora workstation. With that you get nice app stores layered on top of both the traditional dnf/rpm package mgmt as well as flatpak and various other container technologies. For a single home/etc server, just install something like fedora server, and group install one of the desktop/etc profiles during setup (or later if it suits you).
> Edit: Brainstorming here: specifically, I'd like a more accessible UI, automatic updates, sensible defaults on all apps, an easier way to get started and so on.
To some degree, that's sort of like saying "I can drive a car, and cards are simple, why isn't driving an 18-wheeler truck as simple, or a cargo ship, or a cargo plane? I don't see why it has to be more complicated than a car."
It all comes down how much you want to invest for being as safe as possible from accidents. Cost of cargo ship or plane accident is very high and there is no valuable reasons(?) why everyone should be able to drive those vehicles. Therefore it makes sense that those vehicles are driven by professionals and are designed for professionals.
If your server has millions of users and it provide such value that down time is not an options, maintaining such server should be done by professionals and maintenance tools should be designed for professionals.
However thats not case for every server and cost of failing "empty" server is basicly zero (unlike empty cargo plane).
I think it would be interesting to see software designed around not centralized servers, not PCs, but PSs = Personal Servers where user data lives on their own servers and services only link and communicate between them.
CapRover is excellent too but of all the various tooling I've tried over the years, Cloudron is hands-down the most polished option I've seen/used!
When I update an app on my phone, if it fails or changes considerably, it only affects me. When I update anything on a server(s), it's going to affect hundreds, thousands, or even millions of other people and getting back to the state it was in before the update can cost hundreds of hours and thousands of dollars, not to mention potential money lost from the affected users.
Updating a server is much cheaper than that.
Sure (exaggerating)
phone - reboot is your FIRST option
server - reboot is your LAST option
Someone starts a "Brainstorming" and everyone else poo-poos on it. This is how:
1. ideas are killed
2. Entrepreneurs are forged
Related reading: https://www.macleans.ca/society/science/scientists-mrna-covi...
On your phone app store there's a strong and trusted source of identity coming from Apple or Google. They know who you are, what you're allowed to do, etc. and can delegate that authority to your apps.
On the server though... welcome to the wild west. How does your server know the person on the other end of a TCP connection is really you, or the person you shared a document to view, etc? You can put your trust in a third party authority like Google, Facebook, Auth0, Okta, etc. but that usually comes with a financial cost. You can roll your own auth or self-host an auth server, but then you're taking on a huge security burden and it's a big leap in complexity to manage something like Keycloak, an LDAP server, etc. It's just not an easy problem to solve with the tools the web gives us today.
That’s what the GP post was comparing to.
I use LDAP to manage access to multiple servers and it’s more work to setup than /etc/passwd, but much easier to keep things in sync.
Client certs solve this problem quite nicely.
I do think there's probably a good market for a "just plug it into the back of your router" box that has one of these pre-installed and ready to go.
Windows Home Server used to be an attempt by Microsoft to make a home server accessible to the average user crowd. Unfortunately, Microsoft doesn't feel consumers (or businesses, if we're being honest) should have on-premise servers anymore, and has deprecated both Home Server and Small Business Server, and the UI features that made them more accessible to the layman.
You might like some of the pointers here: https://github.com/awesome-selfhosted/awesome-selfhosted#sel...
This is untrue. Sandstorm gets monthly releases, and new features tend to show up every couple months or so. Several major improvements to the platform are in the works at the moment. It's definitely true we could use more help, but it's still probably the most secure way to self-host cloud services for personal use.
> Cloudron is not even open source
True, though it's probably the best "successful" approach right now, in that the Cloudron devs have a functional business that allows them to very actively support the platform. (Sandstorm failed here, so as a Sandstorm contributor, I can't really knock their approach.)
> Bitnami and Yunohost are also major options.
Yunohost has zero isolation between applications, a single compromised app can hose your entire server. I would bear that in mind when recommending it widely.
Bitnami is going to leave you mostly on your own to decide how you're going to host it's app packages. I'm not sure it's directly comparable, it's more like a Docker Hub than a managed self-hosting platform.
It would be great if Sandstorm could get enough attention to thrive because it looked promising, but the activity of the blog¹ doesn't give me much hope. Since 2019 when it announced the hosting was shutting down there have been just 4 posts and apparently no major releases.
I push at least one release each month. The change log is here:
https://github.com/sandstorm-io/sandstorm/blob/master/CHANGE...
But it's certainly true that development is much slower today than it was in 2016 when there were seven people working full-time on it.
For what it's worth, the "just four posts" constitute some major things:
1. Continuing Sandstorm as a community project
2. The 1.0 release of the main app packaging tool
3. Let's Encrypt support built-in
4. A major security improvement in disabling apps from making outgoing HTTP requests without permission
Isn't this kind of what Ubuntu does with the snaps? You just snap install someapp and there it goes. It will helpfully restart to update whenever the developer publishes a new version, etc.
There's an infamous, quite involved debate, over this exact thing with a bunch of people wanting an option to actually disable this behavior and another bunch arguing why that's not a good idea [0].
I guess the issue with servers is that there isn't really a one size fits all, or at the very least it's not easy to figure out what it is. All this combined with the fact that one argument in favor of running Linux is the customizability, I'm not sure all that many people are looking for such a solution.
---
[0] https://forum.snapcraft.io/t/disabling-automatic-refresh-for...
Yes. "running software on a server" is actually done when running a business, which requires careful attention to detail, quality of service, actual work and dedication to customers. "running software on a phone" is just being a consumer, the hard part of that is done by Google/Apple. In short, provider vs. consumer, it can't be easier to provide than to consume.
EDIT Yes one can run software on a server as easily as on a phone, it's just few clicks or installation command away. But most people running software on servers do not want that, because they want control and understanding and security etc... That is, not yet, maybe in future every family will have their own home NAS server with apps.
With a better protocol and set of primitives it shouldn’t be as complicated (even though the challenges of scale can be unique to server software)
Cockpit is definitely nice, but it still feels pretty incomplete compared to virt-manager.
virt-manager appears to still be developed, though, just without the same blessing/level of support from Red Hat.
PS: I think both are good, but I too use virt-manager for all my VM twitting because nothing else on linux is both as feature complete for qemu/KVM while also avoiding having to read the manual just to adjust some VM parameter.
Cockpit: "here is no graphical file manager, and we don't plan to add one." https://github.com/cockpit-project/cockpit/issues/11011
CuberDuck: "FTP and SFTP do not support a copy operation."
Is there a way with GUI?
edit: reddit.com/r/selfhosted always has good threads on self-hosted web file managers too
Edit: Cloud Commander works, gives you two-pane webgui with a row of Fx buttons below. F5 copies files locally.
Or, if that's not a good option, what about a installing a TUI remotely that you can use in the console like midnight commander?
Just some ideas. YMMV.
This was it :)) Even mouse works in Terminal!
For anyone experienced it's probably just a hinderance.
It works just fine in my experience. I’ve configured mdraid with it for fun - and it worked. Ditched it in favour of Zfs which is not yet supported unfortunately.
I think it’s a good direction. It will become the default “GUI” for server maintenance I think.
I find it interesting that I didn’t come across this one in all of my research I did last week or so, even though it’s backed by Redhat.
I actually think although we’re in a time of striving for serverless, there will always be a market for self hosting, be it niche.
Not everyone is building a huge SaaS platform but wants to run more than just a blog or website.
I don’t think this is the answer though. I think what these type of servers need is a standardised layer to interact with them, an API, something like how we have EPP for domains.
Because as we know, frontend will change so fast. The underlying hardware and OS changes too. Now seems like the right time to invent a new level of abstraction.
I’m not aware of anything that exists like this.
Back in the day the closest thing to this was software called webmin.
In short, most likely, unless you are reckless with it.
I highly recommend it to anyone here, especially on something like a headless server where you don't want or can't have an X11 UI running.
If anyone deploys this, make sure to bind only to localhost, and use an ssh tunnel to access it remotely, otherwise you're opening a massive attack surface.
EDIT: Actually they seem to have fixed it now. Nifty.
But for my homelab I run UnRAID (https://unraid.net/) which is an amazing software to rollout your own NAS and run services as Docker containers. Furthermore, the web UI is amazing to manage Docker containers and VMs.
And the community is awesome if you need any help.