Luke GustafsonandZacharyZcR 0ce0fe71a6 release-2.9.1 (#1558)
* fix(sso): send the PKCE verifier for GitHub login (#1534)

* fix(remote-desktop): clip cursor overflow without disabling zoom (#1535)

* test(remote-desktop): preserve sessions beyond one hour (#1536)

* fix(hosts): expose controls for overflowing editor tabs (#1537)

* fix(hosts): expose controls for overflowing editor tabs

* test(hosts): mock resize observation in admin panel tests

* fix(status): skip TCP probes while host sessions are active (#1538)

* fix(database): batch session activity persistence (#1539)

* docs(api): describe cookie and API key authentication (#1540)

* fix(snippets): repair missing note column on SQLite upgrades (#1541)

* fix(docker): retain stored SSH credential association (#1543)

* fix(file-manager): render transfer toasts without plugin hooks (#1546)

* feat(hosts): keep compact row actions inline (#1547)

* fix(auth): allow retrying unavailable second-factor interfaces (#1549)

* fix(auth): reject unresolved legacy identity provisioning (#1550)

* fix(desktop): ship the plugin SDK inside Mac App Store builds (#1551)

* fix(tmux): pass full session info to the terminal's session picker (#1552)

The tmux.sessions service reduced detected sessions to bare names, but the
picker reads session.name, so every entry rendered blank and selecting one
sent an empty name, which created a new session instead of attaching.

* fix(ssh): read force keyboard-interactive as a boolean when resolving hosts (#1553)

The column holds the text "true"/"false", and the resolver passed it
through as-is. The string "false" is truthy, so the password provider
treated every saved host as forced keyboard-interactive and left the
password out. Jump hops are built straight from the resolved host, so a
password hop whose server doesn't offer keyboard-interactive failed with
"All configured authentication methods failed".

* fix(database): batch database saves for bulk host writes (#1554)

* fix(database): yield to the event loop between database saves

Each SQLite save serializes and encrypts the whole database into new
buffers, which V8 only releases once the event loop turns. Boot
migrations and bulk host import write plugin settings per host and per
key in an awaited loop, so hundreds of full copies piled up and the
container ran out of memory.

* fix(database): save once per bulk host write instead of once per row

On SQLite every repository write force-saves the whole database. Boot
plugin data migrations, host defaults materialization and the bulk
host routes write one row per host per setting, so they serialized and
encrypted the full database hundreds of times in a row.

DatabaseSaveTrigger.batched wraps a function so force saves made while
it runs collapse into a single save when it finishes. Nested scopes fold
into the outer one, and work that outlives its scope saves normally.

* feat(hosts): add instance-wide predefined tag suggestions (#1548)

* feat(hosts): add shared predefined tag suggestions

* style(hosts): format tag catalog routes

* test(database): advance fake timers past the save yield (#1555)

* fix(i18n): complete Simplified Chinese core and plugin translations (#1542)

* fix(i18n): complete Chinese onboarding and navigation labels

* fix(i18n): translate remaining Chinese core and plugin interfaces

* fix(i18n): translate host editor tab overflow controls

* fix(i18n): use consistent Chinese fleet terminology

* fix(i18n): localize hardcoded controls and plugin views

* fix(i18n): translate built-in homepage widget catalog

* test(homepage): follow translated timezone placeholder

* fix(i18n): translate plugin-provided homepage widgets

* fix(i18n): localize feature settings section titles

* fix: 2.8 oidc accounts unable to sign in after upgrading (#1381)

* fix: plugins losing the saved ssh login when copying a host (#1391)

* fix: fleets, proxmox and automations not getting the host sudo password

* fix: host imports running a defaults pass and metrics restart per host (#1384)

* fix: high cpu from status probes and full database saves on every sample (#1300)

* fix: user data export freezing the server (#1393)

* fix: op:// secret references rejected as ssh keys on credentials (#1394)

* fix: slow file deletes from the trash lookups on every delete (#1390)

* fix: add openapi docs and error handling to host tag routes

* test: compare download stream buffers directly so it stops timing out

* chore: drop em dash from host row comment

* chore: update release notes for 2.9.1

* fix: restore space to add host tags and redesign predefined tags editor

* fix: host key silently accepted when the host is missing from the database (#1397)

* fix: clearer host login failed status label and fix its translations (#1396)

* chore: add host key and status label fixes to release notes

* fix: sso and ldap provider dialogs overflowing the screen and using mismatched toggles

* chore: increment ver

* fix(audit): store plugin entries with no acting user as a null user_id (#1556)

Plugin audit entries written outside a request used the literal "system"
as user_id. That column references users.id, so the insert was refused
(Postgres logs it as an FK violation) and the entry was silently dropped.
Write null instead and keep "system" / plugin:<id> in username.

* chore: add sso/ldap dialog and audit log fixes to release notes

* fix: tunnels and host settings missing from shared hosts on desktop

* fix: remote desktop logins missing from shared hosts on desktop

* fix: simplify host status to online/offline and keep it live without a refresh

* chore: sync Crowdin translations for 2.9.1

* fix: build docker frontend/backend natively to stop arm64 hang, build sdk before openapi

---------

Co-authored-by: ZacharyZcR <zacharyzcr1984@gmail.com>
2026-10-04 15:50:49 -05:00
2026-10-01 16:20:16 -05:00
2026-10-01 16:20:16 -05:00
2026-08-19 14:12:06 -05:00
2026-10-01 22:22:47 +00:00
2026-09-20 14:56:39 -05:00
2026-10-04 15:50:49 -05:00
2026-10-01 16:20:16 -05:00
2026-10-01 16:20:16 -05:00
2026-10-01 16:20:16 -05:00
2026-10-04 15:11:41 -05:00
2026-10-04 15:11:41 -05:00
2026-10-04 15:11:41 -05:00
2026-10-01 16:20:16 -05:00
2026-10-01 16:20:16 -05:00
2026-10-04 15:11:41 -05:00
2026-05-06 15:12:07 -05:00
2025-11-05 10:36:16 -06:00
2026-07-19 12:29:52 -05:00
2026-05-06 15:12:07 -05:00
2026-05-06 15:12:07 -05:00
2026-10-01 16:20:16 -05:00
2026-05-06 15:12:07 -05:00
2026-05-06 15:12:07 -05:00
2026-08-22 19:47:40 -05:00
2025-11-05 10:36:16 -06:00
2025-11-05 10:36:16 -06:00
2026-10-01 16:20:16 -05:00
2026-08-06 14:41:39 -05:00
2026-08-06 14:41:39 -05:00
2026-08-06 14:41:39 -05:00
2026-10-01 16:20:16 -05:00
2026-10-01 16:20:16 -05:00
2026-09-20 14:56:39 -05:00
2026-10-01 16:20:16 -05:00
2025-08-07 02:20:27 -05:00
2026-10-04 15:11:41 -05:00
2026-10-04 15:50:49 -05:00
2026-10-01 16:20:16 -05:00
2026-10-01 16:20:16 -05:00
2026-10-04 15:11:41 -05:00
2026-09-20 14:56:39 -05:00
2026-10-01 16:20:16 -05:00
2026-10-01 16:20:16 -05:00
2026-06-04 14:16:53 -05:00
2026-10-01 16:20:16 -05:00
2026-10-01 16:20:16 -05:00
2026-10-01 16:20:16 -05:00
2026-10-01 16:20:16 -05:00
2026-10-01 16:20:16 -05:00

Termix Logo

Termix

Self-hosted server management, from SSH and remote desktop to automations

English · 中文 · 日本語 · 한국어 · Français · Deutsch · Español · Português · Русский · العربية · हिन्दी · Türkçe · Tiếng Việt · Italiano

Discord Donate

Donations this month


Termix is free and open source. If you find it useful, consider donating to help cover server costs and development time.


Termix Banner

Repo of the Day Achievement
Achieved on September 1st, 2025


Overview

Termix is a free, open source, self-hosted platform for managing your servers. It puts SSH terminals, remote desktops (RDP, VNC, Telnet), file transfers, tunnels, Docker, metrics, and automations in one place, on web, desktop, and mobile. It is a self-hosted alternative to Termius that stays free forever.


Features

SSH Terminal: A full terminal with browser-like tabs and split screen, up to 6 panels at once. Pick your theme, font, and colors. A toolbar sits above each session with live CPU, memory, and disk, plus quick links to that host's files, Docker, tunnels, and metrics.

Remote Desktop: RDP, VNC, and Telnet in the browser, in tabs and split screen like any other session. Includes a file browser for RDP drives and drag-and-drop upload. On Windows desktop you can also open a host in the native RDP client.

SSH Tunnels: Local, remote, and dynamic SOCKS forwarding with auto reconnect and health checks. Client-to-server tunnels on the desktop app are stored on that machine, and you can save presets to the server to move a setup to another client.

File Manager: Browse, edit, upload, download, rename, move, and delete files over SFTP, with sudo support. View and edit code, images, audio, and video. Copy files straight from one server to another in a dedicated transfer tab, with the fastest route picked for you and transfers checked for integrity. The desktop app also has a side-by-side local and remote view.

Docker and Podman: Start, stop, pause, and remove containers, watch their stats, and open a shell inside one. Works with both Docker and Podman. It is not meant to replace Portainer or Dockge, just to manage containers you already have.

Host Manager: Save and organize hosts with tags and nested folders you can name and color. Reuse saved credentials across hosts, deploy SSH keys automatically, group hosts under a parent host, bulk edit and export, and use Quick Connect for one-off connections you do not want to save.

Host Metrics: CPU, memory, disk, network, temperature, NVIDIA GPU, uptime, processes, ports, logins, and system info on most Linux servers, with history graphs. Manager cards let you handle services, cron jobs, packages, users, firewall rules, WireGuard, Tailscale, SSL certs, logs, and health checks without leaving Termix.

Automations: Pick a trigger, then say what should happen. Triggers include a metric crossing a threshold, a host going up or down, a health check changing, a schedule, a container event, or an incoming webhook. Steps can run commands and snippets, control containers and tunnels, wake a host, call a URL, wait, branch on a condition, run another automation, and notify you over ntfy, Discord, or a webhook. Test runs let you try it safely first.

Fleets: Group hosts into a fleet by picking them or with tag rules, so new hosts join on their own. Run one command on every host at once, push and pull files across all of them, install packages, and collect an inventory of OS, kernel, arch, and uptime.

AI Assistant: Optional, and off until you turn it on. Connect OpenAI, Anthropic, Gemini, Ollama, or any OpenAI compatible endpoint and ask about your setup. It reads hosts, fleets, snippets, and alerts, and proposes changes for you to approve instead of making them. It can never touch credentials, users, or settings. Admins can leave it off for the whole instance, and you can hide it during setup.

Login and Users: Local accounts plus OIDC, LDAP, GitHub, and Google sign-in, with 2FA (TOTP), passkeys (WebAuthn), and trusted devices. Admins can manage users, map OIDC groups to roles, see every active session across platforms, and revoke them. Link your local and OIDC accounts together, and read the audit log of what everyone did.

Roles and Sharing: Create roles and share hosts with users or roles at four levels: connect, view, edit, and manage. Works with every auth type and every protocol, and you can override the credentials used for a shared host.

Alerts: Set rules on host metrics like CPU, memory, and disk, and get notified over ntfy, Discord, or a webhook when they fire. See firing and resolved alerts in a history log, and dismiss the ones you do not care about.

Homepage: A drag-and-drop widget grid you build yourself. Widgets for host status, pings, service links, bookmarks, search, clocks, calendars, countdowns, notes, RSS, weather, images, iframes, Docker, tunnels, metrics charts, custom APIs, and even a live terminal.

Snippets and Tools: Save commands you run often and fire them off in one click, with variables for the host and your own inputs. Run a single command across every open terminal, and search your command history with autocomplete.

Session Sharing: Share a live terminal, RDP, VNC, or Telnet session in real time. Send a link anyone can join without an account, or share with a specific Termix user, in read-only or read-write mode. Shares can expire on their own or be revoked, and can be turned off globally or per host.

Session Recording and Logs: Record terminal, RDP, and VNC sessions and play them back later. Download plain text logs of a session, and check the connection log to see exactly what happened during a connection.

Serial Connections: Talk to serial devices like routers, switches, and microcontrollers from the browser or desktop app. Set baud rate, data bits, stop bits, and parity. Uses the Web Serial API in supported browsers, or a native backend in the desktop app.

Tailscale: Pull devices from your tailnet to add them as hosts in a couple of clicks, and connect with Tailscale SSH so your tailnet ACLs handle access and no credentials are stored. Headscale and custom endpoints work too.

Proxmox: Import hosts straight from a Proxmox instance, and watch node and guest stats, including CPU, memory, and storage, in their own tab.

Workspaces and Tabs: Save a set of tabs with their split layout and reopen the whole thing in one click. Termix also remembers your last session, so your tabs come back across refreshes and devices.

Command Line Interface: A termix CLI for your shell and your scripts. Open terminals, run a command on one host or a whole fleet, move files over SFTP, and manage hosts, snippets, and credentials. Install with npm install -g @termix-cli/cli or grab a standalone binary. See the CLI docs.

Security: Passwords, keys, and other secrets are encrypted per user, and the database files themselves can be encrypted on disk. See the docs for how it works.

Languages: Around 30 languages built in, managed through Crowdin.


More features
  • Dashboard - Your servers at a glance, with cards you arrange yourself
  • Network Graph - See your homelab drawn out from your hosts, with live status
  • Tmux Monitor - Browse tmux sessions, windows, and panes, with previews and search
  • API Keys - User-scoped keys with expiry dates for scripts and CI
  • Export and Import - Move hosts, credentials, and file manager data in and out
  • Automatic SSL - Certificates generated and renewed for you, with HTTPS redirects, or bring your own
  • Databases - SQLite by default, with PostgreSQL and MySQL supported too
  • Modern UI - Clean React interface that works on desktop and mobile, with themes like light, dark, and Dracula. Any connection can open full screen from a URL
  • Command Palette - Double tap left shift to jump to a host from the keyboard
  • Keyboard Shortcuts - Move between tabs, close tabs, and more, all rebindable
  • Wake-on-LAN - Wake a machine from Termix or from an automation step
  • Trusted Proxy Auth - Let a reverse proxy handle sign-in and pass the user through
  • White Label - Admins can rebrand the instance with their own name, logo, and colors
  • Web Endpoints - Open a host's own web UI, like a router admin page, embedded inside Termix instead of a separate tab
  • Collaboration Rooms - Persistent rooms where a group can jump between sessions together, with a presenter stage and invites
  • SSH Feature Rich - Jump hosts, Warpgate, TOTP prompts, SOCKS5, host key verification, password autofill, OPKSSH, tmux, port knocking, terminal logging, agent forwarding, Bitwarden SSH agent, HashiCorp Vault SSH signing, Step CA, 1Password Connect, and more
  • Termix ID - A built-in take on sshid.io. Claim a handle, publish your public keys at a resolver URL, and issue SSH certificates from the built-in CA
  • Command History Autosuggestions - Inline suggestions in the terminal as you type, based on your command history
  • Desktop Standalone and Sync - The desktop app runs on its own with a local backend and database, and can optionally sync with a Termix server

Platform Support

Platform Distribution
Web Any modern browser (Chrome, Safari, Firefox) · PWA support
Windows x64/ia32 Portable · MSI Installer · Chocolatey
Linux x64/ia32 Portable · AUR · AppImage · Deb · Flatpak
macOS x64/ia32, v12.0+ Apple App Store · DMG · Homebrew
iOS/iPadOS v15.1+ Apple App Store · IPA
Android v7.0+ Google Play Store · APK

Installation

Visit the Termix Docs for full installation instructions across all platforms.

Deploying to Kubernetes? The Helm chart is in charts/termix, and setup instructions covering Ingress, Traefik, Argo CD, GitHub Actions, and GitLab CI are at docs.termix.site/install/server/kubernetes.

Sample Docker Compose file (you can omit guacd and the network if you don't plan on using remote desktop features):

services:
  termix:
    image: ghcr.io/lukegus/termix:latest
    container_name: termix
    restart: unless-stopped
    ports:
      - "8080:8080"
    volumes:
      - termix-data:/app/data
    environment:
      PORT: "8080"
    depends_on:
      - guacd
    networks:
      - termix-net

  guacd:
    image: guacamole/guacd:1.6.0
    container_name: guacd
    restart: unless-stopped
    ports:
      - "4822:4822"
    networks:
      - termix-net

volumes:
  termix-data:
    driver: local

networks:
  termix-net:
    driver: bridge

Command Line Interface

Termix also has a CLI, so you can manage your servers from a terminal and use Termix in your own scripts.

npm install -g @termix-cli/cli
termix login --url https://termix.example.com
termix ssh 1

It can open terminals, run a command on one host or a whole fleet, move files over SFTP, and manage hosts, snippets and credentials. Full documentation is at docs.termix.site/cli.

Cloud Hosting

You can run the Termix server on a VPS instead of inside your own network. If Termix runs on the network it manages, an outage takes Termix down with it, right when you need it to fix things. Running it elsewhere keeps it reachable, gives you a static IP, and lets you get in from anywhere without a VPN or port forward.

GINERNET sponsors Termix, and the docs have a step by step guide for deploying to their VPS platform.


Telemetry

Termix sends a small anonymous report once a day so I can see how many instances are running and which features get used. It contains a random instance ID, the app version, and how many users and hosts you have. It can also include your platform (OS, architecture, Node.js version, database type, and whether you run Docker, the desktop app or a plain server), how often each kind of tab was opened and how many SSH logins happened, and which built-in features are running. It never contains usernames, hostnames, IP addresses, credentials, or anything else that identifies you or your servers.

It is on by default. Turn it off, or choose what it includes, in Admin Settings under Usage Statistics, where you can also preview the exact report. Each user can leave out their own feature usage in their profile. Setting ENABLE_TELEMETRY=false turns it off and locks the switch.


Donate

Termix is free and open source with no subscriptions or paid plans. If you find it useful, consider donating to help cover server costs, domains, and development time. Donations also help fund the time to research and learn what's needed to build features like SAML, Kubernetes, and Agent support. Track progress and donate below.

Donate


Sponsors

Interested in a paid placement to support development? Email mail@termix.site.


DigitalOcean     Crowdin     Blacksmith     Cloudflare     Akamai     AWS     Rack Genius     Ginernet     Hetzner

Support

Need help or want to request a feature? Open a new issue and add as much detail as you can, in English if possible. You can also ask in the support channel on Discord, though replies there can take longer.


Screenshots


YouTube

Watch update overviews on YouTube



Termix Screenshot 1 Termix Screenshot 2
Termix Screenshot 3 Termix Screenshot 4
Termix Screenshot 5 Termix Screenshot 6
Termix Screenshot 7 Termix Screenshot 8
Termix Screenshot 9 Termix Screenshot 10
Termix Screenshot 11 Termix Screenshot 12
Termix Screenshot 13 Termix Screenshot 14
Termix Screenshot 15 Termix Screenshot 16

Some videos and images may be out of date or may not perfectly showcase features.


Planned Features

See Projects for all planned features. If you are looking to contribute, see Contributing.


License

Distributed under the Apache License Version 2.0. See LICENSE for more information.

Languages
TypeScript 97.1%
JavaScript 2.6%
CSS 0.2%