LockFlare

Tools on every server

Tunnels. Local, remote and proxy (SOCKS5 + HTTP on one port here, traffic leaving from the server) forwards riding the SSH login Lens already has, saved per server and started when the shell is up; "on connect" opens them by themselves. A list of what a tunnel could reach on this server (what listens on loopback, judged), templates for the things people tunnel to with their ports and whether they open in a browser, start · stop · open · copy · forget, and in words what a bind host means for coworkers sharing it (only this computer, one interface, the VPN, every network). SHARED ON YOUR NETWORK: with Advertise on, a tunnel bound to the office Wi-Fi is announced by mDNS/Bonjour as _lens-tunnel._tcp (and as _http._tcp when the far end speaks HTTP, so Safari's and Chrome's Bonjour lists see it as a plain web service); any other Lens on the same network lists it with the address ready to copy or open. Never announced wider than its bind.

HTTP Tunnel (Browse through this server). One switch and this computer's browsers leave the internet from the box — its address, its network, its DNS. Underneath: the proxy tunnel plus the computer's system proxy pointed at it while on; off with the shell, the setting restored the moment it goes (and on next launch if Lens died with it on). One switch per computer: on for server B turns off for A and says so. A second door that never depends on the system: a browser window Lens opens (Chrome, Edge or Brave, its own profile, --proxy-server at the tunnel). A lookup box asks a name on the box and here and shows both answers.

Run Template. A Server Template walked on THIS box (see §10), the run owning the whole screen.

Browse files. The server one pane full width, riding the live shell's login as ordinary commands — nothing installed on the far side. Downloads and uploads through the system's own open/save panels; reads fall back to root on their own ("read as root"), changes as root through the saved password. Right-click a text file → Edit opens a code editor beside the pane (syntax colours guessed from the name, correctable); saving writes the bytes back with the mode and owner the file had, and says when a save had to become root to keep the owner. A permissions dialog in the order a person asks: what can I do here, who else and what (classic bits and the ACL as one list, the acl tools installed from here when missing), who owns it and how far it reaches. Bulk delete in one call; compress a selection into an archive on the box, extract one, or download a folder as an archive.

The bucket. References to files on ANY server (or this computer), collected in one pane and dropped onto another server's folder: Lens relays them box to box through this computer over the two sessions already open, nothing on disk. Buckets can be saved by name — the recipe (server ids, folders, names), never the files and never a credential.

Backups (plans on the box). The box is the record: every plan is two files on it and a cron line, the runner lives there too, so a backup at 3 am needs nothing from this computer. The screen reads every plan on the box as a card — what · when · keep · where · last run — with findings worst first and the fix beside each, Run now, the last run's log, Pause/Resume, Edit, Forget, and Bring back (what every destination holds for this plan, newest first; picked, pulled, opened with the key on this pen drive and placed where its kind's Put back looks). What: a folder, a website, a database (made on the engine's tab), mailboxes. Where: the repositories under Setup, set up on this box as rclone remotes (root-only, scoped at the store). Encryption before the push with age: the operator's backup public key on the box, the secret half sealed on the pen-drive key, so what a store receives is unreadable without the key. Mail from the box on failure through Setup › Notifications.

Themis AI on one server. The AI sysadmin, inside Lens, with nothing installed: she reads through curated probes and a leashed read-only shell over the session already open, and proposes, never changes. Enabling her creates one folder, /var/lib/lens, where her reports, the baseline and the run ledger live — no agent, no daemon, and removing the folder removes every trace. Tabs: Ask (a conversation), Security report, Health, Forensics, On this box (the box's memory: enable, ask, report, compare), Settings. Proposals come one at a time with Run / Show me / No — the row says in words what Run does and why, Show me prints the exact script — and Lens never answers as Themis after a Run. A report is confirmed before it is spent because it is the operator's own account at their own provider. Answers render as a document — headings, lists, commands — never as raw text from a model. A sheet beside any page lets a container's logs, a failed job or a NOC wire be asked about where it was seen.

Themis's security audit in LockFlare Lens with an exposure table and findings carrying their evidence
The audit: every port with its firewall rule and who can reach it, findings with their evidence, and what she dismissed and why.