Every server you have, read at once. A row each, a dot per check.

Overview is a chair of its own: pick the servers, pick a kind of reading — security, health, disks, backups, databases, updates, who can get in, who is knocking, what is exposed, certificates, drift — and every server answers in one row. No tab is opened for any of them. Green is fine, yellow is worth a look, red needs you, and a click on a dot says why.

Eleven readings, each a row per server

Each kind is one script per server and one verdict per column. Where Vigia already reads the same thing on a server's own screen, the Overview runs that screen's own reading, so a dot here and the card there never disagree.

Security

Firewall, Fail2Ban, SSH hardening, kernel, AppArmor or SELinux, the WAF, automatic updates, password rules, integrity, audit, certificates and accounts — the server's own Security reading, on every server.

Health

Load against the CPUs, memory, swap, failed services, processes the kernel killed for memory in the last day, whether the clock is in sync, uptime, zombies.

Disk

The fullest filesystem, the root one, inodes, a filesystem the kernel turned read-only, disk errors in the kernel log, what the drives say through SMART, the size of the journal.

Backups

Vigia's backup plans on each server: the last run, how old the newest good copy is against the plan's own schedule, whether the copy leaves the server, encrypted, and the room for the next one.

Databases

MongoDB, MariaDB or MySQL, PostgreSQL: running or not, the role in the set, replication and its lag, connections against the limit, listening to the world, authentication, TLS between members.

Updates

Security updates first, then everything pending, a reboot owed, how fresh the package lists are, whether updates install themselves, and whether the release still gets security fixes.

Access

Root over SSH, SSH with passwords, who becomes root and which of them with no password, accounts with an empty password, weak keys.

Knocking

Fail2Ban, its jails and its bans, and the SSH logins that failed in the last 24 hours — each connection counted once — where they came from, the names they tried, and who got in.

Exposure

Not what the firewall's rules say but what is actually reachable from anywhere: the database and admin ports among it, SSH taking passwords, the firewall itself, Docker past it.

Certificates

The certificate that runs out first, any already expired, Let's Encrypt with nothing renewing it, a self-signed one handed to visitors.

Drift

The release, the kernel, OpenSSL, OpenSSH, database and web server versions, sshd's settings and the time zone — each server against the rest of its own group.

Built for five hundred servers

There is no tab per server and no agent on any of them. A server with a shell already open is read through that session; any other is logged in to with its saved login, read in one script, and let go. Twenty-four are read at a time, and each has a time limit of its own, so a server that does not answer costs its own row and never the sweep.

Check Now reads the picked servers, Stop lets go at once, and Auto reads them again every five or fifteen minutes while you work elsewhere. The rows fill in as they answer; the last reading stays on screen while a new one is taken, with how long ago it was read.

The servers come from the same pick as Actions, Snippets, Flows and Ask Themis: Pick Servers… by name, by group, or a saved set. Overview reads Vigia servers — the ones on a slot — because it reads as root.

A dot, and why it is that colour

Every column head says what turns it yellow or red: past 80% full, a security update waiting, a replica more than thirty seconds behind. Where a number says more than a colour — failed logins in a day, a backup's age, a replica's lag — the cell is the number, coloured the same way.

Click a yellow or red dot, or a number, and a small panel opens on it: what the server said, the findings behind it — the failed units, the packages waiting, the addresses that knocked, the certificates by how soon they run out — and the rule that coloured it. Filters keep only the servers that need you, the ones that could not be read, or the ones worth a look; Worst First and a column's own head put the worst on top.

Drift: the server that quietly stopped being like the others

The servers of a group are meant to be alike — three members of a replica set, four web boxes behind one balancer. Drift reads the facts that should match and compares each server with the rest of its group: green where it is like most of them, yellow where it is not, with the group's whole spread a click away. The one kernel a reboot behind, the one OpenSSL nobody upgraded, the one sshd that still takes passwords.

A database or a web server is compared only among the servers of the group that run one, so a group that mixes web boxes and database boxes is not drift for having both.

What it will not do

A screen that reads five hundred servers has to be honest about the ones it could not read, and gentle with the ones it can.

Change nothing

Every kind is a reading. Nothing is installed, configured or restarted on any server to answer it.

Guess nothing

A reading cut short — the time limit, sudo refusing, a dropped connection — is that row's error, never a set of green dots. Read without root, a log only root can read is said to be unread, not quiet.

Knock twice on nothing

A saved login a server refuses is not tried again until you change it, so a sweep every five minutes cannot lock an account or get your computer banned.

Pick the servers, pick a reading

Every server you have, one row each, the ones that need you on top.

Download Vigia