linux system monitor + remote task manager
runs as root on purpose so the web panel can manage the full machine
ubuntu/debian is the main target
server releases are linux amd64, arm64 and armv7. armv7 is for 32-bit ARMv7 machines
ports 80 and 443 need to be reachable for https setup and renewal
- point a domain at the server
- extract the release
- run
sudo bash ./setup.shsetup asks for the domain, owner username, owner password and optional letsencrypt email
it installs the service, nginx config and https certificate then starts DSM
open
https://your-domain.example
extract the new release over a temporary folder then run
sudo bash ./update.shfrom source use sudo bash ./scripts/update.sh
users, 2fa, audit history and config stay in place
requires a current Go release
linux/macOS
sh ./build.shwindows
build.cmdoutputs go to dist/
release archives: bash ./scripts/make-release.sh (requires tar and zip)
linux clients come in amd64, arm64 and armv7. windows clients come in amd64 and arm64
github makes a nightly prerelease daily. pushing a v tag matching VERSION makes a tagged release
put desktop.config.json beside the desktop executable
{
"url": "https://your-domain.example/"
}the website also works normally in desktop/mobile browsers and can be installed as a PWA
Task Manager separates ordinary applications, Docker-container processes, systemd services, infrastructure helpers and kernel threads. Helper and kernel rows remain available but are hidden by default so host infrastructure does not overwhelm the useful process list.
On Linux, DSM also associates processes with cgroup-owned Docker containers and systemd services. Listening sockets are shown with public, private or loopback exposure labels, and process inspection provides structured runtime details instead of a raw JSON dump.
DSM reads process metadata from /proc. Sensitive command-line values associated with passwords, secrets, tokens, API keys, credentials and credential-bearing URLs are redacted on the server before API responses are produced. Applications should still avoid placing secrets on command lines when a file descriptor, protected file or environment-based mechanism is available.
list users
sudo /opt/dons-system-monitor/dsm-server -config /etc/dons-system-monitor/config.json -list-usersreset a user
sudo systemctl stop dons-system-monitor
sudo /opt/dons-system-monitor/dsm-server -config /etc/dons-system-monitor/config.json -reset-user admin
sudo systemctl start dons-system-monitor/etc/dons-system-monitor/config.json
/var/lib/dons-system-monitor/users.json
/var/lib/dons-system-monitor/audit.jsonl
back those up if the install matters to you