Termix

repository·main·Indexed 11 days ago

https://github.com/termix-ssh/termix

A self-hosted, all-in-one server management platform providing SSH terminal access, remote desktop control (RDP, VNC, Telnet), SSH tunneling, and container management (Docker, Podman) through a unified web or desktop interface. Version 2.6.1 supports multiple database backends including SQLite, Postgres, and MySQL, and is available across Web, Windows, Linux, macOS, iOS, and Android.

Tokens
17K
Snippets
40
Records
76
Agent score
96%

What's inside Termix

  1. Overview of Termix features and capabilities

    main

    Termix is an open-source, self-hosted, all-in-one server management platform designed as a free alternative to Termius. It provides a single interface for managing infrastructure across multiple platforms.

    Core Capabilities:

    • SSH Terminal: Full-featured terminal with browser-style tabs, split-screen (up to 4 panels), and customizable themes/fonts.
    • Remote Desktop: Browser-based support for RDP, VNC, and Telnet with split-screen capabilities.
    • SSH Tunnel Management: Supports local, remote, and dynamic SOCKS forwarding with automatic reconnection and state monitoring.
    • Remote File Manager: Direct management of files on remote servers (upload, download, rename, move, delete) with sudo support and support for viewing/editing code, images, audio, and video.
    • Container Management: Manage Docker and Podman containers (start, stop, pause, remove, view stats, and docker exec).
    • SSH Host Management: Organize connections using tags and nested folders; automates SSH key deployment.
    • Host Metrics: Monitors CPU, memory, disk, network, uptime, firewall, and logs with threshold-based alerts via ntfy or webhooks.
    • User Authentication & RBAC: Supports OIDC/LDAP/SSO, 2FA (TOTP), and Passkeys (WebAuthn). Role-Based Access Control (RBAC) allows sharing specific hosts with specific users.
    • Tailscale Integration: Quickly add devices from a Tailscale network and use Tailscale SSH for credential-less authentication via network ACLs.
    • Serial Connection: Connect to serial devices (routers, microcontrollers) via Web Serial API in browsers or native backends in the Electron app.
    • Session Sharing: Real-time sharing of Terminal, RDP, VNC, or Telnet sessions via links (anonymous or authenticated) with read-only or read/write permissions.
    • Desktop App & Sync: An Electron-based desktop app that can run independently or sync hosts, credentials, and snippets bi-directionally with a remote Termix server.
  2. Overview of Termix

    main

    Termix is an open-source, self-hosted server management platform designed to provide a unified, intuitive interface for managing servers and infrastructure. It serves as a free alternative to commercial tools like Termius and is compatible with multiple platforms.

    Key capabilities include:

    • SSH Terminal Access: Direct command-line access to remote servers.
    • Remote Desktop Management: Support for RDP, VNC, and Telnet protocols.
    • SSH Tunneling: Capabilities for creating secure tunnels.
    • Remote File Management: Managing files over SSH.
    • Infrastructure Management: A centralized way to handle multiple servers and remote environments.
  3. Overview of Termix features

    main

    Termix is an open-source, self-hosted, all-in-one server management platform. It provides a multi-platform solution for managing infrastructure through a single interface. Key capabilities include:

    • SSH Terminal Access: Full terminal with split-screen support (up to 4 panels), browser-like tabs, and customizable themes/fonts.
    • Remote Desktop: Browser-based support for RDP, VNC, and Telnet with split-screen capabilities.
    • SSH Tunnel Management: Create and manage server-to-server tunnels with automatic reconnection, status monitoring, and local, remote, or dynamic SOCKS forwarding.
    • Remote File Manager: Direct file management on remote servers (upload, download, rename, delete, move) with support for code, image, audio, and video editing, including sudo support and server-to-server transfers.
    • Docker & Podman Management: Start, stop, pause, and delete containers; view container statistics; and control containers via docker exec.
    • SSH Host Management: Organize connections using labels and nested folders, with support for automated SSH key deployment.
    • Host Metrics: Monitor CPU, memory, disk, network, uptime, system info, firewall, ports, logs, and more, featuring time-series graphs and threshold-based alerts (via ntfy or webhooks).
    • User Authentication & RBAC: Secure user management with OIDC/LDAP/SSO, 2FA (TOTP), and Passkeys (WebAuthn). Role-Based Access Control (RBAC) allows sharing specific hosts with users or roles.
    • Tailscale Integration: Quickly add Tailscale network devices as hosts and use Tailscale SSH for authentication.
    • Serial Connections: Connect to serial devices (routers, switches, microcontrollers) via Web Serial API in browsers or a native backend in the Electron app.
    • Session Sharing: Share live terminal, RDP, VNC, or Telnet sessions in real-time via links (anonymous) or specific users, with read-only or read-write permissions.
    • Desktop Application: An independent Electron app with its own local backend/database, which can optionally sync bidirectionally with a remote Termix server.
    • Advanced SSH Features: Supports jump hosts, Warpgate, TOTP-based connections, SOCKS5, host key verification, password autocompletion, OPKSSH, tmux, port knocking, terminal logging, SSH agent forwarding, Bitwarden SSH agent, and HashiCorp Vault SSH signing.
  4. Termix Core Features Overview

    main

    Termix is a comprehensive management platform for remote server access and infrastructure. Key capabilities include:

    • SSH Terminal Access: Full-featured terminal with browser-style tab systems and split-screen support (up to 4 panels).
    • Remote Desktop Access: Support for RDP, VNC, and Telnet via browser with customization and split-screen.
    • SSH Tunnel Management: Creation and management of server-to-server SSH tunnels, including Local, Remote, and Dynamic SOCKS forwarding. Supports automatic reconnection and health monitoring.
    • Remote File Manager: Direct management of files on remote servers (upload, download, rename, delete, move) with sudo support and cross-server file movement.
    • Container Management: Support for Docker and Podman to start, stop, pause, delete, and view container statistics.
    • SSH Host Manager: Organize connections using tags and nested folders; automates SSH key deployment.
    • Host Metrics & Alerting: Monitoring for CPU, memory, disk, network, and more, with threshold-based alerts via ntfy or webhooks.
    • User Authentication & RBAC: Secure management via OIDC/LDAP/SSO, 2FA (TOTP), and Passkeys (WebAuthn), with Role-Based Access Control (RBAC) for sharing hosts.
    • Serial Connection: Direct connection to serial devices (routers, switches, etc.) using Web Serial API in browsers or native backends in Electron.
    • Session Sharing: Real-time sharing of terminal, RDP, VNC, or Telnet sessions via links (anonymous or authenticated) with read-only or read/write permissions.
    • Tailscale Integration: Quickly add Tailnet devices as hosts and use Tailscale SSH for authentication.
  5. Share terminal and remote sessions

    main

    Termix allows real-time sharing of active sessions (Terminal, RDP, VNC, or Telnet).

    Sharing Methods:

    • Link Sharing: Generate a link for anonymous joining (no account required).
    • User Sharing: Share with a specific Termix user.

    Access Control:

    • Permissions: Choose between read-only or read-write access.
    • Expiration: Set sessions to expire automatically or revoke access manually at any time.
    • Scope: Session sharing can be enabled globally or configured for individual hosts.
  6. Understand encryption differences between backends

    main

    Termix employs two layers of encryption. The behavior of these layers depends on your chosen backend.

    1. Field-level Encryption (Identical on all backends)

    Sensitive values are encrypted in the application before reaching the database using a per-user data key. This protects:

    • ssh_data: passwords, private keys, passphrases, etc.
    • ssh_credentials: passwords, private/public keys.
    • users: TOTP secrets and backup codes.
    • vault_tokens, opkssh_tokens, termix_identity_ca: certificates and keys.
    • shared_host_secrets: re-encrypted per recipient.
    • Installation secrets (OIDC client secret, LDAP bind password): encrypted under the system key.

    2. Storage-level Encryption (Backend dependent)

    • SQLite: The entire database file is encrypted at rest. If the file is stolen, everything (including metadata) is protected.
    • Postgres / MySQL: Termix does not provide whole-file encryption. Metadata such as hostnames, addresses, ports, usernames, folder/snippet names, and audit logs are readable by anyone with database access.

    Requirement: If running Postgres or MySQL, you are responsible for encryption at rest (e.g., via transparent data encryption, encrypted volumes, or encrypted filesystems).

  7. Advanced SSH and Automation features in Termix

    main

    Beyond basic management, Termix includes several advanced tools for power users and automation:

    • API Keys: Create user-scoped API keys with expiration dates for CI/CD and automation.
    • Data Portability: Export and import SSH hosts, credentials, and file manager data.
    • Proxmox Integration: Automatically discover and add hosts from your Proxmox instance.
    • Rich SSH Support: Includes support for jump hosts, Warpgate, TOTP-based connections, SOCKS5, host key verification, password auto-fill, OPKSSH, tmux, port knocking, terminal logging, SSH agent forwarding, Bitwarden SSH agent, and HashiCorp Vault SSH signing.
    • Termix ID: An integrated service similar to sshid.io for reserving identifiers, publishing public SSH keys to a resolution URL, and using a built-in CA to issue SSH certificates.
    • Command Palette: Quickly access SSH connections by pressing the Left Shift key twice.
    • Command Snippets: Create reusable command snippets that can be executed with a single click or simultaneously across multiple open terminals.
  8. Manage SSH tunnels and SOCKS forwarding

    main

    Termix allows for the creation and management of inter-server SSH tunnels.

    Key features:

    • Automatic Reconnection: Tunnels automatically reconnect if dropped.
    • Monitoring: Real-time status monitoring of tunnel health.
    • Forwarding Types: Supports local, remote, and dynamic SOCKS forwarding.
    • Configuration Portability: While 'desktop client-to-server' (C2S) settings are stored locally by default, you can save, rename, upload, or delete optional C2S-preset snapshots on the server to migrate tunnel configurations between different clients.
  9. Manage Docker and Podman containers

    main

    Termix provides a UI for managing container lifecycles and monitoring. It supports both Docker and Podman runtimes.

    Capabilities:

    • Lifecycle Management: Start, stop, pause, and delete containers.
    • Monitoring: View container statistics.
    • Execution: Manage containers directly through the terminal using docker exec commands.
  10. Configure Postgres or MySQL backends

    main

    Termix uses SQLite by default. For self-hosted deployments requiring multiple replicas or external backups, you can use Postgres or MySQL by setting the DATABASE_DIALECT and DATABASE_URL environment variables.

    Important Notes:

    • Point the connection string to an empty database; migrations are applied automatically at startup.
    • There is no migration path from an existing SQLite database to Postgres or MySQL.
    • mariadb:// schemes are accepted for MySQL.
    • DATA_DIR is still used for uploads and recordings regardless of the database backend.
    # For Postgres
    DATABASE_DIALECT=postgres
    DATABASE_URL=postgres://user:password@host:5432/termix
    
    # For MySQL
    DATABASE_DIALECT=mysql
    DATABASE_URL=mysql://user:password@host:3306/termix