v1.0.0-beta.4 is outChangelog

Self-hosted VPS monitoring, down to every route.

Live metrics, network quality, IP reputation, alerts and costs for every VPS you run, in one self-hosted panel. Drag-and-drop dashboards and a native iOS app are built in.

$curl -fsSL https://raw.githubusercontent.com/ZingerLittleBee/ServerBee/main/deploy/install.sh | sudo sh -s -- server --method docker -y

The installer prints your panel URL and a one-time admin password.

$curl -fsSL https://raw.githubusercontent.com/ZingerLittleBee/ServerBee/main/deploy/install.sh | sudo sh -s -- server --method binary -y

The installer prints your panel URL and a one-time admin password.

One-click deploy on Railway, with HTTPS and a persistent volume.Open the Railway template
  • One server binary with the web UI and SQLite built in
  • Terminal and remote exec off by default
  • Open source, AGPL-3.0-or-later

Build the wall you actually want to look at.

17 built-in widgets on a 12-column grid: drag, resize, lock. Build an ops overview, a customer board or a wallboard, as many as you need.

Dashboard docs
  • Real-time, charts, statusStat tiles, gauges, multi-line comparisons, traffic bars, a world map, uptime timelines, Markdown runbooks…
  • Many dashboardsSwitch from the header and set a default. Admins edit; members get read-only views.
  • Widget SDKWrite your own widgets with @serverbee/widget-sdk and install them as a .js file, a .zip pack or an HTTPS URL.

Latency and loss, carrier by carrier.

96 probe targets ship with the server: China Telecom, Unicom and Mobile in all 31 provinces, plus Cloudflare, Google DNS and AWS Tokyo. Assign up to 20 per server and watch latency and loss live, or split by carrier to see which line drops first at peak hours.

  • 96 preset targets31 provinces × three carriers, plus 3 international anchors. Compiled in, so there is no IP list to maintain.
  • Split by carrierTelecom, Unicom and Mobile side by side, each with its own average latency and loss.
  • Real time to 30 daysProbe every 30–600 s. Raw data is kept 7 days, hourly rollups 90 days, with CSV export.
  • Built-in tracerouteICMP, UDP or TCP traceroute from the agent via embedded trippy, no mtr install needed.
Network quality docs
Network panel view

What each IP can unlock, in one table.

Every server checks 9 services from its own egress IP. Checks run every 12 hours, again as soon as the IP changes, and whenever you ask.

IP quality docs
  • Streaming, AI, socialNetflix separates full access from originals-only, and ChatGPT reports the detected region.
  • IP risk profileIP type plus proxy, VPN, Tor, abuser and hosting flags. Add an ipapi.is key for a 0–100 risk score.
  • Custom checksMatch on status code, response body or redirect URL to add your own services, no code needed.
  • ShareableShow unlock results on your status page, with the IP masked for visitors.

A monitoring agent shouldn’t be a backdoor.

Terminal, remote exec, file manager and Docker ship switched off. The host running the agent decides what it may do; the server can read that setting but never change it. Need a shell for half an hour? Grant it on the host and it expires on its own.

Capabilities docs
ops@hk-cn2: ~
# run on the VPS itself; revoked after 30 minutes
$sudo serverbee-agent grant terminal --for 30m --reason "disk check"
  • High-risk off by defaultThe default set covers probes, security events, the firewall blocklist, IP quality and upgrades.
  • Only the host can turn them onCapabilities live in the agent’s config. Neither the panel nor the API can open a terminal remotely.
  • Grants that expire24 hours max by default (the host can change it). When a grant lapses, live terminal sessions close with it.
  • Everything leaves a trailTerminal sessions, exec runs, file operations and capability grants are audit-logged for 180 days.

Your whole fleet, in your pocket.

Open source · App Store soon · iOS 17+

A native SwiftUI app built only on Apple frameworks, with no third-party SDKs and no analytics. Servers, alerts, network quality, IP quality and Docker, all on your phone.

  • Scan to sign inShow a QR code in the web panel and scan it. No URL, no password. Codes expire after 5 minutes and work once.
  • Push alertsAlerts arrive through APNs and open the affected server. For now you need your own Apple push key.
  • Act from anywhereAdmins can restart containers, block an attacking IP or schedule maintenance from the phone.
  • Bilingual and privateFully localized in English and Chinese. Privacy mode masks IPs before you share a screenshot.
iOS docs

And the rest of the toolbox.

  • Alerts & notifications26 rule types. Metric thresholds fire only when 70% of samples in 10 minutes breach, so a single spike won’t page you; maintenance windows mute alerts. Webhook, Telegram, Bark, email and APNs.
  • Public status pageOne /status page with live health, 90-day uptime, network and IP quality. Addresses stay hidden. Off until you enable it.
  • Service monitorsSSL expiry, DNS records, HTTP keywords, TCP ports and WHOIS expiry, checked from the server.
  • Web terminalA real PTY in the browser, up to 3 sessions per server, closed after 10 idle minutes. Off by default.
  • File managerBrowse, upload and download inside allowed root paths, and edit configs in Monaco. Keys and .env files are denied by default.
  • DockerContainers with live stats, log streaming and events; start, stop, restart, remove. Off by default.
  • Security events & firewallDetects SSH brute force, new-source logins and port scans, and can drop the source IP into an nftables blocklist.
  • Traffic & costTraffic cycles that follow your billing day, with overage projection. Cost per core, GB and TB, plus flags for idle or offline boxes you still pay for.
  • Accounts & accessAdmins and read-only members, GitHub, Google and OIDC sign-in, TOTP 2FA and API keys.
  • Upgrades & opsUpgrade agents from the panel one at a time: SHA-256 verified, rolled back on failure. Scheduled commands with cron (needs remote exec).

Two commands and you’re live.

Your servers
serverbee-agent
  • HK · CN2 GIAlinux/amd64
  • TYO · BGPlinux/arm64
  • FRA · Storagelinux/amd64
WebSocketAgents dial out, so no inbound ports on your VPS
One executable
ServerBee server
  • REST API and WebSocket
  • Web UI (built in)
  • SQLite (built in)
BrowserWeb panel and public status page
iOS appLive data and push alerts
NotificationsWebhook · Telegram · Bark · Email · APNs
1

Install the server

Docker or a binary, one command. It prints the panel URL and a one-time admin password. Or deploy on Railway.

curl -fsSL https://raw.githubusercontent.com/ZingerLittleBee/ServerBee/main/deploy/install.sh | sudo sh -s -- server --method docker -y
2

Add a server

Click Add server in the panel and paste the generated command on your VPS. The enrollment code works once, within 10 minutes.

curl -fsSL https://raw.githubusercontent.com/ZingerLittleBee/ServerBee/main/deploy/install.sh | sudo bash -s -- agent --server-url 'https://panel.example.com' --enrollment-code '<enrollment-code>'
  • 3 s1
    metrics interval
  • 13.7 MB2
    agent binary
  • ≈ 27 MB3
    agent memory
  • 3,800+4
    automated tests

Sources

  1. Set by the server; each report is pushed to browsers as it arrives.
  2. v1.0.0-beta.4 linux-amd64 release asset; linux-arm64 is 12.4 MB.
  3. Measured on v0.9.3: 4-core KVM, cgroup memory after 8 hours. Not yet re-measured on 1.0.
  4. Rust and frontend tests combined; see the testing docs.

Questions

Does it cost anything?

No. ServerBee is open source under AGPL-3.0-or-later. You run it on your own machine, and the data stays with you.

Do my servers need open ports?

No. Agents dial out to the server over WebSocket, so monitored hosts need no inbound ports. Put the server behind HTTPS; the installer’s --domain flag sets up Caddy and a certificate.

What does the carrier latency measure?

The agent opens TCP connections from your VPS to probe endpoints for each province and carrier, and records round-trip latency and loss. The endpoints are third-party CDN nodes, so read the numbers as path quality, not any single user’s experience.

Can I share it publicly?

Yes. Turn on the public status page to show health, uptime, network and IP quality without exposing addresses. It’s off by default.

Which systems are supported?

Static Linux binaries for amd64 and arm64, plus Docker images, for both the server and the agent. The installer handles systemd and OpenRC. macOS and Windows builds exist (Windows support is basic); security events and the firewall are Linux-only.

Where do I get the iOS app?

It’s coming to the App Store. Until then, build it from apps/ios in the repository with Xcode and install it on an iPhone running iOS 17 or later.

Put your first VPS on the radar.

One command for the server, one more for each VPS.