Unified Access
One landing page for the stack.
Launch the services you use, then jump into the canonical inventory when you need configuration, IPs, ports, or operational notes.
Onboard a host β install our key + monitoring
Run on the new machine. Installs the shared
netmon_access SSH key (so ops/monitoring can connect) + a metrics agent, then registers it so Prometheus watches it automatically β like every other host.Linux
curl -fsSL http://192.168.0.28:8097/api/onboard/linux.sh | sudo bash
Windows (elevated PowerShell)
iwr http://192.168.0.28:8097/api/onboard/windows.ps1 -UseBasicParsing | iex
Enrolled hosts & live targets: /api/onboard/hosts
Terminal
idle
Ask the LLMs
Scheduler
Scripts from
scheduled/ in the netmon repo, run FROM netmon on any enrolled host. Times are netmon's local time (cron: minute hour day month weekday). Failures alert ntfy lab-critical.Run on:
Recent runs
Review
What only you can do, so nothing gets forgotten. Agents add items here; click Done when it is done.
Containers
Every Docker container, grouped by host. Inventory from
docker inspect, metrics from cadvisor via
Prometheus. Read-only. Click a container for charts, labels, mounts and logs.Spark
DGX Spark
spark-b4fb (192.168.0.78): monitoring, models, workloads.
Grafana: Spark LLM Β·
DGX dashboardFiles β hand a file to an application's host
Upload the file here once. The target host pulls it itself with a
single-use bearer token that is bound to that host's IP address and expires, so the
file never needs to be scp'd by hand and a leaked token is useless from anywhere else.
Staged drops
Recent activity
MCP hub
π Run an agent on the hub β ONE command
One-time per machine, then just
lab-claude in any project (instead of claude). It loads all servers, applies the agent prompt + memory contract, and auto-approves β no pasting, no per-restart steps.# one-time per machine (installs to /usr/local/bin, which is on PATH): sudo /usr/bin/curl -fsS http://192.168.0.35:8097/api/mcp/launcher -o /usr/local/bin/lab-claude && sudo chmod +x /usr/local/bin/lab-claude # then, in any project dir, run instead of `claude`: lab-claude
π macOS β use THIS instead (the command above gets killed)
On a locked-down/managed Mac, endpoint-security software SIGKILLs user-space
curl (Killed: 9), so the Linux installer above and its per-launch fetches fail. This version uses no curl at all β it installs via sudo tee and writes the (static) hub config directly. Paste the whole block.# macOS one-time install β no curl anywhere:
sudo tee /usr/local/bin/lab-claude >/dev/null <<'EOF'
#!/usr/bin/env bash
set -euo pipefail
command -v claude >/dev/null || { echo "claude not installed"; exit 1; }
printf '%s\n' '{"mcpServers":{"hub":{"type":"http","url":"http://192.168.0.35:8990/mcp"}}}' > .mcp.json
exec claude --dangerously-skip-permissions "$@"
EOF
sudo chmod +x /usr/local/bin/lab-claude
# then, in any project dir, run instead of `claude`:
lab-claude
Fallback: paste this prompt manually
Only if you're not using
lab-claude (e.g. a non-Claude-Code client). The launcher already injects this.Loadingβ¦
Git Mirrors
Agents
Live from each agent's MCP working-memory (
mcp:agent:<name>:state on the hub redis). Shows who's checkpointing, what they're on, and how fresh.Broadcast β one message to every agent's inbox, your phone (ntfy lab-critical) and every logged-in terminal on enrolled hosts.
LLM Providers
Which models agents can reason with. API keys are stored in the
Netmon secrets vault, are never returned by the API, and are never rendered here.
Agent Definitions
Who the agents are: role, prompt, model, executor, permissions and
which operations need your approval. Configuration only β the Agents tab shows live
sessions, this one defines the roster.
Agent Jobs
Describe a goal; the Manager works out how. Jobs run server-side β
close the browser, come back later, the job carries on.
LLM Cost & Usage
Tokens, provider calls and cost across every agent job. Derived from
the event log, so these totals cannot drift from what each job reports.
Controller
What the agent guardrails blocked (central policy and the hook's local floor), which
rules cost the most, and the levers: approve one call, revoke it, or disable a rule.
LangGraph
The graphs that orchestrate agent work, and every repo that pins LangGraph.
LangChain
Every repo that pins LangChain, where it is deployed, and the tracing story.