sitescope a small health monitor and status page for a few hosts

Health monitor · status page · NixOS

A few hosts, watched closely.

sitescope is one static Go binary that watches a small fleet from the inside and the outside. Agents report what each host knows about itself, a hub probes what the world sees, and you get an email when something changes and a status page for everyone else.

What sitescope does

It is named after HP SiteScope, and has the same idea at a much smaller scale: a few servers, a few zones, a mail relay or two, and one person who needs to know when any of it goes wrong.

Inside

The agent

Runs on every host and serves one JSON report on its WireGuard address: disk, memory, swap, load, failed units, whether a reboot is pending, how old nixpkgs is, WireGuard handshakes, the postfix queue and Knot zone status, plus CPU, pressure, disk and network counters. The same facts are on /metrics for Prometheus.

Outside

The hub

Polls the agents and probes from the outside: DNS serials and delegation, domain expiry over RDAP, certificate lifetimes and ALPN, Certificate Transparency logs, HTTP status and latency, SMTP banners, an open-relay probe, blocklists, Linode billing, Cloudflare record drift and API token expiry.

Out loud

Alerts and status

An email when a check changes state, a daily digest of what isn’t healthy, a dead-man’s-switch heartbeat, a public page of traffic lights, and a detailed view with 30 days of history behind a password.

What it promises

Read only, everywhere. sitescope never changes the infrastructure it watches. Its API tokens are read-only, its probes only ask, and the open-relay probe ends the conversation before any message is sent.

How it fits together

agent host A
agent host B
agent host C

GET /v1/report over WireGuard, bearer token

sitescope hub scheduler · probes · state machine · mailer
status page public lights, detail behind auth
control.sock unlock · lock · status
history.db bbolt, 35 days
vault.age age, scrypt

The hub runs on one host, behind a reverse proxy on 127.0.0.1:8470. Each agent listens on its host’s wg0 address, port 9105. The NixOS module sets up both, with hardened systemd units.

A first look

sitescope check -config config.json            # every check once, no daemon
sitescope check -config config.json -match dns.soa
sitescope unlock                               # on the hub host, after a restart
sitescope status