Repository files navigation

MaidKit

MaidKit Logo

A cross-platform SSH server manager

LicenseDownload

English · 简体中文


MaidKit is a collection of tools used by LittleSheep when acting as a "maid" for servers (i.e., performing server maintenance). The goal is to provide a more convenient way to maintain servers that is non-intrusive — day-to-day management is 100% SSH-based, installing nothing on the server. The optional MaidCafe Cloud layer adds a small outbound-only daemon for fleet management, alarms, and push notifications — no inbound ports required.

Built with Flutter, MaidKit runs on desktop and mobile platforms alike. Inspired by the Island project's desktop-native approach, it brings the same calm, functional philosophy to server administration.


Table of Contents


Features

Servers

FeatureDescription
DashboardGrid of server cards with live status, latency (network and SSH round-trip), load, memory, and uptime; reorder via context menu, organize into groups, tag, and customize with environment variables; pin runtimes and watched processes for a realtime multi-server overview
ActivityReal-time performance charts (CPU, memory, network, disk), backed by MaidCafe history when the daemon is installed
TerminalFull SSH terminal with split panes, drag-and-drop tabs, command palette, right-click menu, OSC 52 clipboard support, and terminal color schemes
File ManagementDual-pane SFTP browser with drag-and-drop transfers, in-app editor, and keyboard shortcuts (copy/cut/paste, rename, refresh, search, delete)
ProcessesList and kill running processes; pin and watch processes with usage history (realtime via the MaidCafe daemon)
ServicesSystemd unit management (start/stop/enable/disable)
Web Serversnginx and Caddy configuration management
CrontabEdit scheduled tasks
PackagesPackage management (apt, dnf, and more)
FirewallUFW, firewalld, nftables, and iptables management
Port ForwardingLocal and remote tunnel configuration with saved presets that auto-start on connect
ProxyReach hosts through a per-server HTTP CONNECT or SOCKS5 proxy
Jump HostReach a server through another managed server
DatabasesPostgreSQL, MySQL, and MariaDB: engine inspection, logical backups and restores, quick maintenance, and pgBackRest
TailscaleConnect over your tailnet with an embedded node — no Tailscale app required

MaidCafe Cloud

  • Sign in with a Solarpass account and select a workspace
  • One-flow daemon setup: MaidKit probes the server over SSH, installs the MaidCafe daemon, and registers it in the workspace automatically
  • The daemon runs on its own — MaidKit does not need to stay open — and only connects outbound, so no extra ports are opened to the internet
  • Fleet view with per-daemon live metrics (load, swap, disk, network) streamed over SSE in real time
  • Reusable action scripts with template variables, working directory, run-as user, environment, and per-action timeout
  • Native host operations through the daemon: container start/stop/restart/pause/kill/remove, process kill, systemd unit actions, and compose project actions — the container, process, systemd, and deployment views route through the daemon when it is installed (SSH stays the fallback), so these work from anywhere via the cloud relay, not just from a workstation SSH session
  • Scheduled jobs on the daemon: cron or @every intervals targeting actions and native ops, with failure notifications and a full audit trail
  • Container log tracking: the daemon tails running containers to disk and streams the delta over SSE, so logs are inspectable without an SSH session
  • Optional cloud log upload (opt-in because logs may contain sensitive data), persisted in the workspace with retention; daemon-side regex log alerts surface daemon.log_alert notifications with cooldowns
  • Hot reload: the daemon watches its config and fragment files, answers systemctl reload (SIGHUP), and exposes a redacted read + safe-subset patch API (GET/PATCH /api/v1/config) — config saves apply without a service restart
  • Alarm thresholds evaluated locally by the daemon, surfaced as notifications
  • Audit log with invocation provenance and captured output; clear and filter
  • API credentials for CI/CD, scoped to daemons, hosts, and actions; the cloud webhook relay delivers invocations to daemons that poll the cloud
  • Push notifications via Firebase (APNs/FCM) and the in-app Metoer feed

Containers

  • Docker and Podman container management
  • Start, stop, restart, pause, kill, and remove containers
  • Compose project grouping with detail view (per-service status, merged logs, lifecycle actions)
  • Container image management
  • Runtime installation assistance

Projects

  • Deployment project catalog
  • Group compose stacks, web servers, and containers
  • Import and export as TOML

Snippets

  • Create and edit reusable shell scripts
  • Execute on one or more connected servers
  • Streaming output with progress tracking

Agent

  • Chat with an AI agent that can operate your servers through tools
  • Bring your own AI provider or use Solar Network AI
  • MCP servers and reusable skills extend the agent's toolset
  • Auto-discover models from your AI providers
  • Proposed actions require approval (review mode) before they run
  • Conversation history is stored on-device, outside the vault

GitHub

  • Sign in with device-flow authorization
  • Pin repositories and follow workflow runs, pull requests, and releases
  • Access tokens are stored encrypted in the vault
  • GitHub tools are available to the agent

Local MCP Server

  • Expose MaidKit's SSH servers, snippets, and skills to other agents on this machine through a local Model Context Protocol server
  • Connect from Claude Desktop or any MCP client

Security

  • AES-GCM 256-bit encrypted credential vault
  • PBKDF2 key derivation (310,000 iterations)
  • Biometric unlock support
  • Optional per-vault cloud sync over encrypted blobs (Solar Network)
  • Encrypted backup archives (.mkb)
  • GitHub access tokens encrypted in the vault

Settings

  • Theme (system/light/dark), accent color, and workspace background image
  • Language (English / 简体中文)
  • Terminal renderer selection (Ghostty libghostty-vt or xterm), font, and color scheme
  • Connect on startup
  • Hide server addresses when screen sharing or recording
  • Metrics refresh intervals
  • Tailscale sign-in and connection settings
  • MaidCafe cloud endpoint configuration (self-hosted clouds supported)
  • Cloud sync per vault, import and export of server connections
  • Update release channel and check for updates via Solsynth Express

Getting Started

Prerequisites

  • Flutter SDK installed (SDK ^3.12.2)
  • For iOS App Store archives, install Zig 0.15.2 for the vendored Ghostty terminal library. The current Ghostty source is not compatible with Zig 0.16:
    brew install zig@0.15
  • For Windows development, install NASM (required by webcrypto native assets):
    winget install NASM.NASM
  • For Linux development, install additional dependencies:
    sudo apt-get update -y
    sudo apt-get install -y \
    ninja-build \
    libgtk-3-dev \
    libayatana-appindicator3-dev \
    keybinder-3.0 \
    libnotify-dev

Running the App

# Install dependencies
flutter pub get
# Run in debug mode
flutter run
# Build release version
flutter build <platform>

Linux AppImage

Bundle a self-contained AppImage for Linux after building the release bundle:

flutter build linux
bash buildtools/build-appimage.sh

The script packs the x64 release bundle with the desktop entry and run helpers into MaidKit-x86_64.AppImage.

iOS App Store Archive

The bundled Ghostty terminal library is compiled from source for iOS so the binary is linked by Apple's linker and includes the encryption metadata required by App Store Connect. After installing zig@0.15, the build hook selects it automatically when creating an IPA:

flutter clean
flutter pub get
flutter build ipa

The build stops if the generated Ghostty framework lacks LC_ENCRYPTION_INFO_64, preventing an invalid IPA from being produced.

Development

After changing route annotations or Drift schema:

dart run build_runner build

Run checks before committing:

dart format lib test
flutter analyze
flutter test

Architecture

Features are flat and live directly under lib/<feature>/. The app uses:

  • Riverpod for state management with ConsumerWidget for reactive views
  • auto_route for declarative nested navigation
  • Drift for local SQLite persistence
  • dartssh2 for SSH connections
  • island_ui_foundation for the desktop window frame

See docs/architecture.md for the full architecture guide.


Tech Stack

LayerTechnology
FrameworkFlutter with Material 3
StateRiverpod + flutter_hooks
Navigationauto_route
DatabaseDrift (SQLite)
SSHdartssh2
Encryptioncryptography (AES-GCM, PBKDF2)
Terminallibghostty-vt / xterm
Tailscaletailscale (embedded node, macOS/Linux)
Pingdart_ping
FirebaseCloud Messaging push (APNs/FCM), Analytics
Updatessolsynth_express
MCPModel Context Protocol client + local server
Desktopwindow_manager + island_ui_foundation

Contributing

Contributions are welcome! Please feel free to submit issues or pull requests.


Licensing

This project is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0).

If you deploy an instance, fork this project, or redistribute modified versions of this software, you must comply with the AGPL-3.0 license terms, including:

  • Including a copy of the original license
  • Preserving existing copyright notices and attribution
  • Clearly stating any modifications you made
  • Providing corresponding source code to users interacting with the service over a network

Original authorship and copyright attribution to LittleSheep, Solsynth, and this project's contributors must be retained where applicable.

Please note that the AGPL-3.0 license applies to the software source code only. Certain assets, logos, icons, branding materials, and trademarks may be licensed separately and are not automatically covered under the same terms.

See LICENSE.txt for the full license text.


Made by LittleSheep with ❤️

About

The ultimate SSH toolkit for developers

Topics

Resources

Code of conduct

Stars

453 stars

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

MaidKit

MaidKit Logo

A cross-platform SSH server manager

LicenseDownload

English · 简体中文


MaidKit is a collection of tools used by LittleSheep when acting as a "maid" for servers (i.e., performing server maintenance). The goal is to provide a more convenient way to maintain servers that is non-intrusive — day-to-day management is 100% SSH-based, installing nothing on the server. The optional MaidCafe Cloud layer adds a small outbound-only daemon for fleet management, alarms, and push notifications — no inbound ports required.

Built with Flutter, MaidKit runs on desktop and mobile platforms alike. Inspired by the Island project's desktop-native approach, it brings the same calm, functional philosophy to server administration.


Table of Contents


Features

Servers

FeatureDescription
DashboardGrid of server cards with live status, latency (network and SSH round-trip), load, memory, and uptime; reorder via context menu, organize into groups, tag, and customize with environment variables; pin runtimes and watched processes for a realtime multi-server overview
ActivityReal-time performance charts (CPU, memory, network, disk), backed by MaidCafe history when the daemon is installed
TerminalFull SSH terminal with split panes, drag-and-drop tabs, command palette, right-click menu, OSC 52 clipboard support, and terminal color schemes
File ManagementDual-pane SFTP browser with drag-and-drop transfers, in-app editor, and keyboard shortcuts (copy/cut/paste, rename, refresh, search, delete)
ProcessesList and kill running processes; pin and watch processes with usage history (realtime via the MaidCafe daemon)
ServicesSystemd unit management (start/stop/enable/disable)
Web Serversnginx and Caddy configuration management
CrontabEdit scheduled tasks
PackagesPackage management (apt, dnf, and more)
FirewallUFW, firewalld, nftables, and iptables management
Port ForwardingLocal and remote tunnel configuration with saved presets that auto-start on connect
ProxyReach hosts through a per-server HTTP CONNECT or SOCKS5 proxy
Jump HostReach a server through another managed server
DatabasesPostgreSQL, MySQL, and MariaDB: engine inspection, logical backups and restores, quick maintenance, and pgBackRest
TailscaleConnect over your tailnet with an embedded node — no Tailscale app required

MaidCafe Cloud

  • Sign in with a Solarpass account and select a workspace
  • One-flow daemon setup: MaidKit probes the server over SSH, installs the MaidCafe daemon, and registers it in the workspace automatically
  • The daemon runs on its own — MaidKit does not need to stay open — and only connects outbound, so no extra ports are opened to the internet
  • Fleet view with per-daemon live metrics (load, swap, disk, network) streamed over SSE in real time
  • Reusable action scripts with template variables, working directory, run-as user, environment, and per-action timeout
  • Native host operations through the daemon: container start/stop/restart/pause/kill/remove, process kill, systemd unit actions, and compose project actions — the container, process, systemd, and deployment views route through the daemon when it is installed (SSH stays the fallback), so these work from anywhere via the cloud relay, not just from a workstation SSH session
  • Scheduled jobs on the daemon: cron or @every intervals targeting actions and native ops, with failure notifications and a full audit trail
  • Container log tracking: the daemon tails running containers to disk and streams the delta over SSE, so logs are inspectable without an SSH session
  • Optional cloud log upload (opt-in because logs may contain sensitive data), persisted in the workspace with retention; daemon-side regex log alerts surface daemon.log_alert notifications with cooldowns
  • Hot reload: the daemon watches its config and fragment files, answers systemctl reload (SIGHUP), and exposes a redacted read + safe-subset patch API (GET/PATCH /api/v1/config) — config saves apply without a service restart
  • Alarm thresholds evaluated locally by the daemon, surfaced as notifications
  • Audit log with invocation provenance and captured output; clear and filter
  • API credentials for CI/CD, scoped to daemons, hosts, and actions; the cloud webhook relay delivers invocations to daemons that poll the cloud
  • Push notifications via Firebase (APNs/FCM) and the in-app Metoer feed

Containers

  • Docker and Podman container management
  • Start, stop, restart, pause, kill, and remove containers
  • Compose project grouping with detail view (per-service status, merged logs, lifecycle actions)
  • Container image management
  • Runtime installation assistance

Projects

  • Deployment project catalog
  • Group compose stacks, web servers, and containers
  • Import and export as TOML

Snippets

  • Create and edit reusable shell scripts
  • Execute on one or more connected servers
  • Streaming output with progress tracking

Agent

  • Chat with an AI agent that can operate your servers through tools
  • Bring your own AI provider or use Solar Network AI
  • MCP servers and reusable skills extend the agent's toolset
  • Auto-discover models from your AI providers
  • Proposed actions require approval (review mode) before they run
  • Conversation history is stored on-device, outside the vault

GitHub

  • Sign in with device-flow authorization
  • Pin repositories and follow workflow runs, pull requests, and releases
  • Access tokens are stored encrypted in the vault
  • GitHub tools are available to the agent

Local MCP Server

  • Expose MaidKit's SSH servers, snippets, and skills to other agents on this machine through a local Model Context Protocol server
  • Connect from Claude Desktop or any MCP client

Security

  • AES-GCM 256-bit encrypted credential vault
  • PBKDF2 key derivation (310,000 iterations)
  • Biometric unlock support
  • Optional per-vault cloud sync over encrypted blobs (Solar Network)
  • Encrypted backup archives (.mkb)
  • GitHub access tokens encrypted in the vault

Settings

  • Theme (system/light/dark), accent color, and workspace background image
  • Language (English / 简体中文)
  • Terminal renderer selection (Ghostty libghostty-vt or xterm), font, and color scheme
  • Connect on startup
  • Hide server addresses when screen sharing or recording
  • Metrics refresh intervals
  • Tailscale sign-in and connection settings
  • MaidCafe cloud endpoint configuration (self-hosted clouds supported)
  • Cloud sync per vault, import and export of server connections
  • Update release channel and check for updates via Solsynth Express

Getting Started

Prerequisites

  • Flutter SDK installed (SDK ^3.12.2)
  • For iOS App Store archives, install Zig 0.15.2 for the vendored Ghostty terminal library. The current Ghostty source is not compatible with Zig 0.16:
    brew install zig@0.15
  • For Windows development, install NASM (required by webcrypto native assets):
    winget install NASM.NASM
  • For Linux development, install additional dependencies:
    sudo apt-get update -y
    sudo apt-get install -y \
    ninja-build \
    libgtk-3-dev \
    libayatana-appindicator3-dev \
    keybinder-3.0 \
    libnotify-dev

Running the App

# Install dependencies
flutter pub get
# Run in debug mode
flutter run
# Build release version
flutter build <platform>

Linux AppImage

Bundle a self-contained AppImage for Linux after building the release bundle:

flutter build linux
bash buildtools/build-appimage.sh

The script packs the x64 release bundle with the desktop entry and run helpers into MaidKit-x86_64.AppImage.

iOS App Store Archive

The bundled Ghostty terminal library is compiled from source for iOS so the binary is linked by Apple's linker and includes the encryption metadata required by App Store Connect. After installing zig@0.15, the build hook selects it automatically when creating an IPA:

flutter clean
flutter pub get
flutter build ipa

The build stops if the generated Ghostty framework lacks LC_ENCRYPTION_INFO_64, preventing an invalid IPA from being produced.

Development

After changing route annotations or Drift schema:

dart run build_runner build

Run checks before committing:

dart format lib test
flutter analyze
flutter test

Architecture

Features are flat and live directly under lib/<feature>/. The app uses:

  • Riverpod for state management with ConsumerWidget for reactive views
  • auto_route for declarative nested navigation
  • Drift for local SQLite persistence
  • dartssh2 for SSH connections
  • island_ui_foundation for the desktop window frame

See docs/architecture.md for the full architecture guide.


Tech Stack

LayerTechnology
FrameworkFlutter with Material 3
StateRiverpod + flutter_hooks
Navigationauto_route
DatabaseDrift (SQLite)
SSHdartssh2
Encryptioncryptography (AES-GCM, PBKDF2)
Terminallibghostty-vt / xterm
Tailscaletailscale (embedded node, macOS/Linux)
Pingdart_ping
FirebaseCloud Messaging push (APNs/FCM), Analytics
Updatessolsynth_express
MCPModel Context Protocol client + local server
Desktopwindow_manager + island_ui_foundation

Contributing

Contributions are welcome! Please feel free to submit issues or pull requests.


Licensing

This project is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0).

If you deploy an instance, fork this project, or redistribute modified versions of this software, you must comply with the AGPL-3.0 license terms, including:

  • Including a copy of the original license
  • Preserving existing copyright notices and attribution
  • Clearly stating any modifications you made
  • Providing corresponding source code to users interacting with the service over a network

Original authorship and copyright attribution to LittleSheep, Solsynth, and this project's contributors must be retained where applicable.

Please note that the AGPL-3.0 license applies to the software source code only. Certain assets, logos, icons, branding materials, and trademarks may be licensed separately and are not automatically covered under the same terms.

See LICENSE.txt for the full license text.


Made by LittleSheep with ❤️

About

The ultimate SSH toolkit for developers

Topics

Resources

Code of conduct

Stars

453 stars

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

MaidKit

MaidKit Logo

A cross-platform SSH server manager

LicenseDownload

English · 简体中文


MaidKit is a collection of tools used by LittleSheep when acting as a "maid" for servers (i.e., performing server maintenance). The goal is to provide a more convenient way to maintain servers that is non-intrusive — day-to-day management is 100% SSH-based, installing nothing on the server. The optional MaidCafe Cloud layer adds a small outbound-only daemon for fleet management, alarms, and push notifications — no inbound ports required.

Built with Flutter, MaidKit runs on desktop and mobile platforms alike. Inspired by the Island project's desktop-native approach, it brings the same calm, functional philosophy to server administration.


Table of Contents


Features

Servers

FeatureDescription
DashboardGrid of server cards with live status, latency (network and SSH round-trip), load, memory, and uptime; reorder via context menu, organize into groups, tag, and customize with environment variables; pin runtimes and watched processes for a realtime multi-server overview
ActivityReal-time performance charts (CPU, memory, network, disk), backed by MaidCafe history when the daemon is installed
TerminalFull SSH terminal with split panes, drag-and-drop tabs, command palette, right-click menu, OSC 52 clipboard support, and terminal color schemes
File ManagementDual-pane SFTP browser with drag-and-drop transfers, in-app editor, and keyboard shortcuts (copy/cut/paste, rename, refresh, search, delete)
ProcessesList and kill running processes; pin and watch processes with usage history (realtime via the MaidCafe daemon)
ServicesSystemd unit management (start/stop/enable/disable)
Web Serversnginx and Caddy configuration management
CrontabEdit scheduled tasks
PackagesPackage management (apt, dnf, and more)
FirewallUFW, firewalld, nftables, and iptables management
Port ForwardingLocal and remote tunnel configuration with saved presets that auto-start on connect
ProxyReach hosts through a per-server HTTP CONNECT or SOCKS5 proxy
Jump HostReach a server through another managed server
DatabasesPostgreSQL, MySQL, and MariaDB: engine inspection, logical backups and restores, quick maintenance, and pgBackRest
TailscaleConnect over your tailnet with an embedded node — no Tailscale app required

MaidCafe Cloud

  • Sign in with a Solarpass account and select a workspace
  • One-flow daemon setup: MaidKit probes the server over SSH, installs the MaidCafe daemon, and registers it in the workspace automatically
  • The daemon runs on its own — MaidKit does not need to stay open — and only connects outbound, so no extra ports are opened to the internet
  • Fleet view with per-daemon live metrics (load, swap, disk, network) streamed over SSE in real time
  • Reusable action scripts with template variables, working directory, run-as user, environment, and per-action timeout
  • Native host operations through the daemon: container start/stop/restart/pause/kill/remove, process kill, systemd unit actions, and compose project actions — the container, process, systemd, and deployment views route through the daemon when it is installed (SSH stays the fallback), so these work from anywhere via the cloud relay, not just from a workstation SSH session
  • Scheduled jobs on the daemon: cron or @every intervals targeting actions and native ops, with failure notifications and a full audit trail
  • Container log tracking: the daemon tails running containers to disk and streams the delta over SSE, so logs are inspectable without an SSH session
  • Optional cloud log upload (opt-in because logs may contain sensitive data), persisted in the workspace with retention; daemon-side regex log alerts surface daemon.log_alert notifications with cooldowns
  • Hot reload: the daemon watches its config and fragment files, answers systemctl reload (SIGHUP), and exposes a redacted read + safe-subset patch API (GET/PATCH /api/v1/config) — config saves apply without a service restart
  • Alarm thresholds evaluated locally by the daemon, surfaced as notifications
  • Audit log with invocation provenance and captured output; clear and filter
  • API credentials for CI/CD, scoped to daemons, hosts, and actions; the cloud webhook relay delivers invocations to daemons that poll the cloud
  • Push notifications via Firebase (APNs/FCM) and the in-app Metoer feed

Containers

  • Docker and Podman container management
  • Start, stop, restart, pause, kill, and remove containers
  • Compose project grouping with detail view (per-service status, merged logs, lifecycle actions)
  • Container image management
  • Runtime installation assistance

Projects

  • Deployment project catalog
  • Group compose stacks, web servers, and containers
  • Import and export as TOML

Snippets

  • Create and edit reusable shell scripts
  • Execute on one or more connected servers
  • Streaming output with progress tracking

Agent

  • Chat with an AI agent that can operate your servers through tools
  • Bring your own AI provider or use Solar Network AI
  • MCP servers and reusable skills extend the agent's toolset
  • Auto-discover models from your AI providers
  • Proposed actions require approval (review mode) before they run
  • Conversation history is stored on-device, outside the vault

GitHub

  • Sign in with device-flow authorization
  • Pin repositories and follow workflow runs, pull requests, and releases
  • Access tokens are stored encrypted in the vault
  • GitHub tools are available to the agent

Local MCP Server

  • Expose MaidKit's SSH servers, snippets, and skills to other agents on this machine through a local Model Context Protocol server
  • Connect from Claude Desktop or any MCP client

Security

  • AES-GCM 256-bit encrypted credential vault
  • PBKDF2 key derivation (310,000 iterations)
  • Biometric unlock support
  • Optional per-vault cloud sync over encrypted blobs (Solar Network)
  • Encrypted backup archives (.mkb)
  • GitHub access tokens encrypted in the vault

Settings

  • Theme (system/light/dark), accent color, and workspace background image
  • Language (English / 简体中文)
  • Terminal renderer selection (Ghostty libghostty-vt or xterm), font, and color scheme
  • Connect on startup
  • Hide server addresses when screen sharing or recording
  • Metrics refresh intervals
  • Tailscale sign-in and connection settings
  • MaidCafe cloud endpoint configuration (self-hosted clouds supported)
  • Cloud sync per vault, import and export of server connections
  • Update release channel and check for updates via Solsynth Express

Getting Started

Prerequisites

  • Flutter SDK installed (SDK ^3.12.2)
  • For iOS App Store archives, install Zig 0.15.2 for the vendored Ghostty terminal library. The current Ghostty source is not compatible with Zig 0.16:
    brew install zig@0.15
  • For Windows development, install NASM (required by webcrypto native assets):
    winget install NASM.NASM
  • For Linux development, install additional dependencies:
    sudo apt-get update -y
    sudo apt-get install -y \
    ninja-build \
    libgtk-3-dev \
    libayatana-appindicator3-dev \
    keybinder-3.0 \
    libnotify-dev

Running the App

# Install dependencies
flutter pub get
# Run in debug mode
flutter run
# Build release version
flutter build <platform>

Linux AppImage

Bundle a self-contained AppImage for Linux after building the release bundle:

flutter build linux
bash buildtools/build-appimage.sh

The script packs the x64 release bundle with the desktop entry and run helpers into MaidKit-x86_64.AppImage.

iOS App Store Archive

The bundled Ghostty terminal library is compiled from source for iOS so the binary is linked by Apple's linker and includes the encryption metadata required by App Store Connect. After installing zig@0.15, the build hook selects it automatically when creating an IPA:

flutter clean
flutter pub get
flutter build ipa

The build stops if the generated Ghostty framework lacks LC_ENCRYPTION_INFO_64, preventing an invalid IPA from being produced.

Development

After changing route annotations or Drift schema:

dart run build_runner build

Run checks before committing:

dart format lib test
flutter analyze
flutter test

Architecture

Features are flat and live directly under lib/<feature>/. The app uses:

  • Riverpod for state management with ConsumerWidget for reactive views
  • auto_route for declarative nested navigation
  • Drift for local SQLite persistence
  • dartssh2 for SSH connections
  • island_ui_foundation for the desktop window frame

See docs/architecture.md for the full architecture guide.


Tech Stack

LayerTechnology
FrameworkFlutter with Material 3
StateRiverpod + flutter_hooks
Navigationauto_route
DatabaseDrift (SQLite)
SSHdartssh2
Encryptioncryptography (AES-GCM, PBKDF2)
Terminallibghostty-vt / xterm
Tailscaletailscale (embedded node, macOS/Linux)
Pingdart_ping
FirebaseCloud Messaging push (APNs/FCM), Analytics
Updatessolsynth_express
MCPModel Context Protocol client + local server
Desktopwindow_manager + island_ui_foundation

Contributing

Contributions are welcome! Please feel free to submit issues or pull requests.


Licensing

This project is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0).

If you deploy an instance, fork this project, or redistribute modified versions of this software, you must comply with the AGPL-3.0 license terms, including:

  • Including a copy of the original license
  • Preserving existing copyright notices and attribution
  • Clearly stating any modifications you made
  • Providing corresponding source code to users interacting with the service over a network

Original authorship and copyright attribution to LittleSheep, Solsynth, and this project's contributors must be retained where applicable.

Please note that the AGPL-3.0 license applies to the software source code only. Certain assets, logos, icons, branding materials, and trademarks may be licensed separately and are not automatically covered under the same terms.

See LICENSE.txt for the full license text.


Made by LittleSheep with ❤️

About

The ultimate SSH toolkit for developers

Topics

Resources

Code of conduct

Stars

453 stars

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

MaidKit

MaidKit Logo

A cross-platform SSH server manager

LicenseDownload

English · 简体中文


MaidKit is a collection of tools used by LittleSheep when acting as a "maid" for servers (i.e., performing server maintenance). The goal is to provide a more convenient way to maintain servers that is non-intrusive — day-to-day management is 100% SSH-based, installing nothing on the server. The optional MaidCafe Cloud layer adds a small outbound-only daemon for fleet management, alarms, and push notifications — no inbound ports required.

Built with Flutter, MaidKit runs on desktop and mobile platforms alike. Inspired by the Island project's desktop-native approach, it brings the same calm, functional philosophy to server administration.


Table of Contents


Features

Servers

FeatureDescription
DashboardGrid of server cards with live status, latency (network and SSH round-trip), load, memory, and uptime; reorder via context menu, organize into groups, tag, and customize with environment variables; pin runtimes and watched processes for a realtime multi-server overview
ActivityReal-time performance charts (CPU, memory, network, disk), backed by MaidCafe history when the daemon is installed
TerminalFull SSH terminal with split panes, drag-and-drop tabs, command palette, right-click menu, OSC 52 clipboard support, and terminal color schemes
File ManagementDual-pane SFTP browser with drag-and-drop transfers, in-app editor, and keyboard shortcuts (copy/cut/paste, rename, refresh, search, delete)
ProcessesList and kill running processes; pin and watch processes with usage history (realtime via the MaidCafe daemon)
ServicesSystemd unit management (start/stop/enable/disable)
Web Serversnginx and Caddy configuration management
CrontabEdit scheduled tasks
PackagesPackage management (apt, dnf, and more)
FirewallUFW, firewalld, nftables, and iptables management
Port ForwardingLocal and remote tunnel configuration with saved presets that auto-start on connect
ProxyReach hosts through a per-server HTTP CONNECT or SOCKS5 proxy
Jump HostReach a server through another managed server
DatabasesPostgreSQL, MySQL, and MariaDB: engine inspection, logical backups and restores, quick maintenance, and pgBackRest
TailscaleConnect over your tailnet with an embedded node — no Tailscale app required

MaidCafe Cloud

  • Sign in with a Solarpass account and select a workspace
  • One-flow daemon setup: MaidKit probes the server over SSH, installs the MaidCafe daemon, and registers it in the workspace automatically
  • The daemon runs on its own — MaidKit does not need to stay open — and only connects outbound, so no extra ports are opened to the internet
  • Fleet view with per-daemon live metrics (load, swap, disk, network) streamed over SSE in real time
  • Reusable action scripts with template variables, working directory, run-as user, environment, and per-action timeout
  • Native host operations through the daemon: container start/stop/restart/pause/kill/remove, process kill, systemd unit actions, and compose project actions — the container, process, systemd, and deployment views route through the daemon when it is installed (SSH stays the fallback), so these work from anywhere via the cloud relay, not just from a workstation SSH session
  • Scheduled jobs on the daemon: cron or @every intervals targeting actions and native ops, with failure notifications and a full audit trail
  • Container log tracking: the daemon tails running containers to disk and streams the delta over SSE, so logs are inspectable without an SSH session
  • Optional cloud log upload (opt-in because logs may contain sensitive data), persisted in the workspace with retention; daemon-side regex log alerts surface daemon.log_alert notifications with cooldowns
  • Hot reload: the daemon watches its config and fragment files, answers systemctl reload (SIGHUP), and exposes a redacted read + safe-subset patch API (GET/PATCH /api/v1/config) — config saves apply without a service restart
  • Alarm thresholds evaluated locally by the daemon, surfaced as notifications
  • Audit log with invocation provenance and captured output; clear and filter
  • API credentials for CI/CD, scoped to daemons, hosts, and actions; the cloud webhook relay delivers invocations to daemons that poll the cloud
  • Push notifications via Firebase (APNs/FCM) and the in-app Metoer feed

Containers

  • Docker and Podman container management
  • Start, stop, restart, pause, kill, and remove containers
  • Compose project grouping with detail view (per-service status, merged logs, lifecycle actions)
  • Container image management
  • Runtime installation assistance

Projects

  • Deployment project catalog
  • Group compose stacks, web servers, and containers
  • Import and export as TOML

Snippets

  • Create and edit reusable shell scripts
  • Execute on one or more connected servers
  • Streaming output with progress tracking

Agent

  • Chat with an AI agent that can operate your servers through tools
  • Bring your own AI provider or use Solar Network AI
  • MCP servers and reusable skills extend the agent's toolset
  • Auto-discover models from your AI providers
  • Proposed actions require approval (review mode) before they run
  • Conversation history is stored on-device, outside the vault

GitHub

  • Sign in with device-flow authorization
  • Pin repositories and follow workflow runs, pull requests, and releases
  • Access tokens are stored encrypted in the vault
  • GitHub tools are available to the agent

Local MCP Server

  • Expose MaidKit's SSH servers, snippets, and skills to other agents on this machine through a local Model Context Protocol server
  • Connect from Claude Desktop or any MCP client

Security

  • AES-GCM 256-bit encrypted credential vault
  • PBKDF2 key derivation (310,000 iterations)
  • Biometric unlock support
  • Optional per-vault cloud sync over encrypted blobs (Solar Network)
  • Encrypted backup archives (.mkb)
  • GitHub access tokens encrypted in the vault

Settings

  • Theme (system/light/dark), accent color, and workspace background image
  • Language (English / 简体中文)
  • Terminal renderer selection (Ghostty libghostty-vt or xterm), font, and color scheme
  • Connect on startup
  • Hide server addresses when screen sharing or recording
  • Metrics refresh intervals
  • Tailscale sign-in and connection settings
  • MaidCafe cloud endpoint configuration (self-hosted clouds supported)
  • Cloud sync per vault, import and export of server connections
  • Update release channel and check for updates via Solsynth Express

Getting Started

Prerequisites

  • Flutter SDK installed (SDK ^3.12.2)
  • For iOS App Store archives, install Zig 0.15.2 for the vendored Ghostty terminal library. The current Ghostty source is not compatible with Zig 0.16:
    brew install zig@0.15
  • For Windows development, install NASM (required by webcrypto native assets):
    winget install NASM.NASM
  • For Linux development, install additional dependencies:
    sudo apt-get update -y
    sudo apt-get install -y \
    ninja-build \
    libgtk-3-dev \
    libayatana-appindicator3-dev \
    keybinder-3.0 \
    libnotify-dev

Running the App

# Install dependencies
flutter pub get
# Run in debug mode
flutter run
# Build release version
flutter build <platform>

Linux AppImage

Bundle a self-contained AppImage for Linux after building the release bundle:

flutter build linux
bash buildtools/build-appimage.sh

The script packs the x64 release bundle with the desktop entry and run helpers into MaidKit-x86_64.AppImage.

iOS App Store Archive

The bundled Ghostty terminal library is compiled from source for iOS so the binary is linked by Apple's linker and includes the encryption metadata required by App Store Connect. After installing zig@0.15, the build hook selects it automatically when creating an IPA:

flutter clean
flutter pub get
flutter build ipa

The build stops if the generated Ghostty framework lacks LC_ENCRYPTION_INFO_64, preventing an invalid IPA from being produced.

Development

After changing route annotations or Drift schema:

dart run build_runner build

Run checks before committing:

dart format lib test
flutter analyze
flutter test

Architecture

Features are flat and live directly under lib/<feature>/. The app uses:

  • Riverpod for state management with ConsumerWidget for reactive views
  • auto_route for declarative nested navigation
  • Drift for local SQLite persistence
  • dartssh2 for SSH connections
  • island_ui_foundation for the desktop window frame

See docs/architecture.md for the full architecture guide.


Tech Stack

LayerTechnology
FrameworkFlutter with Material 3
StateRiverpod + flutter_hooks
Navigationauto_route
DatabaseDrift (SQLite)
SSHdartssh2
Encryptioncryptography (AES-GCM, PBKDF2)
Terminallibghostty-vt / xterm
Tailscaletailscale (embedded node, macOS/Linux)
Pingdart_ping
FirebaseCloud Messaging push (APNs/FCM), Analytics
Updatessolsynth_express
MCPModel Context Protocol client + local server
Desktopwindow_manager + island_ui_foundation

Contributing

Contributions are welcome! Please feel free to submit issues or pull requests.


Licensing

This project is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0).

If you deploy an instance, fork this project, or redistribute modified versions of this software, you must comply with the AGPL-3.0 license terms, including:

  • Including a copy of the original license
  • Preserving existing copyright notices and attribution
  • Clearly stating any modifications you made
  • Providing corresponding source code to users interacting with the service over a network

Original authorship and copyright attribution to LittleSheep, Solsynth, and this project's contributors must be retained where applicable.

Please note that the AGPL-3.0 license applies to the software source code only. Certain assets, logos, icons, branding materials, and trademarks may be licensed separately and are not automatically covered under the same terms.

See LICENSE.txt for the full license text.


Made by LittleSheep with ❤️

About

The ultimate SSH toolkit for developers

Topics

Resources

Code of conduct

Stars

453 stars

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

MaidKit

MaidKit Logo

A cross-platform SSH server manager

LicenseDownload

English · 简体中文


MaidKit is a collection of tools used by LittleSheep when acting as a "maid" for servers (i.e., performing server maintenance). The goal is to provide a more convenient way to maintain servers that is non-intrusive — day-to-day management is 100% SSH-based, installing nothing on the server. The optional MaidCafe Cloud layer adds a small outbound-only daemon for fleet management, alarms, and push notifications — no inbound ports required.

Built with Flutter, MaidKit runs on desktop and mobile platforms alike. Inspired by the Island project's desktop-native approach, it brings the same calm, functional philosophy to server administration.


Table of Contents


Features

Servers

FeatureDescription
DashboardGrid of server cards with live status, latency (network and SSH round-trip), load, memory, and uptime; reorder via context menu, organize into groups, tag, and customize with environment variables; pin runtimes and watched processes for a realtime multi-server overview
ActivityReal-time performance charts (CPU, memory, network, disk), backed by MaidCafe history when the daemon is installed
TerminalFull SSH terminal with split panes, drag-and-drop tabs, command palette, right-click menu, OSC 52 clipboard support, and terminal color schemes
File ManagementDual-pane SFTP browser with drag-and-drop transfers, in-app editor, and keyboard shortcuts (copy/cut/paste, rename, refresh, search, delete)
ProcessesList and kill running processes; pin and watch processes with usage history (realtime via the MaidCafe daemon)
ServicesSystemd unit management (start/stop/enable/disable)
Web Serversnginx and Caddy configuration management
CrontabEdit scheduled tasks
PackagesPackage management (apt, dnf, and more)
FirewallUFW, firewalld, nftables, and iptables management
Port ForwardingLocal and remote tunnel configuration with saved presets that auto-start on connect
ProxyReach hosts through a per-server HTTP CONNECT or SOCKS5 proxy
Jump HostReach a server through another managed server
DatabasesPostgreSQL, MySQL, and MariaDB: engine inspection, logical backups and restores, quick maintenance, and pgBackRest
TailscaleConnect over your tailnet with an embedded node — no Tailscale app required

MaidCafe Cloud

  • Sign in with a Solarpass account and select a workspace
  • One-flow daemon setup: MaidKit probes the server over SSH, installs the MaidCafe daemon, and registers it in the workspace automatically
  • The daemon runs on its own — MaidKit does not need to stay open — and only connects outbound, so no extra ports are opened to the internet
  • Fleet view with per-daemon live metrics (load, swap, disk, network) streamed over SSE in real time
  • Reusable action scripts with template variables, working directory, run-as user, environment, and per-action timeout
  • Native host operations through the daemon: container start/stop/restart/pause/kill/remove, process kill, systemd unit actions, and compose project actions — the container, process, systemd, and deployment views route through the daemon when it is installed (SSH stays the fallback), so these work from anywhere via the cloud relay, not just from a workstation SSH session
  • Scheduled jobs on the daemon: cron or @every intervals targeting actions and native ops, with failure notifications and a full audit trail
  • Container log tracking: the daemon tails running containers to disk and streams the delta over SSE, so logs are inspectable without an SSH session
  • Optional cloud log upload (opt-in because logs may contain sensitive data), persisted in the workspace with retention; daemon-side regex log alerts surface daemon.log_alert notifications with cooldowns
  • Hot reload: the daemon watches its config and fragment files, answers systemctl reload (SIGHUP), and exposes a redacted read + safe-subset patch API (GET/PATCH /api/v1/config) — config saves apply without a service restart
  • Alarm thresholds evaluated locally by the daemon, surfaced as notifications
  • Audit log with invocation provenance and captured output; clear and filter
  • API credentials for CI/CD, scoped to daemons, hosts, and actions; the cloud webhook relay delivers invocations to daemons that poll the cloud
  • Push notifications via Firebase (APNs/FCM) and the in-app Metoer feed

Containers

  • Docker and Podman container management
  • Start, stop, restart, pause, kill, and remove containers
  • Compose project grouping with detail view (per-service status, merged logs, lifecycle actions)
  • Container image management
  • Runtime installation assistance

Projects

  • Deployment project catalog
  • Group compose stacks, web servers, and containers
  • Import and export as TOML

Snippets

  • Create and edit reusable shell scripts
  • Execute on one or more connected servers
  • Streaming output with progress tracking

Agent

  • Chat with an AI agent that can operate your servers through tools
  • Bring your own AI provider or use Solar Network AI
  • MCP servers and reusable skills extend the agent's toolset
  • Auto-discover models from your AI providers
  • Proposed actions require approval (review mode) before they run
  • Conversation history is stored on-device, outside the vault

GitHub

  • Sign in with device-flow authorization
  • Pin repositories and follow workflow runs, pull requests, and releases
  • Access tokens are stored encrypted in the vault
  • GitHub tools are available to the agent

Local MCP Server

  • Expose MaidKit's SSH servers, snippets, and skills to other agents on this machine through a local Model Context Protocol server
  • Connect from Claude Desktop or any MCP client

Security

  • AES-GCM 256-bit encrypted credential vault
  • PBKDF2 key derivation (310,000 iterations)
  • Biometric unlock support
  • Optional per-vault cloud sync over encrypted blobs (Solar Network)
  • Encrypted backup archives (.mkb)
  • GitHub access tokens encrypted in the vault

Settings

  • Theme (system/light/dark), accent color, and workspace background image
  • Language (English / 简体中文)
  • Terminal renderer selection (Ghostty libghostty-vt or xterm), font, and color scheme
  • Connect on startup
  • Hide server addresses when screen sharing or recording
  • Metrics refresh intervals
  • Tailscale sign-in and connection settings
  • MaidCafe cloud endpoint configuration (self-hosted clouds supported)
  • Cloud sync per vault, import and export of server connections
  • Update release channel and check for updates via Solsynth Express

Getting Started

Prerequisites

  • Flutter SDK installed (SDK ^3.12.2)
  • For iOS App Store archives, install Zig 0.15.2 for the vendored Ghostty terminal library. The current Ghostty source is not compatible with Zig 0.16:
    brew install zig@0.15
  • For Windows development, install NASM (required by webcrypto native assets):
    winget install NASM.NASM
  • For Linux development, install additional dependencies:
    sudo apt-get update -y
    sudo apt-get install -y \
    ninja-build \
    libgtk-3-dev \
    libayatana-appindicator3-dev \
    keybinder-3.0 \
    libnotify-dev

Running the App

# Install dependencies
flutter pub get
# Run in debug mode
flutter run
# Build release version
flutter build <platform>

Linux AppImage

Bundle a self-contained AppImage for Linux after building the release bundle:

flutter build linux
bash buildtools/build-appimage.sh

The script packs the x64 release bundle with the desktop entry and run helpers into MaidKit-x86_64.AppImage.

iOS App Store Archive

The bundled Ghostty terminal library is compiled from source for iOS so the binary is linked by Apple's linker and includes the encryption metadata required by App Store Connect. After installing zig@0.15, the build hook selects it automatically when creating an IPA:

flutter clean
flutter pub get
flutter build ipa

The build stops if the generated Ghostty framework lacks LC_ENCRYPTION_INFO_64, preventing an invalid IPA from being produced.

Development

After changing route annotations or Drift schema:

dart run build_runner build

Run checks before committing:

dart format lib test
flutter analyze
flutter test

Architecture

Features are flat and live directly under lib/<feature>/. The app uses:

  • Riverpod for state management with ConsumerWidget for reactive views
  • auto_route for declarative nested navigation
  • Drift for local SQLite persistence
  • dartssh2 for SSH connections
  • island_ui_foundation for the desktop window frame

See docs/architecture.md for the full architecture guide.


Tech Stack

LayerTechnology
FrameworkFlutter with Material 3
StateRiverpod + flutter_hooks
Navigationauto_route
DatabaseDrift (SQLite)
SSHdartssh2
Encryptioncryptography (AES-GCM, PBKDF2)
Terminallibghostty-vt / xterm
Tailscaletailscale (embedded node, macOS/Linux)
Pingdart_ping
FirebaseCloud Messaging push (APNs/FCM), Analytics
Updatessolsynth_express
MCPModel Context Protocol client + local server
Desktopwindow_manager + island_ui_foundation

Contributing

Contributions are welcome! Please feel free to submit issues or pull requests.


Licensing

This project is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0).

If you deploy an instance, fork this project, or redistribute modified versions of this software, you must comply with the AGPL-3.0 license terms, including:

  • Including a copy of the original license
  • Preserving existing copyright notices and attribution
  • Clearly stating any modifications you made
  • Providing corresponding source code to users interacting with the service over a network

Original authorship and copyright attribution to LittleSheep, Solsynth, and this project's contributors must be retained where applicable.

Please note that the AGPL-3.0 license applies to the software source code only. Certain assets, logos, icons, branding materials, and trademarks may be licensed separately and are not automatically covered under the same terms.

See LICENSE.txt for the full license text.


Made by LittleSheep with ❤️

About

The ultimate SSH toolkit for developers

Topics

Resources

Code of conduct

Stars

453 stars

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

MaidKit

MaidKit Logo

A cross-platform SSH server manager

LicenseDownload

English · 简体中文


MaidKit is a collection of tools used by LittleSheep when acting as a "maid" for servers (i.e., performing server maintenance). The goal is to provide a more convenient way to maintain servers that is non-intrusive — day-to-day management is 100% SSH-based, installing nothing on the server. The optional MaidCafe Cloud layer adds a small outbound-only daemon for fleet management, alarms, and push notifications — no inbound ports required.

Built with Flutter, MaidKit runs on desktop and mobile platforms alike. Inspired by the Island project's desktop-native approach, it brings the same calm, functional philosophy to server administration.


Table of Contents


Features

Servers

FeatureDescription
DashboardGrid of server cards with live status, latency (network and SSH round-trip), load, memory, and uptime; reorder via context menu, organize into groups, tag, and customize with environment variables; pin runtimes and watched processes for a realtime multi-server overview
ActivityReal-time performance charts (CPU, memory, network, disk), backed by MaidCafe history when the daemon is installed
TerminalFull SSH terminal with split panes, drag-and-drop tabs, command palette, right-click menu, OSC 52 clipboard support, and terminal color schemes
File ManagementDual-pane SFTP browser with drag-and-drop transfers, in-app editor, and keyboard shortcuts (copy/cut/paste, rename, refresh, search, delete)
ProcessesList and kill running processes; pin and watch processes with usage history (realtime via the MaidCafe daemon)
ServicesSystemd unit management (start/stop/enable/disable)
Web Serversnginx and Caddy configuration management
CrontabEdit scheduled tasks
PackagesPackage management (apt, dnf, and more)
FirewallUFW, firewalld, nftables, and iptables management
Port ForwardingLocal and remote tunnel configuration with saved presets that auto-start on connect
ProxyReach hosts through a per-server HTTP CONNECT or SOCKS5 proxy
Jump HostReach a server through another managed server
DatabasesPostgreSQL, MySQL, and MariaDB: engine inspection, logical backups and restores, quick maintenance, and pgBackRest
TailscaleConnect over your tailnet with an embedded node — no Tailscale app required

MaidCafe Cloud

  • Sign in with a Solarpass account and select a workspace
  • One-flow daemon setup: MaidKit probes the server over SSH, installs the MaidCafe daemon, and registers it in the workspace automatically
  • The daemon runs on its own — MaidKit does not need to stay open — and only connects outbound, so no extra ports are opened to the internet
  • Fleet view with per-daemon live metrics (load, swap, disk, network) streamed over SSE in real time
  • Reusable action scripts with template variables, working directory, run-as user, environment, and per-action timeout
  • Native host operations through the daemon: container start/stop/restart/pause/kill/remove, process kill, systemd unit actions, and compose project actions — the container, process, systemd, and deployment views route through the daemon when it is installed (SSH stays the fallback), so these work from anywhere via the cloud relay, not just from a workstation SSH session
  • Scheduled jobs on the daemon: cron or @every intervals targeting actions and native ops, with failure notifications and a full audit trail
  • Container log tracking: the daemon tails running containers to disk and streams the delta over SSE, so logs are inspectable without an SSH session
  • Optional cloud log upload (opt-in because logs may contain sensitive data), persisted in the workspace with retention; daemon-side regex log alerts surface daemon.log_alert notifications with cooldowns
  • Hot reload: the daemon watches its config and fragment files, answers systemctl reload (SIGHUP), and exposes a redacted read + safe-subset patch API (GET/PATCH /api/v1/config) — config saves apply without a service restart
  • Alarm thresholds evaluated locally by the daemon, surfaced as notifications
  • Audit log with invocation provenance and captured output; clear and filter
  • API credentials for CI/CD, scoped to daemons, hosts, and actions; the cloud webhook relay delivers invocations to daemons that poll the cloud
  • Push notifications via Firebase (APNs/FCM) and the in-app Metoer feed

Containers

  • Docker and Podman container management
  • Start, stop, restart, pause, kill, and remove containers
  • Compose project grouping with detail view (per-service status, merged logs, lifecycle actions)
  • Container image management
  • Runtime installation assistance

Projects

  • Deployment project catalog
  • Group compose stacks, web servers, and containers
  • Import and export as TOML

Snippets

  • Create and edit reusable shell scripts
  • Execute on one or more connected servers
  • Streaming output with progress tracking

Agent

  • Chat with an AI agent that can operate your servers through tools
  • Bring your own AI provider or use Solar Network AI
  • MCP servers and reusable skills extend the agent's toolset
  • Auto-discover models from your AI providers
  • Proposed actions require approval (review mode) before they run
  • Conversation history is stored on-device, outside the vault

GitHub

  • Sign in with device-flow authorization
  • Pin repositories and follow workflow runs, pull requests, and releases
  • Access tokens are stored encrypted in the vault
  • GitHub tools are available to the agent

Local MCP Server

  • Expose MaidKit's SSH servers, snippets, and skills to other agents on this machine through a local Model Context Protocol server
  • Connect from Claude Desktop or any MCP client

Security

  • AES-GCM 256-bit encrypted credential vault
  • PBKDF2 key derivation (310,000 iterations)
  • Biometric unlock support
  • Optional per-vault cloud sync over encrypted blobs (Solar Network)
  • Encrypted backup archives (.mkb)
  • GitHub access tokens encrypted in the vault

Settings

  • Theme (system/light/dark), accent color, and workspace background image
  • Language (English / 简体中文)
  • Terminal renderer selection (Ghostty libghostty-vt or xterm), font, and color scheme
  • Connect on startup
  • Hide server addresses when screen sharing or recording
  • Metrics refresh intervals
  • Tailscale sign-in and connection settings
  • MaidCafe cloud endpoint configuration (self-hosted clouds supported)
  • Cloud sync per vault, import and export of server connections
  • Update release channel and check for updates via Solsynth Express

Getting Started

Prerequisites

  • Flutter SDK installed (SDK ^3.12.2)
  • For iOS App Store archives, install Zig 0.15.2 for the vendored Ghostty terminal library. The current Ghostty source is not compatible with Zig 0.16:
    brew install zig@0.15
  • For Windows development, install NASM (required by webcrypto native assets):
    winget install NASM.NASM
  • For Linux development, install additional dependencies:
    sudo apt-get update -y
    sudo apt-get install -y \
    ninja-build \
    libgtk-3-dev \
    libayatana-appindicator3-dev \
    keybinder-3.0 \
    libnotify-dev

Running the App

# Install dependencies
flutter pub get
# Run in debug mode
flutter run
# Build release version
flutter build <platform>

Linux AppImage

Bundle a self-contained AppImage for Linux after building the release bundle:

flutter build linux
bash buildtools/build-appimage.sh

The script packs the x64 release bundle with the desktop entry and run helpers into MaidKit-x86_64.AppImage.

iOS App Store Archive

The bundled Ghostty terminal library is compiled from source for iOS so the binary is linked by Apple's linker and includes the encryption metadata required by App Store Connect. After installing zig@0.15, the build hook selects it automatically when creating an IPA:

flutter clean
flutter pub get
flutter build ipa

The build stops if the generated Ghostty framework lacks LC_ENCRYPTION_INFO_64, preventing an invalid IPA from being produced.

Development

After changing route annotations or Drift schema:

dart run build_runner build

Run checks before committing:

dart format lib test
flutter analyze
flutter test

Architecture

Features are flat and live directly under lib/<feature>/. The app uses:

  • Riverpod for state management with ConsumerWidget for reactive views
  • auto_route for declarative nested navigation
  • Drift for local SQLite persistence
  • dartssh2 for SSH connections
  • island_ui_foundation for the desktop window frame

See docs/architecture.md for the full architecture guide.


Tech Stack

LayerTechnology
FrameworkFlutter with Material 3
StateRiverpod + flutter_hooks
Navigationauto_route
DatabaseDrift (SQLite)
SSHdartssh2
Encryptioncryptography (AES-GCM, PBKDF2)
Terminallibghostty-vt / xterm
Tailscaletailscale (embedded node, macOS/Linux)
Pingdart_ping
FirebaseCloud Messaging push (APNs/FCM), Analytics
Updatessolsynth_express
MCPModel Context Protocol client + local server
Desktopwindow_manager + island_ui_foundation

Contributing

Contributions are welcome! Please feel free to submit issues or pull requests.


Licensing

This project is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0).

If you deploy an instance, fork this project, or redistribute modified versions of this software, you must comply with the AGPL-3.0 license terms, including:

  • Including a copy of the original license
  • Preserving existing copyright notices and attribution
  • Clearly stating any modifications you made
  • Providing corresponding source code to users interacting with the service over a network

Original authorship and copyright attribution to LittleSheep, Solsynth, and this project's contributors must be retained where applicable.

Please note that the AGPL-3.0 license applies to the software source code only. Certain assets, logos, icons, branding materials, and trademarks may be licensed separately and are not automatically covered under the same terms.

See LICENSE.txt for the full license text.


Made by LittleSheep with ❤️

About

The ultimate SSH toolkit for developers

Topics

Resources

Code of conduct

Stars

453 stars

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

MaidKit

MaidKit Logo

A cross-platform SSH server manager

LicenseDownload

English · 简体中文


MaidKit is a collection of tools used by LittleSheep when acting as a "maid" for servers (i.e., performing server maintenance). The goal is to provide a more convenient way to maintain servers that is non-intrusive — day-to-day management is 100% SSH-based, installing nothing on the server. The optional MaidCafe Cloud layer adds a small outbound-only daemon for fleet management, alarms, and push notifications — no inbound ports required.

Built with Flutter, MaidKit runs on desktop and mobile platforms alike. Inspired by the Island project's desktop-native approach, it brings the same calm, functional philosophy to server administration.


Table of Contents


Features

Servers

FeatureDescription
DashboardGrid of server cards with live status, latency (network and SSH round-trip), load, memory, and uptime; reorder via context menu, organize into groups, tag, and customize with environment variables; pin runtimes and watched processes for a realtime multi-server overview
ActivityReal-time performance charts (CPU, memory, network, disk), backed by MaidCafe history when the daemon is installed
TerminalFull SSH terminal with split panes, drag-and-drop tabs, command palette, right-click menu, OSC 52 clipboard support, and terminal color schemes
File ManagementDual-pane SFTP browser with drag-and-drop transfers, in-app editor, and keyboard shortcuts (copy/cut/paste, rename, refresh, search, delete)
ProcessesList and kill running processes; pin and watch processes with usage history (realtime via the MaidCafe daemon)
ServicesSystemd unit management (start/stop/enable/disable)
Web Serversnginx and Caddy configuration management
CrontabEdit scheduled tasks
PackagesPackage management (apt, dnf, and more)
FirewallUFW, firewalld, nftables, and iptables management
Port ForwardingLocal and remote tunnel configuration with saved presets that auto-start on connect
ProxyReach hosts through a per-server HTTP CONNECT or SOCKS5 proxy
Jump HostReach a server through another managed server
DatabasesPostgreSQL, MySQL, and MariaDB: engine inspection, logical backups and restores, quick maintenance, and pgBackRest
TailscaleConnect over your tailnet with an embedded node — no Tailscale app required

MaidCafe Cloud

  • Sign in with a Solarpass account and select a workspace
  • One-flow daemon setup: MaidKit probes the server over SSH, installs the MaidCafe daemon, and registers it in the workspace automatically
  • The daemon runs on its own — MaidKit does not need to stay open — and only connects outbound, so no extra ports are opened to the internet
  • Fleet view with per-daemon live metrics (load, swap, disk, network) streamed over SSE in real time
  • Reusable action scripts with template variables, working directory, run-as user, environment, and per-action timeout
  • Native host operations through the daemon: container start/stop/restart/pause/kill/remove, process kill, systemd unit actions, and compose project actions — the container, process, systemd, and deployment views route through the daemon when it is installed (SSH stays the fallback), so these work from anywhere via the cloud relay, not just from a workstation SSH session
  • Scheduled jobs on the daemon: cron or @every intervals targeting actions and native ops, with failure notifications and a full audit trail
  • Container log tracking: the daemon tails running containers to disk and streams the delta over SSE, so logs are inspectable without an SSH session
  • Optional cloud log upload (opt-in because logs may contain sensitive data), persisted in the workspace with retention; daemon-side regex log alerts surface daemon.log_alert notifications with cooldowns
  • Hot reload: the daemon watches its config and fragment files, answers systemctl reload (SIGHUP), and exposes a redacted read + safe-subset patch API (GET/PATCH /api/v1/config) — config saves apply without a service restart
  • Alarm thresholds evaluated locally by the daemon, surfaced as notifications
  • Audit log with invocation provenance and captured output; clear and filter
  • API credentials for CI/CD, scoped to daemons, hosts, and actions; the cloud webhook relay delivers invocations to daemons that poll the cloud
  • Push notifications via Firebase (APNs/FCM) and the in-app Metoer feed

Containers

  • Docker and Podman container management
  • Start, stop, restart, pause, kill, and remove containers
  • Compose project grouping with detail view (per-service status, merged logs, lifecycle actions)
  • Container image management
  • Runtime installation assistance

Projects

  • Deployment project catalog
  • Group compose stacks, web servers, and containers
  • Import and export as TOML

Snippets

  • Create and edit reusable shell scripts
  • Execute on one or more connected servers
  • Streaming output with progress tracking

Agent

  • Chat with an AI agent that can operate your servers through tools
  • Bring your own AI provider or use Solar Network AI
  • MCP servers and reusable skills extend the agent's toolset
  • Auto-discover models from your AI providers
  • Proposed actions require approval (review mode) before they run
  • Conversation history is stored on-device, outside the vault

GitHub

  • Sign in with device-flow authorization
  • Pin repositories and follow workflow runs, pull requests, and releases
  • Access tokens are stored encrypted in the vault
  • GitHub tools are available to the agent

Local MCP Server

  • Expose MaidKit's SSH servers, snippets, and skills to other agents on this machine through a local Model Context Protocol server
  • Connect from Claude Desktop or any MCP client

Security

  • AES-GCM 256-bit encrypted credential vault
  • PBKDF2 key derivation (310,000 iterations)
  • Biometric unlock support
  • Optional per-vault cloud sync over encrypted blobs (Solar Network)
  • Encrypted backup archives (.mkb)
  • GitHub access tokens encrypted in the vault

Settings

  • Theme (system/light/dark), accent color, and workspace background image
  • Language (English / 简体中文)
  • Terminal renderer selection (Ghostty libghostty-vt or xterm), font, and color scheme
  • Connect on startup
  • Hide server addresses when screen sharing or recording
  • Metrics refresh intervals
  • Tailscale sign-in and connection settings
  • MaidCafe cloud endpoint configuration (self-hosted clouds supported)
  • Cloud sync per vault, import and export of server connections
  • Update release channel and check for updates via Solsynth Express

Getting Started

Prerequisites

  • Flutter SDK installed (SDK ^3.12.2)
  • For iOS App Store archives, install Zig 0.15.2 for the vendored Ghostty terminal library. The current Ghostty source is not compatible with Zig 0.16:
    brew install zig@0.15
  • For Windows development, install NASM (required by webcrypto native assets):
    winget install NASM.NASM
  • For Linux development, install additional dependencies:
    sudo apt-get update -y
    sudo apt-get install -y \
    ninja-build \
    libgtk-3-dev \
    libayatana-appindicator3-dev \
    keybinder-3.0 \
    libnotify-dev

Running the App

# Install dependencies
flutter pub get
# Run in debug mode
flutter run
# Build release version
flutter build <platform>

Linux AppImage

Bundle a self-contained AppImage for Linux after building the release bundle:

flutter build linux
bash buildtools/build-appimage.sh

The script packs the x64 release bundle with the desktop entry and run helpers into MaidKit-x86_64.AppImage.

iOS App Store Archive

The bundled Ghostty terminal library is compiled from source for iOS so the binary is linked by Apple's linker and includes the encryption metadata required by App Store Connect. After installing zig@0.15, the build hook selects it automatically when creating an IPA:

flutter clean
flutter pub get
flutter build ipa

The build stops if the generated Ghostty framework lacks LC_ENCRYPTION_INFO_64, preventing an invalid IPA from being produced.

Development

After changing route annotations or Drift schema:

dart run build_runner build

Run checks before committing:

dart format lib test
flutter analyze
flutter test

Architecture

Features are flat and live directly under lib/<feature>/. The app uses:

  • Riverpod for state management with ConsumerWidget for reactive views
  • auto_route for declarative nested navigation
  • Drift for local SQLite persistence
  • dartssh2 for SSH connections
  • island_ui_foundation for the desktop window frame

See docs/architecture.md for the full architecture guide.


Tech Stack

LayerTechnology
FrameworkFlutter with Material 3
StateRiverpod + flutter_hooks
Navigationauto_route
DatabaseDrift (SQLite)
SSHdartssh2
Encryptioncryptography (AES-GCM, PBKDF2)
Terminallibghostty-vt / xterm
Tailscaletailscale (embedded node, macOS/Linux)
Pingdart_ping
FirebaseCloud Messaging push (APNs/FCM), Analytics
Updatessolsynth_express
MCPModel Context Protocol client + local server
Desktopwindow_manager + island_ui_foundation

Contributing

Contributions are welcome! Please feel free to submit issues or pull requests.


Licensing

This project is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0).

If you deploy an instance, fork this project, or redistribute modified versions of this software, you must comply with the AGPL-3.0 license terms, including:

  • Including a copy of the original license
  • Preserving existing copyright notices and attribution
  • Clearly stating any modifications you made
  • Providing corresponding source code to users interacting with the service over a network

Original authorship and copyright attribution to LittleSheep, Solsynth, and this project's contributors must be retained where applicable.

Please note that the AGPL-3.0 license applies to the software source code only. Certain assets, logos, icons, branding materials, and trademarks may be licensed separately and are not automatically covered under the same terms.

See LICENSE.txt for the full license text.


Made by LittleSheep with ❤️

About

The ultimate SSH toolkit for developers

Topics

Resources

Code of conduct

Stars

453 stars

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

MaidKit

MaidKit Logo

A cross-platform SSH server manager

LicenseDownload

English · 简体中文


MaidKit is a collection of tools used by LittleSheep when acting as a "maid" for servers (i.e., performing server maintenance). The goal is to provide a more convenient way to maintain servers that is non-intrusive — day-to-day management is 100% SSH-based, installing nothing on the server. The optional MaidCafe Cloud layer adds a small outbound-only daemon for fleet management, alarms, and push notifications — no inbound ports required.

Built with Flutter, MaidKit runs on desktop and mobile platforms alike. Inspired by the Island project's desktop-native approach, it brings the same calm, functional philosophy to server administration.


Table of Contents


Features

Servers

FeatureDescription
DashboardGrid of server cards with live status, latency (network and SSH round-trip), load, memory, and uptime; reorder via context menu, organize into groups, tag, and customize with environment variables; pin runtimes and watched processes for a realtime multi-server overview
ActivityReal-time performance charts (CPU, memory, network, disk), backed by MaidCafe history when the daemon is installed
TerminalFull SSH terminal with split panes, drag-and-drop tabs, command palette, right-click menu, OSC 52 clipboard support, and terminal color schemes
File ManagementDual-pane SFTP browser with drag-and-drop transfers, in-app editor, and keyboard shortcuts (copy/cut/paste, rename, refresh, search, delete)
ProcessesList and kill running processes; pin and watch processes with usage history (realtime via the MaidCafe daemon)
ServicesSystemd unit management (start/stop/enable/disable)
Web Serversnginx and Caddy configuration management
CrontabEdit scheduled tasks
PackagesPackage management (apt, dnf, and more)
FirewallUFW, firewalld, nftables, and iptables management
Port ForwardingLocal and remote tunnel configuration with saved presets that auto-start on connect
ProxyReach hosts through a per-server HTTP CONNECT or SOCKS5 proxy
Jump HostReach a server through another managed server
DatabasesPostgreSQL, MySQL, and MariaDB: engine inspection, logical backups and restores, quick maintenance, and pgBackRest
TailscaleConnect over your tailnet with an embedded node — no Tailscale app required

MaidCafe Cloud

  • Sign in with a Solarpass account and select a workspace
  • One-flow daemon setup: MaidKit probes the server over SSH, installs the MaidCafe daemon, and registers it in the workspace automatically
  • The daemon runs on its own — MaidKit does not need to stay open — and only connects outbound, so no extra ports are opened to the internet
  • Fleet view with per-daemon live metrics (load, swap, disk, network) streamed over SSE in real time
  • Reusable action scripts with template variables, working directory, run-as user, environment, and per-action timeout
  • Native host operations through the daemon: container start/stop/restart/pause/kill/remove, process kill, systemd unit actions, and compose project actions — the container, process, systemd, and deployment views route through the daemon when it is installed (SSH stays the fallback), so these work from anywhere via the cloud relay, not just from a workstation SSH session
  • Scheduled jobs on the daemon: cron or @every intervals targeting actions and native ops, with failure notifications and a full audit trail
  • Container log tracking: the daemon tails running containers to disk and streams the delta over SSE, so logs are inspectable without an SSH session
  • Optional cloud log upload (opt-in because logs may contain sensitive data), persisted in the workspace with retention; daemon-side regex log alerts surface daemon.log_alert notifications with cooldowns
  • Hot reload: the daemon watches its config and fragment files, answers systemctl reload (SIGHUP), and exposes a redacted read + safe-subset patch API (GET/PATCH /api/v1/config) — config saves apply without a service restart
  • Alarm thresholds evaluated locally by the daemon, surfaced as notifications
  • Audit log with invocation provenance and captured output; clear and filter
  • API credentials for CI/CD, scoped to daemons, hosts, and actions; the cloud webhook relay delivers invocations to daemons that poll the cloud
  • Push notifications via Firebase (APNs/FCM) and the in-app Metoer feed

Containers

  • Docker and Podman container management
  • Start, stop, restart, pause, kill, and remove containers
  • Compose project grouping with detail view (per-service status, merged logs, lifecycle actions)
  • Container image management
  • Runtime installation assistance

Projects

  • Deployment project catalog
  • Group compose stacks, web servers, and containers
  • Import and export as TOML

Snippets

  • Create and edit reusable shell scripts
  • Execute on one or more connected servers
  • Streaming output with progress tracking

Agent

  • Chat with an AI agent that can operate your servers through tools
  • Bring your own AI provider or use Solar Network AI
  • MCP servers and reusable skills extend the agent's toolset
  • Auto-discover models from your AI providers
  • Proposed actions require approval (review mode) before they run
  • Conversation history is stored on-device, outside the vault

GitHub

  • Sign in with device-flow authorization
  • Pin repositories and follow workflow runs, pull requests, and releases
  • Access tokens are stored encrypted in the vault
  • GitHub tools are available to the agent

Local MCP Server

  • Expose MaidKit's SSH servers, snippets, and skills to other agents on this machine through a local Model Context Protocol server
  • Connect from Claude Desktop or any MCP client

Security

  • AES-GCM 256-bit encrypted credential vault
  • PBKDF2 key derivation (310,000 iterations)
  • Biometric unlock support
  • Optional per-vault cloud sync over encrypted blobs (Solar Network)
  • Encrypted backup archives (.mkb)
  • GitHub access tokens encrypted in the vault

Settings

  • Theme (system/light/dark), accent color, and workspace background image
  • Language (English / 简体中文)
  • Terminal renderer selection (Ghostty libghostty-vt or xterm), font, and color scheme
  • Connect on startup
  • Hide server addresses when screen sharing or recording
  • Metrics refresh intervals
  • Tailscale sign-in and connection settings
  • MaidCafe cloud endpoint configuration (self-hosted clouds supported)
  • Cloud sync per vault, import and export of server connections
  • Update release channel and check for updates via Solsynth Express

Getting Started

Prerequisites

  • Flutter SDK installed (SDK ^3.12.2)
  • For iOS App Store archives, install Zig 0.15.2 for the vendored Ghostty terminal library. The current Ghostty source is not compatible with Zig 0.16:
    brew install zig@0.15
  • For Windows development, install NASM (required by webcrypto native assets):
    winget install NASM.NASM
  • For Linux development, install additional dependencies:
    sudo apt-get update -y
    sudo apt-get install -y \
    ninja-build \
    libgtk-3-dev \
    libayatana-appindicator3-dev \
    keybinder-3.0 \
    libnotify-dev

Running the App

# Install dependencies
flutter pub get
# Run in debug mode
flutter run
# Build release version
flutter build <platform>

Linux AppImage

Bundle a self-contained AppImage for Linux after building the release bundle:

flutter build linux
bash buildtools/build-appimage.sh

The script packs the x64 release bundle with the desktop entry and run helpers into MaidKit-x86_64.AppImage.

iOS App Store Archive

The bundled Ghostty terminal library is compiled from source for iOS so the binary is linked by Apple's linker and includes the encryption metadata required by App Store Connect. After installing zig@0.15, the build hook selects it automatically when creating an IPA:

flutter clean
flutter pub get
flutter build ipa

The build stops if the generated Ghostty framework lacks LC_ENCRYPTION_INFO_64, preventing an invalid IPA from being produced.

Development

After changing route annotations or Drift schema:

dart run build_runner build

Run checks before committing:

dart format lib test
flutter analyze
flutter test

Architecture

Features are flat and live directly under lib/<feature>/. The app uses:

  • Riverpod for state management with ConsumerWidget for reactive views
  • auto_route for declarative nested navigation
  • Drift for local SQLite persistence
  • dartssh2 for SSH connections
  • island_ui_foundation for the desktop window frame

See docs/architecture.md for the full architecture guide.


Tech Stack

LayerTechnology
FrameworkFlutter with Material 3
StateRiverpod + flutter_hooks
Navigationauto_route
DatabaseDrift (SQLite)
SSHdartssh2
Encryptioncryptography (AES-GCM, PBKDF2)
Terminallibghostty-vt / xterm
Tailscaletailscale (embedded node, macOS/Linux)
Pingdart_ping
FirebaseCloud Messaging push (APNs/FCM), Analytics
Updatessolsynth_express
MCPModel Context Protocol client + local server
Desktopwindow_manager + island_ui_foundation

Contributing

Contributions are welcome! Please feel free to submit issues or pull requests.


Licensing

This project is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0).

If you deploy an instance, fork this project, or redistribute modified versions of this software, you must comply with the AGPL-3.0 license terms, including:

  • Including a copy of the original license
  • Preserving existing copyright notices and attribution
  • Clearly stating any modifications you made
  • Providing corresponding source code to users interacting with the service over a network

Original authorship and copyright attribution to LittleSheep, Solsynth, and this project's contributors must be retained where applicable.

Please note that the AGPL-3.0 license applies to the software source code only. Certain assets, logos, icons, branding materials, and trademarks may be licensed separately and are not automatically covered under the same terms.

See LICENSE.txt for the full license text.


Made by LittleSheep with ❤️

About

The ultimate SSH toolkit for developers

Topics

Resources

Code of conduct

Stars

453 stars

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages