Skip to main content

EXTENSIONS

Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.

Filter by what you need and pull what fits.

Selection
53 results
label:homelab

N8n

@sntxrr/n8n · v2026.10.05.1

Read a running n8n deployment and report how far its pinned version has drifted behind the channel n8n itself calls stable, and which active workflows have no usable error workflow attached. All three methods are strictly read-only — this extension never upgrades n8n, edits a workflow, touches a credential, or restarts a container; it tells you an update exists and stops there. `audit_error_workflows` takes an optional n8n API key (used by no other method), because n8n has no instance-wide default error workflow and only the authenticated public API discloses each workflow's `settings.errorWorkflow`; it flags missing or wrong handlers and a handler that is inactive or archived, and never attaches one. `drift` takes the running version as an argument rather than reading it, because n8n does not disclose one: its `/rest/settings` answers 200 unauthenticated but with `settingsMode: public`, a reduced payload carrying no version field at all, and `versionCli` reaches authenticated callers only — so the version comes from the pinned image tag on the host, which is what the deployment actually is rather than what a process predating the current pin believes itself to be. The upgrade target is npm's dist-tag, never the newest published release: n8n ships its in-progress minor into the same GitHub release namespace flagged `prerelease: true` and promotes that line later, so on 2026-09-05 the newest release was 2.38.3 while stable was 2.37.10, and the 2.37 line had itself been prerelease through 2.37.6. GitHub releases are still read, but only to enumerate the stable releases that were missed and to link the notes, since the `prerelease` flag is the historical record of which line was stable when and dist-tags do not retain it. Image existence is verified against `registry-1.docker.io` rather than the `docker.n8n.io` mirror the pin names: that mirror 404s its own token endpoint, delegates auth to Docker Hub, and then answers 429 to every manifest request for tags that exist and tags that do not alike, so it cannot return a usable answer — and a 429 is raised as indeterminate rather than folded into `absent`, which would suppress every update forever while the check looked healthy. An exhausted GitHub rate limit, an unreachable registry, and an unparseable running version are all raised as errors rather than reported as a reassuring `current`.

upd Oct 533 pullsA100/100

Glinet Kvm

@sntxrr/glinet-kvm · v2026.10.02.2

Operate GL.iNet KVMs (Comet GL-RM1 / GL-RM1PE) from swamp: health, screenshots, ATX power and virtual media. The firmware is a fork of PiKVM's kvmd, and three of its behaviours shape this model. The factory TLS certificate is self-signed, names CN=localhost and expired in 1979, so it cannot be validated or pinned; HTTP goes through curl and the viewer through openssl, with credentials on stdin rather than argv. The video streamer sleeps until a viewer connects, so a bare snapshot request answers 503 whether or not there is a signal; screenshot and health open a receive-only viewer session first and never send input. Without the ATX add-on board, the API still reports power 'off' for a running machine; this model reports the state as unknown and refuses to press a button wired to nothing. health flags available firmware updates, missing HDMI signal, offline USB HID, forgotten virtual media that could hijack the next boot, clock skew, and security posture (2FA off, browser root shell on, untrusted TLS). atx and msd are dry runs unless apply is true.

upd Oct 214 pullsA100/100

Nextcloud

@sntxrr/nextcloud · v2026.09.30.1

Health, version drift, setup checks, app updates and compatibility, verified backups and occ maintenance for a self-hosted Nextcloud. `sync` reads status.php and, with a serverinfo token, storage and user statistics; `drift` compares the running version against stable GitHub releases and reports the patch target and the next major separately, because Nextcloud refuses to skip a major and the newest release is often not a legal target; `setupchecks` records the admin overview's warnings as data; `talkBots` flags a Nextcloud Talk bot that is not enabled, whose webhook delivery errors rose since the last reading (Talk drops a message whose delivery fails and never resets the count, so the rise is the signal, not the total), or that is expected and missing; `apps` lists app store updates and, given a targetVersion, which enabled store apps have no release for it. `backup` dumps MySQL/MariaDB and archives the web-root directories an upgrade changes onto the machine swamp runs on, then reads both back (dump completion line and table count, tar header checksums and gzip CRC) and renames a backup that fails `.FAILED`; the database password stays in the container's environment and never reaches a command line. `maintenance`, `dbRepair`, `updateApps` and `backup` change state and are dry runs unless apply=true; each apply path re-reads the state afterwards and fails if the change did not take. occ runs through `docker exec`, locally or on a host over SSH with BatchMode. Four behaviours shape the implementation. Nextcloud 34 enforces trusted_domains on status.php and answers HTTP 400/code 15 when probed by IP, and Deno's fetch silently drops a Host header override, so baseUrl must be a trusted name and the error is named rather than reported as a bare 400. `occ setupchecks` exits 1 whenever any check warns, so exit 1 with a JSON report is data, not failure. Prerelease tags are spelled inconsistently (`rc2` and `RC2` both exist), so any suffixed tag is excluded, not parsed. And updates.nextcloud.com answers an empty 200 both for `nothing to offer` and for a query it did not understand, so it is not used. A failure to measure is raised, never reported as healthy, current or `no updates`.

upd Sep 3035 pullsA100/100

Vikunja Kanban

@sntxrr/vikunja-kanban · v2026.09.27.4

Vikunja kanban orchestrator — creates tasks in a Vikunja project directly

upd Sep 2756 pullsA100/100

Pihole Denylist

@sntxrr/pihole-denylist · v2026.09.27.1

Declare a Pi-hole v6 exact-deny list in swamp and converge an appliance to it: plan by default, apply on request, prune only when asked

upd Sep 2723 pullsA100/100

Apprise Notify

@sntxrr/apprise-notify · v2026.09.24.1

Send notifications through an Apprise API server, fanning out to Matrix, Discord, ntfy, email and 100+ other services

upd Sep 2445 pullsA100/100

Backrest

@sntxrr/backrest · v2026.09.23.2

Keep a Backrest server's snapshot index current for restic repositories it does not itself back up, and report how fresh each one is. Backrest indexes snapshots only for repositories it runs backups for; one that is merely configured — the normal shape when restic runs from systemd timers on each host and Backrest is only the console — is never indexed at all, and reports no error while doing so. The repository simply stays empty in the UI, which reads as `no backups` for a host whose backups are in fact current. `sync` reads the operation log and reports each repository's newest indexed snapshot. `reindex` triggers Backrest's own TASK_INDEX_SNAPSHOTS for every configured repository, waits for them to appear, and reports the same shape; it reads repositories and never creates, forgets or prunes a snapshot, so it is safe to schedule. Four server behaviours shape the implementation because each one silently produces a wrong answer if ignored. GetOperations' repoId selector does not filter — a selector matching nothing returns the ENTIRE operation log rather than an empty set, so a per-repository query makes every repository report the whole fleet's totals; operations are therefore fetched once and grouped on each operation's own repoId. A failed index task leaves no trace in the operation log, only successes being recorded, so a repository the server cannot read is indistinguishable through the API from one whose task has not run yet — both are reported as `unindexed` with the reason named as the server log rather than invented. The task queue is serial, so triggering N repositories enqueues N tasks behind each other and one whose credentials were revoked does not fail fast but retries with exponential backoff for six minutes or more while everything behind it waits, which is why the wait is a deadline over the whole set rather than a per-task timeout. And a repository with no indexed snapshot at all is a different failure from one whose snapshots have stopped advancing — the first is a credential this server holds that no longer exists, the second is a backup that has stopped running — so they are counted separately as `unindexed` and `stale` instead of being folded into one unhelpful total. Because it reaches repositories through the server's own stored credentials rather than the ones the backup hosts use, disagreement with a host-side view is informative: it means exactly one of the two credential sets has gone bad.

upd Sep 2338 pullsA100/100

Swamp Go Brr

@magistr/swamp-go-brr · v2026.09.19.2

An autonomous, driver-free development loop for coding agents. You hand it an

upd Sep 1917 pullsA100/100

Pihole

@magistr/pihole · v2026.09.19.2

Pi-hole custom DNS record management for swamp — list, add, delete, and

upd Sep 1994 pullsA100/100

Libvirt

@bad-at-naming/libvirt · v2026.09.19.2

Comprehensive libvirt/virsh management — VMs, networks, storage pools,

upd Sep 1924 pullsA100/100

Firecracker

@magistr/firecracker · v2026.09.19.2

Firecracker microVM lifecycle management via SSH + the Unix-socket REST API.

upd Sep 1956 pullsA100/100

Diskio

@magistr/diskio · v2026.09.19.2

Answer "what is actually reading this disk?" on a Linux host whose storage

upd Sep 1916 pullsA100/100

Docker Reclaim

@sntxrr/docker-reclaim · v2026.09.06.2

Measure what a Docker host's disk is actually spent on, plan what can be freed without destroying a rollback target, and free it. The command people reach for is the wrong one: `docker image prune` — dangling or `-a` — never touches the BUILD CACHE, and on a host that builds its own images the build cache is usually most of the footprint. On the host this was written against it was 59.5GB of a 77GB reclaim, which no amount of image pruning would have recovered. Three behaviours are deliberate because each one corresponds to a way the obvious command does damage or lies. `docker image prune -a` removes every image no container references, which is precisely the set of previous versions a rollback needs; this model instead protects the newest `keepVersions` tags of each repository and removes specific image IDs, so reclaiming space does not quietly cost you the ability to go back. `docker builder prune -af` deletes the cache that makes the next build fast, and cache that is minutes old is the most valuable cache there is; pruning is therefore age-filtered via `--filter until=`, so a scheduled run takes cold layers and leaves the working set. And Docker reports sizes as rounded human strings where 1000 versus 1024 is a real 7% at terabyte scale, so parsing is explicit and unit-aware and the freed figure is measured by observing free space before and after rather than by summing estimates. Each method writes its own data instance — `usage`, `plan`, `reclaim` — so an expression always gets the schema it expects rather than whichever method ran last. `observe` and `plan` are read-only and safe to schedule at any frequency; `reclaim` is dry-run unless passed `apply: true`, and even then never removes an image that any container references, running or stopped. Host key checking is left ON by default — `StrictHostKeyChecking=no` is available but is not the default, because a model whose entire purpose is running destructive commands as a privileged user is the last place to accept an unverified host key.

upd Sep 635 pullsA100/100

Unifi Dhcp Reservation

@sntxrr/unifi-dhcp-reservation · v2026.08.20.1

Declarative DHCP fixed-IP reservations on a local UniFi controller (UDM / UDM Pro / UDM SE). `sync` reads every reservation the controller holds; `drift` compares a desired set against it without writing, reporting missing, mismatched, unmanaged, duplicate and DHCP-pool-overlapping entries; `apply` reconciles the controller to the desired set and supports `dryRun`. `device_drift` does the same read-only comparison for adopted hardware, which cannot hold reservations at all and is addressed through device config instead — the one surface `drift` is blind to. Reservations live on the legacy Network API as `user` objects carrying `use_fixedip`/`fixed_ip`. Adds TOTP/MFA login support, which the upstream @mgreten/unifi auth flow lacks — UniFi SSO accounts with MFA reject password-only logins with MFA_AUTH_REQUIRED. Catches the failure mode where a reservation silently never takes effect because its address is already claimed by a statically-configured host. `forget_client` prunes stale client records the controller still remembers, refusing any MAC that holds a reservation or a live lease unless forced.

upd Aug 2018 pullsA100/100

Unifi Fabric

@sntxrr/unifi-fabric · v2026.08.20.1

Structural health monitoring for a UniFi fabric. The `@sntxrr/unifi-fabric/topology` model's `check` method compares a declared topology against live `/stat/device` rows and reports the failures that outcome-based monitoring cannot see: a device expected on the wire that has silently fallen back to a wireless mesh uplink, attachment to the wrong upstream device, links negotiated below their expected speed, ports carrying error counters, and — the one with no equivalent elsewhere — ports that are down but have carried real traffic before, which identifies a run that used to work. An access point that loses its wired uplink does not fail; it meshes, keeps serving clients, and every uptime check stays green while latency quietly goes from sub-millisecond to tens of milliseconds and jittery. `uplink.type` flipping from `wire` to `wireless` is a boolean, so it is asserted exactly rather than thresholded. Read-only: never writes to the controller. Emits a flat Prometheus-ready metric series alongside the verdict, including for healthy devices, so alerts can fire on a series dropping to zero rather than on a document changing shape. Authenticates with an API key over `X-API-KEY`, which sidesteps the HTTP 499 that MFA-enabled SSO accounts return for password logins.

upd Aug 2014 pullsA100/100

Image Updater

@lint/image-updater · v2026.08.20.1

Auto-applier for docker image updates — pulls + restarts compose stacks with deny lists, cooling periods, and a per-run cap.

upd Aug 2030 pullsA100/100

Technitium

@jamesakeech/technitium · v2026.08.15.1

Manage a Technitium DNS server or cluster: zones, records, block/allow lists, cache, diagnostics, settings backup and restore, and cluster membership. Written after rebuilding a live authoritative pair, and shaped by what that exposed. `record_ensure` is an idempotent upsert Technitium's own API cannot express — add fails on an existing record, update fails on an absent one — and it works for every record type including TLSA, because the read and write field names for TLSA, SSHFP and URI are not the same names and are mapped per type rather than renamed globally. `settings_backup` includes every section by default, so it produces a backup a server can actually be rebuilt from. `cluster_init`, `cluster_join` and `cluster_state` cover the membership a settings backup can never carry, alongside the TLS listener and certificate it also omits — the three things that make a restored node look broken.

upd Aug 1516 pullsA100/100

Docker Host

@lint/docker-host · v2026.08.09.1

Docker container discovery + autoheal across a Proxmox cluster — SSHes to each PVE node, runs `pct exec <vmid> docker ps` on every docker-tagged LXC; the autoheal method restarts unhealthy containers within deny-list/cooldown/cap guardrails.

upd Aug 930 pullsA100/100

Truenas

@mccormick/truenas · v2026.08.09.1

Hypervisor-layer VM inventory for TrueNAS SCALE, via the JSON-RPC WebSocket API.

upd Aug 921 pullsA100/100

Pocket Id

@jamesakeech/pocket-id · v2026.08.08.1

Observability for a Pocket ID instance — the passkey-based OIDC provider. `health` is a cheap, admin-free probe that separates an unreachable host from a wrong API key from a key whose owner is not an admin, and reports version drift; it writes its result as data rather than throwing, so a failed run still leaves a truthful record. `sync` fans out one resource per user, OIDC client, group and API key, joins each user against their passkeys and their sign-ins and each client against its authorizations, then scores the whole instance into `instance.findings`: accounts with no passkey that therefore cannot sign in, public clients with PKCE disabled, clients nobody has authorized, empty groups, and the API key whose expiry will silently stop the sync. `syncActivity` reads a bounded window of the audit log on its own — Pocket ID has no date filter, so the window is applied by walking newest-first and stopping early, which makes a short window genuinely cheap. Read-only throughout.

upd Aug 814 pullsA100/100

Nginx Proxy Manager

@jamesakeech/nginx-proxy-manager · v2026.08.08.1

Full lifecycle management of an Nginx Proxy Manager instance. `sync` fans out one resource per proxy host, redirection host, dead host, stream, access list and certificate, plus an instance rollup that flags expiring certificates, plain-HTTP hosts and domains claimed by more than one host. The `apply*` methods are idempotent — they match an existing object by its natural key (domain set, listening port, access list name) and update it in place, so re-running a workflow converges instead of accumulating duplicates. `setEnabled` and `delete` dispatch on an object kind and take a list of ids, so a batch is one fan-out call rather than a run per id. Let's Encrypt certificates can be requested over HTTP-01 or DNS-01 (wildcards included), renewed, or replaced with uploaded PEM files.

upd Aug 818 pullsA100/100

Openwebui

@sntxrr/openwebui · v2026.08.07.1

Read a running OpenWebUI instance and report how far its version has drifted behind upstream. Both methods are strictly read-only — this extension never upgrades the instance, edits its settings, manages users, or touches the container; it tells you an update is available and stops there. `sync` records what the instance reports about itself: version plus the feature flags that decide what automation can reach it, including `enable_api_keys`, which when false blocks every token-authenticated integration and cannot be worked around with any credential — reported as `null` rather than `false` when the instance withholds it, which OpenWebUI has done for unauthenticated callers since v0.9.6, because absent is not the same as off. `drift` compares the running version against the repo's published GitHub releases and reports status (`current`/`behind`/`ahead`), how many releases were missed, and which ones. Needs no credentials at all: both endpoints it uses answer before login. Versions are compared numerically because OpenWebUI's break lexical ordering in both directions — `0.8.12` sorts above `0.11.0` and below `0.8.9` as strings — so a string compare reports an instance eleven releases behind as up to date. An exhausted GitHub rate limit, a missing repo, and an unparseable running version are all raised as errors rather than folded into a reassuring `current`, and a release page that fills up before reaching the running version is reported as `truncated` rather than passed off as a total.

upd Aug 815 pullsA100/100

Swamp Version

@sntxrr/swamp-version · v2026.08.08.1

Read the swamp version a host or container is running and report how far it has drifted behind the published channel. Read-only — it never updates, installs, or restarts anything; it tells you a newer build exists and stops there. Fills the gap `swamp update --check` leaves: that answers for the binary invoking it, on the platform invoking it, which is no help when the install you care about is a pinned binary inside a container on another host. `sync` records what a target reports about itself — its version and, via `uname`, the artifact platform it runs on. `drift` resolves the newest build published on a channel for THAT platform and reports status (`current`/`behind`/`ahead`) plus the lag in hours. Targets are reached three ways: the local binary, `docker exec` (optionally through a named docker context, so one host can check a container on another), or SSH with BatchMode so an unattended run fails fast instead of hanging on a password prompt. The channel is resolved by a single HEAD against the `stable` alias, reading the resolved version out of its website-redirect metadata — one request rather than the ~90 MB the archive weighs — and the same pass verifies the platform-specific archive is actually fetchable, which is the precondition for pinning a rebuild to it. Versions are compared numerically because the build ordinal in `YYYYMMDD.HHMMSS.N` is not zero-padded: as strings `20260808.001107.10` sorts below `...9`, so a string compare reports a target one build behind as up to date the day a tenth build ships. `hoursBehind` is derived from the timestamps embedded in each version and is documented as a lag, not a count of missed builds — swamp publishes no release list, so the builds in between cannot be enumerated and this extension does not pretend otherwise. An unreachable target, an unparseable version at either end, a channel alias that answers without its redirect header, and a resolved archive that 404s are all raised as errors rather than folded into a reassuring `current`.

upd Aug 815 pullsA100/100

Libvirt Vm Pool

@evrardjp/libvirt-vm-pool · v2026.08.04.1

Desired-state local libvirt VM pool reconciler for Swamp. Defines, starts, removes, and publishes per-VM connection facts for downstream SSH/config models.

upd Aug 422 pullsA100/100