Skip to main content

EXTENSIONS

Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.

Filter by what you need and pull what fits.

Selection
17 results
from:@jamesakeech

Mongodb Datastore

@jamesakeech/mongodb-datastore · v2026.09.11.1

MongoDB datastore for shared Swamp repositories: namespace-aware sync, managed configuration refresh, atomic remote control plane, distributed locks and content-addressed storage. Fork of @keeb/mongodb-datastore with a companion maintenance model and workflow. Requires a MongoDB replica set.

upd Sep 1118 pullsA100/100

Bootstrap

@jamesakeech/bootstrap · v2026.09.11.1

Bootstrap a project for any Swamp-integrated agent with a reviewed architecture control plane and the official Swamp software-factory engine. Captures content-addressed accepted baselines, preserves existing project files, reserves one factory and a unique verification workflow per work item, and checks workspace isolation and source-digest provenance. Includes guided project design, personal working policy, factory-driving skills, and a readiness report that distinguishes configuration acceptance from successful verification. Local intake works without tracker credentials; selected tracker extensions supply remote reads.

upd Sep 1125 pullsA100/100

Container Verification

@jamesakeech/container-verification · v2026.09.10.1

Docker verification with structured read-only source mounts, cancellation protection, and retained evidence. Reuses the official container-image runner.

upd Sep 1019 pullsA100/100

Gitlab Work Items

@jamesakeech/gitlab-work-items · v2026.09.10.3

Manage GitLab issues, tasks and incidents: create, read, update, label, close, reopen, link parents and delete, with bounded read pagination.

upd Sep 1020 pullsA100/100

Technitium

@jamesakeech/technitium · v2026.08.15.1

Manage a Technitium DNS server or cluster: zones, records, block/allow lists, cache, diagnostics, settings backup and restore, and cluster membership. Written after rebuilding a live authoritative pair, and shaped by what that exposed. `record_ensure` is an idempotent upsert Technitium's own API cannot express — add fails on an existing record, update fails on an absent one — and it works for every record type including TLSA, because the read and write field names for TLSA, SSHFP and URI are not the same names and are mapped per type rather than renamed globally. `settings_backup` includes every section by default, so it produces a backup a server can actually be rebuilt from. `cluster_init`, `cluster_join` and `cluster_state` cover the membership a settings backup can never carry, alongside the TLS listener and certificate it also omits — the three things that make a restored node look broken.

upd Aug 1516 pullsA100/100

Pocket Id

@jamesakeech/pocket-id · v2026.08.08.1

Observability for a Pocket ID instance — the passkey-based OIDC provider. `health` is a cheap, admin-free probe that separates an unreachable host from a wrong API key from a key whose owner is not an admin, and reports version drift; it writes its result as data rather than throwing, so a failed run still leaves a truthful record. `sync` fans out one resource per user, OIDC client, group and API key, joins each user against their passkeys and their sign-ins and each client against its authorizations, then scores the whole instance into `instance.findings`: accounts with no passkey that therefore cannot sign in, public clients with PKCE disabled, clients nobody has authorized, empty groups, and the API key whose expiry will silently stop the sync. `syncActivity` reads a bounded window of the audit log on its own — Pocket ID has no date filter, so the window is applied by walking newest-first and stopping early, which makes a short window genuinely cheap. Read-only throughout.

upd Aug 814 pullsA100/100

Omada

@jamesakeech/omada · v2026.08.08.1

Observability and safe operational control for a TP-Link Omada controller. One fan-out sync reads every site, device, client, switch port, gateway WAN and SSID into addressable resources, and writes a drift record comparing configuration — not telemetry — against the previous sync, so an idle network reports nothing and a firmware bump, a re-addressed WAN, a disabled PoE port or a device that stopped answering each report themselves. Talks the supported Open API in client-credentials mode, with the controller's own web API as an optional fallback for reads the Open API does not expose. Writes are limited to reversible operational actions — reboot, PoE, client block, reconnect, LED, locate, firmware — each fanning out over a list in one controller session.

upd Aug 815 pullsA100/100

Nginx Proxy Manager

@jamesakeech/nginx-proxy-manager · v2026.08.08.1

Full lifecycle management of an Nginx Proxy Manager instance. `sync` fans out one resource per proxy host, redirection host, dead host, stream, access list and certificate, plus an instance rollup that flags expiring certificates, plain-HTTP hosts and domains claimed by more than one host. The `apply*` methods are idempotent — they match an existing object by its natural key (domain set, listening port, access list name) and update it in place, so re-running a workflow converges instead of accumulating duplicates. `setEnabled` and `delete` dispatch on an object kind and take a list of ids, so a batch is one fan-out call rather than a run per id. Let's Encrypt certificates can be requested over HTTP-01 or DNS-01 (wildcards included), renewed, or replaced with uploaded PEM files.

upd Aug 818 pullsA100/100

Esxi

@jamesakeech/esxi · v2026.07.31.3

Read-only VM inventory for standalone VMware ESXi hosts, shaped for planning a migration off one and decommissioning it. Collects over SSH from vim-cmd, esxcli and the guests' own .vmx files — virtual hardware, storage with provisioned vs allocated bytes, in-guest identity (hostname, addressing, DNS, default route, mounted filesystems) via VMware Tools, live usage for rightsizing, and the complete vmx verbatim — plus a warnings list of what blocks a clean rebuild. One fan-out inventory method does the whole host in a single SSH round trip.

upd Jul 3114 pullsA100/100

Ansible

@jamesakeech/ansible · v2026.07.30.1

Drive an existing Ansible playbook from swamp. `check` runs --check --diff and never mutates, so changed=0 across every host is a machine-readable 'already matches its declaration' gate; `apply` runs for real. Parses the PLAY RECAP into typed per-host tallies for CEL, accepts inventory as content so a workflow can build it from model data instead of a render script, and keeps vault and sudo passwords in 0600 temp files rather than argv.

upd Jul 3018 pullsA100/100

Forgejo Code

@jamesakeech/forgejo-code · v2026.07.30.1

Code-reading methods for @shrug/forgejo — map a repository's file tree, read individual files, and snapshot every matching text file into one reviewable data blob. Turns a metadata-only forge node into a source for code review and IaC analysis.

upd Jul 3015 pullsA100/100

Jellyfin Playback

@jamesakeech/jellyfin-playback · v2026.07.23.1

Watch-activity methods for @keeb/jellyfin — pull per-session events from the Jellyfin Playback Reporting plugin, plus a core-API watch-history fallback, for building watch-time dashboards.

upd Jul 2330 pullsA100/100

Hardcover

@jamesakeech/hardcover · v2026.07.20.2

Monitor a single user's Hardcover reading activity via the Hardcover GraphQL API — profile, the whole tracked library (shelf status, rating, review, pages, read dates), and individual reading sessions (start/finish dates, progress). Read-only, token-authenticated.

upd Jul 2024 pullsA100/100

Letterboxd

@jamesakeech/letterboxd · v2026.07.20.1

Monitor a single user's Letterboxd film diary via their public RSS feed — one record per logged watch (watched date, star rating, like/rewatch flags, film title/year, TMDB id, poster, review). No credentials required; the feed is a rolling window, so run on a schedule to accumulate history.

upd Jul 2021 pullsA100/100

Audiobookshelf

@jamesakeech/audiobookshelf · v2026.07.13.1

Monitor a self-hosted Audiobookshelf server — libraries, audiobooks/podcasts, listening progress, listening sessions, and aggregate listening statistics — via the Audiobookshelf REST API.

upd Jul 1328 pullsA100/100

Spotify

@jamesakeech/spotify · v2026.07.11.1

Monitor a single user's Spotify listening activity via the Spotify Web API — recently-played tracks (accumulate over time), plus top-artists and top-tracks rankings — with built-in OAuth helpers to obtain the refresh token.

upd Jul 1128 pullsA100/100

Fly

@jamesakeech/fly · v2026.07.01.3

Monitor Fly.io organisations and applications — discover apps, machine/deploy state, volumes, snapshots, events — and take safe volume snapshots, via the Fly Machines API.

upd Jun 3024 pullsA100/100