Open sourceSelf-hostedNo cloudVersion 0.1.0

Every KVM you run, on one wall.

QKVM shows the live screen and the state of every IP KVM and server you look after on a single page, and lets you act on one machine or on many at once. It runs on your own computer and talks to each device directly.

The demo is the real page with made-up machines. Nothing to sign up for, nothing sent anywhere.

The wall, as a drawing. The demo is the page itself.
Direct
Talks to each device over your LAN or Tailscale. Nothing passes through a cloud.
Yours
One small program on your own machine. No account, no device limit, no telemetry.
Careful
Saved passwords are encrypted with yours, and every device's certificate is checked.
Open
Free software under the AGPL-3.0. Read it, run it, change it.

Product

One page for the whole room.

For whoever looks after a rack, an office or a lab full of machines, and wants one place that shows which of them needs attention.

The wall

A live picture and the status of every machine on one page, drawn pixel for pixel. Enlarge one, filter by state, search, group by rack or room, or put it on a monitor in display mode.

Act on one, or on all

Key combinations, typed text, your own saved actions, power and reset, Wake-on-LAN, port switching. Tick several machines and run it on all of them, with a confirmation first.

Servers next to KVMs

A server's management controller (BMC) goes on the same wall over Redfish: power state, health, temperatures and fans in place of a picture, with its power buttons and locator light.

Accounts for a team

Three roles, accounts limited to some of the machines, two-factor sign-in, a recovery key, and an activity log that says who did what.

Alerts

ntfy, Slack, Discord or any webhook hears about it when a machine goes offline, loses its picture, reports a fault, or comes back.

Finds your devices

QKVM looks on your network and among your Tailscale peers. A device reachable by two addresses is listed once, and each one is checked before it is added.

Security

Built for what it holds.

QKVM keeps the passwords of your KVMs and can press the power button of what is behind them. So the question is not whether it has a sign-in page. It is what somebody walks away with.

If somebodycopies the data folder
Nothing usable. No password is stored. Yours derives the key that the saved device passwords are encrypted with; without it the files are noise.
If somebodyanswers at a device's address
Never sent the password. Each device's certificate is remembered the first time, like an SSH host key. Anything else at that address is refused, and the tile says so.
If somebodytakes over one of your KVMs
A wrong picture, no more. What a device sends is read only up to a limit and reduced to plain values. It cannot fill the memory of the computer QKVM runs on, or put a page of its own in your browser.
If somebodylures you to a page of theirs
Refused. Every change has to come from QKVM's own page, which runs under a strict content security policy and loads nothing from other servers.
If somebodyguesses at passwords
Locked out. Repeated wrong passwords lock the address out, for longer each time. Two-factor sign-in asks for a code on top.
If somebodytampers with an update
Not installed. A new version is installed only when it carries the publisher's signature, and never without you asking for it.

How each of these works

Install

Four commands, then your browser.

QKVM is one small program for a computer that can reach your devices: a server, a mini PC, the machine on your desk. Python 3.11 or newer, or a container.

git clone https://github.com/qkvm/qkvm
cd qkvm
pip install .
python -m qkvm
now open http://127.0.0.1:8787/
git clone https://github.com/qkvm/qkvm
cd qkvm
docker compose up -d
docker compose logs qkvm
the log shows the setup code asked for on the first visit
  1. PasswordChoose the password of the first account.
  2. Recovery keyShown once: the way back in if a password is forgotten.
  3. NetworkThis computer only, Tailscale, or the local network.
  4. DevicesLet QKVM find them, or paste their addresses.

The full instructions

Works with

The devices people actually have.

  • GL.iNet CometGL-RM1 and GL-RM10, on the GLKVM firmware.
  • GL.iNet Comet XFour computers on one KVM, with port switching from the wall.
  • PiKVM-style KVMsAnything that speaks the kvmd interface.
  • JetKVMBuilt from its published source.
  • Servers with a BMCOver Redfish: AMI MegaRAC boards so far.

What it does not do, and what is not proven yet

  • QKVM shows and acts. Typing and moving the mouse happen in the device's own console, one click away.
  • On a real JetKVM the picture, the status and restarting it have been tried and work; typed text and power control have so far only been tried against a stand-in.
  • Servers are new. On real boards (ASRock Rack, Gigabyte) reading a server's state, its locator light, shutting it down, switching it on and restarting its controller work. A power cut was once accepted by a controller and not carried out; QKVM now says so when that happens, and why it happened is still being looked into. A server has no picture on the wall, because Redfish has none.
  • KVMs that have two-factor login switched on are not supported.

Look at it before you install anything.

The demo is the real page with made-up machines. Nothing to sign up for, nothing sent anywhere.