Linux server workspace · hardened development build

Keep watch.
Keep control.

Warden combines live monitoring, multi-user access, files, code, durable agent conversations, multiple terminal sessions, alert rules and revisioned website operations in one authenticated Go service.

Warden interactive terminal with PTY sessions
01

Operate

Explore files, edit workspaces, manage Git and use structured controls for services, users, SSH, firewall, Docker and more.

02

Multiple terminals

Run independent authenticated PTYs in tabs, retain bounded SQLite scrollback and move the same terminal surface between Editor and Terminal.

03

Agent sessions

Supervise parallel OpenCode conversations with account-owned transcripts, durable run evidence, provider selection and Markdown-aware output.

04

Alerts

Create duration-aware CPU, memory, disk and load rules with firing/resolved history and per-account acknowledgement.

05

Websites

Manage static sites and loopback proxies with unique domains, immutable revisions and explicit Caddy-fragment publish jobs.

06

Durable foundation

Transactional SQLite migrations persist operational state while compatibility mirrors preserve established backup and export workflows.

Know the boundary

Powerful by design.
Not a sandbox by implication.

Warden has server-side accounts, roles and capabilities, TOTP, encrypted secrets, CSRF protection, local-proxy hardening, WebSocket origin checks and SQLite audit history. Terminal and Agent access still execute with the Warden process user's OS authority.

Read the security and deployment notes