MARK PAUL
All projects
/projects/mytermix·systems· 2026
Featuredactive

mytermix — Self-Hosted SSH Platform

Deployment layer for running Termix as a bare-metal Node.js service behind Caddy + nginx on a small VM. Reverse-proxy configs, process supervision, firewall rules, and a runbook.

Overview

Termix is an open-source, self-hosted alternative to Termius — it packages SSH terminals, remote desktop, file management, tunnels, containers and host metrics into one web interface. mytermix is the deployment layer for running it bare-metal on a small Linux VM rather than through its Docker image. Only Caddy is reachable from the internet: it terminates TLS via Let's Encrypt HTTP-01, redirects HTTP to HTTPS and sets HSTS, then hands off to nginx, which routes by path, upgrades WebSockets and serves the built SPA. Termix's twelve internal subsystem ports (REST API, terminal WebSocket, tunnel relay, SFTP, metrics, Docker API, Guacamole, and more) are all bound to loopback only — never exposed. The repository holds no vendored application code, only the deployment layer: reverse-proxy configuration, process supervision, firewall rules and the runbook that ties it together.

Highlights

  • Bare-metal deployment instead of the upstream Docker image
  • Twelve subsystem ports all bound to loopback, none exposed
  • Reverse-proxy config, process supervision, firewall rules and runbook in one place

Technical architecture

  • Edge: Caddy on :443 and :80 — automatic TLS via Let's Encrypt HTTP-01, HTTP→HTTPS redirect, HSTS.
  • Internal hop: nginx on :8081 routes by path, upgrades WebSockets and serves the built SPA from dist/.
  • Backend: Termix runs as a supervised Node.js service with one listener per subsystem, all bound to 127.0.0.1.
  • Isolation: none of Termix's twelve internal ports appear in UFW; only Caddy is internet-reachable.
  • Repo scope: configuration and runbook only — the application itself is not vendored.
Stack
CaddynginxShellUFWLet's EncryptNode.jssystemd
Statusactive
Year2026