Drop a container. Your stack is monitored.
When something breaks, fixed rules catch it, the alert is pushed to you, and your AI agent investigates through the built-in MCP server.
Docker, Kubernetes, uptime, TLS, cron jobs, live logs, image updates, CVEs: auto-discovered, alerting on every one of them,
from a single Go binary that idles under 30 MB of RAM. No PromQL, no exporters, no dashboards to build.
Quick Start • Why maintenant • Agents • Features • Documentation • Editions • Pricing
# docker-compose.yml
services:
maintenant:
image: ghcr.io/kolapsis/maintenant:latest
ports:
# ⚠️ SECURITY: publishes the UI/API (no authentication of their own) on
# every interface; put an auth reverse proxy in front, or bind "127.0.0.1:8080:8080". See https://docs.maintenant.dev/security/#reverse-proxy-setup.
- "8080:8080"
read_only: true
security_opt:
- no-new-privileges:true
tmpfs:
- /tmp:noexec,nosuid,size=64m
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- /proc:/host/proc:ro
- /etc/os-release:/host/etc/os-release:ro
- maintenant-data:/data
environment:
MAINTENANT_ADDR: "0.0.0.0:8080"
MAINTENANT_DB: "/data/maintenant.db"
restart: unless-stopped
volumes:
maintenant-data:docker compose up -dOpen http://localhost:8080. Your containers are already there, with their health, restart loops, resources and logs. Nothing to configure.
Docker socket access is automatic: the entrypoint reads the mounted socket's group and grants it to the unprivileged user, on Compose and on Swarm (where docker stack deploy silently ignores group_add). A socket owned by group root needs DOCKER_GID=0. If containers do not show up, see Troubleshooting.
Kubernetes
kubectl create namespace maintenant
kubectl apply -f deploy/kubernetes/In-cluster API auto-detected, read-only RBAC, namespace filtering, workloads (Deployments, DaemonSets, StatefulSets) as first-class citizens. Kubernetes guide.
Bare Linux, no Docker at all (systemd, amd64 and arm64, statically linked)
curl -fsSL https://install.maintenant.dev | sudo bashEndpoints, certificates and heartbeats work without any container runtime. Container monitoring switches on by itself the moment a runtime shows up. Install documentation for pinned versions, air-gapped installs and supply-chain verification.
Cloud: one cloud-init file boots a hardened host with maintenant running on Hetzner Cloud, DigitalOcean, Scaleway, OVHcloud or Vultr.
Monitoring your own infrastructure with the standard stack means running Prometheus, Grafana, Alertmanager, node-exporter, cAdvisor, blackbox-exporter, a certificate exporter, Loki, Promtail, Trivy and something for image updates. Ten-odd components, each with its own config, upgrades and dashboards, to answer one question: is my stack up, and what is burning?
maintenant answers that question with one container.
| Built into maintenant | What you would assemble instead |
|---|---|
| Container state, health checks, restart loops | cAdvisor + node-exporter + alert rules you write |
| CPU, memory, network and disk, per container and per host | cAdvisor + node-exporter + Grafana dashboards you build |
| HTTP / TCP endpoint checks, declared as Docker labels | blackbox-exporter + a config file per target |
| TLS certificate expiry and chain validation | ssl_exporter |
| Cron and heartbeat deadlines | Pushgateway + alert rules you write |
| Live container logs, stdout/stderr demuxed | Dozzle, or Loki + Promtail |
| Image update detection, with compose-aware update and rollback commands | Diun or Watchtower |
Network exposure audit: 0.0.0.0 binds, exposed database ports, host network, privileged containers |
nothing standard |
| CVE enrichment and per-container risk score (Personal) | Trivy + its exporter |
| Alerts routed to Discord, webhooks, email, Telegram, Slack and Teams, with escalation (Pro) | Alertmanager |
| Public status page with incidents and subscribers | Cachet, Uptime Kuma, or a SaaS |
| One real-time dashboard for all of the above | Grafana + dashboards you build and maintain |
Do I still need Prometheus? maintenant monitors your infrastructure. Prometheus monitors your application. There is no PromQL here, no custom exporters, no panels to design: maintenant already knows what a container, a certificate, an endpoint, a cron job and a CVE are, and starts watching them the moment they appear. If you ship business metrics and write your own queries, keep Prometheus for that. The two answer different questions, and plenty of people run both.
Against the tools usually stacked up next to it:
| maintenant | Uptime Kuma | Portainer | Dozzle | |
|---|---|---|---|---|
| Container auto-discovery | Yes | No | Yes | Yes |
| MCP server, agent-ready | Built in | Third-party | Separate | No |
| Live container logs | Yes | No | Yes | Yes |
| HTTP/TCP endpoint checks | Yes | Yes | No | No |
| Cron/heartbeat monitoring | Yes | Yes | No | No |
| SSL certificate tracking | Yes | Yes | No | No |
| CPU/memory/network metrics | Yes | No | Limited | No |
| Image update detection | Yes | No | Yes | No |
| Network security insights | Yes | No | No | No |
| CVE enrichment, risk scoring | Personal | No | No | No |
| Public status page | Yes | Yes | No | No |
| Alerting with routing | Yes | Yes | Limited | No |
| Kubernetes native | Yes | No | Yes | No |
| Single binary, zero deps | Yes | Node.js | Docker API | Docker API |
| Runs without a runtime | Yes | No | No | No |
One container. One dashboard. Everything monitored.
Dashboard: uptime, response times, resources, unified monitors |
|
Unified alerts across every source |
Security posture with CVE enrichment and risk scoring (Personal) |
More screenshots
maintenant watches, your AI agent investigates. The loop has three steps:
- Detect. Fixed rules decide that something is down: consecutive failures, thresholds, missed deadlines, restart loops. No model is involved, so an alert is never invented and nothing is spent while everything is fine.
- Push. The alert leaves as a webhook:
alert.firedwhen it starts,alert.resolvedwhen it recovers, with the host it belongs to (agent_id) and a link back to it. - Investigate. Your agent receives the alert and queries maintenant's built-in MCP server: the container's logs, the endpoint's check history, CPU and memory, the other active alerts on the same host. You get a diagnosis, not just a red light.
flowchart LR
S[containers, endpoints,<br>certificates, cron jobs, hosts] --> M[maintenant<br>rules fire an alert]
M -- webhook --> A[your agent<br>Claude Code, OpenCode, n8n]
A -- MCP: logs, history,<br>active alerts --> M
With Claude Code. A small receiver (Python, standard library only) runs on the host next to maintenant. Each fired alert starts a headless Claude Code session that can only call maintenant's read-only MCP tools, and the diagnosis lands in reports/<alert-id>.md:
export RECEIVER_TOKEN=$(openssl rand -hex 32)
python3 examples/agent-webhook/receiver.py # listens on 127.0.0.1:9099# what the receiver runs for each alert
claude -p "maintenant just fired this alert: {...} Investigate it read-only." \
--setting-sources project --mcp-config mcp.json --strict-mcp-config --tools "" \
--allowedTools mcp__maintenant__list_alerts mcp__maintenant__get_container_logs \
mcp__maintenant__get_endpoint_history mcp__maintenant__get_resourcesmcp.json reaches maintenant over stdio with docker exec -i maintenant /app/maintenant --mcp-stdio, so no MCP port is opened. Point a webhook channel at the receiver with an Authorization: Bearer <token> header and route alerts to it with a trigger. The AI agents guide walks through the setup.
With OpenCode, the same receiver calls opencode run instead of claude -p, with maintenant declared as a local MCP server in opencode.json. With n8n, a Webhook trigger feeds an AI Agent node whose MCP Client tool points at your instance's /mcp endpoint.
Built-in Model Context Protocol server with 51 tools. Ask your AI assistant what is burning, read a container's logs, check the alert queue, acknowledge an alert, open an incident. stdio and Streamable HTTP transports, OAuth2 with a client id and secret for remote clients (Claude web, mobile and Desktop).
Every section links to its full documentation.
Zero-config auto-discovery for Docker, Docker Swarm and Kubernetes. Every container is tracked the moment it starts: state changes, health checks, restart loops, live log streaming with stdout/stderr demux. Compose projects are grouped automatically. Read-only: maintenant observes, it never touches your containers.
One central server, lightweight read-only agents on your other hosts, a persistent mutually-authenticated gRPC stream between them. No shared database, no message queue, no PKI to run: an agent enrolls with a one-time token and an Ed25519 keypair generated locally, and every stream is challenge-response authenticated. Revoke it from the UI at any time.
# On each remote host, one command, generated for you in the UI
docker run -d --name maintenant-agent --restart unless-stopped \
-v /var/run/docker.sock:/var/run/docker.sock:ro \
-v /proc:/host/proc:ro \
-v /etc/os-release:/host/etc/os-release:ro \
-v maintenant-agent-data:/var/lib/maintenant \
ghcr.io/kolapsis/maintenant:latest \
--mode=agent --server=grpcs://monitoring.example.com \
--enrollment-token=mnt_enr_XXXXXXXXXXXXXXXX --label="prod-worker-01"Agents detect their local runtime (Docker, Swarm or Kubernetes), stream container state, endpoints, certificates, host CPU/memory/disk, and reconnect on their own, replaying what they saw while disconnected as history. Every entity is attributed to its host, so nothing gets mixed across machines. Personal: up to 20 remote machines. Pro: unlimited.
Scans OCI registries: newer versions for fixed tags, and for floating tags like latest a comparison between the digest your container runs and the one the tag points at now. You know which images have an update before you docker pull blindly. Update and rollback commands for Compose, plain Docker, Swarm and Kubernetes, with the right cd into the Compose project. No Diun, no Watchtower, no extra container: it is part of the monitor.
Every monitored host reports its distribution and version; maintenant checks it against the support cycles of Debian, Ubuntu, RHEL, Rocky, Alma, Alpine and SLES and alerts 30 days before the free security support ends, then again once it has. Dates ship with the binary and refresh daily from endoflife.date when the network allows.
HTTP and TCP checks declared as Docker labels, picked up when the container starts, or added by hand. Endpoints can also be derived from Traefik and Caddy labels (opt-in). Response times, uptime history, 90-day sparklines, failure and recovery thresholds.
labels:
maintenant.endpoint.http: "https://api:3000/health"
maintenant.endpoint.interval: "15s"
maintenant.endpoint.failure-threshold: "3"Create a monitor, get a URL, add one curl to the job. maintenant tracks start and finish, duration, exit code, and alerts when the deadline is missed. Outbound heartbeats let two maintenant instances watch each other, so a dead monitor does not go unnoticed.
curl -fsS -o /dev/null https://now.example.com/ping/{uuid}/$?Auto-detected from your HTTPS endpoints, plus standalone monitors for any domain. Full chain validation, alerts at 30, 14, 7, 3 and 1 day before expiry, OCSP stapling checks (Personal).
Real-time CPU, memory, network and disk I/O per container and per host, top-consumers view for instant triage, per-container thresholds with debounce. History: 7 days on Community, 30 on Personal, 90 on Pro.
Flags what should not be there: ports bound to 0.0.0.0, exposed database ports, host-network mode, privileged containers, Kubernetes Services of type NodePort or LoadBalancer, and database ports exposed through them. Personal adds CVE enrichment (each image is mapped to its software ecosystem through OCI manifest inspection), a risk score per container and a unified security posture dashboard.
One alert pipeline for every source: container restart loops, unhealthy checks and stopped containers, endpoint failures, missed heartbeats, expiring or invalid certificates, CPU and memory thresholds, available updates, Swarm and Kubernetes health, agents going offline, hosts whose OS loses support. Channels are silent by default and routed through triggers (severity, source, scope). Alerts can be acknowledged. Silence rules for planned maintenance, three delivery attempts per notification.
Channels: Discord and webhooks (Community), email and Telegram (Personal), Slack and Microsoft Teams (Pro). Pro adds escalation policies of up to five levels that page the on-call, then the backup, then the lead, plus maintenance windows.
Real-time status page with severity aggregation across every monitor, live over SSE. Personal adds incident timelines, Pro adds email subscribers (double opt-in, through your own SMTP server), maintenance windows and branding.
Everything is driven by Docker labels and a handful of environment variables. No YAML to maintain.
- Environment variables: bind address, database, base URL, PostgreSQL DSN, MCP, Kubernetes namespaces, license key, telemetry.
- Docker labels reference: endpoints, TLS, alert severity, restart thresholds, update tracking, grouping, ignore.
- REST API under
/api/v1/, plus an SSE event stream.
Full stack example
services:
maintenant:
image: ghcr.io/kolapsis/maintenant:latest
ports:
# ⚠️ SECURITY: publishes the UI/API (no authentication of their own) on
# every interface; put an auth reverse proxy in front, or bind "127.0.0.1:8080:8080". See https://docs.maintenant.dev/security/#reverse-proxy-setup.
- "8080:8080"
read_only: true
security_opt:
- no-new-privileges:true
tmpfs:
- /tmp:noexec,nosuid,size=64m
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- /proc:/host/proc:ro
- /etc/os-release:/host/etc/os-release:ro
- maintenant-data:/data
environment:
MAINTENANT_ADDR: "0.0.0.0:8080"
MAINTENANT_DB: "/data/maintenant.db"
api:
image: myapp:latest
labels:
maintenant.group: "production"
maintenant.endpoint.http: "http://api:3000/health"
maintenant.endpoint.interval: "15s"
maintenant.alert.severity: "critical"
postgres:
image: postgres:16
labels:
maintenant.endpoint.tcp: "postgres:5432"
maintenant.alert.severity: "critical"
redis:
image: redis:7-alpine
labels:
maintenant.endpoint.tcp: "redis:6379"
volumes:
maintenant-data:- No built-in authentication, by design. Like Dozzle and Prometheus, maintenant sits behind your reverse proxy and auth middleware (Traefik or Caddy, Authelia or Authentik).
/ping/{uuid}and/status/are meant to stay public. Reverse proxy setup. - Read-only everywhere. Docker socket mounted
:ro, read-only RBAC on Kubernetes, read-only agents. maintenant never starts, stops or modifies a container. A socket proxy is supported if you would rather not mount the socket at all. - Hardened container. Drops to
nobody(uid 65534) once it has fixed the ownership of its volume,read_onlyroot filesystem,no-new-privileges. - Anonymous, opt-out telemetry. One snapshot per hour: counts of monitored objects, edition, storage engine, version and runtime figures (OS, architecture, CPU cores, memory). No hostnames, IPs, names, URLs or keys, ever.
MAINTENANT_DISABLE_TELEMETRY=1turns it off with no background goroutine and no outbound packet. Exact payload and details.
- One binary, three modes. Go backend, Vue 3 frontend embedded via
embed.FS, SQLite inside. The same file runsembedded(single host, default),server(central ingestion) andagent(remote host). - Zero dependencies. SQLite is the only datastore. No Redis, no queue, nothing to administer. A fleet operator may back the server on a PostgreSQL they already run; agents always stay on SQLite.
- Runtime optional. Endpoints, certificates and heartbeats run without any Docker socket or Kubernetes API. Container monitoring resumes on its own when a runtime becomes reachable.
- Real-time. SSE pushes every state change to the browser and to the status page instantly.
- Under 30 MB of RAM at idle. Runs on a Raspberry Pi, a €4 VPS or a NAS.
Full write-up in the architecture documentation.
Community is free forever and runs production infrastructure every day: it is the full product on a single host, not a crippled trial. Personal is bought once. Pro is what a team needs.
| Community | Personal | Pro | |
|---|---|---|---|
| Price | Free, Apache-2.0 | €149 once, for life | €29/mo or €290/yr, 14-day trial |
| Hosts | 1 | up to 20 remote machines | unlimited |
| Endpoints | 10 | unlimited | unlimited |
| Heartbeats | 5 | unlimited | unlimited |
| Certificates | 5 | unlimited | unlimited |
| Resource history | 7 days | 30 days | 90 days |
| Alert channels | Discord, webhooks | + email, Telegram, advanced filters | + Slack, Teams, escalation, maintenance windows |
| Security | network insights | + CVE enrichment, risk scoring, security posture, OCSP | same |
| Status page | 3 components | unlimited, incident timelines | + subscriber notifications, branding |
| Use | anything | your own infrastructure | + running it for others, email support |
Personal covers one person on infrastructure they own or run for themselves, freelancers included, and ships with one year of updates (then €59 per extra year; every version released inside a paid year stays licensed for life). Pro adds the right to monitor other people's infrastructure. Volume pricing and custom agreements: license@maintenant.dev.
Paid editions are the same binary, self-hosted the same way. The key is verified against the license server and the signed answer is cached: the instance falls back to Community only after 60 days without reaching the server, so a few weeks offline change nothing. Your monitoring data never leaves your infrastructure.
MAINTENANT_LICENSE_KEY=your-license-key # Personal or Pro, restart, done
Buy Personal, €149 once → · Start a 14-day Pro trial →
Stripe worldwide, Mollie in the EU (SEPA, iDEAL, Bancontact). VAT invoices. Cancel Pro anytime.
maintenant is built by one developer in Bordeaux, France. No VC, no ads, no acquisition exit. 100% of revenue funds full-time development. Ranked by impact:
- Buy a licence. Personal if the infrastructure is yours, Pro if you run it for others. Unlocks features and pays for the roadmap. See editions →
- Sponsor. Any amount, one-off or monthly, credited below. GitHub Sponsors →
- Spread the word. Star the repo, share on HN, Lobsters, Reddit or LinkedIn. Discoverability is oxygen for indie projects.
- Tell me how you use it. Two minutes, read by the developer, quoted only with your permission. Give feedback →
Every Personal owner, Pro subscriber and GitHub sponsor keeps this project independent. Thank you.
Want your company logo here? Become a corporate sponsor: visibility for you, runway for the project.
Code contributions are welcome. Open an issue first for bigger changes; small fixes, typos and docs, just send the PR.
Copyright 2025-2026 Benjamin Touchard / kOlapsis, Bordeaux, France.
The core is licensed under the Apache License 2.0. The code that Personal and Pro keys unlock, under internal/commercial/ and frontend/src/commercial/, is source-available under the Maintenant Commercial Source License: free to read and contribute to, production use requires a matching licence key. See NOTICE and COMMERCIAL-LICENSE.md.

Lauréat de l'AAP Hyper Open X. Ce projet a été financé par le gouvernement dans le cadre de France 2030.
Winner of the Hyper Open X call for projects, funded by the French government under France 2030.













