nm
Node Manager
← Back to dashboard

Help & Getting Started

Everything you need to manage a fleet of Nodofi Nodes from this dashboard β€” from adding your first node to day-to-day review, key rotation, remote access, and shared ghost-protection groups.

Overview

Node Manager is a standalone fleet dashboard for anyone running more than one Nodofi Node β€” your own, or on behalf of clients (an agency/MSP use case). Instead of signing in to every node individually, you add each one here once and manage all of them from a single screen: review queues, app keys, remote access, and Beezifi ghost protection.

This dashboard never asks for, or stores, a node's real admin password. Each node mints its own narrowly-scoped management token (looks like bnm_a1b2c3…), which you paste in here. A token can only reach that node's admin API β€” nothing wider β€” and you can revoke it from the node itself at any time, instantly cutting this dashboard off from it.

Note: A Node Manager account and a Nodofi Node's own admin login are completely separate things. Signing in here does not sign you in to any node, and vice versa.

Before you start

You'll need:

  • One or more Nodofi Nodes already running and reachable at an address you can type into a browser (e.g. https://node1.example.com, or http://localhost:8800 for a node on this same machine).
  • Remote access turned on for each node you want to manage from here (a node's own dashboard β†’ Remote access section) β€” a management token only works while that's on, the same kill switch that governs an interactive remote login.
  • Admin access to each node, to create a management token (see Step 2).

1 Create your Node Manager account

Open this dashboard and click Need an account? Register instead on the sign-in screen. Enter an email and a password (at least 8 characters) and submit β€” you're signed in immediately, no email confirmation step.

Example
Email: ops@acmehosting.com  Β·  Password: a real, unique password β€” this account can reach the admin API of every node you add, so treat it with the same care as those nodes' own remote-access credentials (see Security notes).

Want a second factor? Set one up any time afterward from Account settings β€” it's optional and off by default.

2 Mint a management token on each node

This has to be done on the node itself, not here β€” only a node's own owner can decide it should trust this dashboard.

  1. Open that node's own admin dashboard (e.g. https://node1.example.com) and sign in.
  2. Go to the Security section.
  3. Under Management tokens, click Create token.
  4. Give it a label that tells you where it's used β€” this matters once you have several nodes, each possibly with tokens for more than one fleet manager.
  5. Copy the token shown (bnm_…). This is the only time it's ever shown β€” if you lose it, revoke it and create a new one.
Example
Label: Node Manager β€” Acme Ops
Token: bnm_7f3a9c2e1d8b4056a1f0e9c7d2b8a4f6e3c1d9b7a5f2e0c8

A descriptive label is especially useful if the same node is ever managed by more than one Node Manager instance (e.g. one for you, one for a client) β€” each gets its own token, independently revocable.

Warning: Anyone with this token can do anything a signed-in admin session on that node can do. Copy it straight into Node Manager (next step) and don't paste it anywhere else, store it in plain text, or send it over an unencrypted channel.

3 Add the node here

  1. In Node Manager's sidebar, click + Add node (or + Add your first node on the empty-state screen).
  2. Fill in three fields:
FieldWhat to enterExample
LabelAnything that helps you recognize it in a listClient A β€” production
Node addressThe full URL you use to reach that node's dashboardhttps://node1.example.com
Management tokenThe bnm_… token from Step 2bnm_7f3a9c2e…

Click Add node. Node Manager verifies the token against the real node before saving anything β€” if it's wrong, already revoked, or the node can't be reached, you'll see a clear error right there and nothing broken is left sitting in your list.

Note: Repeat Steps 2–3 for every node you want to manage from here. There's no limit on how many you can add.

4 Tour the dashboard

Once you've added a node, the sidebar lists it with a status dot. Click it to open its detail view:

At a glance β€” app count, pending submissions, relay/registry status
Review queue β€” apps submitted without a key, waiting on your decision
Actions β€” rotate app key, toggle remote access, toggle ghost protection

Everything you do here is a thin pass-through to that node's own admin API β€” the node itself always has the final say on what's actually allowed.

Reviewing submissions

Anyone can send a node an app with no key at all β€” it queues for the node's owner to approve or reject rather than going live immediately. Each entry in the queue shows the app's name, description, publisher, size, and whether it would replace an already-live app at the same id.

  • Approve β€” publishes it through the exact same path a trusted, keyed send uses.
  • Reject β€” optionally give a reason; the submitter (who has no account on that node) can check their submission's status and see it.
Example
A submission named "Weather Widget v2" shows up in the queue. You open it, review the files, and click Reject with the reason "Please resubmit with an app icon". The submitter resubmits the same app id after adding one β€” their fix automatically clears the earlier rejection.

Rotating the app key

A node's app key is what Nodofi Studio uses in its "Send to Node…" dialog to publish directly (skipping the review queue). From a node's detail view here, Rotate key immediately invalidates the old one and generates a new one β€” copy it and update it wherever it's used (e.g. in Studio) before the old one is needed again.

Warning: Rotating is immediate and has no undo. Anything still using the old key (a saved "Send to Node…" config in Studio, a script) will start failing until it's updated with the new one.

Remote access

Toggles whether that node's own admin dashboard is reachable remotely at all (its interactive login, and management tokens like the one this dashboard uses). Turning it off here is an emergency lockdown you can reach for from anywhere β€” including cutting this dashboard itself off from that node instantly. Turning it back on has to be done from the node itself (physically, or over SSH) β€” the same deliberate asymmetry a node's own dashboard already enforces.

Ghost protection

Beezifi Security "Ghost Response" protection in front of a node's remote-login page only. From a node's detail view, toggle it on/off and set the Beezifi API key it should use. A request Beezifi's own rules reject gets back exactly the ghost response configured there (a fake page, a redirect, a plain block) instead of ever reaching the node's real login.

Managing several nodes that should all share the same Beezifi ruleset? See Groups below instead of setting this individually on each one.

Removing a node

From a node's detail view, This dashboard β†’ Remove unlinks it from Node Manager only.

Warning: Removing a node here does not revoke its management token. The token keeps working until you also revoke it from that node's own Security section β€” do both if you want the node fully cut off from this dashboard.

Groups: nodes that share one ghost-protection setting

A group lets you manage Beezifi ghost protection for several nodes as a single shared setting β€” since Beezifi's rules are keyed by API key, "shared protection" really means "shared key."

Worked example
  1. Click Groups in the sidebar β†’ + New group β†’ name it West Coast Clients.
  2. From each node's own detail view, open its Group card and assign it to West Coast Clients β€” do this for three nodes: client-a, client-b, client-c.
  3. Back in Groups…, click Ghost protection… for West Coast Clients, turn it on, and paste in one Beezifi API key.
  4. Click Save & apply β€” Node Manager pushes that setting to all three nodes and reports success/failure for each individually, so one unreachable node never hides whether the other two got it.

A grouped node's own individual ghost-protection toggle is refused (not just hidden) so it can never quietly drift out of sync with the rest of the group β€” remove it from the group first if you need individual control again. Deleting a group only detaches its members; whatever setting was last pushed keeps running on each of them.

Reading status at a glance

DotMeaning
● reachableNode answered normally on the last check.
● degradedNode answered, but something about the response wasn't fully as expected.
● unreachableCould not reach the node, or its management token was rejected (wrong or revoked).

Changing your password

Account settings… (sidebar) β†’ enter your current password and a new one (at least 8 characters). It takes effect immediately and signs you out everywhere, including this session β€” sign back in right away with the new password.

Authenticator app (2FA)

Optional, off by default. From Account settings…:

  1. Click Set up an authenticator app… β€” a QR code appears.
  2. Scan it with Google Authenticator, Authy, 1Password, or similar (or enter the text secret shown underneath by hand).
  3. Enter the current 6-digit code it shows you and click Confirm and finish.

Confirming it enabled signs out every other open session, since a newly-required factor shouldn't leave an already-open tab exempt from it. To turn it back off, go to the same place and enter your password to confirm β€” this does not sign anyone out, since removing a factor is a verified relaxation, not something that needs a fresh login.

Note: Sign-in is rate-limited per IP address (a growing delay after a few wrong attempts) β€” relevant now that a 6-digit code is part of what's being guessed against, not just a password.

Troubleshooting

"That token was rejected" when adding a node

Either the token was mistyped/truncated when copied, it was already revoked on the node, or that node's Remote access is currently switched off (a management token stops working the instant remote access does β€” see Remote access). Create a fresh token from the node's own Security section and try again.

A node shows "unreachable" but I can open its dashboard in a browser

  • Confirm the address saved here is the exact one the node answers on, including https:// vs. http:// and any non-default port.
  • Confirm nothing between this dashboard's server and the node (a firewall, a reverse proxy) blocks the request even though your own browser, elsewhere on the network, can reach it fine.
  • Confirm the node's Remote access is on β€” a browser session already signed in locally can look fine to you while a token-based request from elsewhere is correctly refused.

I can't toggle ghost protection on one of my nodes

It's probably in a group β€” a grouped node's individual toggle is refused on purpose, so it can't drift out of sync with the rest of the group. Remove it from the group to regain individual control, or change the setting at the group level instead.

I lost a management token before saving it anywhere

It can't be retrieved β€” go to that node's own Security section, revoke the old (effectively already lost) token, create a new one, and update it here (remove and re-add the node, or edit it if your version of the dashboard supports editing in place).

FAQ

Does Node Manager store my nodes' admin passwords?

No β€” never. Only an encrypted management token per node, which can only reach that node's admin API, nothing wider, and is only as powerful as that token's own scope.

Can more than one person manage the same node from different Node Manager accounts?

Yes β€” mint a separate, clearly labeled management token on the node for each one. Revoking one never affects the others.

What happens to a node if I delete my Node Manager account?

Nothing on the node itself changes β€” its management tokens keep working until revoked from the node's own Security section. Removing/deleting things here only ever affects what this dashboard remembers.

Is there a limit to how many nodes I can manage?

No hard limit built into the product.

Security notes

  • This dashboard can do anything a signed-in admin session on a managed node can do β€” treat your Node Manager account with the same care as a node's own remote-access credentials.
  • A management token is encrypted at rest, but this service must be able to decrypt it to call the node β€” protect this service's own deployment (its .env, its database) the same way you'd protect any credential store.
  • Removing a node here is not the same as revoking its access β€” see Removing a node.
  • Set up an authenticator app on your Node Manager account, especially if more than one person has its login.