The lightweight, Linux-native process & application management platform.
Quick Install • Terminal UI • CLI Reference • Public Tunnels • Web Terminal • Web Dashboard • Comparison
Fire PM manages Linux systemd services without background daemons or extra state files. It includes a CLI, an interactive terminal UI (TUI), and a Next.js 15 web dashboard, plus quick HTTPS tunnels and a persistent web terminal (fire ssh).
- ⚡ Zero Daemon Overhead: Operates directly against
systemdand Linuxcgroups. No continuous runtime daemon eating 80+ MB of RAM just to monitor your processes. - 🖥️ Three Surfaces: Switch between a scriptable CLI, an interactive keyboard-driven TUI, and a full-featured web dashboard.
- 🌐 Zero-Config HTTPS Tunnels: Expose any local service to the internet with Cloudflare Quick Tunnels, or route through your own wildcard domain with dynamic Nginx mapping.
- 🔒 Persistent Remote Web Terminal (
fire ssh): Access an xterm-backed, password-protected server terminal in your browser with session persistence, 128 KB scrollback replay, and process group signal dispatching. - 📊 Live Log Streaming & Metrics: Real-time Server-Sent Events (SSE) streaming from
journalctl, live CPU/memory stats, and instant log flushing. - 🛡️ Kernel-Level Resource Limiting: Adjust Memory and CPU cgroup limits on running services on the fly (
fire limit api 512M 50%). - 🔄 State Snapshots & Boot Persistence: Save and restore process lists (
fire save/fire restore), and toggle system boot persistence (fire startup/fire unstartup). - 📦 Automatic Runtime Detection: Detects Python (virtualenv-aware), Node.js, shell scripts, and compiled binaries automatically.
Run the official installation script in your Linux terminal:
curl -fsSL https://raw.githubusercontent.com/Fire-Package/fire-pm/main/install.sh | sudo bashgit clone https://github.com/Fire-Package/fire-pm.git
cd fire-pm
sudo ./install.sh| Flag / Environment Variable | Description |
|---|---|
--with-web / FIRE_INSTALL_WEB=1 |
Build and configure the Next.js Web Dashboard during installation. |
--no-web / FIRE_INSTALL_WEB=0 |
Skip Web Dashboard build (installs CLI and TUI only). |
--force / -f |
Overwrite local modifications when reinstalling or updating. |
- Operating System: Linux with
systemd(Ubuntu 22.04+, Debian 12+, Fedora, RHEL/CentOS, Arch Linux). - Runtimes: Python 3.10+ (for TUI &
fire ssh), Node.js 20+ &pnpm(for Web Dashboard). - System Utilities:
procps,iproute2,curl.
Launch the full-screen terminal dashboard by running fire without arguments:
fire┌── Fire PM Terminal Dashboard ────────────────────────────────────────────────────────┐
│ NAME STATUS PID CPU MEM UPTIME AUTOSTART PORT │
│ api-server running 14201 0.4% 48.2 MB 2d 4h enabled :8080 │
│ worker-queue running 14255 1.2% 112.0 MB 2d 4h enabled - │
│ frontend running 15110 0.0% 64.5 MB 1d 18h enabled :3000 │
│ test-service stopped - 0.0% 0.0 MB - disabled - │
└──────────────────────────────────────────────────────────────────────────────────────┘
| Key | Action | Description |
|---|---|---|
| s | Start / Stop | Toggle execution state of the selected process. |
| r | Restart | Gracefully restart the selected service. |
| e | Edit Unit | Open built-in editor for the service unit file with instant reload. |
| m | Resource Limits | Configure Memory (e.g. 512M) and CPU quota (e.g. 50%) limits. |
| l | Logs | Open real-time journalctl log viewer. |
| c | Clear Logs | Flush accumulated logs for the selected service. |
| v | Live Cockpit | Open focused real-time monitoring cockpit. |
| i | Inspect | Display detailed systemd properties and environment variables. |
| t | Tunnels | Open the interactive tunnel manager modal. |
| d | Delete | Stop and remove service unit from systemd. |
| / | Search | Filter process list by name or status. |
| F5 | Refresh | Force immediate reload of system status. |
| q | Quit | Exit the terminal dashboard. |
# Start a script or binary (auto-detects Python, Node.js, or Bash)
fire start app.py --name my-api --env PORT=8080
# Load environment variables from a .env file (flags override file values)
fire start app.py --name my-api --env-file .env --env DEBUG=true
# Pass arguments directly to the target application
fire start worker.py --name worker -- --concurrency 4 --verbose
# Start with cgroup resource limits
fire start app.py --name heavy-task --memory 1G --cpu 80%
# Start a temporary process without auto-start on system boot
fire start worker.py --name temp-worker --no-startup
# Run under a specific Linux user
fire start app.py --name api --user www-data
# List all managed processes (tabular format)
fire list
# Machine-readable JSON output for scripting
fire list --json# Stop, restart, or delete a service
fire stop my-api
fire restart my-api
fire delete my-api
# Stop all processes or delete all stopped services
fire stop all
fire delete --stopped
# Inspect detailed service metadata and configuration
fire info my-api
# Open live monitoring cockpit for a specific process
fire live my-api
# Update CPU and Memory limits on an active service
fire limit my-api 512M 50%# Stream real-time logs from journalctl
fire logs my-api
# Flush and vacuum accumulated logs
fire flush my-api
fire flush all
# Real-time multi-process resource monitor
fire monit
# Comprehensive system health and configuration check
fire doctor
fire doctor --json# Enable or disable auto-start on system boot
fire startup my-api
fire startup all
fire unstartup my-api
# Save current running process state to snapshot dump
fire save
fire save /path/to/backup.json
# Restore all processes from snapshot dump
fire restore
fire restore /path/to/backup.json# Install automatic shell completions (Bash, Zsh, Fish)
fire completion install
# Output completion script for manual sourcing
fire completion bash
fire completion zsh
fire completion fish
# Self-update Fire PM to the latest version
fire update
# Force overwrite local changes during update
fire update --forceFire PM includes built-in reverse-proxy tunneling to expose local ports over secure public HTTPS URLs without requiring third-party CLI tools or paid accounts.
Instantly expose any local port over a Cloudflare-backed HTTPS URL with zero setup:
# Open a tunnel for local port 3000
fire tunnel open 3000
# Output: https://random-words.trycloudflare.com
# List active tunnels
fire tunnel list
fire tunnel list --json
# Close an active tunnel
fire tunnel close 3000Note
Fire PM forces Cloudflare tunnels to communicate via HTTP/2 over standard TCP port 443, preventing UDP/QUIC packet loss and ERR_QUIC_PROTOCOL_ERROR in restricted environments.
If you own a domain with a wildcard DNS record (*.yourdomain.com) and an SSL certificate, set up persistent, custom-branded tunnels powered by Nginx:
# Launch interactive configuration wizard
fire tunnel setup
# Open tunnel using your custom domain
fire tunnel open 3000 --provider custom
# Output: https://a1b2c3d4-tunnel.yourdomain.com
# Override default provider at any time
fire tunnel open 3000 --provider quick| Feature | Fire PM (Quick) | Fire PM (Custom) | ngrok (Free) | localtunnel | Tailscale Funnel |
|---|---|---|---|---|---|
| Setup Required | ❌ None | fire tunnel setup |
Account signup | npm install |
Tailscale auth |
| Account / Sign-up | ❌ None | ❌ None | ✅ Required | ❌ None | ✅ Required |
| Custom Wildcard Domain | ❌ | ✅ Your domain | Paid plan only | ❌ | ❌ |
| Persistent Hostnames | ❌ Dynamic | ✅ Stable | Paid plan only | ❌ Dynamic | ✅ Stable |
| Automatic HTTPS | ✅ Yes | ✅ Your certs | ✅ Yes | ✅ Yes | ✅ Yes |
| Rate Limits | Cloudflare fair-use | None (your server) | 40 req/min | Severe / unstable | Tailscale quotas |
| Concurrent Tunnels | Unlimited | Unlimited | 1 (free tier) | 1 | Restricted |
| Built into Process Manager | ✅ Yes | ✅ Yes | ❌ Separate tool | ❌ Separate tool | ❌ Separate tool |
Access your server's interactive terminal directly from any web browser over an encrypted, password-protected HTTPS tunnel.
- 📑 Multi-Tab Terminal Sessions: Open isolated PTY tabs (
1: bash,2: bash) in a single browser window with process-aware badges, title auto-sync, and independent tab kill/switch shortcuts (Alt+T, Alt+W, Alt+1..9). - 🔗 Read-Only Live Session Sharing: Share time-bound live terminal feeds (15m, 1h, 6h, 24h) for safe collaborative debugging or customer support without granting shell input access.
- 🔔 Task Alerts & Audio Chimes: Background tabs notify you via sound chimes and native desktop notifications whenever long-running commands or AI coding agent turns complete.
- 📁 Drag-and-Drop File Transfers: Drag files directly into the terminal window to upload them to the current working directory (
$PWD), or download files with one click. - 📶 Live Latency Telemetry: Real-time round-trip WebSocket ping monitor displayed on the toolbar badge.
# Start remote terminal session (interactively prompts for password)
fire ssh
# Start with a specific password and run in background
fire ssh --password mysecret123 --daemon
# Set or update persistent default password
fire ssh password
# List active terminal sessions
fire ssh list
# Terminate active remote terminal session
fire ssh close- Salted PBKDF2 Password Hashing: Passwords are authenticated using
PBKDF2-HMAC-SHA256with 100,000 iterations and a cryptographically unique 16-byte random salt. - Brute-Force Rate Limiting: Automatic IP lockout after 5 consecutive failed authentication attempts within a 5-minute window.
- Persistent PTY Lifecycle: PTY processes remain alive independently of browser disconnects. Reconnecting replays the last 128 KB scrollback buffer seamlessly.
- Kernel Signal Dispatching: Pressing Ctrl+C, Ctrl+Z, or Ctrl+D resolves the active foreground process group via
tcgetpgrpand dispatches signals directly to the process group (os.killpg), instantly stopping infinite stdout loops (e.g.yesor runaway logs). - Full Terminal Emulation: Backed by Xterm.js with 256-color support, dynamic window resize negotiation (
TIOCSWINSZ), and complete compatibility with interactive applications (fire,htop,vim,tmux).
A full-stack, responsive dashboard built with Next.js 15 (App Router), React 19, and Tailwind CSS v4.
# Start Web UI as a managed background service
fire start /opt/fire-pm/web/start.sh --name fire-web --env PORT=3000Open http://localhost:3000 (or your configured port). On first launch, set your administrator password to unlock:
- Live Process Overview: Real-time process cards and data tables updated every 3 seconds.
- Live SSE Log Streaming: Stream
journalctllogs with auto-scroll, regex search filtering, and line wrapping. - In-Browser Unit File Editor: Edit
/etc/systemd/system/fire-*.servicefiles with syntax validation and instantsystemctl daemon-reload. - Resource Limiting Controls: Dynamically slide and apply Memory & CPU limits.
- Integrated Tunnel Manager: Open and monitor Quick or Custom tunnels directly from the browser.
- Zero External Database: Reads directly from
systemdand/etc/fire-pm/config.json.
| Feature | Fire PM | PM2 | Supervisord | Raw systemd |
|---|---|---|---|---|
| Underlying Engine | Linux systemd |
Node.js daemon | Python daemon | Linux systemd |
| Daemon Memory Footprint | 0 MB (CLI / stateless) | ~80-120 MB | ~30-50 MB | 0 MB |
| Native Cgroups Limits | ✅ Instant (fire limit) |
❌ (Memory restart only) | ❌ | |
| Interactive Terminal UI (TUI) | ✅ Built-in (Textual) | pm2 monit |
❌ | ❌ |
| Developer Web Dashboard | ✅ Modern Next.js 15 | ❌ Paid / PM2 Plus | ❌ | |
| Public HTTPS Tunnels | ✅ Zero-config Quick + Custom | ❌ | ❌ | ❌ |
Remote Web Terminal (fire ssh) |
✅ Built-in PTY / xterm.js | ❌ | ❌ | ❌ |
| Live Log Streaming | ✅ Server-Sent Events (SSE) | journalctl -f |
||
| Multi-Language Detection | ✅ Python (venv), Node, Shell | ❌ Manual config | ❌ Manual config | |
| Boot Persistence | ✅ Native systemctl enable |
pm2 startup |
✅ Native | |
| Process State Snapshots | ✅ fire save / restore |
✅ pm2 save / resurrect |
❌ | ❌ |
flowchart TD
subgraph Interfaces["User Interfaces"]
CLI["CLI Engine (`app/fire`)"]
TUI["Terminal UI (`tui/fire_tui.py`)"]
WEB["Web Dashboard (Next.js 15 / React 19)"]
SSH["Web Terminal (`fire_ssh.py` / xterm.js)"]
end
subgraph Core["Linux Kernel & System Services"]
SYSTEMD["systemd (Single Source of Truth)"]
CGROUPS["cgroups v2 (CPU / Memory Quotas)"]
JOURNALD["journald (Structured Logs)"]
PTY["Kernel PTY Subsystem"]
end
subgraph Networking["Public Edge & Reverse Proxy"]
CF["Cloudflare Quick Tunnels (HTTP/2)"]
NGINX["Custom Wildcard Domain (Nginx)"]
end
CLI -->|systemctl / dbus| SYSTEMD
CLI -->|cgroups API| CGROUPS
CLI -->|journalctl| JOURNALD
TUI -->|IPC / subprocess| CLI
TUI -->|Direct query| SYSTEMD
WEB -->|systemctl execFile| SYSTEMD
WEB -->|SSE log tail| JOURNALD
WEB -->|cgroup limits| CGROUPS
SSH -->|WebSocket / PTY| PTY
SYSTEMD -->|Manages| CGROUPS
SYSTEMD -->|Streams to| JOURNALD
CF -.->|Encrypted HTTPS| WEB
CF -.->|Encrypted HTTPS| SSH
NGINX -.->|Encrypted HTTPS| WEB
NGINX -.->|Encrypted HTTPS| SSH
┌────────────────────────────────────────────────────────────────────────┐
│ USER INTERFACES │
│ CLI (`app/fire`) • TUI (`tui/fire_tui.py`) • Web (`web/`) │
└───────────────────────────────────┬────────────────────────────────────┘
│
▼
┌────────────────────────────────────────────────────────────────────────┐
│ LINUX KERNEL & SYSTEM LAYER │
│ │
│ • systemd (Single Source of Truth: No Duplicate State Machines) │
│ • cgroups (Kernel Memory & CPU Quota Resource Limits) │
│ • journald (High-Performance Structured System Logging) │
│ • PTY Subsystem (Persistent WebSockets Terminal Emulation) │
│ • Cloudflare HTTP/2 / Nginx (Encrypted Public Tunnels) │
└────────────────────────────────────────────────────────────────────────┘
systemdis the Single Source of Truth: Fire PM never maintains separate database state or caches that can drift out of sync. Status is resolved directly from systemd units.- Strict Argument-Based Execution: All subprocess invocations use structured argument vectors (
execFile/spawn) to prevent shell injection vulnerabilities. - Zero Configuration by Default: Works immediately after installation without requiring external databases, cloud accounts, or complicated configuration files.
fire-pm/
├── app/ # Core Bash process manager engine & fire ssh PTY server
│ ├── fire # Main executable CLI binary
│ ├── ff-service # Service status helper
│ └── fire_ssh.py # Remote Web Terminal WebSocket/PTY persistent engine
│
├── web/ # Next.js 15 App Router Web Dashboard
│ ├── src/app/ # Routes, pages, and REST/SSE API endpoints
│ ├── src/components/ # React 19 UI components
│ └── src/lib/ # Systemd, journalctl, auth, and tunnel services
│
├── tui/ # Python Textual Interactive Terminal Dashboard
│ ├── fire_tui.py # Full-screen TUI application
│ └── requirements.txt # Textual dependencies
│
├── assets/ # Screenshots and visual documentation assets
├── shared/ # Systemd template units and Nginx configs
├── install.sh # Automated multi-distribution Linux installer
├── AGENT.md # AI agent architecture reference & guidelines
└── CONTRIBUTING.md # Contribution guide & development instructions
- Cryptographic Password Storage: Passwords for Web UI and
fire sshare salted and hashed usingbcryptandPBKDF2-HMAC-SHA256(100,000 rounds). - Token Protection: Web authentication utilizes signed JWT tokens stored in
httpOnly,Secure,SameSite=Strictcookies. - Double-Submit CSRF Protection: All mutating API endpoints require valid CSRF header tokens.
- Input Sanitization: Service identifiers, command arguments, and port numbers are validated against strict regex patterns.
- Brute-Force Lockout: IP-level rate limiters automatically lock out repeat authentication failures.
Run fire doctor to perform an automated health audit of your environment:
fire doctor[✓] systemd subsystem: active and functional
[✓] Core utilities: procps, iproute2, curl found
[✓] Python environment: 3.11.2 (venv support ready)
[✓] Node.js environment: v22.16.0
[✓] Configuration: /etc/fire-pm/config.json valid
[✓] Managed services: 4 total (3 running, 0 failed, 1 stopped)
[✓] System health score: 100/100
# Inspect raw unit status
systemctl status fire-<service-name>.service
# Inspect raw journal logs
journalctl -u fire-<service-name>.service -n 50 --no-pager
# Reload systemd daemon after manual unit changes
sudo systemctl daemon-reloadContributions, issues, and feature proposals are warmly welcomed! Please read our Contributing Guide for local environment setup, coding conventions, and pull request workflows.
This project is licensed under the MIT License. See the LICENSE file for details.
Developed with ❤️ by Fire Package.






