UpSnap Wake on LAN Device Power Manager

AWS Networking

self hosted wake on lan and device power management for your own network

Base
Hardened build
minimal ports, security patches applied at build time
Access
Unique credentials
generated on first boot, readable only by root
Verified
Boots working
services pass a health gate before release
Support
24/7, 365 days
by email and live chat, 24 hour response SLA

Overview

UpSnap is a small, fast web application for powering the machines on your own network on and off. Register a device once with its MAC address, then wake it with a single click, reboot it, or shut it down with a command you define. A live dashboard pings every registered device so you always know what is up, and cron style schedules turn the whole thing into unattended automation, so a lab can power itself on before the working day and shut itself down after it.

Why the cloudimg image

The cloudimg image is closed by default. The application is bound to the loopback address and published only over HTTPS, authentication is mandatory on every device, wake, shutdown and discovery route, and the administrator password is generated on your own instance's first boot into a root only file, so no secret is shared between instances. The service runs as a dedicated non root account holding a single Linux capability, so a shutdown command you define can never become a root shell. Devices, schedules and users live on a dedicated, independently resizable volume, and the image ships with no device, no scan range and no scheduled command. A paired deployment guide and 24/7 support are included.

Common uses

  • Bring test labs and build farms up for a nightly job and drop them again afterwards
  • Power on a branch office workstation before someone travels to it, or shut a floor down on a schedule
  • Schedule media players and signage displays on and off around opening hours

Key features

  • Closed by default. The application binds to loopback only and is published solely over HTTPS through a TLS proxy. Authentication is mandatory and covers every device, wake, shutdown and discovery route. The build verifies, with services running, that an unauthenticated caller is refused on all routes and that nothing unexpected listens on a non-loopback address. No manual hardening is required - the security posture is enforced from first boot.
  • Nothing shared, nothing preloaded. The administrator password is generated on first boot of your own instance, is 28 characters, and is written to a root-only file. The database and token signing keys are created fresh on your instance rather than shipped, so no secret is common to two customers. The image carries no device list, no scan range and no scheduled command - it will not touch a machine on your network until you explicitly configure it to do so.
  • Least privilege, automation-ready, and fully supported. The service runs as a dedicated non-root account with exactly one Linux capability, so shutdown commands can never become a root shell. Application, TLS proxy, health endpoint and per-instance certificate are managed by systemd with devices and schedules on a dedicated resizable Amazon EBS volume. Cron-style scheduling enables unattended power-on and power-off for labs, offices and AV estates.

See it running

Real screenshots taken while testing this image against its deployment guide.

UpSnap Wake on LAN Device Power Manager screenshot 1 UpSnap Wake on LAN Device Power Manager screenshot 2 UpSnap Wake on LAN Device Power Manager screenshot 3 UpSnap Wake on LAN Device Power Manager screenshot 4

Description

This is a repackaged open source software product wherein additional charges apply for cloudimg support services.

## UpSnap - Self-Hosted Device Power Management by cloudimg

UpSnap is a small, fast web application for powering the machines on your own network on and

off. Register a device once with its MAC address, then wake it with a single click, put it to

sleep, reboot it, or shut it down with a command you define. A live dashboard pings every

registered device so you always know what is up, and cron-style schedules turn the whole thing

into unattended automation: a lab that powers itself on before the working day and shuts itself

down after it.

See the pricing tab on this listing page for the current software rate. AWS infrastructure costs

(EC2, EBS) are billed separately by AWS. A 7-day free trial is enabled on this listing, so you

can evaluate the product before any software charges apply. A comfortable starting instance is

m5.large.

## What It Is For

Wake on LAN is built into virtually every business-class network adapter, yet almost nobody uses

it because the magic packet has to originate on the same broadcast domain as the target machine.

UpSnap closes that gap: one small always-on host inside your network that holds the device list

and sends the packets, with a browser interface you can reach from anywhere you already trust.

  • Test labs and build farms - bring a rack of runners up for a nightly job and drop them

again after, instead of paying to idle

  • Branch offices and workshops - power on a workstation before someone travels to it, or

shut down a floor of machines on a Friday evening schedule

  • Media, signage and AV estates - schedule players and displays on and off around opening

hours

  • Home and small office servers - keep a NAS or workstation asleep and wake it only when it

is actually needed

## Closed by Default - Security Without Manual Hardening

A device power manager is a powerful thing to put on a network, and the upstream project is

explicit that it should not be published to the open internet. This image is built to match that

advice.

  • The application listens on the loopback address only. It is never bound to a public interface,

and nothing reaches it except through the TLS proxy in front of it.

  • Access is published only over HTTPS. Authentication is mandatory and covers every device,

wake, shutdown and discovery route. The build verifies that an unauthenticated caller is

refused on all of them.

  • The administrator password is generated on the first boot of your own instance, is 28

characters, and is written to a root-only file. Nothing is baked into the image and nothing is

shared between instances.

  • The image ships with no device list, no scan range and no scheduled command. It will not touch

a single machine on your network until you tell it to.

  • The build verifies, with services running, that nothing unexpected is listening on a

non-loopback address before the image is captured.

## Dedicated Amazon EBS Storage

The device database, schedules, permissions and user accounts live on their own dedicated Amazon

EBS volume - independently resizable and snapshotable, separate from the operating system disk.

That is the layout you would build by hand for a production deployment, ready from first boot.

## Ready To Use

  • Application, TLS proxy and health endpoint installed, wired together and managed by systemd,

with a per-instance TLS certificate issued on first boot

  • Administrator account and TLS certificate both created on first boot and written to a

root-only credentials file

  • Device discovery for your own subnet is available on demand, so adding a rack of machines does

not mean typing MAC addresses by hand

  • A per-user permission model lets you give someone the power button for one machine without

giving them the rest of the estate

## Deployment Notes

  • Deploy on any standard EC2 instance type; m5.large is a comfortable default
  • Keep the instance inside your own Amazon VPC and restrict the security group to trusted

networks

  • Magic packets reach devices on the same broadcast domain, so place the instance where it can

reach the network you intend to manage, or bridge to it with your existing VPN or Direct

Connect

## Get Started

Launch the AMI, SSH in, and read your unique administrator credentials from the root-only file.

Open port 443 to your trusted networks and sign in. The paired deployment guide covers the rest.

## cloudimg Support - 24/7

24-by-7 technical support by email and live chat covering deployment, first login, credential

rotation, TLS certificate replacement, device and schedule configuration, reaching your own

network, monitoring and sizing guidance.

UpSnap is distributed under the MIT License. All product and company names are trademarks or

registered trademarks of their respective holders. Use of them does not imply any affiliation

with or endorsement by them.

Related technologies

wake on lanwolmagic packetdevice power managementremote power onscheduled shutdownpower schedulinglab automationenergy savingnetwork device managerremote wakedevice dashboardcron schedule power