Infrastructure Documentation
Zero-fluff technical manual for 56KLabz software, SSH server farm configuration, authentication protocols, and troubleshooting.
01. System Prerequisites
NovaDash communicates directly with target servers via native OpenSSH protocol (Port 22 or custom ports). No proprietary middleman servers or agent daemons are required on your target nodes.
Supported Operating Systems
- • Linux Distributions: Ubuntu (18.04+), Debian (10+), RHEL / Rocky / AlmaLinux (8+), Fedora, Arch Linux, Alpine Linux, Gentoo.
- • Windows Operating Systems: Windows Server 2019, 2022, 2025, Windows 10/11 (with OpenSSH Server capability enabled).
- • UNIX & BSD: FreeBSD, OpenBSD, macOS (10.15+).
Required OpenSSH Daemon Configuration
Verify that your target machine's OpenSSH configuration (/etc/ssh/sshd_config) satisfies the following minimum directives:
After updating sshd_config, restart the SSH daemon to apply changes:
02. Authentication & Key Management
56KLabz software supports both standard password authentication and military-grade RSA / Ed25519 keypair authentication.
Step 1: Generate Keypair (Ed25519 / RSA 4096)
Open a terminal on your client machine and execute one of the following key generation commands:
Step 2: Install Public Key onto Remote Server
Copy your generated public key (~/.ssh/id_ed25519.pub) to the target server's authorized keys list:
Step 3: Enforce Strict POSIX File Permissions
OpenSSH will silently reject authentication if permissions on .ssh or authorized_keys are too permissive. Run these commands on the target server:
03. Everyday Playbooks & Real-World Uses
You don't need a computer science degree or 10 years of Linux terminal experience to get incredible value out of NovaDash. Whether you want to restart a crashed gaming server from your couch, monitor GPU temps, move 4K videos without paying cloud fees, or turn an old phone in your junk drawer into a 24/7 server, here is how real people use NovaDash every day.
⚡ The Non-Nerd Jargon Buster
Tech terms sound scary until you realize they are just fancy names for simple everyday tools:
🎮 Real-World Playbooks
- Open NovaDash on your phone and tap your gaming machine or server.
- Tap the Docker tab (if your game runs in Docker) or the Services tab (if it runs as a WindowsGSM or Linux service).
- Find your game server in the list (e.g.
palworld-server,minecraft-paper). - Tap Restart. NovaDash sends the restart signal instantly—your server boots back up in 3 seconds without you ever touching a keyboard.
- Tap View Logs to see live player connect/disconnect events and in-game console messages scrolling right on your phone.
- Pro Lag Tip: Glance at the RAM gauge. If RAM is sitting at 99%, you know your server is out of memory and needs a quick restart or player cleanup.
- Install Termux or an SSH server app on your spare Android device.
- Add that phone to NovaDash as an active node using its local Wi-Fi IP.
- Now you have a dedicated 8-core, 8GB RAM computer running automations, Pi-hole network ad-blocking, or a custom Python bot for 30 cents a month in power.
- Built-In Battery Backup: Because it's a phone, if the power flickers or goes out in a storm, your server stays online for 10+ hours on its internal battery while traditional computers turn off.
- ⚠️ How to Prevent Battery Swelling (Crucial!): Never leave an old phone plugged into a charger at 100% 24/7. Plug its charger into a cheap $8 smart plug set to turn off when the battery hits 80% and turn on when it drops to 20%. The battery will never degrade or swell.
- Open NovaDash and tap your computer.
- Tap the Files (SFTP) tab.
- Browse your PC's folders just like a file manager (e.g.
Downloads,Videos, orStorage). - Tap the Upload (⬆️) button in the top corner and pick any photo, video, or folder on your phone.
- Files fly directly across your home Wi-Fi at 500+ Mbps with zero cloud data tracking, zero compression, and zero subscription fees.
- Open NovaDash and tap your PC.
- Glance at the live gauge dashboard:
- Per-Core CPU Usage: See exactly which cores are pegged at 100%.
- NVIDIA GPU Gauges: Live VRAM utilization, core clock speed, power consumption in Watts, and die temperature in °C.
- Disk Fill Rates: See how fast your SSD is filling up as renders complete.
- If a background program freezes or runs away, tap the Processes tab, find it, and tap Kill with one touch.
sudo apt update or docker-compose down.
- In NovaDash, open the Terminal and swipe open the Macros ⚡ panel.
- Tap + New Macro and create one-touch buttons for your favorite commands:
🔄 Reboot Machine→sudo reboot🧹 Clean Junk Files→docker system prune -f && sudo apt autoremove -y📦 Update Everything→sudo apt update && sudo apt upgrade -y
- From now on, whenever you need to run maintenance, just tap the button. NovaDash executes the whole sequence with zero typing errors.
- Use the Modifier Key Bar docked above your keyboard for instant access to
[ESC],[CTRL],[ALT],[TAB], and directional arrows.
- In NovaDash, tap Port Forwarding → + Add Tunnel.
- Set the Remote Port to your dashboard's internal port (e.g.
8080,9000, or10000) and set Local Port to8080. - Tap Start Tunnel.
- Open Chrome or Firefox on your phone and type
http://localhost:8080. - You are now viewing your private home dashboard securely through an encrypted SSH tunnel. No open router ports, no hackers, 100% private.
- When adding your PC to NovaDash, enter its network Ethernet MAC address once (found on your PC under network settings).
- Whenever your PC is turned off or in sleep mode, tap the Wake (⚡) button on its card in NovaDash.
- NovaDash broadcasts a "magic wake packet" across your home Wi-Fi, and your PC powers on instantly.
- Anti-Shoulder Surfing: NovaDash features a scrambled numeric keypad where digits 0–9 randomize their positions every time you open the app, so onlookers and cameras cannot guess your PIN from your finger movements.
- The Duress Panic PIN: In the NovaNox Security Hub, set a secondary secret PIN (e.g., if your real PIN is 1234, set your Duress PIN to 9999).
- If anyone ever forces you to unlock NovaDash, enter
9999. - What Happens: In a fraction of a millisecond, NovaDash silently destroys every saved root password and SSH private key on your phone and displays a clean, empty dashboard with zero alarm banners. Your servers remain 100% protected.
- When safe, restore your servers in seconds using your 16-character offline Emergency Recovery Sheet key.
05. NovaNox Security™ Suite — Field & Operating Manual
NovaNox Security is NovaDash's native, zero-cloud defensive security layer. It protects high-privilege infrastructure credentials, root passwords, and unrestricted Ed25519 private keys using authenticated cryptography, anti-shoulder-surfing mechanisms, and anti-coercion panic safeguards.
1. Security Profiles & Defensive Postures
NovaNox provides pre-configured defensive profiles tailored for different physical threat environments:
| Profile | Auto-Lock Timeout | Default Lock | Defensive Posture |
|---|---|---|---|
| 🛋️ Homelab Chill | 30 Minutes | Standard Layout / Biometrics | Relaxed trusted home LAN posture. Retains session access when switching apps briefly. |
| 🛡️ Standard Pro (Default) | 5 Minutes | Biometrics / Encrypted PIN | Balanced daily professional driver. Biometrics and App Switcher Privacy Shield active. |
| 🏰 Fort Knox | Immediate (0s) | Scrambled PIN + Duress Armed | Maximum physical security. Locks instantly on minimize, randomized anti-shoulder keypad, invisible pattern trail, and Duress Panic armed. |
| 🎛️ Custom | Configurable | User Selected | Granular manual configuration across all security switches and timeouts. |
2. Lock Mechanisms & Setup
Configure your lock under Settings → NovaNox Security Hub → Lock Mechanism:
- • Hardware Biometrics (Fingerprint / Face ID): Direct native integration with Android BiometricPrompt and iOS LocalAuthentication for instant authenticated unlock.
- • Numeric PIN (4–8 Digits): Fast numeric code hashed locally using salted cryptographic PBKDF2 / SHA-256 with optional dynamic keypad scrambling.
- • 3x3 Gesture Pattern: Drag-to-connect 9-dot matrix pattern with optional invisible trail.
- • Master Passphrase: Full alphanumeric passphrase for maximum entropy.
- • Disabled (No Lock): Removes entrance gating for trusted or headless bench devices.
3. Anti-Surveillance & Defensive Controls
- 🔢 Scramble PIN Keypad: Dynamically randomizes the 0–9 keypad positions on every lock screen appearance. Anyone watching finger coordinate positions or overhead CCTV cameras cannot determine your master PIN.
- 〰️ Invisible Pattern Trail: Hides the graphical trace lines when drawing your gesture pattern, eliminating visual pattern leakage.
- 🕶️ Privacy Shield (App Switcher): Instructs the OS window manager to obscure and blur NovaDash's screen buffer in the multitasking switcher, preventing sensitive server IPs, shell histories, and credentials from remaining cached in system screenshots.
- 🔐 Step-Up Re-Authentication: Demands explicit biometric or PIN re-verification before decrypting or revealing stored SSH passwords and private keys, even while the app is actively running.
4. Anti-Coercion Duress Panic Vault
In high-threat scenarios where an operator is compelled under physical duress or seizure to unlock the app:
5. Emergency Recovery Safety Net
If an operator forgets their master code or gesture pattern:
- 1. Emergency Recovery Sheet: A 16-character offline rescue code (
56K-REC-XXXX-XXXX-XXXX) generated upon initialization. Entering this offline key resets lock credentials immediately without data wipe. - 2. Rate-Limiting Throttles: Exponential backoff after 5 incorrect attempts (30s lock, 60s lock, full lockout) to stop brute-force attacks.
- 3. Safe Vault Reset: If recovery is required, your purchased Pro / Lifetime license tier and node configurations are preserved while resetting the lock code.
04. NovaDash Step-by-Step How-To Guide
Welcome to the official NovaDash Step-by-Step How-To Guide! If you're asking "How do I do X in NovaDash?", this is your complete walkthrough. Follow the steps below for each feature.
1. HOW TO ADD YOUR FIRST SERVER
- Open NovaDash and tap the blue "+" (Add Server) button in the bottom corner of your screen.
- In the "Server Name" field, give your server a recognizable nickname (e.g. "Home Plex", "Ubuntu-Main", "Database-01").
- In the "Host / IP" field, enter your server's IP address:
- For home Wi-Fi: use your local IP (e.g. 192.168.1.50 or 10.0.1.50).
- For remote access: use your domain name, WAN IP, or Tailscale / WireGuard VPN IP.
- Set the SSH Port (default is 22 unless you changed your sshd port).
- In the "Username" field, enter the remote user account (e.g. "root", "ubuntu", or "admin").
- Choose your Authentication Method:
- Password: Enter your SSH account password.
- SSH Key: Select an existing key from your NovaDash Key Vault or import a .pem / id_ed25519 file.
- (Optional) Select a Color & Group Tag (e.g., "Homelab", "Production", "Storage") to organize your servers and nodes.
- Tap "Test Connection" to verify everything connects, then tap "Save Server".
2. HOW TO SET UP & USE SSH KEY AUTHENTICATION
- Tap "Settings" in the bottom navigation bar and select "SSH Key Vault".
- Tap "+ Generate Keypair".
- Select "Ed25519" (recommended for modern security) or "RSA 4096", and give the key a name (e.g. "Phone-Master-Key").
- Tap "Generate". NovaDash will generate the pair and display your Public Key.
- Tap "Copy Public Key".
- On your remote server, paste that public key into your authorized keys file:
$ echo "PASTED_PUBLIC_KEY_HERE" >> ~/.ssh/authorized_keys
$ chmod 600 ~/.ssh/authorized_keys - Now edit your server in NovaDash, select "SSH Key", choose your new key, and connect with zero passwords needed.
3. HOW TO CONNECT VIA JUMP HOST (BASTION PROXY)
- Make sure your Jump Host / Bastion server is already added to NovaDash.
- When adding or editing your private, internal server (e.g. 192.168.1.150):
- Scroll down and expand "Advanced Settings / Jump Host".
- Toggle "Use Jump Host" to ON and select your Bastion server from the dropdown.
- Tap "Save Server".
- NovaDash will automatically route SSH traffic through the Bastion proxy so you can reach isolated subnets.
4. HOW TO MONITOR HARDWARE, MULTI-GPU & THERMALS
- Tap on any connected server from your Node Grid to open its NOC Overview.
- Real-time metrics stream automatically:
- CPU & Load: Per-core usage bars and 1m/5m/15m load averages.
- Memory & Swap: Physical RAM percentage, active swap usage, and buffers/cache.
- NVIDIA GPUs: If an NVIDIA card is installed, view core utilization %, VRAM used/total, power draw (W), and die temperature (°C).
- Thermals: Live ACPI thermal zones on Windows and /sys/class/thermal sensors on Linux.
- Disk & Network I/O: Live graphs showing real-time network download/upload bandwidth and disk read/write throughput.
5. HOW TO FIND & KILL HIGH-RESOURCE PROCESSES
- In the server screen, tap the "Processes" tab.
- View running processes sorted by CPU or Memory usage.
- Use the search bar at the top to filter by process name or PID (e.g. "python", "plex", "ffmpeg").
- Tap on any process to view its parent PID, memory usage, and command arguments.
- Tap "Kill Process" and choose:
- SIGTERM (15) for graceful termination.
- SIGKILL (9) for forced immediate kill.
6. HOW TO OPEN A TERMINAL & USE THE KEYBOARD HOTBAR
- From your Node Grid, tap on any connected server card.
- Tap the "Terminal" tab or icon to launch the live SSH shell.
- Tap anywhere in the terminal to bring up your device keyboard.
- Notice the custom Modifier Hotbar docked right above your keyboard:
- Tap [CTRL], [ALT], or [ESC] to send modifier keys.
- Tap [TAB] for bash auto-completion.
- Tap the arrow keys [ ▲ ][ ▼ ][ ◄ ][ ► ] to navigate through htop, btop, or nano.
- Tap the [📋] button to paste multi-line commands from your phone clipboard.
- To open multiple terminal sessions simultaneously on the same server, tap the "+" tab at the top of the terminal screen.
7. HOW TO CREATE & RUN TERMINAL SHORTCUTS (MACROS)
- Open the Terminal screen and tap the "Macros ⚡" drawer button.
- Tap "+ New Macro".
- Enter a Title (e.g. "Docker Restart All" or "Apt Update") and the command script.
- Save the macro.
- Next time you are in the terminal, open the macro drawer and tap your saved macro — NovaDash will execute it instantly without you typing it out.
8. HOW TO MANAGE DOCKER CONTAINERS & STREAM LIVE LOGS
- Tap on your server from the Node Grid and select the "Docker" tab.
- View the list of all running and stopped containers.
- Tap on any container card to open its action panel:
- Tap "Start", "Stop", "Restart", or "Pause".
- To view real-time container output, tap "View Logs". You will see live standard output and errors stream directly to your phone screen.
- To view Docker Compose stacks or prune unused images/volumes, swipe to the "Compose" or "Prune" sub-tabs.
9. HOW TO RESTART OR INSPECT A LINUX SYSTEMD SERVICE
- Inside your server's details screen, tap "Services".
- Use the search bar at the top to find your service (e.g., "nginx", "plex", "ssh", "docker").
- Tap on the service name:
- Tap "Restart Service" or "Stop Service" to manage its lifecycle.
- Tap "Enable / Disable" to set whether it boots on startup.
- Tap "Live Journal" to stream real-time journalctl logs for that specific unit.
10. HOW TO STREAM SYSTEM LOGS (JOURNALCTL)
- Inside your server's details screen, tap "Logs".
- View the unified system log stream.
- Filter logs by priority (Emergency, Alert, Error, Warning, Info) or filter by unit name.
- Tap "Auto-Scroll" to watch log entries stream live in real time.
11. HOW TO MANAGE VIRTUAL MACHINES (KVM / VIRTUALBOX)
- In the server screen, tap the "VMs" tab.
- NovaDash will query virsh (KVM/Proxmox) and VBoxManage to list your virtual machines.
- View each VM's state (Running, Paused, Shut Off), assigned RAM, and virtual CPUs.
- Tap on any VM to trigger power actions: Start, ACPI Shutdown, or Force Reset.
12. HOW TO USE THE SFTP FILE BROWSER
- In the server screen, tap the "Files / SFTP" tab.
- Browse remote directories by tapping folders.
- Tap the "Upload" icon in the top right to pick a file from your phone storage and send it to the current server directory.
- Long-press on any file or folder to:
- Download it to your phone.
- Rename or Delete it.
- Change POSIX permissions (chmod) using interactive permission checkboxes.
13. HOW TO SET UP SSH PORT FORWARDING (DATABASE / WEB ACCESS)
- In the server screen, tap "Port Forwarding".
- Tap "+ Add Tunnel".
- Configure your tunnel:
- Remote Port: The port on your server (e.g., 5432 for Postgres, 8000 for a web dashboard, or 10000 for Webmin).
- Local Port: The port on your phone (e.g., 5432).
- Tap "Start Tunnel".
- You can now open your mobile web browser or mobile database app and navigate to "http://localhost:5432" — NovaDash securely routes the connection through your encrypted SSH tunnel.
14. HOW TO POWER ON A SLEEPING SERVER (WAKE-ON-LAN)
- When adding or editing your server profile, enter your server motherboard's Ethernet MAC Address (e.g. "B0:35:9F:F3:C4:74").
- Save the server.
- When that server is powered off or asleep, tap the "Wake-on-LAN (⚡)" button directly on its server card.
- NovaDash will broadcast a magic packet over your local network to power the machine on.
15. HOW TO ORGANIZE YOUR SERVERS & NODES WITH TAGS & COLORS
- Edit any server in your list.
- Under "Tags", type or choose a tag name (e.g. "Homelab", "Production", "Storage", "Gaming", "Cloud").
- Choose an accent color for the server card.
- Save the server.
- On the Node Grid, tap any tag pill at the top of the screen to filter your servers instantly.
16. HOW TO SET UP NovaNox SECURITY & LOCK STYLES
- Tap "Settings" in the bottom navigation bar and select "NovaNox Security Hub".
- Choose one of the 4 Security Profiles:
- Homelab Chill: 30-minute auto-lock, standard layout.
- Standard Pro: 5-minute auto-lock, biometrics, App Switcher privacy shield.
- Fort Knox: immediate lock, scrambled keypad, invisible pattern trail.
- Custom: configure individual toggles yourself.
- Tap "Configure Master Lock":
- Choose your lock method: Scrambled PIN, 3x3 Gesture Pattern, Master Passphrase, or Biometrics.
- Enter and confirm your PIN/Pattern.
- On the next screen, NovaDash will generate your 16-character Emergency Recovery Sheet Key (e.g. "56K-REC-XXXX-XXXX-XXXX"). Write this key down in a safe place.
17. HOW TO SET UP THE DURESS PANIC PIN (COERCION PROTECTION)
- Inside the NovaNox Security Hub, tap "Duress Panic PIN".
- Enter a secondary PIN that is DIFFERENT from your main unlock PIN (e.g., if your real PIN is 1234, set duress to 9999).
- Save the Duress PIN.
- HOW TO USE IT: If you are ever forced or coerced into unlocking NovaDash against your will, enter the Duress PIN on the lock screen.
- WHAT HAPPENS: NovaDash silently purges every stored root password, SSH key, and server credential from your phone's encrypted vault in a split second, and cleanly opens an empty dashboard with no error alerts. Your servers remain 100% safe.
18. HOW TO RECOVER ACCESS IF YOU FORGET YOUR PIN OR PATTERN
- On the NovaNox lock screen, tap "Forgot PIN / Emergency Recovery" at the bottom.
- Select your recovery option:
- Option 1 (Emergency Key): Enter your 16-character sheet key (56K-REC-...). Your lock is reset instantly.
- Option 2 (Account Challenge): Verify your identity through your registered 56klabz.io account.
- Option 3 (Safe Vault Reset): Resets forgotten locks and clears stored passwords, while preserving your purchased Pro / Lifetime license.
19. HOW TO UNLOCK PRO & ACTIVATE YOUR LICENSE
- METHOD A (Online Auto-Unlock):
- Open NovaDash and tap "Account" or go to Settings.
- Enter your 56klabz.io account email and password and tap "Sign In".
- NovaDash automatically downloads your cryptographic Pro license key and unlocks Pro forever.
- METHOD B (Offline / Air-Gapped Activation):
- Log into your account at https://56klabz.io on any browser and copy your signed License Key string.
- Open NovaDash on your offline device.
- When on the Lockout / License screen, paste your key into the "Offline License Key" field and tap "Activate".
- The app validates the cryptographic Ed25519 signature on-device and unlocks immediately with zero internet connection needed.
20. HOW TO BACK UP & RESTORE YOUR ENTIRE SERVER ENVIRONMENT (.novabak)
- In NovaDash, tap "Settings" → "Export Encrypted Backup".
- Enter a strong backup password (used for PBKDF2 100,000-iteration AES-256 encryption).
- Tap "Export .novabak" and choose where to save or share the file.
- To restore on another phone or tablet:
- Open NovaDash on the new device, tap "Settings" → "Import Backup".
- Select your .novabak file, type your password, and your entire server list, macros, and settings will appear instantly.
06. Troubleshooting & Error Reference
Quick reference matrix for diagnosing and resolving common SSH network connection errors.
| Error Code | Root Cause | Resolution Procedure |
|---|---|---|
| Connection Refused | SSH daemon is stopped or port 22 is blocked by host firewall. | Verify daemon status: systemctl status sshd. Ensure UFW allows SSH: ufw allow 22/tcp. |
| Connection Timed Out | Host IP unreachable, network route missing, or WAN firewall blocking. | Verify IP with ping <IP>. If using Tailscale or WireGuard, confirm VPN status is active. |
| Permission Denied (publickey) | Public key not present in authorized_keys or file permissions incorrect. |
Execute POSIX permission fix: chmod 700 ~/.ssh && chmod 600 ~/.ssh/authorized_keys. |
| Host Key Verification Failed | Target server host key changed or IP address was reassigned. | Clear stale host key entry: ssh-keygen -R <IP_ADDRESS> and reconnect. |
Live Debugging Logs
To inspect real-time connection attempts on the target server, stream OpenSSH systemd logs: