Linux
curl -fsSL https://locus.casa/releases/install | sh
The script asks for a language, checks the machine, asks for the listen address, port, and data directory, then starts the service and prints the address to open.
Local Object & Capability Unified Space
Fewer addresses to remember.
Less upkeep for your start page.
Self-hosted. Find and open your NAS, servers, and self-hosted apps from one page.
Example environment. Device names and service data are for demonstration.
Machines pile up at home: a NAS, a home server running several apps, a dev box, and a router and a Raspberry Pi with admin pages of their own. Each one has its own address and port.
That is what LOCUS is for: NAS boxes, home servers, dev machines, and self-hosted apps. It is not a smart-home control panel, and it is not a monitoring system.
LOCUS runs on a Linux machine at home. It listens for devices announcing themselves on your network and gathers the services you can open onto one page, grouped by device.
nas or ssh nas. Several words narrow the list together, so you never need the address. Web pages open in a new tab; SSH, SMB, and VNC go to the client already on your computer.
The dot beside each entry shows its last check: reachable, unreachable, not checked yet, or a server error (such as a web page answering with HTTP 5xx).
locus system user and registers a systemd or OpenRC service that starts on boot. If a firewall is active, it asks before opening the port and the multicast used for discovery.
http://<this machine’s IP>:3033 or http://<hostname>.local:3033 in a browser.
--network host or it cannot hear devices announcing themselves, so there is no port mapping. Data lives in the locus-data volume. Docker is only how LOCUS runs; LOCUS does not manage containers.
curl -fsSL https://locus.casa/releases/install | sh
The script asks for a language, checks the machine, asks for the listen address, port, and data directory, then starts the service and prints the address to open.
curl -fsSL https://locus.casa/releases/latest/docker-linux-amd64.tar.gz | docker load
docker run -d --name locus --network host --restart unless-stopped -v locus-data:/data locus:latest
On ARM64, replace amd64 with arm64. To use another port, add --bind 0.0.0.0:<port> at the end.
Release builds check for new versions now and then. When one is out, an upgrade icon appears at the top right of the LOCUS page. Choose “Upgrade and restart”: LOCUS downloads the file for its architecture, checks it against SHA256SUMS, test-runs it, then switches over and restarts. Running the install command again also upgrades. The new program is written to the data directory (the /data volume under Docker); upgrading inside the Docker volume does not update the image itself. Set LOCUS_UPDATE_CHECK=off to turn the check off.
Before upgrading, stop the service, back up the whole data directory, then start it again and upgrade. Going back needs data the older program can read; do not downgrade just by deleting the upgraded program.
If you would rather not pipe curl into sh, download, check, then run. Each version has a fixed directory, locus.casa/releases/0.1.0.000037/, and the same files are on the GitHub release:
Download the program, check it, and run it directly (data goes to ~/.local/share/locus; no service is registered):
V=0.1.0.000037
curl -fsSLO https://locus.casa/releases/$V/linux-x86_64.tar.gz
curl -fsSLO https://locus.casa/releases/$V/SHA256SUMS
sha256sum -c --ignore-missing SHA256SUMS
tar -xzf linux-x86_64.tar.gz
./locus-$V-linux-x86_64/locus --bind 0.0.0.0:3033
Or read the installer before running it. It downloads linux-install.sh and checks it against SHA256SUMS from the same directory before running it:
curl -fsSL https://locus.casa/releases/install -o install
less install
sh install
SHA256SUMS sits next to the files, so it catches a damaged or incomplete download. It does not prove where a file came from, and it is not a digital signature. You can compare the lists on locus.casa and on the GitHub release (GitHub file names carry a locus-<version>- prefix; the hashes are the same).
LOCUS assumes your home network is trusted. The points below shape how you should run it; open any of them for details.
LOCUS has no login. Anyone who can open the page can change its settings and use the device controls described below. Its access checks stop cross-site requests and DNS rebinding in the browser; they are not authentication. Use it on a trusted local network.
There are three kinds for now. UPnP media players (DLNA renderers on TVs and speakers, for example) can play, pause, stop, skip back or forward, mute, change the volume, and switch source; which buttons appear depends on what the device allows at that moment. IPP printers are read-only (model, queue length, state) with a link to the print queue. ONVIF cameras are read-only (device information) with a link to the video stream. Nothing else is managed.
No separate permission is needed: any computer that can open the LOCUS page can control these devices once they are discovered. To restrict it, list the allowed IPs or subnets in LOCUS_CONTROL_CLIENTS (none allows nobody), or switch control off item by item in the Situation panel; LOCUS then sends no requests for that item.
The host name in the browser’s address must be one LOCUS accepts (this machine’s IPs, localhost, its host name, hostname.local, or a name added to LOCUS_ALLOWED_HOSTS), and the port must match the port LOCUS listens on. Changes are accepted only from that same http address. Behind a typical reverse proxy, requests are refused (421 or 403). There is no reverse-proxy example yet. Please do not strip the Origin header or turn the checks off to get around this.
When on, LOCUS actively connects to ports on local devices (candidate probing runs every 15 minutes), and a sweep sends packets across a whole subnet. Traffic like this can set off alerts in routers, firewalls, or security software. On a network someone else runs, such as at work, ask first. It is not a vulnerability scan or an asset inventory.
Discovery uses mDNS, SSDP/UPnP, and WS-Discovery, and only sees announcements that actually reach the machine running LOCUS. It does not cross a VLAN, an isolated Wi-Fi, or a VPN on its own. Another subnet usually needs forwarding on the network side, or entries you add by hand. The service itself also has to be announcing.
https://locus.casa/releases/latest/version without sending anything about your machine; upgrades download from the same place. LOCUS_UPDATE_CHECK=off turns it off.
Device records, entries, the launchpad, names and groups, settings, usage history, and uploaded icons and backgrounds all live in the data directory: /var/lib/locus by default with the installer, the locus-data volume under Docker, and ~/.local/share/locus when run directly. Upgrades are downloaded here too. To back up or move it, stop the service and copy the directory.
SSH, SMB, VNC, and similar entries open as ssh://, smb://, and so on, which the browser hands to a program on your computer. Without a client installed, or without the system linking that scheme to one, nothing opens, and the browser may ask first. Phones usually handle fewer of these. LOCUS does not include a terminal, a file manager, or a remote desktop.
An IP address is not a permanent identity. When a stable identifier such as a MAC address is available, LOCUS puts records from different sources on one device and updates its address when it changes. When it cannot be sure, the records stay separate; the same name or the same IP does not guarantee a merge. A manual entry with an IP address can follow its host to a new address using the host’s MAC and the neighbor table, but this is not dynamic DNS: several interfaces, an address conflict, or a missing record will need your confirmation, and HTTPS on a new IP may not match the certificate.
Status comes from the most recent check. A device can go offline between checks, and an open port does not mean the application is healthy or that you are signed in.
No metrics, alerts, password storage, or container management, and it does not sign you in to the services it opens; each application still handles its own login.
LOCUS ships as a binary; the source is not published. You may run unmodified copies for free on machines you control, for personal or internal use. You may not redistribute, modify, or reverse engineer it. See the license for the full terms and the third-party notices for bundled components; Debian system components in the Docker image are listed in SYSTEM_COMPONENTS.txt inside the image.