Local Object & Capability Unified Space

LOCUS

Fewer addresses to remember.
Less upkeep for your start page.

Self-hosted. Find and open your NAS, servers, and self-hosted apps from one page.

Install LOCUS Releases Feedback

Current release 0.1.0.000037

What it looks like

LOCUS home page: the launchpad pins Jellyfin, Immich, Nextcloud, NAS Admin, NAS Files, Gitea and Shell, plus the sites GitHub, r/selfhosted and YouTube; below are recent entries and devices and sites grouped as storage, development, network, home and external.
Home: the launchpad, recent entries, and devices and sites grouped by category.
LOCUS search: typing nas lists the NAS's two entries, the HTTP admin page and the SMB file share.
Search: type nas to find the NAS admin page and its file share.
LOCUS device menu: the NAS opens to its HTTP admin page and SMB share, each with a status dot in front and a pin button behind.
Device menu: several services on one NAS; each dot shows the last check.

Example environment. Device names and service data are for demonstration.

01 Casa Your devices. Your services.

Machines pile up at home: a NAS, a home server running several apps, a dev box, and a router and a Raspberry Pi with admin pages of their own. Each one has its own address and port.

One NAS, several ways in
Files over SMB, an admin page in the browser, sometimes SSH as well. It is one machine, but the ways in are scattered.
Ports nobody remembers
Jellyfin on 8096, Immich on 2283, Nextcloud on 8080. A few months later all you remember is “it’s on the server.”
Bookmarks need upkeep
Some links live in bookmarks, some on a start page you wrote, some only in browser history. Every new service means another edit.
DHCP moves things around
The router hands out a new IP, and the old bookmark stops working.

That is what LOCUS is for: NAS boxes, home servers, dev machines, and self-hosted apps. It is not a smart-home control panel, and it is not a monitoring system.

02 Locus Find your services. Open what you need.

LOCUS runs on a Linux machine at home. It listens for devices announcing themselves on your network and gathers the services you can open onto one page, grouped by device.

Search
Type a few letters, such as nas or ssh nas. Several words narrow the list together, so you never need the address. Web pages open in a new tab; SSH, SMB, and VNC go to the client already on your computer.
Pin what you use
Pin the services you use to the launchpad, then order and group them. What you opened lately shows up under Recent. A pinned entry that goes missing keeps its name and fades instead of disappearing.
Add services that stay quiet
Many self-hosted apps never announce themselves. Paste the address: LOCUS checks the connection, fills in a name from the page title, and lets you choose which device it belongs to. Outside websites can be added too, kept apart from your own devices.
Review candidates
Optional and off by default. With candidate probing on, LOCUS checks common ports on devices it already knows. Anything it finds is listed as a candidate for you to add or ignore.

The dot beside each entry shows its last check: reachable, unreachable, not checked yet, or a server error (such as a web page answering with HTTP 5xx).

03 Install

System
Linux on x86_64 or ARM64 (aarch64).
Native binary
Needs glibc 2.34 or newer, which Debian 12, Ubuntu 22.04, and later releases have. On musl systems such as Alpine, use Docker.
Permissions
The installer needs root and re-runs itself with sudo. It creates a locus system user and registers a systemd or OpenRC service that starts on boot. If a firewall is active, it asks before opening the port and the multicast used for discovery.
Access
Default port 3033. When it is done, open http://<this machine’s IP>:3033 or http://<hostname>.local:3033 in a browser.
Docker
Runs on Linux, as a user allowed to run docker (root or the docker group). It must use --network host or it cannot hear devices announcing themselves, so there is no port mapping. Data lives in the locus-data volume. Docker is only how LOCUS runs; LOCUS does not manage containers.

Linux

curl -fsSL https://locus.casa/releases/install | sh

The script asks for a language, checks the machine, asks for the listen address, port, and data directory, then starts the service and prints the address to open.

Docker

curl -fsSL https://locus.casa/releases/latest/docker-linux-amd64.tar.gz | docker load
docker run -d --name locus --network host --restart unless-stopped -v locus-data:/data locus:latest

On ARM64, replace amd64 with arm64. To use another port, add --bind 0.0.0.0:<port> at the end.

Upgrading

Release builds check for new versions now and then. When one is out, an upgrade icon appears at the top right of the LOCUS page. Choose “Upgrade and restart”: LOCUS downloads the file for its architecture, checks it against SHA256SUMS, test-runs it, then switches over and restarts. Running the install command again also upgrades. The new program is written to the data directory (the /data volume under Docker); upgrading inside the Docker volume does not update the image itself. Set LOCUS_UPDATE_CHECK=off to turn the check off.

Before upgrading, stop the service, back up the whole data directory, then start it again and upgrade. Going back needs data the older program can read; do not downgrade just by deleting the upgraded program.

Manual download and checksums

If you would rather not pipe curl into sh, download, check, then run. Each version has a fixed directory, locus.casa/releases/0.1.0.000037/, and the same files are on the GitHub release:

Download the program, check it, and run it directly (data goes to ~/.local/share/locus; no service is registered):

V=0.1.0.000037
curl -fsSLO https://locus.casa/releases/$V/linux-x86_64.tar.gz
curl -fsSLO https://locus.casa/releases/$V/SHA256SUMS
sha256sum -c --ignore-missing SHA256SUMS
tar -xzf linux-x86_64.tar.gz
./locus-$V-linux-x86_64/locus --bind 0.0.0.0:3033

Or read the installer before running it. It downloads linux-install.sh and checks it against SHA256SUMS from the same directory before running it:

curl -fsSL https://locus.casa/releases/install -o install
less install
sh install

SHA256SUMS sits next to the files, so it catches a damaged or incomplete download. It does not prove where a file came from, and it is not a digital signature. You can compare the lists on locus.casa and on the GitHub release (GitHub file names carry a locus-<version>- prefix; the hashes are the same).

04 Before you start

LOCUS assumes your home network is trusted. The points below shape how you should run it; open any of them for details.

No accounts, so keep it off the public internet

LOCUS has no login. Anyone who can open the page can change its settings and use the device controls described below. Its access checks stop cross-site requests and DNS rebinding in the browser; they are not authentication. Use it on a trusted local network.

Device control covers a few kinds of devices, and is on by default

There are three kinds for now. UPnP media players (DLNA renderers on TVs and speakers, for example) can play, pause, stop, skip back or forward, mute, change the volume, and switch source; which buttons appear depends on what the device allows at that moment. IPP printers are read-only (model, queue length, state) with a link to the print queue. ONVIF cameras are read-only (device information) with a link to the video stream. Nothing else is managed.

No separate permission is needed: any computer that can open the LOCUS page can control these devices once they are discovered. To restrict it, list the allowed IPs or subnets in LOCUS_CONTROL_CLIENTS (none allows nobody), or switch control off item by item in the Situation panel; LOCUS then sends no requests for that item.

Built for direct access; no tested reverse-proxy setup yet

The host name in the browser’s address must be one LOCUS accepts (this machine’s IPs, localhost, its host name, hostname.local, or a name added to LOCUS_ALLOWED_HOSTS), and the port must match the port LOCUS listens on. Changes are accepted only from that same http address. Behind a typical reverse proxy, requests are refused (421 or 403). There is no reverse-proxy example yet. Please do not strip the Origin header or turn the checks off to get around this.

Probing and network sweeps are off by default; use them only where you may

When on, LOCUS actively connects to ports on local devices (candidate probing runs every 15 minutes), and a sweep sends packets across a whole subnet. Traffic like this can set off alerts in routers, firewalls, or security software. On a network someone else runs, such as at work, ask first. It is not a vulnerability scan or an asset inventory.

Discovery stops at the edge of your network

Discovery uses mDNS, SSDP/UPnP, and WS-Discovery, and only sees announcements that actually reach the machine running LOCUS. It does not cross a VLAN, an isolated Wi-Fi, or a VPN on its own. Another subnet usually needs forwarding on the network side, or entries you add by hand. The service itself also has to be announcing.

What network requests LOCUS makes
  • Discovery: mDNS, SSDP, and WS-Discovery multicast queries on the local network, and listening for announcements.
  • Device descriptions: reading the description files UPnP devices publish.
  • Entry checks: connecting to entries now and then to see whether they are reachable, including outside websites you added.
  • Pages and icons: reading page titles and icons when you add or check an entry, outside websites included.
  • Candidate probing and sweeps: only after you turn them on.
  • Device control: reading state from the media players, printers, and cameras described above, or sending an action when you press a button; nothing is sent for items whose control is switched off.
  • Update check: reading https://locus.casa/releases/latest/version without sending anything about your machine; upgrades download from the same place. LOCUS_UPDATE_CHECK=off turns it off.
Your data stays on the machine running LOCUS

Device records, entries, the launchpad, names and groups, settings, usage history, and uploaded icons and backgrounds all live in the data directory: /var/lib/locus by default with the installer, the locus-data volume under Docker, and ~/.local/share/locus when run directly. Upgrades are downloaded here too. To back up or move it, stop the service and copy the directory.

Non-web entries need a client on your computer

SSH, SMB, VNC, and similar entries open as ssh://, smb://, and so on, which the browser hands to a program on your computer. Without a client installed, or without the system linking that scheme to one, nothing opens, and the browser may ask first. Phones usually handle fewer of these. LOCUS does not include a terminal, a file manager, or a remote desktop.

Recognising a device and following it to a new address both have limits

An IP address is not a permanent identity. When a stable identifier such as a MAC address is available, LOCUS puts records from different sources on one device and updates its address when it changes. When it cannot be sure, the records stay separate; the same name or the same IP does not guarantee a merge. A manual entry with an IP address can follow its host to a new address using the host’s MAC and the neighbor table, but this is not dynamic DNS: several interfaces, an address conflict, or a missing record will need your confirmation, and HTTPS on a new IP may not match the certificate.

A green dot is the last check, not a promise

Status comes from the most recent check. A device can go offline between checks, and an open port does not mean the application is healthy or that you are signed in.

An entry point, not an operations console

No metrics, alerts, password storage, or container management, and it does not sign you in to the services it opens; each application still handles its own login.

Free to use, closed source

LOCUS ships as a binary; the source is not published. You may run unmodified copies for free on machines you control, for personal or internal use. You may not redistribute, modify, or reverse engineer it. See the license for the full terms and the third-party notices for bundled components; Debian system components in the Docker image are listed in SYSTEM_COMPONENTS.txt inside the image.