Local Object & Capability Unified Space

Remember fewer addresses.
Maintain one less page.

少记几个地址,少维护一张导航页。

在一个页面里,找到并打开你的 NAS、服务器、管理后台和自建应用。 Find and open your NAS, servers, admin consoles, and self-hosted apps, from one page.

它发现正在广播的设备与服务,把文件共享、终端、远程桌面和网页入口整理到一起。不会广播的应用,也可以手动添加。你不必先维护一份完整的配置文件。 It finds devices and services that are announcing themselves, and gathers file shares, shells, remote desktops, and web entries in one place. Apps that never announce themselves can be added by hand. You do not start from a finished configuration file.

01场景Cases

适合有 NAS、自建应用、家庭实验室或小型可信内网的人。它回答的是现在该从哪里打开这个服务,不是服务器指标、告警或设备控制。 For people with a NAS, self-hosted apps, a home lab, or a small trusted network. It answers where to open a service now, not metrics, alerts, or device control.

地址和端口记不住Addresses you cannot remember
自动发现可见的服务,按设备整理,也能按名称、用途和协议搜索。 Visible services are found and grouped by device. You can also search by name, purpose, and protocol.
同一台设备散在不同书签里One device, scattered bookmarks
同一台 NAS 可以同时有文件共享、管理后台和终端。有足够身份依据时,不同来源的记录归到同一设备。 One NAS can offer files, an admin page, and a shell together. When the identity is strong enough, records from different sources settle on that one device.
自建应用不会广播Apps that never announce themselves
粘贴地址、检查连接、填写名称即可添加。也可以开启候选探测,确认后再收进页面。 Paste an address, check the connection, and give it a name. Or turn on candidate probing and keep an entry only after you confirm it.
DHCP 换了 IPDHCP changed the address
符合条件的手动 IP 入口,可按宿主 MAC 和邻居记录跟随地址。不确定时提示确认,不承诺无条件跟随。 A manual entry that qualifies can follow a new address from the host MAC and the neighbor table. When that is uncertain, LOCUS asks. It does not promise to follow every change.
广播太多,能打开的不好找Too many announcements
可打开的入口和后台协议分开。按协议类型,或只对一台设备,允许、忽略或重新询问。 Entries you can open are kept apart from background protocols. Allow, ignore, or ask again, for a protocol or for one device.

02打开Open

搜索Search
输入 ssh nas,找名字里有 nas 的 SSH;输入 存储 nas,找相应的文件访问。多个词一起筛,不必记得完整地址。同一台机器上的 SMB 和 HTTPS 可以分开选。最近打开和使用次数会影响排序。网页在新标签打开;SSH、SMB、VNC 交给系统里已有的客户端。LOCUS 不内置终端、文件管理器或远程桌面。 Type ssh nas for an SSH entry whose name matches nas, or storage nas for file access. Several words filter together. You do not need the full address. SMB and HTTPS on the same machine stay separate choices. Recent opens and how often you use an entry affect the order. Web pages open in a new tab. SSH, SMB, and VNC go to a client already on the system. LOCUS does not include a terminal, a file manager, or a remote desktop.
启动台Pins
从搜索结果或设备菜单固定入口,也可以拖进启动台,再排序、分组。例如把「NAS 文件」「NAS 后台」和「开发服务器」放在习惯的位置。暂时找不到的固定项保留上次的名称并灰显。最近使用区回到刚打开过的服务。 Pin an entry from search or from a device menu, or drag it onto the launcher, then reorder and group it. A pin that cannot be found keeps its last name and fades, instead of vanishing. Recent use brings back what you just opened.
添加Add
在设置里「添加入口」,填内网控制台、应用或外部站点。HTTP(S) 可以检查页面,并用标题预填名称;其他受支持的协议检查端口能不能连上。宿主可以选已有设备,也可以新建。入口可以编辑和撤回。外部站点与内网设备分开。证书不可信时会警告。检查成功不代表连接安全,也不代表已经登录。 In settings, add an entry for an internal console, an app, or an outside site. HTTP(S) can be checked, and the page title can fill the name. Other supported protocols check whether the port connects. Choose an existing host or make a new one. Entries can be edited or withdrawn. Outside sites stay apart from local devices. An untrusted certificate is called out. A successful check is not a secure connection, and it is not a login.
候选Candidates
候选探测默认关闭。开启后,定期检查已知内网设备上你配置的端口,认出网页以及部分 SSH、FTP、SMB、AFP、VNC、RDP。候选按主机整理,由你逐项添加或忽略,不会因为端口开着就进启动台。同一主机有多个网页端口时,可以比较页面,看是不是疑似同一服务,仍由你决定。也可以手动或每天扫一次网段。扫描会发出主动流量,只在你有权探测的网络上开。它不是漏洞扫描,也不是资产盘点。 Candidate probing is off by default. When on, LOCUS checks the ports you configured on known local devices, and recognizes web pages plus some SSH, FTP, SMB, AFP, VNC, and RDP. Candidates are grouped by host. You add or ignore each one. An open port does not put itself on the launcher. Several web ports on one host can be compared. You still decide. A sweep can be started by hand or scheduled daily. It sends traffic, so use it only on a network you may probe. It is not a vulnerability scan or an asset inventory.

入口会标出最近检查是可达、不可达、尚未确认,还是服务异常。HTTP 5xx 不算正常。设备是否仍有发现证据,和入口上次能不能连上,是两种状态。两次检查之间设备可能离线;端口能连上,也不代表应用本身正常。 An entry is marked from its last check: reachable, unreachable, not yet checked, or the service itself is failing. An HTTP 5xx is not treated as healthy. Whether discovery evidence is still present, and whether the entry connected last time, are two different states. A device can go offline between checks. An open port does not mean the application is fine.

03安装Install

单个 Linux 二进制,页面随程序提供,不必另外部署前端。配置与发现记录留在运行的这台机器上,没有 LOCUS 云端账户。当前是 0.1 早期版本。安装文件在 /releases,latest 指向当前版本。下载后用该版本目录里的 SHA256SUMS 核对。GitHub 自动生成的源码压缩包不是安装包。 One Linux binary. The page comes with the program. Configuration and discovery records stay on the machine that runs it. There is no LOCUS cloud account. This is an early 0.1 release. Install files live under /releases. latest names the current version. Check SHA256SUMS in that version's directory. A source archive GitHub generates is not the installer.

Linux 安装器Linux installer

curl -fsSL https://locus.casa/releases/install | sh

这条命令读取 latest 指向的版本,核对 SHA-256,再运行安装器。要装指定版本,在前面加上 LOCUS_VERSION=版本号。已经安装过时再运行一次,会升级程序并保留设置和数据。面向 x86_64 与 ARM64 Linux。向导可设置监听地址、端口、数据目录和访问主机名,并在支持的系统上配置 systemd 或 OpenRC。需要 glibc 2.34 或更新。ARM64 包是 ARM64 Linux,不是 macOS 或 Android。Alpine 等 musl 系统不适用这份原生二进制。 The command reads the version latest points at, checks SHA-256, then runs the installer. To pin a version, prefix LOCUS_VERSION= and the version. Run it again on an existing install to upgrade the program and keep settings and data. For x86_64 and ARM64 Linux. The wizard sets the listen address, port, data directory, and allowed host names, and can install a systemd or OpenRC service. glibc 2.34 or newer. The ARM64 package is ARM64 Linux, not macOS or Android. musl systems such as Alpine cannot use this native binary.

压缩包Archive

./locus --bind 0.0.0.0:3033 --data ./locus-data

解压后在二进制所在目录运行。浏览器打开 http://<服务器 IP>:3033。0.0.0.0 向这台机器所连的网络开放;只给本机用时改为 127.0.0.1:3033。直接运行时,数据默认在 $XDG_DATA_HOME/locus,否则 ~/.local/share/locus。安装器默认用 /var/lib/locus。升级前先停服务,备份整个数据目录。 Unpack it and run the binary from that directory. Open http://<server IP>:3033. 0.0.0.0 exposes it to the networks this machine is on. For this machine only, use 127.0.0.1:3033. A direct run keeps data in $XDG_DATA_HOME/locus, or ~/.local/share/locus. The installer defaults to /var/lib/locus. Stop the service and back up the whole data directory before an upgrade.

Docker

已有 Docker 打包,这里不假设存在可拉取的公开镜像。镜像地址和命令以 Releases 的说明为准。部署时要让 LOCUS 接触用于发现的宿主网络,普通桥接网络看不到同样的广播。持久化 /data。Docker 部署不表示 LOCUS 能管理容器。 A Docker build exists. This page does not assume a public image you can pull. The image name and the command belong to the notes on Releases. The container has to see the host network used for discovery. A bridge does not. Persist /data. Running in Docker does not mean LOCUS manages containers.

第一次打开:等广播里的服务出现,试着打开一个 NAS 或管理后台;搜索并固定常用入口;给不广播的应用添加入口;需要找遗漏时再开候选探测;最后选语言、明暗和主题。 The first time: wait for announced services and open a NAS or an admin page; search and pin what you use; add apps that do not announce themselves; turn on candidate probing only when you are looking for something missed; then choose language, appearance, and theme.

04使用前Before you start

发现有网络边界Discovery has a network boundary
自动发现用 mDNS 与 SSDP/UPnP,只能看到运行主机实际收得到的广播。它不会自动跨过 VLAN、隔离的 Wi-Fi 或 VPN。跨网段通常要网络侧转发,或手动添加入口。服务自己也得开着相应广播。 Discovery uses mDNS and SSDP/UPnP, and only hears broadcasts this host actually receives. It does not cross a VLAN, an isolated Wi-Fi, or a VPN by itself. Another segment usually needs forwarding on the network, or an entry you add. The service has to be announcing itself.
认成同一台是有条件的Sameness has conditions
IP 不是永久身份。有稳定标识时,LOCUS 尝试保持这台设备并更新地址。不能确认时,记录可以分开留着。同名或同 IP 并不保证合并。 An IP is not a permanent identity. When a stable identifier holds, LOCUS tries to keep the device and update the address. When it cannot tell, the records may stay apart. The same name, or the same IP, does not guarantee a merge.
地址跟随不是动态 DNSAddress following is not dynamic DNS
它依赖宿主身份和当前的邻居记录。多网卡、地址冲突或缺少记录时要人工确认。HTTPS 换了 IP,证书名称也可能对不上。 It depends on the host's identity and the neighbor records it has now. Several interfaces, a conflicting address, or a missing record needs a person to confirm. HTTPS on a new IP can also fail the certificate name.
没有账户和权限体系No accounts
Host 与同源校验挡住的是浏览器里的跨站请求,不是登录。能访问 LOCUS 的网络成员仍可能修改配置。不要直接放到公网。远程访问应放在经过验证的认证网关或受控网络后面。反向代理还要自己适配 Host、Origin 和监听端口;允许一个域名,不等于代理已经配好。 Host and same-origin checks stop a browser on another site from writing. They are not a login. Anyone on the network who can reach LOCUS may still change it. Do not put it on the public internet as it is. Remote access belongs behind an authenticating gateway or a network you control. A reverse proxy must also satisfy the Host, Origin, and listen-port checks. Allowing a name does not mean the proxy is already correct.
它是入口,不是运维控制台An entry point, not an ops console
不做指标监控、告警、设备控制、密码保管或容器管理。也不会替你登录目标服务。打开之后,仍由那个应用自己认证。 No metrics, alerts, device control, password storage, or container management. LOCUS does not log you into the service you open. That application still does its own authentication.

产品按闭源二进制发布。使用与再分发以发行包随附的许可为准,不把产品当成 MIT 或 Apache-2.0。第三方组件保留各自的许可。反馈请到 Issues,写上版本(页面底部或 ./locus --version)、系统和架构、安装方式、预期和复现步骤。不要公开密码、令牌、私钥,或未经检查的整库。 The product is published as a closed-source binary. Use and redistribution follow the license shipped with the package, not MIT or Apache-2.0. Third-party components keep their own licenses. Feedback goes to Issues: the version (the bottom of the page, or ./locus --version), the system and architecture, how you installed it, what you expected, and how to reproduce it. Do not post passwords, tokens, private keys, or an unchecked copy of the database.