| Label | Status | Join link | Expires | |
|---|---|---|---|---|
| No sessions yet. | ||||
| Requester | Note | Status | When | |
|---|---|---|---|---|
| No requests. | ||||
Device enrolled. Its setup is personalized below, and the token is shown once.
Download Setup.exe for this deviceRun it on the device and approve the UAC prompt. It installs the always-on service (LocalSystem) without any PowerShell.
Same one-step Access model as Windows: pick the customer, download the installer, and run it on the target with sudo. It self-enrolls and installs a boot service (systemd on Linux, launchd on macOS), then reconnects as SYSTEM with full console access. Android is attended only (on-demand screen view, so it cannot run unattended): sideload the app and enter the session details in it.
Linux and macOS: make it executable (chmod +x), then sudo ./RubixRemoteLinux (or RubixRemoteMac) with no arguments. It is preconfigured for this customer and installs the service.
The macOS client is experimental and has not been tested yet. Use it for evaluation only.
Prefer native packages? Install with apt or dnf, then run the enroll command on the target.
Logins, session creation, pairings and connections, and admin changes. Most recent first.
| When | Actor | Action | Target | IP |
|---|---|---|---|---|
| No events. | ||||
| Click Refresh. |
pg_dump (custom format) into the data directory. Scheduled nightly backups run via the systemd timer installed by the installer.| Backup file | Size | When | |
|---|---|---|---|
| No backups yet. | |||
These run automatically on the server via systemd timers. They need root, so they live outside the web app:
certbot.timer) renews the TLS certificate and restarts the relay on renewal.rubix-maintenance.timer) runs VACUUM ANALYZE and prunes old audit rows.rubix-backup.timer) runs backup.sh and applies the retention above.Restore a backup on the server with sudo relay/deploy/restore.sh <file>, or use the Restore button on a row (destructive, asks for confirmation).
| User | Name | Role | 2FA | Last login |
|---|
Redirect URI to register at the provider: set a public base URL first. By default users must already exist here (username is their email); SSO authenticates and links them. Turn on auto-provisioning below to auto-create allowlisted logins.
When on, a verified Google or Entra login whose email domain is allowlisted is auto-created in a low-privilege role. Leave it off for no open registration. An empty allowlist creates nobody.
POST /api/v1/messages with Authorization: Bearer <key>. Leave the endpoint blank to use the default.…The license verification key and product code are built into this release and cannot be edited here. That is what prevents the license from being bypassed with a different key.
Checking…
https://<domain>. Renewal also runs automatically (daily maintenance timer).| Blocked (manual) |
|---|
| Auto-banned IP | Until |
|---|
Checking…
Add this secret to your authenticator app (Google Authenticator, Authy, 1Password):
Or use this URI:
Saved. Store these one-time recovery codes somewhere safe: