ipmideck

Security

Your BMC credentials never leave your hardware

ipmideck is built for people who read the source instead of trusting a vendor. Every claim below is grounded in the product's own backend code. Not marketing.

Jump to install

Data & account security

Credentials are encrypted at rest, logins are hashed, and sessions are signed. The database alone is never enough to get in.

AES-256-CBC

AES-256-CBC credential encryption

BMC credentials are encrypted at rest with AES-256-CBC and a random IV per secret. The encryption key lives in a separate key file (data/encryption.key, 32 random bytes, owner-only permissions), never in the database, so a stolen database alone cannot decrypt anything.

BCRYPT · HMAC-SHA256

bcrypt logins + HMAC-SHA256 signed sessions

Login passwords are hashed with bcrypt (per-password salt, constant-time verify). Session tokens are signed with HMAC-SHA256, revalidated on every request, and invalidated when a username changes; cookies are HttpOnly and SameSite=Lax.

EXP-BACKOFF

Brute-force lockout

Per-username lockout with exponential backoff after five failed attempts (up to an hour), plus timing-leak-safe generic errors so an attacker learns nothing from how a login fails.

IPMITOOL

No-shell ipmitool, fully offline

ipmitool is invoked through an argument list (create_subprocess_exec), never a shell, so there is no command injection surface. The whole system runs fully offline: no telemetry, no cloud, no external calls.

Hardware protection

FanPilot is built to fail safe: thermal limits win over any curve, and the control loop keeps running even when you are not watching.

Safety override at the critical temperature

Fans are forced to 100% at or above the critical temperature (default 85°C, configurable). No fan curve can override the override. The thermal limit always wins.

The FanPilot control panel showing the safety threshold set to 85°C, with fans forced to 100% once that temperature is reached.The FanPilot control panel showing the safety threshold set to 85°C, with fans forced to 100% once that temperature is reached.
Hysteresis to stop oscillation
A configurable hysteresis margin (default 3°C) prevents fans from rapidly oscillating up and down around a temperature limit, keeping speed changes smooth and predictable.
Autonomous background loop
Fan control runs in a background task (~30s poll) that keeps working with the dashboard closed. Protection does not depend on a browser tab being open.
Unclean-shutdown recovery + graceful shutdown
After an unclean stop (power loss or kill -9) ipmideck restores the BMC's own auto mode, and it auto-recovers on server-offline and stale-sensor detection. A clean shutdown hands fans back to the BMC's thermal management.

Verify it yourself

Don't trust us. Read the source.

The encryption, the lockout, the safety override: each one is real backend code, not a marketing checkbox. ipmideck runs fully offline, with no cloud and no telemetry.

Install in one line:

docker
docker run --network host devluigi06/ipmideck:latest
pip
pip install ipmideck