Open SourceOpen Source

OPNMGR

Self-hosted OPNsense fleet management for MSPs and IT teams: monitor every firewall, back up and diff configurations against an approved baseline, and roll out updates in safe, staged rings.

OPNMGR fleet dashboard showing firewall health, incidents, and update status across a demo fleet
OPNMGR fleet dashboard with demo data. Source: the OPNMGR GitHub repository.

The problem

An MSP with firewalls at many customer sites needs to know which are healthy, which configs changed, and which still need updates. Doing that one web interface at a time doesn’t scale, and updating a high-availability pair carelessly can take a site offline.

Why existing tools fell short

OPNsense has no built-in way to manage a fleet: each firewall has its own web interface, and there’s no central view of health, config drift, or update state.

The solution

OPNMGR collects regular check-ins from an agent on each OPNsense firewall, raises incidents, keeps configuration backups, and compares each config with an approved baseline. Updates roll out as campaigns through canary, pilot, and production rings inside maintenance windows. Nothing is ever restored automatically.

  • Agent check-ins for gateways, VPN, CARP, services, and certificate expiry
  • Configuration backups and drift detection against an approved baseline
  • Update campaigns through canary, pilot, and production rings
  • Incidents, maintenance windows, and grouping by customer and site
  • Optional AI configuration review with secrets redacted

Engineering involved

Verified from the public repository: README, dependency manifests, and source files.

Backend
Plain PHP 8 with no framework, on Apache or Nginx; scheduled work runs from cron.
Database design
MySQL 8 / MariaDB with an 80-table schema covering customers, sites, firewalls, check-ins, incidents, backups, and update campaigns.
Agent
An OPNsense plugin that checks in every two minutes with a per-firewall API key; agent updates are Ed25519-signed.
Security
Secrets encrypted with XChaCha20-Poly1305 via libsodium; TOTP two-factor sign-in.
Automation
Ringed update campaigns with high-availability safety rules and maintenance windows.
Testing
A custom test runner with around fifty test files, run in CI.

What makes it interesting

High-availability pairs get special treatment in update rollouts: both members of a CARP pair are never updated at the same time, and the second member isn’t touched until the first comes back healthy. It’s a small rule that prevents the worst possible outcome of “update everything.”

Outcome

Measured Public GitHub figures as of 10 October 2026: 28 stars, 1 forks, and 20 published releases since the repository was created in February 2026. Stars and forks show public interest, not active installations — the project doesn’t collect usage data.

Current status

Open Source Free, MIT-licensed, self-hosted. The source code is public on GitHub.

Open source under the MIT license and actively developed. Customers and sites are an organizational grouping, not separate tenant logins.

See it working

Screenshots with demo data are in the repository: github.com/agit8or1/OPNMGR. Overview: mspzero.com/tools/opnmgr.

Want something similar?

Need a system like this, built around your own business? MyAppDone can design, build, deploy, and maintain an application tailored to your workflow.

Related projects