netwatch ~ ~/labs.tsx
main·labs
netwatchlabs
★ 4.9k
// 01 · what we ship

> tools for the
terminal.

Zero-config diagnostics for the machines you run — network, system, disk, audio, SSH. Real-time, local-first, MIT-licensed.

4.9k
github_stars
6
tools
MIT
license
~ $ netwatchtui
// netwatch · loops · no audio▶ play demo
// 02 · tools
6 repos
netwatch.tuiv0.32.5
Network diagnostics in your terminal.

Inspect connections, capture packets and investigate network problems. Available on Linux, macOS and Windows; capture access and diagnostic coverage vary by platform.

$brew install netwatch
$ man netwatch — how to use →
TUILinuxmacOSWindowsMIT
★ 3.4k↗
syswatch.tuiv0.14.2
Single-host system diagnostics TUI.

Twelve tabs covering CPU, memory, disks, processes, GPU, power, services, and network — plus a Timeline scrubber and an Insights anomaly engine. The terminal you open when something feels off, before you reach for htop, iostat, nettop, and a notebook of one-liners. Sibling to netwatch.

$brew install syswatch
$ man syswatch — how to use →
TUILinuxmacOSMIT
★ 902↗
diskwatch.tuiv0.5.8
Single-host disk diagnostics in your terminal.

Eight tabs across devices, volumes, filesystems, IO, SMART, hot files, and insights — capacity trends, throughput, p99 latency, and the files being written right now. Read-only, no daemon. Sibling to netwatch and syswatch.

$brew install diskwatch
$ man diskwatch — how to use →
TUILinuxmacOSWindowsMIT
★ 472↗
kernwatch.tuiv0.4.1
Linux kernel observability in your terminal.

Investigate CPU contention, scheduling delays, memory pressure and block I/O with host counters and optional bounded eBPF tracing.

$cargo install kernwatch --locked
$ man kernwatch — how to use →
TUILinuxeBPFMIT
★ 61↗
soundwatch.tuiv0.2.0
Read-only audio diagnostics, in ten tabs.

Ten tabs across devices, streams, meters, a real-time spectrum analyser, latency, xruns, and routing — for the one question no other terminal tool answers: why does my audio sound wrong? macOS and Linux, read-only by construction. Fourth sibling to netwatch.

$git clone https://github.com/matthart1983/soundwatch && cd soundwatch && make install
$ man soundwatch — how to use →
TUImacOSLinuxMIT
★ 13↗
essh.tuiv0.4.1
Persistent SSH sessions and live health dashboards.

An SSH workspace using OpenSSH and tmux. Reconnect to remote shells and inspect host health without leaving your terminal.

$git clone https://github.com/matthart1983/essh.git && cd essh && cargo install --path . --locked
$ man essh — how to use →
TUISSHLinuxmacOSMIT
★ 117↗
// 03 · learn
9 learning experiences

Complete Linux learning pathways and interactive teaching decks — systems, eBPF, networking, kernel contribution, Rust and the sequencer architecture. Explore mechanisms in your browser, then run guided C and Rust labs.

training / linux-systems

Linux systems training

Two complete pathways, from systems foundations to advanced kernel concepts. Each lesson includes guided experiments, worked explanations and checkpoints, with a downloadable C and Rust lab kit.

linux.advanced-pathway12 lessons · advanced
Advanced Linux systems pathway
From a running request to kernel evidence

Twelve complete lessons with guided experiments, worked explanations, checkpoints and an engineering capstone. Includes a C and Rust lab kit, local progress tracking and an exportable notebook.

$ open linux-systems#advanced — start pathway →
kernellabsC / Rustperformance
interactive ↗
linux.foundations-pathway8 lessons · foundations
Linux systems foundations
Build a service you can explain

Eight guided lessons connect processes, descriptors, memory, concurrency, networking and persistence. Run the supplied experiments, check your reasoning and finish with a reproducible systems investigation.

$ open linux-systems#intro — start pathway →
processesmemorynetworkinglabs
interactive ↗
interactive teaching decks
ebpf.deep-dive23 slides · deep dive
eBPF, end to end
From a kernel hook to a process name

Builds eBPF from first principles up to NetWatch’s real aya kprobe — the VM, the verifier, maps and ring buffers, CO-RE — with drive-able simulations of the verifier, the issue-#38 timing bug, and the full connect()-to-process-name trace.

$ open ebpf-deep-dive — launch deck →
eBPFayaverifierkprobes
interactive ↗
netwatch.architecture18 slides · tour
NetWatch architecture tour
How NetWatch works, from the kernel up

A contributor walkthrough of the running system: the event loop, the DPI and TLS/QUIC decryption pipeline, eBPF attribution, the Landlock sandbox, the flight recorder, and the remote-publishing seam to the cloud.

$ open architecture-tour — launch deck →
architectureDPIsandboxTUI
interactive ↗
linux.net-stack19 slides · deep dive
Inside the Linux network stack
From a NIC ring buffer to recv() — and back

Follows a packet through every layer of the kernel: NIC/IRQ/NAPI, the sk_buff and struct sock, the RX and TX paths, netfilter’s five hooks, qdiscs, and the eBPF tap points. Drive the sk_buff pointers, step the TCP state machine, traverse the hooks.

$ open linux-network-stack — launch deck →
networkingsk_buffTCPnetfilter
interactive ↗
linux.kernel-dev21 slides · foundations
Contributing to the Linux kernel
The craft and the culture

The machinery of upstream kernel work: maintainer trees, the release cycle, the email-patch workflow, and surviving review. Explore the tree topology, scrub a release cycle, decode a patch email, and run the review gauntlet.

$ open linux-kernel-dev — launch deck →
kernelpatchesmaintainersnetdev
interactive ↗
rust.ownership21 slides · foundations
Learning Rust
Ownership is the whole idea

Rust’s hard part, made legible: ownership, borrowing, lifetimes, traits, errors, and fearless concurrency. Drive the borrow checker, scrub a lifetime, and watch a move invalidate a value — grounded in real NetWatch code.

$ open learning-rust — launch deck →
Rustownershipborrow checkertraits
interactive ↗
ticktape.sequencer15 slides · deep dive
The sequencer architecture
Deterministic, replicated services on one tape

The pattern behind Island/INET, Nasdaq, and LMAX, taught by driving it: stamp a command through the sequencer, crash and replay a node, reproduce a seeded VOPR fuzz run, drop packets on the A/B feeds, and kill a leader mid-stream — the machinery of ticktape, in Rust.

$ open ticktape-sequencer — launch deck →
sequencerdeterminismsimulation testingRust
interactive ↗
// 04 · writing
5 posts
// 05 · cloud

Same agent, hosted dashboard.

Run the same 5 MB Rust agent. Get fleet-wide metrics, alerts, and 72-hour history without standing up your own backend.

netwatch labs · 20266 repos · 4.9k starsmain