Tikpilot

Fifty routers in one window

Central management for a MikroTik fleet: status, bulk operations, backups and alerts, for fifty routers or for five. Runs on your own server and sends nothing outside.

git clone https://github.com/maximdr86/tikpilot
cd tikpilot && cp .env.example .env
docker compose up -d
How to install Code on GitHub MIT · Python · no cloud, no build step · works in a network with no internet
Dashboard: the needs attention block with six items, fleet tiles, a breakdown by group and RouterOS versions

The screenshots come from a live fleet of 49 routers with screenshot mode on: site names, addresses and client names are replaced by the panel itself.

See

What the fleet is doing, without opening WinBox fifty times.

Do

The repetitive part, across the whole fleet at once.

Do not miss

The panel tells you when it is worth looking.

Screens

Device list: name, address, group, model, mobile operator and RouterOS version
Device list. The mobile operator is detected automatically and search works on it too.
Monitoring: summary, fleet map by group and uptime over the last 24 hours
Monitoring: the fleet map by group and uptime over 24 hours with the downtime.
Bulk action dialog: target is all 49 devices, with the list of available actions
One action across all 49 sites. The dangerous ones are marked, every run becomes a job.
A speed test job: bandwidth from each of the 49 sites to a single target, one line per site
Bandwidth from every site to the centre, measured by the routers themselves. Sites go one at a time, otherwise they share the target's channel and lie.
WireGuard: hub settings and the table of links with handshakes and traffic
WireGuard: hub, links, handshakes and traffic. The spoke config is generated for you.
The script library and a table of which sites they sit on
The script library and the answer to which router has which script.
Device logs: time, site, message topic and text, with highlighting rules
Syslog from the whole fleet. Highlight and hide rules take out the repetitive noise.

Install

Any server with Docker that can reach the routers. The panel comes up on port 8080.

git clone https://github.com/maximdr86/tikpilot
cd tikpilot
cp .env.example .env
docker compose up -d

Then: create an API user on the routers and add devices by hand or by CSV import. The panel talks to RouterOS over the API (8728/8729) and over SSH for the terminal. To update: git pull and docker compose up -d --build.

What it does not do

Frequently asked

Is Tikpilot an alternative to The Dude?

Partly. The Dude and Zabbix answer “what is happening in my network” and do it better. Tikpilot answers “do this on all my routers”: run a script, take a backup, upgrade RouterOS, and show a result for every device. It also keeps availability history, so for a small fleet it often replaces both. The full comparison is here. There are also walkthroughs of a bulk RouterOS upgrade, config backups and fleet monitoring.

How do I upgrade RouterOS on all routers at once?

Pick the devices or a whole group, choose “Check for RouterOS updates” and then “Upgrade RouterOS”. Every run becomes a job with a per-device result, the panel waits for each router to come back, refuses downgrades and checks free space before it starts.

Can it back up MikroTik configs on a schedule?

Yes. Rules run on their own: binary .backup, text .rsc or both, N copies kept per device. Any two configs can be compared line by line, and there is full-text search across everything stored.

Does it work without internet access?

Yes. The panel talks only to your routers over the RouterOS API and SSH. The two optional exceptions are looking up the mobile operator in the address registry and downloading the MAC vendor database, both of which you switch on yourself.

How much does it cost?

Nothing. MIT licence, the source is on GitHub, there is no paid edition and no cloud account.

Why it is built this way

One process and a database file

Python, FastAPI, SQLite. No Redis, no queues, no frontend build.

No outbound requests

Pages are rendered on the server, fonts and scripts are local. The panel has to work in an isolated network.

Passwords and access

Router passwords are encrypted with a key kept outside the database, every capability is granted separately, and everything is written to an audit log.

Tested against a real protocol

More than three hundred tests on three versions of Python, against a stub that speaks the real RouterOS protocol.

Who wrote this

I am a sysadmin looking after 49 sites: shops, canteens and remote locations. The panel grew out of that work and runs my own fleet, so the bugs reach me first.

The code was written by an AI model (Claude) under my direction. I say so up front rather than let anyone find it in the commit history. MIT licence: read the code before you trust it with your routers.

Open the file at full size