Skip to content

Neko Master

A self-hosted dashboard that shows where a home gateway’s traffic actually goes — by domain, by IP, by proxy node — reading it live from Clash, mihomo or OpenClash over WebSocket.

Screenshot of Neko Master
Editor screenshot, 29 Sep 2026Neko Master ↗

What it is

A self-hostable traffic dashboard for a local gateway: it collects from Clash, mihomo or OpenClash over WebSocket and reports where the traffic went — per domain, per IP with ASN and geolocation, per proxy node — with trends over half an hour, an hour and a day, multiple gateway backends at once, a PWA shell, dark mode and English and Chinese interfaces. It runs from a single Docker image with SQLite by default and ClickHouse optional, and ships a separate command-line agent for gateways that cannot run the container.

Who built itCommits as foru17, under the name luolei and the address i@luolei.org, which is 173 of the 175 commits here. The other two are single contributions that were cherry-picked with authorship preserved, a detail the maintainer mentions in the release notes. Unlike most repositories of this size, every commit is attached to a real account, so the contributor graph says what it appears to say.

Build log

7 stages
  1. 01

    The model is named in the first commit

    The initial commit, on 2026-02-05, reads init:create clash master project,powered by kimi k2.5. Very few repositories state what built them, and fewer still put it in the first line of their history. The later commits keep the habit: forty of the 175 carry a co-author trailer naming a model — Claude Fable 5 on fifteen, Claude Sonnet 4.6 on nine, Claude Opus 4.8 on eight, Opus 4.6 and 4.7 with a million-token context on five between them, and one plain Claude Code. Read in order, the trailers describe a project that started on one model and moved to another, which is a more useful record than a claim that it was built with AI.

  2. 02

    A dashboard for traffic you cannot otherwise see

    A gateway running Clash, mihomo or OpenClash decides where every connection goes and then forgets it. Neko Master keeps it: a collector subscribes over WebSocket and writes to SQLite, and the interface answers the questions that follow — which domains were used, which IPs they resolved to with their ASN and location, how traffic split across proxy nodes, and how all of it moved over the last half hour, hour or day. Several gateway backends can be monitored at once, and it installs as a PWA. The README carries a disclaimer worth quoting because the subject invites the wrong assumption: the project provides no network access service, no proxy subscription and no cross-network connectivity, and every figure it shows comes from the user’s own network. It is a viewer, and it says so.

  3. 03

    February did the work

    The commit distribution is lopsided in a way that is worth recording rather than smoothing over: 140 of the 175 commits landed in February 2026, the month the project opened, followed by 4 in March, 5 in April, 2 in May, 6 in June and 18 in July. Eighteen releases came out over the same period on two parallel tracks: an agent-v1.3.1 through agent-v1.4.5 series for the command-line collector that runs where the container cannot, and a v1.3.9 through v1.4.0 series for the application. The agent track starts first and runs ahead of the app track for months, which matches the shape of the issue tracker, where a good share of the reports come from OpenWrt routers and Raspberry Pis rather than from servers.

  4. 04

    The repository ships the instructions its agents worked from

    At the top level sit AGENTS.md at 12,446 bytes and a 664-byte CLAUDE.md that points at it, and .claude/skills/ holds six skills — add-stats-dimension, agent-probe-dev, db-conventions, release, ui-conventions and verify-changes — each with its own SKILL.md. This is the same arrangement PocketPilot and DeepSeek Harness use, and here it is not merely present but load-bearing: a community pull request adding Korean translations states that all keys match the structure of en.json per AGENTS.md contract number five, and reports its own coverage as 339 of 505 keys. An instruction file that outside contributors cite by clause number is doing real work.

  5. 05

    Root-cause work done in public

    The issue threads contain some of the better debugging published on this scale. One reporter measured stats.db at roughly 770 megabytes after thirty days on a Raspberry Pi 4B and listed the row counts behind it; the maintainer replied that the data made it trivial to confirm and that three separate bugs had been silently disabling retention — autoCleanup defaulting to false when no configuration row existed, contradicting its own declared default; a startup path using an inline cleanup that only covered the minute and hourly tables while the real cleanup service, which also prunes health logs, was never instantiated; and that service returning early when the flag was false anyway. A second thread began with a backend that stopped collecting after a credential change; the answer was that the edit form rebuilt the URL from host, port and TLS only, dropping any path, query string or embedded credentials, so every edit — including a token-only change — silently repointed the collector. Both replies name the mechanism rather than the symptom.

  6. 06

    A contributor’s fix, cherry-picked with authorship preserved — and then lost

    A contributor reported that the traffic collector hangs silently: GatewayCollector reconnected only on the WebSocket error and close events, so a connection dropped without a reset — a router reboot, a mihomo restart, a NAT idle timeout — left the socket in the open state forever while traffic sync stopped. Because backend health is checked by a separate HTTP poll, the interface kept showing green; the reporter had a backend out of sync for over a week before noticing. He sent a heartbeat watchdog, and the maintainer cherry-picked it into v1.3.9 with authorship preserved and added exponential backoff with jitter on top. A second contributor fixed proxy groups being recorded as rules, and got the same treatment in the same release. On 2026-07-30 that second contributor asked why his change had been reverted, because the proxy groups were appearing as rules again. The question is public and has no answer.

  7. 07

    What the issue tracker is made of

    Most of it is deployment reality rather than feature debate. A tablet installs the PWA in portrait and will not rotate, with the reporter diagnosing the manifest’s orientation: "natural" against the W3C specification and explaining why it locks phones and tablets differently. A command-line agent reports itself stopped while ps shows it running on OpenWrt. A request for process-level attribution — which program actually generated this traffic — arrives with the observation that Clash Verge can already show it under TUN mode. Someone asks for a read-only mode that needs no password so a public instance can be shown without being editable. Someone else asks for sing-box support. The feature requests are mostly people running this on the hardware they already own, which is the audience the agent track exists for.

Adjacent records

All records →