most monitoring assumes a fleet - exporter, tsdb, dashboard, alertmanager. for one vps and one laptop that is more infrastructure than the thing being watched, so i went the other way: one static binary per machine, talking to a telegram bot you create yourself. no central server, nothing to host, no third party in the path. the systemd unit is capped at MemoryMax=128M.
the parts that took actual thought:
ssh. alerts on every login with geo-ip of the source, root escalated. brute force is a sliding window per source ip with a quiet period, so an attack in progress doesn't turn into 200 messages. it also hashes root's authorized_keys and every home user's, and tells you when one of them changes.
power. edge triggered off /sys/class/power_supply/*/online rather than a threshold. mains flips 1 to 0 and it fires within one sample (15s by default) with the battery percent and an estimated runtime worked out from the current draw. a machine with no AC adapter device at all, so any vps, is never considered "on battery", so nothing misfires there.
false alarms. cpu and memory need the condition held for about a minute before anything is sent, temperature needs several consecutive samples. a nightly backup or a cpu touching 90C mid-boost stays quiet.
remediation is deliberately small and always behind a confirmation: disconnect an ssh session, or open and close 22 through ufw. a host without ufw is told it can't manage the firewall there rather than guessing what is open.
what it is not: a fleet tool. one agent, one bot, one chat, no cross-server correlation and no time-series to query. if you want to know what cpu did last tuesday this is the wrong thing and prometheus is the right one. linux only, amd64 and arm64, and it is v0.x.
https://github.com/eliau2005/statixagent (MIT, go 1.25)