PANTAW is a lightweight Linux Node Operations Guardian for passive observation, deterministic triage foundations, comprehensive audit evidence and explicitly controlled operations. Version 0.0.2 completes the Linux Collectors milestone while real system-changing execution remains disabled by mandatory dry-run safety.
Why the name PANTAW
The name comes from the Malay word pantau: to observe, monitor or keep watch. Its acronym keeps that meaning in the engineering identity.
P
Passive
A
Analysis
N
Node
T
Triage
A
Awareness
W
Watch
Core principles
Passive observationRead-only by designDeterministic behaviourExplicit authorizationVerification-first operationsComplete auditabilityLeast privilegeFail-safe behaviour
Architecture
01Linux node
02Collectors
03Structured observations
04Analysis and triage foundations
05Monitoring integration
AuditCross-cutting JSONL and SQLite evidence across the operational lifecycle
Version 0.0.2 provides collectors, structured observations, the existing deterministic foundations and audit backends. Notification providers, richer analysis and controlled SOP automation remain roadmap work and must not be read as shipped capability.
Linux collectors
Seventeen registered collectors cover system, storage, network, hardware and GPU facts. Availability depends on kernel interfaces, drivers, firmware, permissions, utilities, virtualization and physical exposure.
System systemd, process, memory, CPU/load, OS/uptime
The validated deployment pattern uses a systemd user timer, a bounded oneshot collection cycle, mandatory dry_run: true, and equivalent JSONL and SQLite audit writes. PANTAW v0.0.2 performs no system-changing action.
Structured cycle and audit data can be presented in a private administrator dashboard through a read-only connector. The current KPanel integration remains private and is not part of this public portal; no private route, node data or control surface is exposed here.
Alpha/development; Linux Collectors milestone completed, not stable or Production GA
Validated platform
Debian 13
Runtime
Linux only; Python 3.12 or 3.13
Other distributions
Architecturally expected to be compatible, but not yet release-validated
Release packages are currently provided through an approved deployment or support engagement.
Evaluate or deploy
Discuss an authorized package, private installation, hardware-specific validation, custom collector work, an air-gapped plan or a read-only control-panel connector. No fake download or invented pricing is offered.