backend/.golangci.yml declared version: "2" on line 1 but used the golangci-lint v1 schema below it: a top-level linters-settings key and an issues.exclude-use-default key that does not exist in v2. Under v2 that config does not validate, so every threshold in it was inert -- lll fell back to its 120-column default rather than the intended 88, and funlen, cyclop and dupl were not applied at all. The `0 issues.` result the repo has been relying on was therefore meaningless. Replace it with the org-standard file verbatim (sha256 021cc83f4e6fc7c31b95b34b846723dfcf20b66b7baeea1dc40406e643346bcb) and repoint the golangci-lint pin in Dockerfile.backend from v2.7.2 to the org-standard v2.12.2. Guard against the config drifting from the standard again by asserting its sha256 as the first step of the backend lint target. The check is a local hash comparison against a constant in the Makefile: it needs no network, fetches nothing, and adds no unpinned external reference to the build path. It also catches a strictly larger class of breakage than schema validation would, since a schema-valid but non-canonical config is exactly how this file got into its broken state. With the config actually loading, lll reports server.go:65 at 93 columns. Fix it, plus the two other over-long lines called out on the issue (server.go:97 at 81 and reportbuf.go:166 at 88) which are inside the 88-column lint limit but over the 77-column hard wrap in the Go styleguide. All three were long //nolint justifications on the code line; move the justification into a preceding comment block and leave a short directive behind. No suppression is added or widened, and .golangci.yml is not touched after the copy. Drop the //nolint:wsl in server.go entirely rather than relocating it. The standard config disables wsl, so the directive suppressed nothing; removing it still yields `0 issues.` Verified: `cd backend && make check` reports `0 issues.` and passes with the network unavailable, root `make check` passes, and `docker build -f Dockerfile.backend .` builds green against the pinned v2.12.2.
NetWatch is an MIT-licensed JavaScript single-page application by @sneak that provides real-time network latency monitoring to common internet hosts, displayed with color-coded figures and sparkline graphs, served from a static bucket or Docker container.
Getting Started
# Install dependencies
yarn install
# Development server
yarn dev
# Production build
yarn build
# Preview production build
yarn preview
# Docker
docker build -t netwatch .
docker run -p 8080:8080 netwatch
Entrypoints
This repository adheres to the
Scripts to Rule Them All
standard: normalized scripts in script/ are the entrypoints for the
development workflow, and the Makefile targets are thin shims that call them. We
provide:
script/bootstrap— install all dependencies (pinned node via nvm if needed, yarn via corepack,yarn install --frozen-lockfile)script/setup— make a fresh clone ready for development: bootstrap plus the git pre-commit hookscript/projectname— print the project name (used for the Docker image tag)script/test— run the production build as the test (no unit tests yet)script/lint— run prettier in check modescript/fmt— format all files (writes)script/fmt-check— check formatting (read-only)script/check— run test, lint, and fmt-checkscript/docker— build the Docker image tagged viascript/projectnamescript/cibuild— CI entrypoint: plaindocker build .script/precommit— run by the git pre-commit hook; runsscript/checkscript/install-precommit— install the git pre-commit hook
Rationale
When debugging network issues, it's useful to have a persistent at-a-glance view of latency and reachability to multiple well-known internet endpoints. NetWatch provides this as a zero-dependency SPA that can be deployed anywhere static files are served, with no backend required.
Design
The application is a single-page app built with Vite and Tailwind CSS v4. All
code lives in src/main.js with a class-based architecture:
CONFIG: Frozen configuration object (update interval, timeouts, axis ticks, etc.)HostState: Per-host state management — history buffer, latency tracking, status transitionsAppState: Top-level state container — WAN hosts, local hosts, pause state, aggregate statsSparklineRenderer: Canvas 2D sparkline drawing with fixed axes, color-coded line segments, error regions, and DPR-aware scaling- UI functions:
buildUI()constructs the DOM,updateHostRow()/updateSummary()/updateHealthBox()handle incremental updates tick(): Main loop — measures all hosts in parallel viaPromise.all, pushes samples, redraws UI. When paused, pushes blank markers (no probes, no false outage)
Monitoring targets
- 22 WAN hosts: datavi.be, Anthropic API, OpenAI API, AWS Console, GCP Console, Azure, Cloudflare, Fastly, Akamai, GitHub, B2, 7 S3 regional endpoints (Cape Town, London, Bahrain, Tokyo, Sydney, Oregon, São Paulo), 4 GCS locational endpoints (Iowa, Belgium, Singapore, Sydney)
- Local CPE: Cable modem at 192.168.100.1 (always monitored)
- Local Gateway: Auto-detected on startup by probing common default gateway addresses (192.168.1.1, 192.168.0.1, 192.168.8.1, 10.0.0.1); first responder wins. Note: modern browsers enforce Private Network Access restrictions that block public-origin pages from reaching RFC1918 addresses, so local targets only work when NetWatch is served from localhost or a private address.
Local hosts are tracked separately from WAN stats.
Latency measurement
HEAD requests with mode: 'no-cors' and cache: 'no-store', timed with
performance.now(). 1-second timeout; anything over 1000ms is clamped to
unreachable. IPv4 only.
Color coding
| Latency | Color |
|---|---|
| < 50ms | Green |
| < 100ms | Lime |
| < 200ms | Yellow |
| < 500ms | Orange |
| >= 500ms | Red |
| Unreachable | Gray |
Output structure
dist/
├── index.html
└── assets/
├── index-*.css
└── index-*.js
Features
- Real-time monitoring with 2s update interval and 300s history sparklines
- Health indicator: green (HEALTHY) or red (DEGRADED) based on WAN reachability
- Summary stats: reachable count, min/max/avg latency across WAN hosts only
- Fixed chart axes: Y-axis 0–1000ms, X-axis 0–300s
- Color-coded latency figures and sparkline line segments
- Play/pause: pause stops probes but history keeps scrolling (blank gaps, no false outage)
- Clickable service URLs
- Canvas-based sparkline rendering with devicePixelRatio scaling
- Zero runtime dependencies: all resources bundled into build artifacts
Deployment
After running yarn build, deploy the contents of the dist/ directory to any
static file host (S3, GCS, Cloudflare Pages, Vercel, Netlify, GitHub Pages) or
use the Docker image behind a reverse proxy.
The Docker image:
- Listens on port 8080 by default (override with
PORTenv var) - Trusts
X-Forwarded-Forfrom RFC1918 reverse proxies (10/8, 172.16/12, 192.168/16) - Sends access logs to stdout
- Caches static assets with immutable headers
Browser Compatibility
Requires a modern browser with ES modules, Fetch API, Canvas API, and CSS custom properties.
Limitations
- CORS: Some hosts may block cross-origin HEAD requests. The app uses
no-corsmode which allows the request but provides opaque responses. Latency is still measurable based on request timing. - Local gateway: The 192.168.100.1 endpoint requires the host to be accessible from your network.
- Network conditions: Measurements reflect browser-to-endpoint latency, which includes your local network, ISP, and internet routing.
TODO
- Add unit tests
- Add eslint for JS linting (currently lint target runs prettier only)
- Add configurable host list (environment variable or config file)
- Add latency history export (CSV/JSON)
- Add notification/alert when status changes to DEGRADED
License
MIT. See LICENSE.