Background, architecture and history of the pure-standard-library Rust port of Glances.
Glances is a cross-platform system monitor written in Python by Nicolas Hennion (a.k.a. Nicolargo) and a long list of contributors. It surfaces CPU, memory, swap, load, network, disk, sensors, filesystem, processes, alerts, logs and Docker container metrics from a single curses TUI, an embedded browser UI served over HTTP, or one of two dozen remote exporters. Glances is the kind of tool you keep one terminal pane wide on every box you care about.
Python Glances is mature, popular and battle-tested. glances-rs
is not a replacement — it is a reimplementation in Rust with
stricter dependency guarantees. All credit for the original
architecture, plugin model, and CLI surface belongs to
Nicolas Hennion (Nicolargo) and the
upstream contributors;
the port preserves the LGPL-3.0 terms.
Python Glances has a healthy runtime footprint — an interpreter, a web framework, an XML-RPC stack, a dozen exporter libraries, plugin discovery via filesystem walks. That is a lot of moving parts to install on a minimal container image, and a lot of transitive supply-chain to audit when a CVE lands.
Rust lets us keep the same architectural surface area
— plugins, REST API, server, CLI — while
collapsing the entire dependency graph to a handful of libc calls.
The binary that comes out of cargo build --release is a
single stripped executable with no libpython, no
site-packages, no pip, and no
.cargo/registry.
The crate is std-only: no [dependencies]
in Cargo.toml, no extern crate statements,
no third-party build scripts. The crate surface is split into:
core/ — Value, Plugin
trait, Stats, History,
Threshold, Timer, Logger,
Error, Filter.cli/ — hand-written argument parser; no
clap.platform/linux/ — the only platform layer,
gated to Linux; the only place unsafe is allowed.
macOS and Windows support was removed in v0.9.0 because the
maintainer has no hardware to test FFI on.plugins/ — one file per plugin (35 registered).outputs/,
server/ — stdout writers, HTTP server.qa/ — test harness: unit, integration, edge
and lint suites.Layout at a glance:
glances-rs/
├── Cargo.toml no [dependencies]
├── src/
│ ├── main.rs CLI dispatch; binary entry
│ ├── lib.rs re-exports for integration tests
│ ├── cli/ hand-written parser
│ ├── core/ Value, Plugin, Stats, ...
│ ├── platform/
│ │ └── linux/ /proc + /sys readers (pure std, Linux-only)
│ ├── plugins/ one file per plugin (35 registered)
│ ├── outputs/ stdout CSV / JSON / api_doc
│ ├── server/ HTTP/1.1 + SSE + auth
│ └── qa/ tests + lint
└── qa/
├── lint/ no_crates, line_cap, unsafe_allowlist, no_shell
├── unit/ per-module tests
├── integration/ end-to-end smoke
├── edge/ malformed inputs, panic isolation
└── fixtures/ sample /proc + /sys captures
Three hard constraints are enforced by lint, not by convention:
unsafe outside
src/platform/.std::process::Command with explicit argv.The monitor is read-only, but it listens on ports and parses input. What it distrusts, and what it does about it:
[dependencies]
at all. Nothing upstream to compromise.unsafe only
under src/platform/linux/, one portable syscall per block.sh -c.PathBuf::join only; no
format!-built paths.0.0.0.0; enable auth on any public network, terminate TLS
in front of it.ps); stdin prompts or the
0600 password file instead./proc and /sys readers are implemented and exercised by integration tests against a live host.
macOS and Windows support was removed in v0.9.0 because the
maintainer does not have hardware to test FFI on. The build
refuses non-Linux targets with a compile_error!
assertion.
Value, Plugin,
Stats, History,
Threshold, Timer, Logger,
Error, Filter).
/proc/stat,
/proc/meminfo, /proc/loadavg,
/proc/uptime, /proc/net/dev,
/proc/diskstats, /sys/class/net,
/sys/class/hwmon.
cpu,
mem, memswap, load,
uptime, now, system)
reading live /proc.
api_doc outputs
and the HTTP server scaffolding: REST API, auth, SSE.
/RPC2),
Model Context Protocol (MCP) JSON-RPC 2.0 interface for AI
assistants, embedded web templates (index, about, browser), and
removal of the legacy Python codebase (glances-py).
rust-port/ directly into the repository root, purged
all Python-era test suites and artifacts, and added official
LGPL-3.0-only license.
install.sh deployment script,
README overhaul, and upstream contributor credits.
install.sh in repo root
with companion install.sh.sha256 integrity checksum,
and streamlined one-liner installation documentation.
/proc/net
parser panic on short non-combined lines, MCP string request ids
now round-trip instead of returning null, consistent
lock-poisoning recovery in the Prometheus exporter, hardened the
process-filter memo key, and synced README/site (branch
rust is now the default).
verify_constant_time auth helper, and started the
1:1 upstream-parity pass against Python Glances.
processlist (/proc per-process details),
programlist (grouped by name),
smart (smartctl ATA/NVMe health), and
vms (virsh + Multipass) plugins with 25 new tests.
graphite (Carbon plaintext),
graph (self-drawn SVG charts),
timescaledb (PostgreSQL wire protocol + MD5),
zeromq (ZMTP 3.0 PUB), and duckdb
(external CLI) exporters with 29 new tests. No dependencies added.
main.py: all 83 flag spellings parse (display
toggles, --programs, --fetch,
--modules-list, SNMPv3 user/auth, comma-separated
--export, CSV overwrite); real
/api/all/limits, /views and
/history endpoints backed by recorded per-plugin
history (respects --disable-history).
q/arrows/1/h keys — pure
std plus direct libc termios/ioctl, no curses needed.
-2/-3/-4/-5 display
subsets, stdin login/password prompts, and
--fs-free-space end to end.
/dashboard
(CPU, memory, load, network, filesystems, top processes; 2 s
refresh), linked from the landing page. 840 tests green.
nvidia-smi query per tick); clickable
process-table sorting with direction indicators; Sensors
moved above Alerts. 848 tests green.
GLANCES_ROOTFS host-filesystem
view for containers (node-exporter style) plus file-bind
filtering, so the container dashboard shows host mounts
instead of overlay + CDI binds. 850 tests green.
/api/<plugin> routes, upstream GPU ids and
key fields, container in CI. 857 tests green.
/ serves the live dashboard;
marketing index removed from the binary. 858 tests green.
/api/4/status,
/api/4/all, pluginslist, single-process lookup.
861 tests green.
/about and /browser removed (GitHub
Pages keeps them); XML-RPC subsystem dropped
(-s/-p/--browser gone,
-c is SNMP-only). 853 tests green.
/history/60 sparkline seed
(upstream parity) instead of the 1.6 MB serial fetch.
855 tests green.
Full per-release notes in
CHANGELOG.md.