Containers and apps
In preview
Docker Compose stacks for each account. Your compose file is parsed and rewritten from an allow-list before Docker sees it, and checked again on the server.
Built and lab-tested
- privileged, host networking, devices, extra capabilities, Docker socket mounts and paths outside your home are refused, each with the offending line.
- Validated twice: by the control plane, and again by the agent on the server.
- Every container drops all capabilities except a small set, runs with
no-new-privileges, CPU, memory and process limits, user-namespace remapping and log rotation, inside the account's cgroup slice. - Ports are published on 127.0.0.1 only. Secrets are kept in the vault and a root-only environment file, masked everywhere else.
- A signed catalogue of 10 apps: WordPress, Ghost, n8n, Uptime Kuma, Gitea, Nextcloud, Plausible, Metabase, SeaweedFS and Valkey. A tampered catalogue is refused.
- Upgrades take a snapshot first and roll back automatically when health checks fail; manual rollback stays available for 7 days.
- Logs, stats, image pull and prune, and private registries.
Coming soon
- Rootless Podman per account.
- Publishing a stack on a domain through the websites module.
- Git deploys, exec into containers and image vulnerability scans.
Dedicated screens for this area are being built on the RespireCloud design system. Today every action has a generated form in the panel, is one keystroke away in the command palette (Ctrl K), and is callable through the API.