Sign inSign up

konkos1/opensecdash

By konkos1

•Updated 5 days ago

https://opensecdash.app

Image
Security
1

2.2K

konkos1/opensecdash repository overview

⁠OpenSecDash

OpenSecDash is an open-source security dashboard built for homelabs.

It collects security events, access logs, asset information, and update signals from common self-hosted tools. Its Insights engine turns noisy logs into useful context, helping you spot probes, bans, geoblocks, suspicious patterns, and outdated applications without running a full SIEM.

⁠Features

  • Live-first security dashboard
  • Structured event and access-log search
  • IP Explorer for investigating individual addresses
  • Declarative Insights and correlation rules
  • Asset inventory and application update checks
  • SMTP notifications with cooldowns and digests
  • Controlled and audited CrowdSec ban/unban actions
  • Internal authentication with Viewer, Operator, and Admin roles
  • Optional OpenID Connect sign-in
  • Responsive UI and installable web app
  • Plugin and datasource diagnostics

⁠Included integrations

  • CrowdSec LAPI
  • Traefik access logs
  • GeoBlock logs
  • GeoIP enrichment
  • JSON asset inventories
  • Proxmox assets
  • MQTT export

Integrations can be enabled, configured, or completely disabled independently.

⁠Quick start

Docker Compose is the recommended installation method:

services:
  opensecdash:
    image: konkos1/opensecdash:latest
    container_name: opensecdash
    ports:
      - "8765:8000"
    volumes:
      - opensecdash-data:/data
    read_only: true
    tmpfs:
      - /tmp:size=16m,mode=1777
    security_opt:
      - no-new-privileges:true
    cap_drop:
      - ALL
    cap_add:
      - CHOWN
      - SETGID
      - SETUID
    pids_limit: 256
    mem_limit: 1g
    cpus: 2.0
    logging:
      driver: json-file
      options:
        max-size: "10m"
        max-file: "3"
    restart: unless-stopped

volumes:
  opensecdash-data:

Start the container:

docker compose up -d

OpenSecDash listens on port 8000 inside the container. The example exposes it as port 8765 on the Docker host.

⁠First-time setup

New installations start with internal sign-in enabled. The first visit creates the initial Admin account.

Complete this setup through a trusted HTTPS reverse proxy and explicitly configure its address:

environment:
  OSD_TRUSTED_PROXIES: 192.168.1.10

For an intentional local-only trial at http://localhost:8765, internal authentication can be disabled:

environment:
  OSD_AUTH_DISABLED: "true"

When authentication is disabled, every visitor who can reach the application has full access.

Do not expose OpenSecDash directly to the public internet. Keep it on your LAN, behind a VPN, or behind a trusted HTTPS reverse proxy.

⁠Persistent data

The container stores its SQLite database and other persistent application data in:

/data

Always mount /data as a named volume or bind mount. Back up this volume before major upgrades.

⁠Plugin file mounts

Plugins can read logs and asset inventories through read-only mounts:

volumes:
  - opensecdash-data:/data
  - /var/log/traefik/access.log:/logs/access.log:ro
  - /var/log/traefik/geoblock.log:/logs/geoblock.log:ro
  - /var/log/crowdsec/crowdsec.log:/logs/crowdsec.log:ro
  - ./assets/assets.json:/assets/assets.json:ro

Only add the mounts required by the integrations you use.

⁠Environment variables

VariableDefaultDescription
OSD_HOST0.0.0.0Internal bind address
OSD_PORT8000Internal application port
DATABASE_URLsqlite:////data/opensecdash.dbDatabase connection
AUTO_MIGRATEtrueRun database migrations during startup
LOG_LEVELINFOApplication log level
OSD_TRUSTED_PROXIESPrivate and loopback networksProxies allowed to provide forwarded headers
OSD_AUTH_DISABLEDunsetDeliberately disable internal authentication

Plugins can be disabled with:

OSD_PLUGIN_<PLUGIN>_DISABLED=true

For example:

environment:
  OSD_PLUGIN_MQTT_DISABLED: "true"
  OSD_PLUGIN_PROXMOX_ASSETS_DISABLED: "true"

⁠Resource requirements

For a small homelab instance:

  • Minimum: 1 vCPU, 512 MiB RAM
  • Recommended: 2 vCPU, 1 GiB RAM
  • Storage: approximately 1 KB per retained event, depending on event content and indexes

Storage requirements depend mainly on log volume and configured retention.

⁠Image tags

  • latest — latest published release
  • <version> — semantic release version
  • v<version> — Git release tag

Pin a version tag instead of latest when you want controlled upgrades.

⁠Health checks

The image includes a container health check using:

/health

A readiness endpoint is also available at:

/ready

⁠Documentation and source

⁠Project status

OpenSecDash is actively evolving. APIs, plugin interfaces, and deployment packaging may change before the stable 1.0 release.

⁠License

OpenSecDash is released under the GNU Affero General Public License v3.0.

Tag summary

Content type

Image

Digest

sha256:cb9bbc156…

Size

72.2 MB

Last updated

5 days ago

docker pull konkos1/opensecdash