OpenSecDash is an open-source security dashboard built for homelabs.
It collects security events, access logs, asset information, and update signals from common self-hosted tools. Its Insights engine turns noisy logs into useful context, helping you spot probes, bans, geoblocks, suspicious patterns, and outdated applications without running a full SIEM.
Integrations can be enabled, configured, or completely disabled independently.
Docker Compose is the recommended installation method:
services:
opensecdash:
image: konkos1/opensecdash:latest
container_name: opensecdash
ports:
- "8765:8000"
volumes:
- opensecdash-data:/data
read_only: true
tmpfs:
- /tmp:size=16m,mode=1777
security_opt:
- no-new-privileges:true
cap_drop:
- ALL
cap_add:
- CHOWN
- SETGID
- SETUID
pids_limit: 256
mem_limit: 1g
cpus: 2.0
logging:
driver: json-file
options:
max-size: "10m"
max-file: "3"
restart: unless-stopped
volumes:
opensecdash-data:
Start the container:
docker compose up -d
OpenSecDash listens on port 8000 inside the container. The example exposes it as port 8765 on the Docker host.
New installations start with internal sign-in enabled. The first visit creates the initial Admin account.
Complete this setup through a trusted HTTPS reverse proxy and explicitly configure its address:
environment:
OSD_TRUSTED_PROXIES: 192.168.1.10
For an intentional local-only trial at http://localhost:8765, internal authentication can be disabled:
environment:
OSD_AUTH_DISABLED: "true"
When authentication is disabled, every visitor who can reach the application has full access.
Do not expose OpenSecDash directly to the public internet. Keep it on your LAN, behind a VPN, or behind a trusted HTTPS reverse proxy.
The container stores its SQLite database and other persistent application data in:
/data
Always mount /data as a named volume or bind mount. Back up this volume before major upgrades.
Plugins can read logs and asset inventories through read-only mounts:
volumes:
- opensecdash-data:/data
- /var/log/traefik/access.log:/logs/access.log:ro
- /var/log/traefik/geoblock.log:/logs/geoblock.log:ro
- /var/log/crowdsec/crowdsec.log:/logs/crowdsec.log:ro
- ./assets/assets.json:/assets/assets.json:ro
Only add the mounts required by the integrations you use.
| Variable | Default | Description |
|---|---|---|
OSD_HOST | 0.0.0.0 | Internal bind address |
OSD_PORT | 8000 | Internal application port |
DATABASE_URL | sqlite:////data/opensecdash.db | Database connection |
AUTO_MIGRATE | true | Run database migrations during startup |
LOG_LEVEL | INFO | Application log level |
OSD_TRUSTED_PROXIES | Private and loopback networks | Proxies allowed to provide forwarded headers |
OSD_AUTH_DISABLED | unset | Deliberately disable internal authentication |
Plugins can be disabled with:
OSD_PLUGIN_<PLUGIN>_DISABLED=true
For example:
environment:
OSD_PLUGIN_MQTT_DISABLED: "true"
OSD_PLUGIN_PROXMOX_ASSETS_DISABLED: "true"
For a small homelab instance:
Storage requirements depend mainly on log volume and configured retention.
latest — latest published release<version> — semantic release versionv<version> — Git release tagPin a version tag instead of latest when you want controlled upgrades.
The image includes a container health check using:
/health
A readiness endpoint is also available at:
/ready
OpenSecDash is actively evolving. APIs, plugin interfaces, and deployment packaging may change before the stable 1.0 release.
OpenSecDash is released under the GNU Affero General Public License v3.0.
Content type
Image
Digest
sha256:cb9bbc156…
Size
72.2 MB
Last updated
5 days ago
docker pull konkos1/opensecdash