Sign inSign up

morgankryze/cairn

By morgankryze

โ€ขUpdated 4 days ago

The directory page for the people you host services for. No account, multilingual, live status.

Image
Monitoring & observability
0

10K+

morgankryze/cairn repository overview

โ cairn

The directory page for the people you host services for: no account, multilingual, live status, one tiny container.

The cairn home page: a welcome note, service cards grouped by category with live status pills, and a category trail in the margin

You run things for other people. Family, a club, a team, a floor of an office. They have no idea what any of it is called or where it lives, and they should not have to. cairn is the one page you send them: what you host, what it is for, whether it is up, in their own language.

You write two YAML files. cairn serves them. There is no database, no account system, no admin panel, and nothing to log into.

Live demoโ  ยท Source and documentationโ 

โ Run it

docker run --rm -p 8080:8080 -v ./config:/config:ro morgankryze/cairn:stable

Or with Compose, which is how most people run it:

services:
  cairn:
    image: morgankryze/cairn:stable
    ports:
      - 8080:8080
    volumes:
      - ./config:/config:ro
    read_only: true
    cap_drop:
      - ALL
    security_opt:
      - no-new-privileges:true

The getting started guideโ  has the two config files to put in ./config, and it is a five minute read.

โ Tags

TagPoints at
stable, latestthe newest release
<major>, <major>.<minor>, <major>.<minor>.<patch>that major, minor or exact version
unstableevery commit on the main branch
a commit hashthat exact build

Pin the exact version if something else depends on the page looking the way it looks today. 1 and stable move on every release; the upgrading notesโ  say what a version can refuse to load.

Built for linux/amd64 and linux/arm64, so a Raspberry Pi is a first-class target rather than an afterthought.

โ What is in it

A single static Go binary on scratch, with a CA bundle and nothing else. No shell, no package manager, no interpreter: there is nothing in the image to run but cairn. It drops every capability, runs as a non-root user and needs no writable filesystem, which is what makes the Compose block above possible.

โ Verify what you pulled

This image is the same object published to GitHub Container Registryโ , copied here digest for digest rather than built twice. It is signed keylessly, so there is no maintainer key to steal, and it carries SLSA build provenance and a software bill of materials.

cosign verify morgankryze/cairn:stable \
  --certificate-identity-regexp '^https://github.com/MorganKryze/cairn/' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

The security policyโ  explains what that proves and how to report a problem.

โ Licence

GPL-3.0. Issues, translations and pull requests are welcome on GitHubโ .

Tag summary

Content type

Image

Digest

sha256:4c00be1a3โ€ฆ

Size

4.9 MB

Last updated

17 days ago

docker pull morgankryze/cairn