A CLI for managing multiple AdGuard Home instances
508
agh-cli is a command-line client for managing multiple AdGuard Home instances from one place. It supports client, filtering, rewrite, protection, DNS, DHCP, TLS, status, statistics, query-log, and credential-management workflows.
github.com/nicholas-fedor/agh-cli/pkg/adguardscratch runtime image running as a non-root userPublished images support:
linux/amd64linux/386linux/arm/v6linux/arm64/v8linux/riscv64Pull the latest image:
docker pull nickfedor/agh-cli:latest
Display the CLI version:
docker run --rm nickfedor/agh-cli:latest version
List configured instances:
docker run --rm \
-v "$(pwd)/config.yaml:/config.yaml:ro" \
nickfedor/agh-cli:latest \
--config /config.yaml instance list
List rewrite rules across every configured instance:
docker run --rm \
-v "$(pwd)/config.yaml:/config.yaml:ro" \
nickfedor/agh-cli:latest \
--config /config.yaml rewrite list --all
The container does not contain host configuration. Mount a configuration file and pass its path with --config:
instances:
default:
host: adguard.example.com
scheme: https
username: admin
Protect local configuration files because they may contain credentials:
chmod 600 config.yaml
Containers do not have access to the host's desktop keyring. Use an environment credential for container deployments:
instances:
default:
host: adguard.example.com
username: admin
credential:
source: env
env: ADGUARD_PASSWORD
docker run --rm \
-e ADGUARD_PASSWORD \
-v "$(pwd)/config.yaml:/config.yaml:ro" \
nickfedor/agh-cli:latest \
--config /config.yaml filtering status --instance default
Docker and Kubernetes secrets can be read without placing the secret value in the image or command line:
instances:
default:
host: adguard.example.com
username: admin
credential:
source: file
path: /run/secrets/agh-cli-default
docker run --rm \
-e ADGUARD_PASSWORD \
--mount type=bind,source="$(pwd)/adguard-password",target=/run/secrets/agh-cli-default,readonly \
-v "$(pwd)/config.yaml:/config.yaml:ro" \
nickfedor/agh-cli:latest \
--config /config.yaml filtering status --instance default
agh-cli opens mounted secret files read-only and never modifies them.
| Tag | Description |
|---|---|
latest | Latest stable release |
0.1.0 | Specific stable release patch version |
0.1 | Current minor release |
0 | Current major release |
amd64-0.1.0 | Platform-specific amd64 image |
<digest> | Immutable content-addressed image |
For production deployments, prefer a version tag or digest instead of latest.
Stable images are published with:
checksums.txt and image digest manifests1000Verify a downloaded image with Cosign before deployment:
cosign verify ghcr.io/nicholas-fedor/agh-cli:0.1.0
The GHCR image is available at:
ghcr.io/nicholas-fedor/agh-cli
agh-cli is licensed under the GNU Affero General Public License v3.0 or later.
Content type
Image
Digest
sha256:b7fd3c5d2…
Size
4.1 MB
Last updated
2 days ago
docker pull nickfedor/agh-cli