Next.js admin console for Centrifugo v6: dashboard, channel explorer, live tail, message search
1.0K
Next.js admin console for Centrifugo v6 with monitoring comparable to the AWS IoT MQTT console — dashboard, channel explorer with live tail, connections view, message search, and audit log.
The image contains only the admin UI. A full deployment needs:
| Service | Image | Purpose |
|---|---|---|
| admin | patcharp/centrifugo-admin | This image (port 3000) |
| centrifugo | centrifugo/centrifugo:v6 | The broker being administered |
| clickhouse | clickhouse/clickhouse-server:24-alpine | Message archive + metrics |
| redis | redis:7-alpine | Centrifugo engine state |
services:
admin:
image: patcharp/centrifugo-admin:0.1.0
ports:
- "3000:3000"
environment:
- AUTH_SECRET=${AUTH_SECRET} # 32-byte random secret for session JWTs
- SQLITE_PATH=/app/data/admin.db
- CENTRIFUGO_API_URL=http://centrifugo:8000/api
- CENTRIFUGO_API_KEY=${CENTRIFUGO_API_KEY} # must match Centrifugo http_api.key
- CENTRIFUGO_WS_URL=ws://centrifugo:8000/connection/websocket
- CENTRIFUGO_HMAC_SECRET=${CENTRIFUGO_HMAC_SECRET} # must match Centrifugo client token secret
- CLICKHOUSE_URL=http://clickhouse:8123
- CLICKHOUSE_DB=admin
- INGEST_API_KEY=${INGEST_API_KEY} # optional, see "Message archiving"
volumes:
- admin-data:/app/data
volumes:
admin-data:
Then create the first admin account:
curl -X POST http://localhost:3000/api/auth/register \
-H 'content-type: application/json' \
-d '{"username":"admin","password":"<strong-password>"}'
and sign in at http://localhost:3000.
| Variable | Required | Description |
|---|---|---|
AUTH_SECRET | yes | Random 32-byte secret used to sign admin session JWTs |
CENTRIFUGO_API_URL | yes | Centrifugo HTTP API endpoint, e.g. http://centrifugo:8000/api |
CENTRIFUGO_API_KEY | yes | Must match http_api.key in the Centrifugo config |
CENTRIFUGO_WS_URL | yes | Centrifugo WebSocket endpoint (used for live tail) |
CENTRIFUGO_HMAC_SECRET | yes | Must match client.token.hmac_secret_key in the Centrifugo config |
CLICKHOUSE_URL | yes | ClickHouse HTTP endpoint, e.g. http://clickhouse:8123 |
CLICKHOUSE_DB | yes | ClickHouse database name (tables message_archive, metrics) |
SQLITE_PATH | no | Path of the local admin DB (default under /app/data, mount a volume) |
INGEST_API_KEY | no | Enables service-to-service auth on POST /api/ingest via x-api-key header |
The admin never subscribes to channels by itself. Messages reach the archive (and the live events feed) two ways:
/api/centrifugo/publish / broadcast) — archived automatically.curl -X POST http://admin:3000/api/ingest \
-H 'content-type: application/json' \
-H "x-api-key: $INGEST_API_KEY" \
-d '{"channel":"chat:room1","payload":{"text":"hello"},"user":"u1","protocol":"api"}'
Only channel is required. The endpoint returns HTTP 500 when the ClickHouse insert fails, so callers can safely retry. (Centrifugo OSS has no outbound per-publish webhook — proxies only fire for client-side publishes — hence the mirror pattern.)
GET /api/health is unauthenticated and suitable for container health checks:
healthcheck:
test: ["CMD", "node", "-e", "fetch('http://127.0.0.1:3000/api/health').then(r => { if (!r.ok) process.exit(1) })"]
interval: 10s
0.1.1, latest — linux/amd64 (branded favicon fix)0.1.0 — linux/amd64Content type
Image
Digest
sha256:440c12038…
Size
98.2 MB
Last updated
3 months ago
docker pull patcharp/centrifugo-admin