Sign inSign up

saelix/sencho

By saelix

•Updated 10 minutes ago

Buildkit cache
Image
Developer tools
0

100K+

saelix/sencho repository overview

⁠Sencho

Self-hosted Docker Compose management for one machine or a fleet.

GitHub⁠ · Documentation⁠ · Discussions⁠ · License⁠

Sencho is currently in public beta on the path to v1.0. Core workflows are actively tested, but early users should review the known limitations⁠ and avoid deploying it blindly on critical infrastructure without testing in their own environment first.

⁠What Sencho is

Sencho is for homelab operators, small DevOps teams, and platform engineers who run services on Docker Compose, want a graphical interface without giving up file-on-disk workflows, and need to manage more than one machine without SSH gymnastics or a VPN.

It runs as a single container on your hardware and gives you a UI for the work you currently do over SSH on compose stacks: deploying, editing files, watching logs, restarting containers, browsing volumes, and recovering from failures. Your compose files stay on the host filesystem and remain the source of truth.

A Sencho instance is autonomous. To manage another machine, you install a second Sencho on it and connect them with a long-lived API token; the primary dashboard then acts as an authenticated HTTP and WebSocket proxy across your fleet. Use TLS, a VPN, or a private network for any untrusted link. Each node still uses its local Docker socket, but Sencho does not require SSH and does not expose a remote Docker socket on the network. For nodes behind NAT or strict firewalls, the Pilot Agent establishes a single outbound WebSocket tunnel to the primary.

Most capabilities are free in the Community tier. Governance, scale, and orchestration features ship in the paid Admiral tier; pricing lives at sencho.io/pricing⁠.

⁠Before you install

Sencho talks to Docker through the host's /var/run/docker.sock. Mounting this socket grants Sencho the same privilege as sudo docker on the host. This is the same model used by Portainer, Dockge, Komodo, and other Compose dashboards. If your threat model requires stricter isolation, see the self-hosting guide⁠ and front Sencho with a reverse proxy that enforces authentication.

⁠Quick start

Sencho runs in a single container.

services:
  sencho:
    image: saelix/sencho:latest
    container_name: sencho
    restart: unless-stopped
    ports:
      - "1852:1852"
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
      - ./data:/app/data
      # 1:1 Compose Path Rule: the host path MUST match the container path
      - /opt/docker:/opt/docker
    environment:
      - COMPOSE_DIR=/opt/docker
      - DATA_DIR=/app/data
docker compose up -d

Open http://your-server:1852 and create your admin account.

Always front Sencho with a TLS-terminating reverse proxy in production. See the self-hosting guide⁠ for hardening, environment variables, and reverse-proxy examples.

⁠Run with docker run instead
docker run -d --name sencho \
  -p 1852:1852 \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -v sencho_data:/app/data \
  # 1:1 Compose Path Rule: the host path MUST match the container path
  -v /opt/docker:/opt/docker \
  -e COMPOSE_DIR=/opt/docker \
  saelix/sencho:latest

For the full walkthrough, see the quickstart guide⁠.

⁠Adding remote nodes

To manage a second machine, install Sencho on it the same way, then add it from the primary dashboard with its URL and a long-lived API token. The primary proxies authenticated HTTP and WebSocket requests to the remote instance. The remote node does not run SSH for Sencho, does not expose its Docker socket on the network, and does not run a separate agent process. The local Sencho on each node manages its own Docker through the standard socket mount described above. Nodes behind NAT or strict firewalls can opt into the Pilot Agent for outbound-only connectivity.

See the multi-node guide⁠ for the full token-bearer flow.

⁠What you get

  • Full Compose lifecycle: deploy, edit, restart, stop, pull, rollback.
  • Monaco editor with diff preview, Git-sourced stacks, App Store templates, stack labels.
  • Aggregated logs and stats across the fleet, threshold alerts, audit log, network topology.
  • Multi-node management via authenticated proxy or outbound-only Pilot Agent.
  • RBAC with five roles (admin, viewer, deployer, node-admin, auditor), TOTP 2FA, SSO (Custom OIDC, presets for Google / GitHub / Okta, LDAP / Active Directory).
  • Trivy vulnerability scanning with VEX-based suppression, private registries, deploy enforcement on scan policy.
  • Notification routing to Slack, Discord, email, and webhooks.
  • Automation: auto-heal, auto-update, scheduled operations, Blueprints with drift detection, webhooks, Fleet Secrets.

Tier coverage: Most features, including automation (auto-heal, auto-update, scheduled operations, webhooks), are free in the Community tier. The paid Admiral tier adds fleet orchestration and governance: Blueprints with drift detection, Fleet Secrets, Sencho Mesh, host console, audit log analytics and export, private registries, managed cloud backup, deploy enforcement with SARIF / SBOM export, and LDAP / Active Directory SSO. Full breakdown at sencho.io/pricing⁠.

⁠Telemetry and data handling

Sencho does not emit telemetry, analytics, or crash reports. The only outbound traffic is license validation against Lemon Squeezy, and only when a paid license key is activated. Community-tier instances make no outbound calls to Sencho-controlled endpoints. Stack metadata, container inventory, and user activity never leave your instance.

⁠Support

Images are signed with cosign and published with SBOM and VEX attestations on every tagged release; see SECURITY.md⁠ for verification commands.

Tag summary

Content type

Image

Digest

sha256:12a7e1790…

Size

200.5 MB

Last updated

10 minutes ago

docker pull saelix/sencho:preview-fc96137