Incus mobile admin gateway with secure dashboard, Android client, role-based controls, audit logging
701
ScottiBYTE Incus Mobile Server is a self-hosted mobile administration gateway for Incus. It provides a secure web administration console and an Android client for monitoring and managing multiple Incus servers.
Android clients communicate with this server rather than connecting directly to Incus. Incus trust, credentials, authorization policy, and audit history remain centralized on the server.
View the v1.7.0 release on GitHub

Android Client
|
| HTTPS and token-authenticated mobile API
v
ScottiBYTE Incus Mobile Server
|
| Incus CLI, trusted Incus remotes, and SSH
v
One or more Incus Servers
The container maintains its own persistent application database and Incus client configuration. Android devices do not require Incus certificates, SSH keys, or direct access to the Incus API.
Create a project directory:
mkdir -p ~/scottibyte-incus-mobile-server
cd ~/scottibyte-incus-mobile-server
mkdir -p docker-data
Create docker-compose.yml:
services:
incus-mobile-server:
image: scottibyte/incus-mobile-server:1.7.0
container_name: scottibyte-incus-mobile-server
restart: unless-stopped
ports:
- "3088:3088"
environment:
APP_NAME: "ScottiBYTE Incus Mobile Server"
PORT: "3088"
DATA_DIR: "/app/data"
HOME: "/app/data"
INCUS_CONF: "/app/data/incus-client"
APP_TIME_ZONE: "America/Chicago"
# UID and GID that will own persistent data.
PUID: "1000"
PGID: "1000"
# Enable when operating behind a trusted reverse proxy.
TRUST_PROXY: "true"
# Networks permitted to access the web administration console.
ADMIN_ALLOWED_CIDRS: >-
127.0.0.1/32,
10.0.0.0/8,
172.16.0.0/12,
192.168.0.0/16
# Mobile-operation safety controls.
MOBILE_ACTIONS_ENABLED: "true"
MOBILE_TERMINAL_ENABLED: "true"
MOBILE_TERMINAL_IDLE_TIMEOUT_MS: "900000"
# Instances that mobile clients must not operate.
MOBILE_PROTECTED_INSTANCES: "IncusMobileServer"
volumes:
- ./docker-data:/app/data
# Optional: use local DNS resolvers.
# dns:
# - 172.16.1.10
# - 172.16.1.11
# Optional: provide static Incus server mappings.
# extra_hosts:
# - "mondo:172.16.1.225"
# - "vmsmist:172.16.1.50"
# - "vmsrain:172.16.1.51"
Adjust PUID, PGID, time zone, allowed networks, and protected-instance names for your environment.
Start the server:
docker compose up -d
Open the administration console:
http://<docker-host>:3088/admin
Complete the first-run administrator setup and 2FA enrollment before adding Incus servers or authorizing mobile clients.
Persistent application data is stored inside the container at:
/app/data
With the Compose example, it is stored on the Docker host at:
./docker-data
Persistent data includes:
The Incus CLI configuration is stored under:
/app/data/incus-client
Do not recreate the container without preserving /app/data.
The web console can establish Incus trust and add remote servers using SSH.
For each Incus server, provide:
844322Each target must have:
The image includes the Incus CLI, OpenSSH client, and supporting tools needed by this workflow.
Because the application runs inside Docker, the container must be able to resolve the Incus hostnames entered in the administration console.
Supported approaches include:
172.16.2.14
dns:
- 172.16.1.10
- 172.16.1.11
extra_hosts:
- "mondo:172.16.1.225"
- "vmsmist:172.16.1.50"
| Role | Mobile access |
|---|---|
| Viewer | Read-only server and instance inventory |
| Operator | Viewer access plus start, stop, and restart |
| Admin | Operator access plus shell and snapshot management |
The global mobile-actions switch overrides individual roles. When disabled, mobile inventory remains available, but operational controls are hidden and corresponding API requests are rejected.
Download the current Android application from the GitHub release:
ScottiBYTE Incus Mobile Android v0.8.0
HTTPS is strongly recommended whenever the server is accessed outside a trusted local network.


The server queries trusted Incus remotes for:

Uptime represents the Incus daemon uptime reported by the Incus metrics endpoint. It is not necessarily the Linux host’s boot uptime.
To update a version-pinned deployment, change the image tag in docker-compose.yml, then run:
docker compose pull
docker compose up -d
To follow the newest published image automatically, use:
image: scottibyte/incus-mobile-server:latest
Version pinning is recommended when controlled upgrades and predictable rollback are important.
Back up the persistent data directory before upgrades:
cp -a docker-data docker-data.backup
For a live SQLite database, use a consistent database backup method rather than copying a database file while it is being written.
The most important persistent assets are:
mobile.dbincus-client/ssh//app/dataCheck container state:
docker compose ps
Check recent logs:
docker logs --tail 100 scottibyte-incus-mobile-server
Check the mobile health endpoint:
curl http://127.0.0.1:3088/api/mobile/health
Check the advertised Android release:
curl http://127.0.0.1:3088/api/mobile/android-version
If an Incus remote is unavailable, verify:
8443ADMIN_ALLOWED_CIDRS.MOBILE_PROTECTED_INSTANCES./app/data securely.See the project repository for current license and source information.
Content type
Image
Digest
sha256:d2a6843a4…
Size
250.9 MB
Last updated
about 1 month ago
docker pull scottibyte/incus-mobile-server