Get started
Production Configuration
Checklist before using NasDash as a daily dashboard.
Minimal Checklist
-
NASDASH_JWT_SECRETis stable and kept outside of Compose. - Admin and viewer passwords are unique.
- Private mode is enabled if the dashboard reveals internal information.
- Port
2504is limited to the LAN, Tailscale, or127.0.0.1behind a proxy. - HTTPS is active before any access from an untrusted network.
-
X-Forwarded-Proto: httpsheader is passed by the reverse proxy. - Docker proxy is not exposed to the Internet and
DELETE=0unless explicitly required. - Full backup of
/app/datahas been tested. - Previous image digest or tag is retained for rollback.
- Logs and
/api/healthare monitored after each update.
Reduce Port Exposure
Reverse proxy on the same machine:
ports:
- "127.0.0.1:2504:2504"Reverse proxy in the same Docker network: completely remove ports from the NasDash service and use expose: ["2504"]. The proxy must then reach nasdash:2504 via the internal network.
Public or Private Mode
Public mode does not grant mutations to a visitor, but it can expose services and widgets authorized for the viewer. It does not replace a publication decision. For a personal homelab, private mode behind Tailscale or HTTPS is the most prudent starting point.
Single Instance
NasDash stores its data in JSON files and uses in-memory caches. Do not run multiple replicas that write to the same volume. A serverless or multi-instance deployment is not the supported self-hosted production model.