Get started

Production Configuration

Checklist before using NasDash as a daily dashboard.

Minimal Checklist

  • NASDASH_JWT_SECRET is stable and kept outside of Compose.
  • Admin and viewer passwords are unique.
  • Private mode is enabled if the dashboard reveals internal information.
  • Port 2504 is limited to the LAN, Tailscale, or 127.0.0.1 behind a proxy.
  • HTTPS is active before any access from an untrusted network.
  • X-Forwarded-Proto: https header is passed by the reverse proxy.
  • Docker proxy is not exposed to the Internet and DELETE=0 unless explicitly required.
  • Full backup of /app/data has been tested.
  • Previous image digest or tag is retained for rollback.
  • Logs and /api/health are monitored after each update.

Reduce Port Exposure

Reverse proxy on the same machine:

ports:
  - "127.0.0.1:2504:2504"

Reverse proxy in the same Docker network: completely remove ports from the NasDash service and use expose: ["2504"]. The proxy must then reach nasdash:2504 via the internal network.

Public or Private Mode

Public mode does not grant mutations to a visitor, but it can expose services and widgets authorized for the viewer. It does not replace a publication decision. For a personal homelab, private mode behind Tailscale or HTTPS is the most prudent starting point.

Single Instance

NasDash stores its data in JSON files and uses in-memory caches. Do not run multiple replicas that write to the same volume. A serverless or multi-instance deployment is not the supported self-hosted production model.