Understanding NasDash

Architecture and Data

Understanding containers, API routes, and files to protect.

Overview

Navigateur
   │ HTTPS ou HTTP privé
   ▼
Reverse proxy facultatif
   │
   ▼
NasDash / Next.js :2504
   ├── /app/data                    configuration persistante
   ├── APIs Glances / Proxmox / LHM
   ├── API Tailscale
   └── docker-socket-proxy :2375   API Docker filtrée
          └── /var/run/docker.sock:ro

The :ro mount of the socket prevents the proxy from modifying the socket file itself. The allowed operations remain determined by the proxy variables (POST, DELETE, etc.).

Persistent Files

FileRole
config.jsonsettings, devices, hosts, and Docker actions
services.jsoncategories and services
topology.jsonnodes, groups, and connections
calendar.jsonlocal events
custom_tabs.jsoncustom tabs and layouts
users.jsonaccounts, hashes, roles, and session versions
jwt.secretsession and encryption continuity if no environment secret is provided
encryption.keypersistent key used for encrypted credentials
logos/logos uploaded by the administrator

Operational Constraints

  • Use a single NasDash instance per data store.
  • Do not mount /app/data as read-only in normal production.
  • Back up the entire folder or volume, including keys.
  • Never place the actual contents of data/ in Git.
  • A serverless platform is suitable for stateless demos, not for persistent self-hosted instances.

Container Process

The production image is built with Node.js 22 Alpine and runs the application under UID/GID 1001:1001. The health check queries http://127.0.0.1:2504/api/health.