Anjungan can automatically detect and register the host server where it's deployed — no manual server entry needed. This gives you visibility into the Docker host's containers, metrics, and compliance directly from the Anjungan dashboard.
On startup, the backend runs a self-detection routine:
- Check
SELF_SERVER_ENABLED=true— skips if false/unset - Access the Docker socket (
/var/run/docker.sock) - Detect host info — hostname, OS, kernel, CPU model, core count
- Find or Create a server record in the database (matched by hostname)
- Register with
connection_type: docker-socketandis_self: true
The registered server appears as "anjungan-host" by default, visible in:
- Servers list — shows CPU/OS info
- Container page — lists all containers on the host (including Anjungan's own services)
- Dashboard — host metrics (CPU, memory, disk)
- SSH Terminal — if SSH credentials are configured (falls back to Docker nsenter otherwise)
- Compliance scanning — CIS Docker and Lynis scans run on the host
| Variable | Default | Description |
|---|---|---|
SELF_SERVER_ENABLED |
false |
Set to "true" to enable auto-registration |
SELF_SERVER_NAME |
"anjungan-host" |
Display name for the self-server |
DOCKER_SOCKET_PATH |
/var/run/docker.sock |
Path to the Docker socket |
SELF_HOST_NETWORK |
— | Host IP from inside the container (e.g. 172.22.0.1 for Docker Compose networks, or host.docker.internal) |
The backend container needs the Docker socket mounted and the Docker CLI installed:
backend:
environment:
SELF_SERVER_ENABLED: "true"
volumes:
- /var/run/docker.sock:/var/run/docker.sock:rw
group_add:
- "988" # Docker group GID on the host — run `getent group docker` to verifyNote: The Docker group GID (
988in the example) varies by OS. Check with:getent group docker | cut -d: -f3
The Docker CLI must be available inside the backend container. The multi-stage Dockerfile includes it by default. If using a custom image, ensure docker is installed.
The self-server uses connection_type: docker-socket instead of SSH. This means:
- Container listing and management → via Docker socket directly
- Host metrics → via docker run --pid=host --privileged alpine nsenter
- SSH Terminal → via Docker nsenter by default, or SSH if SSH credentials are configured
If you want to SSH into the self-server (e.g. for file editing, package management), generate an SSH key pair and add it to the server:
- Generate a key pair on the host (outside the container)
- Add the public key to
~/.ssh/authorized_keyson the host - Store the private key in Anjungan via Settings → SSH Keys
- Assign the key to the self-server in Server Settings with SSH user
root
Once configured, the SSH Terminal will use SSH instead of Docker nsenter.
When deploying Anjungan on a new server:
- Include the self-server config in your
docker-compose.yml(see deployment.md) - Set
SELF_SERVER_ENABLED: "true"in the backend environment - Mount the Docker socket
- Start the stack
The self-server registers automatically on first startup.
- Same host, same hostname → updates the existing record
- Different host → creates a new record (matched by hostname)
- Same DB, different hostname → creates a new record alongside the old one (old one stays as offline)
Check the backend logs:
docker compose logs backend | grep "\[self\]"Expected output:
[self] Docker host detected: my-server
[self] self-server updated: anjungan-host (abc-123...)
If you see [self] Docker socket not accessible or [self] self-server detection disabled:
- Verify
SELF_SERVER_ENABLED: "true"is set - Verify the Docker socket is mounted (
/var/run/docker.sock) - Verify the container user is in the docker group (check
group_addGID)
This was a known issue where shell-quoted --format arguments were improperly parsed. Fixed in container/handler.go with a shell-aware argument splitter (shellSplit). Ensure you're running the latest build.
Docker socket operations run directly via the socket. Check that:
- The socket is mounted with
:rw(read-write) - The container has docker group access
- The
dockerCLI is installed in the backend container