Skip to content

Arcane¶

Description / nameInput element
Your domain name

Overview¶

Arcane is a free, open-source Docker management UI designed to simplify the administration of container infrastructure through a modern, web-based interface.


Deployment¶

sb install arcane

Usage¶

Visit https://arcane.iYOUR_DOMAIN_NAMEi.

Role Defaults¶

Variables can be customized using the Inventory. (1)

  1. Example override

    arcane_name: "custom_value"
    

    Avoid overriding variables ending in _default

    When overriding variables that end in _default (like arcane_docker_envs_default), you replace the entire default configuration. Future updates that add new default values will not be applied to your setup, potentially breaking functionality.

    Instead, use the corresponding _custom variable (like arcane_docker_envs_custom) to add your changes. Custom values are merged with defaults, ensuring you receive updates.

arcane_name
# Type: string
arcane_name: arcane
arcane_role_admin_username
# Used only while the initial administrator still has its default credentials.
# Type: string
arcane_role_admin_username: "{{ user.name }}"
arcane_role_admin_password
# Default policy requires 12 characters, uppercase, lowercase, a number and a symbol.
# Type: string
arcane_role_admin_password: "{{ user.pass }}"
arcane_role_admin_email
# Type: string
arcane_role_admin_email: "{{ user.email }}"
arcane_role_setup_url
# Internal address used for first-install setup, bypassing the web SSO middleware.
# Type: string
arcane_role_setup_url: "http://{{ lookup('role_var', '_docker_networks_alias', role='arcane') }}:{{ lookup('role_var', '_web_port', role='arcane') }}"
arcane_role_encryption_key
# 64-character hexadecimal key. The default is generated automatically.
# Type: string
arcane_role_encryption_key: "{{ arcane_saltbox_facts.facts.encryption_key }}"
arcane_role_trusted_proxies
# Comma-separated proxy addresses or CIDRs trusted to supply client IP headers.
# Type: string
arcane_role_trusted_proxies: "172.19.0.0/16,fd00:dead:beef::/48"
arcane_role_postgres_enabled
# Use Postgres instead of SQLite. Existing SQLite data is not migrated.
# Type: bool (true/false)
arcane_role_postgres_enabled: false
arcane_role_postgres_deploy
# Deploy a Postgres container. Requires arcane_role_postgres_enabled.
# Type: bool (true/false)
arcane_role_postgres_deploy: true
arcane_role_postgres_name
# Type: string
arcane_role_postgres_name: "{{ arcane_name }}-postgres"
arcane_role_postgres_user
# Empty values use the postgres role defaults.
# Type: string
arcane_role_postgres_user: ""
arcane_role_postgres_password
# Type: string
arcane_role_postgres_password: ""
arcane_role_postgres_docker_env_db
# Type: string
arcane_role_postgres_docker_env_db: "{{ arcane_name }}"
arcane_role_postgres_port
# Connection port for external instances; the managed container listens on 5432.
# Type: string
arcane_role_postgres_port: "5432"
arcane_role_postgres_docker_image_repo
# Type: string
arcane_role_postgres_docker_image_repo: "postgres"
arcane_role_postgres_docker_image_tag
# Type: string
arcane_role_postgres_docker_image_tag: "18"
arcane_role_postgres_url
# Override with a complete Postgres URL to configure external TLS options.
# Type: string
arcane_role_postgres_url: "postgres://{{ lookup('role_var', '_postgres_credentials_lookup', role='arcane') }}@{{ lookup('role_var', '_postgres_name', role='arcane') }}:{{ lookup('role_var', '_postgres_port', role='arcane') }}/{{ lookup('role_var', '_postgres_docker_env_db', role='arcane') }}"
arcane_role_postgres_docker_healthcheck
# Type: dict
arcane_role_postgres_docker_healthcheck:
  test:
    - CMD
    - pg_isready
    - "-d"
    - "{{ lookup('role_var', '_postgres_docker_env_db', role='arcane') }}"
    - "-U"
    - "{{ lookup('role_var', '_postgres_user_lookup', role='arcane') }}"
  start_period: 20s
  interval: 30s
  retries: 5
  timeout: 5s
arcane_role_web_subdomain
# Type: string
arcane_role_web_subdomain: "{{ arcane_name }}"
arcane_role_web_domain
# Type: string
arcane_role_web_domain: "{{ user.domain }}"
arcane_role_web_port
# Type: string
arcane_role_web_port: "3552"
arcane_role_web_url
# Type: string
arcane_role_web_url: "{{ lookup('role_web', role='arcane', scheme='https') }}"
arcane_role_dns_record
# Type: string
arcane_role_dns_record: "{{ lookup('role_var', '_web_subdomain', role='arcane') }}"
arcane_role_dns_zone
# Type: string
arcane_role_dns_zone: "{{ lookup('role_var', '_web_domain', role='arcane') }}"
arcane_role_dns_proxy
# Type: bool (true/false)
arcane_role_dns_proxy: "{{ dns_proxied }}"
arcane_role_traefik_sso_middleware
# Type: string
arcane_role_traefik_sso_middleware: "{{ traefik_default_sso_middleware }}"
arcane_role_traefik_middleware_default
# Type: string
arcane_role_traefik_middleware_default: "{{ traefik_default_middleware }}"
arcane_role_traefik_middleware_custom
# Type: string
arcane_role_traefik_middleware_custom: ""
arcane_role_traefik_middleware_default_api
# Type: string
arcane_role_traefik_middleware_default_api: "{{ traefik_default_middleware_api }}"
arcane_role_traefik_middleware_custom_api
# Type: string
arcane_role_traefik_middleware_custom_api: ""
arcane_role_traefik_certresolver
# Type: string
arcane_role_traefik_certresolver: "{{ traefik_default_certresolver }}"
arcane_role_traefik_enabled
# Type: bool (true/false)
arcane_role_traefik_enabled: true
arcane_role_traefik_api_enabled
# Type: bool (true/false)
arcane_role_traefik_api_enabled: false
arcane_role_traefik_api_endpoint
# Type: string
arcane_role_traefik_api_endpoint: ""

Container

arcane_role_docker_container
# Type: string
arcane_role_docker_container: "{{ arcane_name }}"

Image

arcane_role_docker_image_pull
# Type: bool (true/false)
arcane_role_docker_image_pull: true
arcane_role_docker_image_repo
# Type: string
arcane_role_docker_image_repo: "ghcr.io/getarcaneapp/manager"
arcane_role_docker_image_tag
# Type: string
arcane_role_docker_image_tag: "latest"
arcane_role_docker_image
# Type: string
arcane_role_docker_image: "{{ lookup('role_var', '_docker_image_repo', role='arcane') }}:{{ lookup('role_var', '_docker_image_tag', role='arcane') }}"

Envs

arcane_role_docker_envs_default
# Type: dict
arcane_role_docker_envs_default:
  PUID: "{{ uid }}"
  PGID: "{{ gid }}"
  TZ: "{{ tz }}"
  APP_URL: "{{ lookup('role_var', '_web_url', role='arcane') }}"
  ENCRYPTION_KEY: "{{ lookup('role_var', '_encryption_key', role='arcane') }}"
  DATABASE_URL: "{{ lookup('role_var', '_postgres_url', role='arcane')
                 if (lookup('role_var', '_postgres_enabled', role='arcane') | bool)
                 else 'file:/app/data/arcane.db?_pragma=journal_mode(WAL)&_pragma=busy_timeout(2500)&_txlock=immediate' }}"
  PROJECTS_DIRECTORY: "{{ lookup('role_var', '_paths_projects_location', role='arcane') }}"
  TRUSTED_PROXIES: "{{ lookup('role_var', '_trusted_proxies', role='arcane', default=omit, default_if_empty=true) }}"
arcane_role_docker_envs_custom
# Type: dict
arcane_role_docker_envs_custom: {}

Volumes

arcane_role_docker_volumes_default
# Type: list
arcane_role_docker_volumes_default:
  - "{{ lookup('role_var', '_paths_location', role='arcane') }}:/app/data"
  - "{{ lookup('role_var', '_paths_projects_location', role='arcane') }}:{{ lookup('role_var', '_paths_projects_location', role='arcane') }}"
  - "/var/run/docker.sock:/var/run/docker.sock"
arcane_role_docker_volumes_custom
# Type: list
arcane_role_docker_volumes_custom: []

Cgroup namespace

arcane_role_docker_cgroupns_mode
# Type: string
arcane_role_docker_cgroupns_mode: host

Healthcheck

arcane_role_docker_healthcheck
# Type: dict
arcane_role_docker_healthcheck:
  test:
    - CMD
    - ./arcane
    - health
    - --timeout
    - 2s
  interval: 10s
  timeout: 3s
  retries: 5
  start_period: 15s

Hostname

arcane_role_docker_hostname
# Type: string
arcane_role_docker_hostname: "{{ arcane_name }}"

Networks

arcane_role_docker_networks_alias
# Type: string
arcane_role_docker_networks_alias: "{{ arcane_name }}"
arcane_role_docker_networks_default
# Type: list
arcane_role_docker_networks_default: []
arcane_role_docker_networks_custom
# Type: list
arcane_role_docker_networks_custom: []

Restart Policy

arcane_role_docker_restart_policy
# Type: string
arcane_role_docker_restart_policy: unless-stopped

The following advanced options are available via create_docker_container but are not defined in the role. See: docker_container module

A blank value is YAML null and inherits any lower-precedence role or shared default. Explicit Ansible omit is accepted only for optional Docker settings; default-backed and required settings reject it. Use the documented typed empty value, such as "", [], or {}, when disabling a guaranteed setting.

GPU

arcane_role_docker_gpu_enabled
# Set this to true to let the app use a GPU.
# Intel access also requires gpu.intel: true.
# NVIDIA access also requires nvidia_enabled: true.
# This setting does not install or enable GPU support on the server.
# Type: bool (true/false)
arcane_role_docker_gpu_enabled: false
arcane_role_docker_nvidia_disabled
# Set this to true to turn off automatic NVIDIA access for this app.
# It only has an effect when the app's _docker_gpu_enabled option and
# nvidia_enabled are both true.
# Automatic /dev/dri access may remain.
# Type: bool (true/false)
arcane_role_docker_nvidia_disabled: false
arcane_role_docker_dev_dri_disabled
# Set this to true to stop Saltbox from automatically sharing the
# server's /dev/dri video devices with this app.
# It only has an effect when the app's _docker_gpu_enabled option is true
# and either gpu.intel or nvidia_enabled is true.
# NVIDIA-specific access may remain.
# Type: bool (true/false)
arcane_role_docker_dev_dri_disabled: false

Resource Limits

arcane_role_docker_blkio_weight
# Type: int
arcane_role_docker_blkio_weight:
arcane_role_docker_cpu_period
# Type: int
arcane_role_docker_cpu_period:
arcane_role_docker_cpu_quota
# Type: int
arcane_role_docker_cpu_quota:
arcane_role_docker_cpu_shares
# Type: int
arcane_role_docker_cpu_shares:
arcane_role_docker_cpus
# CPU allocation accepted as a numeric string, such as 1.5
# Type: string (quoted number)
arcane_role_docker_cpus:
arcane_role_docker_cpuset_cpus
# Type: string
arcane_role_docker_cpuset_cpus:
arcane_role_docker_cpuset_mems
# Type: string
arcane_role_docker_cpuset_mems:
arcane_role_docker_kernel_memory
# Type: string
arcane_role_docker_kernel_memory:
arcane_role_docker_memory
# Type: string
arcane_role_docker_memory:
arcane_role_docker_memory_reservation
# Type: string
arcane_role_docker_memory_reservation:
arcane_role_docker_memory_swap
# Type: string
arcane_role_docker_memory_swap:
arcane_role_docker_memory_swappiness
# Type: int
arcane_role_docker_memory_swappiness:
arcane_role_docker_shm_size
# Type: string
arcane_role_docker_shm_size:

Security & Devices

arcane_role_docker_cap_drop
# Type: list
arcane_role_docker_cap_drop:
arcane_role_docker_device_cgroup_rules
# Type: list
arcane_role_docker_device_cgroup_rules:
arcane_role_docker_device_read_bps
# Type: list
arcane_role_docker_device_read_bps:
arcane_role_docker_device_read_iops
# Type: list
arcane_role_docker_device_read_iops:
arcane_role_docker_device_requests
# Type: list
arcane_role_docker_device_requests:
arcane_role_docker_device_write_bps
# Type: list
arcane_role_docker_device_write_bps:
arcane_role_docker_device_write_iops
# Type: list
arcane_role_docker_device_write_iops:
arcane_role_docker_devices
# Type: list
arcane_role_docker_devices:
arcane_role_docker_groups
# Type: list
arcane_role_docker_groups:
arcane_role_docker_privileged
# Type: bool (true/false)
arcane_role_docker_privileged:
arcane_role_docker_security_opts
# Type: list
arcane_role_docker_security_opts:
arcane_role_docker_user
# Type: string
arcane_role_docker_user:
arcane_role_docker_userns_mode
# Type: string
arcane_role_docker_userns_mode:

Networking

arcane_role_docker_dns_opts
# Type: list
arcane_role_docker_dns_opts:
arcane_role_docker_dns_search_domains
# Type: list
arcane_role_docker_dns_search_domains:
arcane_role_docker_dns_servers
# Type: list
arcane_role_docker_dns_servers:
arcane_role_docker_domainname
# Type: string
arcane_role_docker_domainname:
arcane_role_docker_exposed_ports
# Type: list
arcane_role_docker_exposed_ports:
arcane_role_docker_hosts
# Type: dict
arcane_role_docker_hosts:
arcane_role_docker_hosts_use_common
# Type: bool (true/false)
arcane_role_docker_hosts_use_common:
arcane_role_docker_ipc_mode
# Type: string
arcane_role_docker_ipc_mode:
arcane_role_docker_links
# Type: list
arcane_role_docker_links:
arcane_role_docker_network_mode
# Type: string
arcane_role_docker_network_mode:
arcane_role_docker_pid_mode
# Type: string
arcane_role_docker_pid_mode:
arcane_role_docker_ports
# Type: list
arcane_role_docker_ports:
arcane_role_docker_uts
# Type: string
arcane_role_docker_uts:

Storage

arcane_role_docker_keep_volumes
# Type: bool (true/false)
arcane_role_docker_keep_volumes:
arcane_role_docker_mounts
# Type: list
arcane_role_docker_mounts:
arcane_role_docker_storage_opts
# Type: dict
arcane_role_docker_storage_opts:
arcane_role_docker_tmpfs
# Type: list
arcane_role_docker_tmpfs:
arcane_role_docker_volume_driver
# Type: string
arcane_role_docker_volume_driver:
arcane_role_docker_volumes_from
# Type: list
arcane_role_docker_volumes_from:
arcane_role_docker_volumes_global
# Type: bool (true/false)
arcane_role_docker_volumes_global:
arcane_role_docker_working_dir
# Type: string
arcane_role_docker_working_dir:

Monitoring & Lifecycle

arcane_role_docker_auto_remove
# Type: bool (true/false)
arcane_role_docker_auto_remove:
arcane_role_docker_cleanup
# Type: bool (true/false)
arcane_role_docker_cleanup:
arcane_role_docker_force_kill
# Type: bool (true/false)
arcane_role_docker_force_kill:
arcane_role_docker_healthy_wait_timeout
# Healthy-state wait timeout in seconds
# Type: int
arcane_role_docker_healthy_wait_timeout:
arcane_role_docker_init
# Type: bool (true/false)
arcane_role_docker_init:
arcane_role_docker_kill_signal
# Type: string
arcane_role_docker_kill_signal:
arcane_role_docker_log_driver
# Type: string
arcane_role_docker_log_driver:
arcane_role_docker_log_options
# Type: dict
arcane_role_docker_log_options:
arcane_role_docker_oom_killer
# Type: bool (true/false)
arcane_role_docker_oom_killer:
arcane_role_docker_oom_score_adj
# Type: int
arcane_role_docker_oom_score_adj:
arcane_role_docker_output_logs
# Type: bool (true/false)
arcane_role_docker_output_logs:
arcane_role_docker_paused
# Type: bool (true/false)
arcane_role_docker_paused:
arcane_role_docker_recreate
# Type: bool (true/false)
arcane_role_docker_recreate:
arcane_role_docker_restart_retries
# Type: int
arcane_role_docker_restart_retries:
arcane_role_docker_stop_signal
# Type: string
arcane_role_docker_stop_signal:
arcane_role_docker_stop_timeout
# Type: int
arcane_role_docker_stop_timeout:

Other Options

arcane_role_docker_capabilities
# Type: list
arcane_role_docker_capabilities:
arcane_role_docker_cgroup_parent
# Type: string
arcane_role_docker_cgroup_parent:
arcane_role_docker_commands
# Type: list
arcane_role_docker_commands:
arcane_role_docker_create_timeout
# Type: int
arcane_role_docker_create_timeout:
arcane_role_docker_entrypoint
# Type: list
arcane_role_docker_entrypoint:
arcane_role_docker_env_file
# Type: string
arcane_role_docker_env_file:
arcane_role_docker_labels
# Type: dict
arcane_role_docker_labels:
arcane_role_docker_labels_use_common
# Type: bool (true/false)
arcane_role_docker_labels_use_common:
arcane_role_docker_read_only
# Type: bool (true/false)
arcane_role_docker_read_only:
arcane_role_docker_runtime
# Type: string
arcane_role_docker_runtime:
arcane_role_docker_sysctls
# Type: dict
arcane_role_docker_sysctls:
arcane_role_docker_ulimits
# Type: list
arcane_role_docker_ulimits:
arcane_role_autoheal_enabled
# Enable or disable Autoheal monitoring for the container created when deploying
# Type: bool (true/false)
arcane_role_autoheal_enabled: true
arcane_role_depends_on
# List of container dependencies that must be running before the container start
# Type: string
arcane_role_depends_on: ""
arcane_role_depends_on_delay
# Delay in seconds before starting the container after dependencies are ready
# Type: string (quoted number)
arcane_role_depends_on_delay: "0"
arcane_role_depends_on_healthchecks
# Enable healthcheck waiting for container dependencies
# Type: string ("true"/"false")
arcane_role_depends_on_healthchecks:
arcane_role_diun_enabled
# Enable or disable Diun update notifications for the container created when deploying
# Type: bool (true/false)
arcane_role_diun_enabled: true
arcane_role_dns_enabled
# Enable or disable automatic DNS record creation for the container
# Type: bool (true/false)
arcane_role_dns_enabled: true
arcane_role_docker_controller
# Enable or disable Saltbox Docker Controller management for the container
# Type: bool (true/false)
arcane_role_docker_controller: true
arcane_role_docker_networks_alias_custom
# Type: list
arcane_role_docker_networks_alias_custom:
arcane_role_docker_volumes_download
# Type: bool (true/false)
arcane_role_docker_volumes_download:
arcane_role_paths_folders_list_custom
# Extra directories to create
# Type: list
arcane_role_paths_folders_list_custom:
arcane_role_paths_group
# Group for directories created by the role
# Type: string
arcane_role_paths_group:
arcane_role_paths_owner
# Owner for directories created by the role
# Type: string
arcane_role_paths_owner:
arcane_role_paths_permissions
# Permissions for directories created by the role
# Type: string
arcane_role_paths_permissions:
arcane_role_paths_recursive
# Apply owner and group recursively without changing child modes
# Type: bool (true/false)
arcane_role_paths_recursive:
arcane_role_themepark_addons
# ThemePark addon names to enable
# Type: list
arcane_role_themepark_addons:
arcane_role_themepark_app
# Type: string
arcane_role_themepark_app:
arcane_role_themepark_theme
# Type: string
arcane_role_themepark_theme:
arcane_role_traefik_api_middleware_http
# Type: string
arcane_role_traefik_api_middleware_http:
arcane_role_traefik_autodetect_enabled
# Enable Traefik autodetect middleware for the container
# Type: bool (true/false)
arcane_role_traefik_autodetect_enabled: false
arcane_role_traefik_crowdsec_enabled
# Enable CrowdSec middleware for the container
# Type: bool (true/false)
arcane_role_traefik_crowdsec_enabled: false
arcane_role_traefik_error_pages_enabled
# Enable custom error pages middleware for the container
# Type: bool (true/false)
arcane_role_traefik_error_pages_enabled: false
arcane_role_traefik_gzip_enabled
# Enable gzip compression middleware for the container
# Type: bool (true/false)
arcane_role_traefik_gzip_enabled: false
arcane_role_traefik_middleware_http
# Type: string
arcane_role_traefik_middleware_http:
arcane_role_traefik_middleware_http_api_insecure
# Type: bool (true/false)
arcane_role_traefik_middleware_http_api_insecure:
arcane_role_traefik_middleware_http_insecure
# Type: bool (true/false)
arcane_role_traefik_middleware_http_insecure:
arcane_role_traefik_priority
# Type: string
arcane_role_traefik_priority:
arcane_role_traefik_robot_enabled
# Enable robots.txt middleware for the container
# Type: bool (true/false)
arcane_role_traefik_robot_enabled: true
arcane_role_traefik_tailscale_enabled
# Enable Tailscale-specific Traefik configuration for the container
# Type: bool (true/false)
arcane_role_traefik_tailscale_enabled: false
arcane_role_traefik_wildcard_enabled
# Enable wildcard certificate for the container
# Type: bool (true/false)
arcane_role_traefik_wildcard_enabled: true
arcane_role_web_api_http_port
# Type: string (quoted number)
arcane_role_web_api_http_port:
arcane_role_web_api_http_scheme
# Type: string ("http"/"https")
arcane_role_web_api_http_scheme:
arcane_role_web_api_http_serverstransport
# Type: dict/omit
arcane_role_web_api_http_serverstransport:
arcane_role_web_api_port
# Type: string (quoted number)
arcane_role_web_api_port:
arcane_role_web_api_scheme
# Type: string ("http"/"https")
arcane_role_web_api_scheme:
arcane_role_web_api_serverstransport
# Type: dict/omit
arcane_role_web_api_serverstransport:
arcane_role_web_fqdn_override
# Override the Traefik fully qualified domain name (FQDN) for the container
# Type: list
arcane_role_web_fqdn_override:

Example Override

arcane_role_web_fqdn_override:
  - "{{ traefik_host }}"
  - "arcane2.{{ user.domain }}"
  - "arcane.otherdomain.tld"

Note: Include {{ traefik_host }} to preserve the default FQDN alongside your custom entries

arcane_role_web_host_override
# Override the Traefik web host configuration for the container
# Type: string
arcane_role_web_host_override:

Example Override

arcane_role_web_host_override: "Host(`{{ traefik_host }}`) || Host(`{{ 'arcane2.' + user.domain }}`)"

Note: Use {{ traefik_host }} to include the default host configuration in your custom rule

arcane_role_web_http_port
# Type: string (quoted number)
arcane_role_web_http_port:
arcane_role_web_http_scheme
# Type: string ("http"/"https")
arcane_role_web_http_scheme:
arcane_role_web_http_serverstransport
# Type: dict/omit
arcane_role_web_http_serverstransport:
arcane_role_web_scheme
# URL scheme to use for web access to the container
# Type: string ("http"/"https")
arcane_role_web_scheme:
arcane_role_web_serverstransport
# Type: dict/omit
arcane_role_web_serverstransport: