MeshCentral

MeshCentral

Docker app from hoody424's Repository

Overview

MeshCentral is a free, open-source, self-hosted remote management server. Through a small agent you get remote desktop, terminal, file transfer and power control for Windows, Linux and macOS devices, all in the browser. Uses the official image ghcr.io/ylianst/meshcentral. Before the first start: set Server name (HOSTNAME) to the DNS name or IP that agents and browsers use. Keep the HTTPS host port, its container port and PORT the same number: MeshCentral tells the agents to connect to the port it listens on. Then open https://[Server name]:8443, using exactly the Server name: MeshCentral refuses other names and the bare IP with "Invalid origin" after login. The WebUI button uses the IP, so it only works when HOSTNAME is the IP. The first account you create becomes the administrator. DYNAMIC_CONFIG=true writes the values of this template into config.json at every start. Set it to false if you prefer to edit appdata/meshcentral/data/config.json by hand.

MeshCentral for Unraid

MeshCentral is a self-hosted remote management server: remote desktop, terminal, file transfer and power control for Windows, Linux and macOS devices through a small agent.

Template: meshcentral.xml, image: ghcr.io/ylianst/meshcentral (official).

First start

  1. Set Server name (HOSTNAME) to the DNS name or IP that agents and browsers use. It becomes the server certificate name and is built into every agent installer, so set it before you install agents.
  2. Keep the HTTPS port (host side), its container port and PORT the same number (default 8443). MeshCentral tells the agents to connect to the port it listens on, so a different host port breaks the agents.
  3. Start the container and open https://<Server name>:8443, using exactly the name from HOSTNAME. MeshCentral refuses other names and the bare IP: after login you get "Invalid origin in HTTP request". The WebUI button in the Docker tab uses the server IP, so it only works when HOSTNAME is that IP. The browser warns about the self-signed certificate. The first account you create becomes the administrator.

config.json

The container keeps its configuration in appdata/meshcentral/data/config.json.

  • DYNAMIC_CONFIG=true (template default): at every start the template values (HOSTNAME, PORT, ALLOW_NEW_ACCOUNTS, WEBRTC, reverse proxy, database, ...) are written into config.json. Keys the template does not cover (for example aliasPort, title, autoBackup) are kept.
  • DYNAMIC_CONFIG=false: config.json is created once from the image template and then left alone; the template variables have no effect any more.

Own IP (br0 / VLAN)

With a custom network the container gets its own IP and no port mapping is used. Set PORT=443 and edit the HTTPS container port to 443.

Behind a reverse proxy

Agents must connect to the port the proxy publishes, so:

  • PORT = the proxy's public HTTPS port (usually 443); edit the HTTPS container port to the same number. The host port can be anything; point the proxy at it.
  • REVERSE_PROXY = the public name, e.g. mesh.example.com, and REVERSE_PROXY_TLS_PORT=443. MeshCentral loads the proxy certificate from there so the agents accept it.
  • If the proxy talks plain HTTP to MeshCentral, set TLS_OFFLOAD to the proxy's IP. Leave it empty otherwise: any value, even false, switches MeshCentral to plain HTTP.
  • The proxy must pass WebSockets.

More: MeshCentral documentation, section on reverse proxies.

Intel AMT

For Intel AMT CIRA add a port mapping 4433:4433 (host and container the same).

Database

The built-in NeDB database is fine for small setups. For many devices use MongoDB, MariaDB or PostgreSQL through the USE_* variables (advanced view).

Support

Requirements

Set Server name (HOSTNAME) before the first start. It is built into every agent installer.

Related apps

Details

Repository
ghcr.io/ylianst/meshcentral:latest
Last Updated2026-10-11
First Seen2026-10-11

Runtime arguments

Web UI
https://[IP]:[PORT:8443]/
Network
bridge
Shell
bash
Privileged
false

Template configuration

HTTPS portPorttcp

Web UI and agent connections. Host port, container port and PORT must be the same number.

Target
8443
Default
8443
Value
8443
HTTP portPorttcp

Plain HTTP, redirects to HTTPS. Any free host port.

Target
80
Default
8080
Value
8080
DataPathrw

config.json, certificates and the built-in database. Back this up.

Target
/opt/meshcentral/meshcentral-data
Default
/mnt/user/appdata/meshcentral/data
Value
/mnt/user/appdata/meshcentral/data
FilesPathrw

Files stored on the server through the web UI.

Target
/opt/meshcentral/meshcentral-files
Default
/mnt/user/appdata/meshcentral/files
Value
/mnt/user/appdata/meshcentral/files
BackupsPathrw

Server backups (when autoBackup is enabled in config.json).

Target
/opt/meshcentral/meshcentral-backups
Default
/mnt/user/appdata/meshcentral/backups
Value
/mnt/user/appdata/meshcentral/backups
WebPathrw

Custom web pages and themes. Can stay empty.

Target
/opt/meshcentral/meshcentral-web
Default
/mnt/user/appdata/meshcentral/web
Value
/mnt/user/appdata/meshcentral/web
Server name (HOSTNAME)Variable

DNS name or IP that agents and browsers use to reach this server, e.g. mesh.example.com. Used for the server certificate and built into every agent installer.

Target
HOSTNAME
PORTVariable

Port MeshCentral listens on and tells the agents. Must match the HTTPS port above.

Default
8443
Value
8443
DYNAMIC_CONFIGVariable

true: write the values of this template into config.json at every start. false: config.json is only created once and then left alone.

Default
true|false
Value
true
ALLOW_NEW_ACCOUNTSVariable

Let anyone create an account on the login page. The first account is always allowed and becomes the administrator.

Default
false|true
Value
false
WEBRTCVariable

Use WebRTC for direct connections between browser and agent.

Default
false|true
Value
false
ALLOW_PLUGINSVariable

Enable MeshCentral plugins.

Default
false|true
Value
false
IFRAMEVariable

Allow the web UI to be embedded in an iframe.

Default
false|true
Value
false
MINIFYVariable

Serve minified web pages.

Default
true|false
Value
true
LOCAL_SESSION_RECORDINGVariable

Allow recording of remote sessions.

Default
true|false
Value
true
REVERSE_PROXYVariable

Public name of a reverse proxy in front of MeshCentral, e.g. mesh.example.com. MeshCentral loads the proxy certificate from there so agents trust it. See the README.

REVERSE_PROXY_TLS_PORTVariable

HTTPS port of the reverse proxy.

Default
443
Value
443
TLS_OFFLOADVariable

IP of the reverse proxy when it terminates TLS and talks plain HTTP to MeshCentral. Leave EMPTY otherwise: any value, even false, switches TLS off.

TRUSTED_PROXYVariable

Trust X-Forwarded-For from: all, or one IP in double quotes, e.g. &quot;172.17.0.1&quot;.

INSTALL_STYLISHUIVariable

Download and install the third-party Stylish UI theme at every start.

Default
false|true
Value
false
USE_MONGODBVariable

Use MongoDB instead of the built-in database (recommended for many devices).

Default
false|true
Value
false
MONGO_URLVariable

e.g. mongodb://user:password@192.168.1.10:27017/meshcentral

USE_MARIADBVariable

Use MariaDB/MySQL instead of the built-in database.

Default
false|true
Value
false
MARIADB_HOSTVariable

MariaDB server name or IP.

MARIADB_PORTVariable

MariaDB port.

Default
3306
Value
3306
MARIADB_USERVariable

MariaDB user.

MARIADB_PASSVariable

MariaDB password.

MARIADB_DATABASEVariable

MariaDB database name.

Default
meshcentral
Value
meshcentral
USE_POSTGRESQLVariable

Use PostgreSQL instead of the built-in database.

Default
false|true
Value
false
PSQL_HOSTVariable

PostgreSQL server name or IP.

PSQL_PORTVariable

PostgreSQL port.

Default
5432
Value
5432
PSQL_USERVariable

PostgreSQL user.

PSQL_PASSVariable

PostgreSQL password.

PSQL_DATABASEVariable

PostgreSQL database name.

Default
meshcentral
Value
meshcentral