rct-manager

rct-manager

Docker app from GillBates' Repository

Overview

Vendor-neutral REST gateway for RCT Power inverters. Speaks the RCT serial protocol over TCP to one or more inverters and turns it into clean JSON, a Prometheus endpoint, and optional, guarded write access. No vendor app, no protocol knowledge needed. Features: - Read any metric from the full protocol catalog (894 of 895 IDs), partial success on multi-metric requests, RFC 9457 error responses - Energy Manager for dynamic electricity tariffs: charge the battery from the grid or discharge it to the house with a target state of charge, power limit and duration - Data export to your own InfluxDB 2 or QuestDB for Grafana, Telegraf and custom analysis - Administration GUI: Overview, Inverters, Energy Manager, TSDB, Prometheus, API tokens and Settings pages with autosave - Ready-made /metrics endpoint for Telegraf, Grafana and friends; a scrape never touches the inverter - API token authentication, separate admin sessions, read and read/write roles, encrypted SQLite administration storage - Guarded writes: off by default, allowlist-based, with readback confirmation - Several inverters behind one API, requests per endpoint serialized so the device never sees a conflict - Hardened container: read-only root filesystem, all capabilities dropped, non-root user, built-in health check IMPORTANT - Required Environment Variable: - HMAC_SECRET: encrypts the administration database (data/rct.db). Generate with: openssl rand -base64 32. Changing it afterwards makes the database unreadable. First start: The container logs a boxed "FIRST START - admin login" block with the one-time "admin" password in clear text (also saved to /app/data/initial-admin-password as a fallback). The first login requires a password change. Until then, periodic reads, heartbeat and metric export stay paused. Reverse Proxy: rct-manager speaks plain HTTP inside the container. Enable "behind reverse proxy" on the admin Settings page when terminating TLS in front of it. Multi-arch image: linux/amd64 and linux/arm64, published with Trivy scanning, an SBOM and a provenance attestation. Source: https://github.com/Gill-Bates/rct-manager

Your RCT Power inverter is just one REST call away.

License Python 3.13+ Platform Docker Pulls

Documentation Quick Start


What is RCT Manager?

Do you have an RCT inverter and want to do more than the manufacturer’s app allows? RCT Manager connects to one or more inverters via TCP, providing access to readings and controls via a REST API. This means you can build your own integrations without having to work directly with the proprietary RCT protocol.

Built independently from the ground up, it combines the API, monitoring, data export and an administration interface in a single service. No vendor app is required.

RCT Manager administration GUI


✨ Features

Category Highlights
REST API Read values from the full protocol catalogue and control approved functions programmatically with JSON responses and standard error messages.
Your own analytics Use the Prometheus /metrics endpoint or export data to your own InfluxDB 2 or QuestDB for Grafana, Telegraf, and custom analysis.
Dynamic electricity tariffs Use the API to automate your own tariff and charge the battery from the grid or discharge it to supply your home, setting a target state of charge, power limit and duration.
Administration GUI Manage the overview, inverters, Energy Manager, TSDB, Prometheus, API tokens and settings all in one place.
Guarded controls Writes are disabled by default and checked after execution; access is protected by tokens and separate admin sessions.
Multiple devices Connect several inverters to one API. Requests to each endpoint are coordinated to avoid conflicts at the device level.
Hardened container The container uses a read-only root file system, drops capabilities for the server process and runs it as a non-root user. It also includes a health check.

🚀 Quick start

cp settings.env.example settings.env   # set HMAC_SECRET (openssl rand -base64 32) for Docker
docker compose -f docker/compose.yaml up -d

Without Docker, use Python 3.13+:

python -m pip install -e '.[dev]'
python -m app validate
python -m app

Open http://127.0.0.1:8000/. The one-time admin password appears in a FIRST START - admin login block on first startup and is also saved to data/initial-admin-password. You must change this password when you first log in.

Settings are stored in data/rct.db, encrypted and authenticated with HMAC_SECRET from settings.env (generated on a local start, required for Docker). Back up the database and the secret together. See Configuration.

Documentation: https://gill-bates.github.io/rct-manager/.

Container details are in docker/README_docker.md.

If RCT Manager works well for you, please leave a star on GitHub. If something is missing or does not work as expected, open an issue.


[!IMPORTANT] Disclaimer: This is an independent open-source project. It is not affiliated with, endorsed by or connected to RCT Power GmbH, Line-Eid-Str. 1, D-78467 Konstanz. "RCT Power" and related names are trademarks of their respective owners and are used only to describe compatibility.


License

Released under the MIT License. Third-party components retain their respective licenses.

Buy Me A Coffee

Download Statistics

377
Total Downloads

Related apps

Details

Repository
giiibates/rct-manager:latest
Last Updated2026-10-11
First Seen2026-10-11

Runtime arguments

Web UI
http://[IP]:[PORT:8000]
Network
bridge
Shell
bash
Privileged
false
Extra Params
--restart unless-stopped --security-opt=no-new-privileges:true --cap-drop=ALL --cap-add=CHOWN --cap-add=SETUID --cap-add=SETGID --read-only --tmpfs /tmp:rw,noexec,nosuid,nodev,size=1m,mode=1777

Template configuration

HMAC SecretVariable

REQUIRED: Encrypts the administration database (data/rct.db). Generate with: openssl rand -base64 32. Changing it afterwards makes the database unreadable - back it up together with the data volume.

Target
HMAC_SECRET
Bind AddressVariable

Listen address inside the container. Leave at 0.0.0.0 so the published port reaches the service; a loopback value makes the container unreachable through the port mapping.

Target
BIND_ADDRESS
Default
0.0.0.0
Value
0.0.0.0
Bind PortVariable

Listen port inside the container. Must match the container port in the WebUI/Port mapping below.

Target
BIND_PORT
Default
8000
Value
8000
Allow Non-Loopback BindVariable

Explicit consent for a non-loopback listener inside the container. Does not provide TLS; terminate TLS at a reverse proxy and enable 'behind reverse proxy' on the admin Settings page.

Target
ALLOW_NON_LOOPBACK_BIND
Default
true|false
Value
true
Public API DocsVariable

true: serve /docs and /openapi.json without a token. false: both return 404 on every bind address.

Target
DOCS_PUBLIC
Default
false|true
Value
false
Log LevelVariable

Verbosity of the container logs.

Target
LOG_LEVEL
Default
INFO|DEBUG|WARNING|ERROR
Value
INFO
WebUIPorttcp

rct-manager Web UI/API port (container listens on 8000, mapped to host port 8000 by default).

Target
8000
Default
8000
DataPathrw

Encrypted administration database (devices, API tokens, settings), dispatch state and the one-time admin password fallback. Back up together with HMAC_SECRET.

Target
/app/data
Default
/mnt/user/appdata/rct-manager/data