Files
appstore/apps/serverkit

ServerKit

Introduction

ServerKit is a self-hosted panel for connecting remote servers and managing fleet operations, terminals, deployments, monitoring, backups, security, and sites.

This package uses the upstream all-in-one Docker image jhd3197/serverkit, which serves the API, React SPA, and Socket.IO service from one container.

Features

  • Connect to and manage remote servers and server fleets.
  • Provide terminal, deployment, monitoring, backup, and security capabilities.
  • Serve a unified browser panel with real-time Socket.IO communication.

Container scope

This is ServerKit's containerized deployment. The package does not mount the Docker Socket or the host filesystem and does not use privileged mode. As a result, it cannot manage the current 1Panel host's systemd services, host Nginx, host packages, or local sites. It is intended for evaluation, managing other connected remote servers, or running behind a reverse proxy.

First use

  1. During installation, provide unique values for SECRET_KEY, JWT_SECRET_KEY, and the Fernet-format SERVERKIT_ENCRYPTION_KEY.

  2. Generate a Fernet key with:

    python3 -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
    

    Generate the first two keys with openssl rand -hex 32. Keep all keys safe; changing them invalidates existing sessions or encrypted data.

  3. Open ServerKit on the configured HTTP port. On the first visit, use the registration page to create the first user; the first user is given the administrator role.

  4. When using a reverse proxy, set SERVERKIT_PUBLIC_URL. Set TRUST_PROXY_HEADERS to true only when every request is guaranteed to pass through a trusted proxy. Add multiple browser origins as a comma-separated CORS_ORIGINS value.

The SQLite database is persisted at data/serverkit.db in the application install directory and bind-mounted to /app/instance. This keeps the data under the 1Panel application directory for application backups. Do not remove this directory unless the ServerKit data can be discarded. When upgrading from the legacy serverkit-data volume, the target version migrates the SQLite files when the new directory is empty; the legacy volume is retained and is not deleted automatically.

Security notice

The maintainer scanned each packaged serverkit image tag with Trivy; each report contains Critical=5, High=77, Total=82 (both tags resolve to the same image content). These findings originate from the upstream image and its base-system components and are not remediated by this package. Prefer trusted private networks and monitor upstream image updates.

High-risk examples:

  • Critical CVE-2025-7458 (libsqlite3-0): no fix is currently available.
  • Critical CVE-2026-13221, CVE-2026-42496, and CVE-2026-8376 (perl-base): no fix is currently available.
  • Critical CVE-2023-45853 (zlib1g): no fix is currently available.

Versions

Both latest and the pinned 1.11.4 release are available. They use the upstream Docker Hub image and support amd64 and arm64.

The ServerKit upstream project is licensed under the MIT License. See the upstream license.