On this page
Installation
Install Arcane with Docker Compose or the Linux install script.
Arcane runs as a single container that manages Docker on the same host through the Docker socket. Install it with Docker Compose, or on Linux run the install script, which also sets up Docker.
1. Generate an encryption key
Section titled “1. Generate an encryption key”Arcane needs an ENCRYPTION_KEY that is 32 bytes long (raw, base64, or hex). Generate one with any of these commands and copy the output.
With a temporary Arcane container:
docker run --rm ghcr.io/getarcaneapp/manager:latest /app/arcane generate secretWith the Arcane CLI, if you already have it installed:
arcane-cli generate secretWith OpenSSL:
openssl rand -hex 322. Create compose.yaml
Section titled “2. Create compose.yaml”Paste your key in place of <your-encryption-key>, and replace /opt/docker with the folder where your Compose projects live (or where you want Arcane to create them):
services: arcane: image: ghcr.io/getarcaneapp/manager:latest container_name: arcane ports: - '3552:3552' volumes: - /var/run/docker.sock:/var/run/docker.sock - arcane-data:/app/data - /opt/docker:/opt/docker environment: - APP_URL=http://localhost:3552 - PUID=1000 - PGID=1000 - ENCRYPTION_KEY=<your-encryption-key> - PROJECTS_DIRECTORY=/opt/docker cgroup: host restart: unless-stopped
volumes: arcane-data:Projects folder
Section titled “Projects folder”3. Start Arcane
Section titled “3. Start Arcane”docker compose up -dRun the install script
Section titled “Run the install script”On Linux, the install script sets up Docker and Arcane for you:
curl -fsSL https://getarcane.app/install.sh | sudo bashUninstall
Section titled “Uninstall”The recommended uninstall asks before it removes Arcane data, the Arcane user and group, or Docker:
curl -fsSL https://getarcane.app/uninstall.sh -o /tmp/arcane-uninstall.sh && sudo bash /tmp/arcane-uninstall.shTo remove everything without prompting:
curl -fsSL https://getarcane.app/uninstall.sh | sudo bash -s -- --force --remove-allOpen Arcane
Section titled “Open Arcane”Open localhost:3552 in your browser and sign in with the default credentials below. Arcane asks you to change the password the first time you sign in.
Username:
arcanePassword:
arcane-adminMore setup options
Section titled “More setup options”You don’t need any of these to get started. Expand a section if it applies to your setup.
Folders and volumes
What each mount is for, plus optional build and backup folders.
Folders and volumes
What each mount is for, plus optional build and backup folders.
| Mount | Purpose |
|---|---|
/var/run/docker.sock |
Gives Arcane access to Docker. To limit what Arcane can do, use a socket proxy instead. |
arcane-data |
Stores Arcane’s database and data. |
| Projects folder | Holds your Compose projects. See Projects folder. |
/builds |
Optional. Build contexts for the Build Workspace. See Image Builds. |
/backups |
Optional. Where exported backups are stored. See Backups. |
SELinux hosts
Use a socket proxy or relabel the Docker socket mount.
SELinux hosts
Use a socket proxy or relabel the Docker socket mount.
On SELinux hosts, pick one of these:
- Use a socket proxy (recommended). Run a Docker socket proxy, point Arcane at it with
DOCKER_HOST, and add:zto the projects folder mount (/opt/docker:/opt/docker:z). Socket Proxy has the full Compose file. - Mount the socket directly. If you can’t run a proxy, disable SELinux labelling for the Arcane container and relabel the projects mount:
services: arcane: image: ghcr.io/getarcaneapp/manager:latest container_name: arcane ports: - '3552:3552' security_opt: - label:disable volumes: - /var/run/docker.sock:/var/run/docker.sock - arcane-data:/app/data - /opt/docker:/opt/docker:z environment: - PROJECTS_DIRECTORY=/opt/dockerContainer health check
Add a Docker health check using the built-in arcane health command.
Container health check
Add a Docker health check using the built-in arcane health command.
The Arcane image includes an arcane health command for Docker health checks. It calls Arcane’s local /api/health endpoint and exits non-zero if the server isn’t responding. Add it to your compose.yaml:
services: arcane: image: ghcr.io/getarcaneapp/manager:latest # ... healthcheck: test: ['CMD', './arcane', 'health', '--timeout', '2s'] interval: 10s timeout: 3s retries: 5 start_period: 15sstart_period gives Arcane time to run database migrations on first boot before failed checks count against retries.
External Postgres database
Store Arcane's data in Postgres instead of the built-in SQLite file.
External Postgres database
Store Arcane's data in Postgres instead of the built-in SQLite file.
Arcane stores its data in a SQLite file inside arcane-data by default, which works well for most setups. To use Postgres instead, set DATABASE_URL:
postgres://<db_username>:<db_password>@<postgres_url>:<postgres_port>/<postgres_db_name>Replace each placeholder with your database’s username, password, server address, port, and database name.
The default SQLite value, if you need to set it back, is:
file:data/arcane.db?_pragma=journal_mode(WAL)&_pragma=busy_timeout(2500)&_txlock=immediateReverse proxy
Enable WebSocket support when Arcane is behind a proxy or custom domain.
Reverse proxy
Enable WebSocket support when Arcane is behind a proxy or custom domain.
Outbound HTTP proxy
Route Arcane's outbound traffic through an HTTP proxy.
Outbound HTTP proxy
Route Arcane's outbound traffic through an HTTP proxy.
If Arcane has to reach the internet through a proxy, for example to download templates or check for updates, see Outbound Proxy.
Supported architectures
CPU architectures available for the images and binaries.
Supported architectures
CPU architectures available for the images and binaries.
The manager and agent images are published for:
linux/amd64linux/arm64linux/arm/v7linux/riscv64
Docker picks your host’s architecture automatically. CLI and agent binaries on GitHub Releases also cover Linux 386 and macOS (amd64, arm64).
Preview builds
Try features that haven't been released yet.
Preview builds
Try features that haven't been released yet.
Preview builds are published from the main branch under the :next image tag. They’re for testing, not production. See Preview Builds.