Slop alert. Use at your own risk
Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
Yeah, I was looking for that info, because I don't trust any (especially new projects, that use AI).
How did you know, it was AI though? I am just curious
there has to be a better way than giving a slop coded project access to your docker daemon (im assuming?)
'll keep an eye on it and keep asking around. I'm pretty sure there are better ways to do that.
Great idea. Automatic updates (e.g. Watchtower) make me a little nervous.
Automatic updates for bug fixes (e.g. 1.0.0 to 1.0.1) are usually fine - it's major and minor updates that are scarier. I've never used Watchtower so I'm not sure if it has an option to only allow bugfixes.
That would depend on each project properly using semver, which is unlikely.
Personally, I just risk all the updates. It's not a huge deal to recover.
Yeah, I'm a developer and my teammates don't always follow semver standards. I try to but every now and then it's really hard to know which is the right move. I've also had breaks because of minor increments and the author refused to roll back the change because the new behavior was consistent with the spec [that didn't change].
For me, it’s all about finding the right balance. I don’t want to have to manually update for every little bug fix version bump. Most software I find that major.minor version tags, if they exist, are a good compromise with daily auto updates unless it’s a really fast releasing software where just a major version makes sense. I usually just track releases on GitHub or wherever the source is hosted and bump as I need. That takes care of probably 90-95% of the containers I run.
Who vigils the vigil?
That's a great question isn't it? That's why I posted it here, so maybe I can find people interested in working on this project and help me out to clean things up, get it more organized, structured and "free of AI slop". What do you think?
Sorry mate, I was just making a dumb joke.
😅 no worries man, your comment just reminded me a popular saying in my local community; "who watches the watchman"
Can you provide a link to your repo?
Yeah absolutely, my bad. First time publishing things here and I thought it was attached to the post. https://github.com/kumucode/vigil.git
Copying my comment from the homelab community:
I haven't tried it yet, but here's some initial thoughts:
Does it support multiple separate docker-compose.yml files? It would be useful if it could pull the list of containers directly from Docker rather than having to paste the docker-compose.
Does it pull changelogs so that the user can tell if a change is a breaking change that'll require extra work?
It would be useful to support Webauthn/FIDO2 2FA instead of just TOTP. TOTP is being slowly phased out due to its weaknesses (it's phishable). Similarly, it'd be useful to support single sign on using OIDC (OpenID Connect) as a lot of self-hosters use Authentik, Authelia, or Keycloak to have one login for all their self hosted services.
Hi Dan, I'm also copying the answer from homelab community.
Thanks for your feedback. Much appreciated. For the first question, you click on add and past the image you’re currently using on your compose so the app creates a card with the current version. It’s a bit manual and tedious at first, but once it’s done, it’s easier to maintain. I think your idea is great to have the app just ¨find your docker-compose and do the work", but I don’t know how to do it yet. I wanted to test it manually first and see how it’d work out.
Vigil tells you if the newer version of the image is a major change or not. If you set it to update your compose automatically it will notify you and create a log, it something goes wrong you can easily revert it from the dashboard. Did I get your question right? Let me know if you meant something else.
Finally, security is an absolute must! I decided to use 2FA because most people won’t need to expose it to the web.They’ll probably use it on LAN. However, I do have adding OIDC (OpenID Connect) in mind, since many people indeed use Authentik, Authelia (these are the ones I’m familiar with). Since this is the early version, I didn’t want to make things too complex and also, I’m vibecoding it, so I’ll certainly need some experts out there to help me out to implement it correctly and safely.
If you have any question, just let me know and I’ll try my best to answer that.
Looks like a cool project. Starred.
I'm no tech expert either, so I'll keep an eye on how the community reacts to it, in terms of security.
Keep up the good work!
Thanks brother, I appreciate it. Security is one of my main concerns too, that's why I'll rely on the experts around here to point out what could be improved.
Please stop trying to build infrastructure software if you don't know what you're doing. Anyone using this probably puts their server at risk.
Yikes. That doesn’t give me confidence for something that needs root access to the Docker UNIX socket. Was this vibe coded? Do you understand the code and architecture of the application? You wrote you only started a few months ago. I don’t mean to be hard on you, but this kind of application has no business being insecure.
Hi Thaurin, I appreciate your feedback, I understand that security must be a top priority. I'm glad your pointing it out. If you have any advice on how to improve it, it'll be more than welcome.
If you want to learn to develop web applications, try to understand everything you do. Don't let the entire thing be generated by AI. Do small changes and commit those one at a time. Understand the programming language, your application's architecture, internet security, and so forth. Not understanding and then releasing it publicly and later asking for advice on how to improve it, isn't the way. You're still the maintainer of the project now, and will have to understand and approve any PR's people may send your way.
I mean, it can be addictive to just let AI throw everything together in a week without learning anything consequentual. But I wouldn't throw it on my server with root access to Docker. What's your real interest here? Learning or telling AI to make stuff for you?
In this world of technology, applications there are too many areas of expertise required to make things "functional" I'm not sure if I can learn everything required to make applications at the level of the most popular ones. I'm more interested in general knowledge and putting ideas out there. I still think that getting this project to the public even if it's not that great, is still better than have it just on my computer. So, the main purpose is to hear from people what they think of the project, maybe inspire others with more experience to put their projects out there too. My expectations were pretty low about this project, but it turned out to be a great experience to engage with many people from different background just like you.
You are potentially putting yourself at risk and others as well by making it public. I run a VPS in the cloud, so I would never, ever install this app on it, even though I firewall it to my own IP ranges. Your agent has access to the docker group and the tokens are sent and stored in plaintext, as per the SECURITY.md file. That means any leak of a token could lead to total hostile takeover of the server. Adding that you don't understand the codebase yourself just pushes this further over the edge.
Sure, I get it. It's fun to build things. But I've always found it more fun to actually build things myself. These days, everybody is building these huge, monolithic codebases that nobody understands anymore. I don't believe that it's impossible to learn the things required to make a full application. True, you can't learn everything, but that's because there are so many different things that do slightly different things, and each week something new comes along. So you specialize a bit. But it's fun to learn, and just telling an AI to do it makes you lazy.
I don't know, I don't like it. I do use AI during development, but I throw smaller things at it, so I can actually look at the code and approve it every time something changes. In some ways, it feels similar to what I used to do, which was reading documentation and copying the examples in it. Now the AI agent can pull that by itself and insert it into the code. However, I built the structure and original foundation myself, so I keep a firm grasp of it. I personally enjoy creating good code more than I enjoy piling on features generated by the AI, but these days it seems quantity over quality is appreciated more.
I don't develop profesionally anymore, but I've read so many stories online about senior developers getting depressed and considering a career change, because their managers think it's cool to let AI take over their old jobs, while they are left doing code reviews and undoing the fuckups that AI threw at them.
Every week I see several new iOS app on Reddit for tracking your fitness, habits, reminders, expenses, subscriptions, and they are always introduced in the same way: "I grew tired of how x apps do y, so I built my own" while stating that "this is my first app." And there's always a $15/month subscription on it! The internet is filling up with cheap Chinese replicas of applications, except that they are not sold cheaply.
People are writing their posts using AI, and then replying to everyone in the thread in Spanish, because why not? Let's not even try anymore! Open source projects are in trouble, because the volunteer maintainers cannot get through the automatic AI slow pull requests on GitHub to get to the high-quality ones.
I just really don't like how the current landscape looks, especially in the future. The ensloppification of everything.
End of rant. :)
How can you expect to release something secure if you don't know what the fuck you're doing? You're literally just hoping to have AI and the community do all the work for you. What exactly are you here for then?
Make it support Podman next.
I'd love too if I knew how to do that. I still have lots of things to learn and do before putting my toes on these waters, but I'm glad you showed some interest even to mention an integration with other tools. Thanks for that.
This looks fantastic! Great work.
Thanks man, appreciate it!
Thanks for the proof of concept. I suppose it's essentially a self-hosted version of newreleases.io?
That's pretty cool, I've never heard about newreleases.io I might take a look at it later. Thanks
Does it offer notifications?
3 of your docker containers have new versions available
Cool project. Building something that exactly fits a problem you have is one of the most liberating parts of programming!
I wouldn't worry too much about the people mad about you using AI. It's a powerful tool and I would be silly to not make use of it. I guarantee that a everyone using the internet today has had their packets flow through some piece of "vibe code".
One of my favorite features is having the AI tool explain back what every part of the code does. I helps you build understanding of both the code itself and is an excellent place to find bugs!
Keep it up
That's actually a good idea. I was thinking about getting the features "working" as intended. I'll give it a try to the "explain back" method and see how it goes. Thanks
I would always recommend getting the bare minimum working great before adding extra features. If you get too far into features, making foundational changes get significantly harder.
Totally agree with that. I was trying to keep things as simple as possible, but there was always a new thing to try. I'm currently not implementing anything new, just focusing on enhancing what is already there.
I've been looking for a dashboard for my containers, might test it out later
Sounds great, I've just released a small update after some feedback here. There's still a lot to be done, but let me know what you think once you test it.
Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:
| Fewer Letters | More Letters |
|---|---|
| Git | Popular version control system, primarily for code |
| IP | Internet Protocol |
| VPS | Virtual Private Server (opposed to shared hosting) |
3 acronyms in this thread; the most compressed thread commented on today has 16 acronyms.
[Thread #220 for this comm, first seen 7th Apr 2026, 13:50] [FAQ] [Full list] [Contact] [Source code]