Server packages the orchestration engine, web console, node agent, authentication service, proxy, catalog, and database into a Docker image for managing environments, hosts, stacks, services, containers, storage, and networking.
PastureStack is an independent community effort to preserve and modernize the
Rancher 1.6 ecosystem. It is not affiliated with Rancher Labs or SUSE.
This fork of rancher/rancher preserves
upstream history, authorship, licenses, and notices.
Server v1.6.517
includes Web Console 1.6.179 and Orchestration Engine v0.183.333.
The console supports OIDC, TOTP and passkeys, role-aware resource operations,
container resource/hardware settings, and movable terminal/log windows.
Hardware options require compatible node software and actual host capabilities;
GPU device access is not exclusive GPU allocation.
The current patch packages reviewed dependency updates and the official shell-quote security fix in both npm and the browser bundle. Authentication, authorization, API and firewall contracts are unchanged. See the release note for component identities, verification results, and known limits. A published image is not a claim that every resource/role/hardware combination has been tested.
Public GHCR downloads do not require a registry login. Pin the immutable image and keep all three named volumes:
docker run -d --name pasturestack-server --restart unless-stopped -p 8080:8080 \
-v pasturestack-cattle:/var/lib/cattle \
-v pasturestack-mysql:/var/lib/mysql \
-v pasturestack-mysqllog:/var/log/mysql \
ghcr.io/pasturestack/server:v1.6.517@sha256:2bf411c5828b7090f9dab950942befcc22295c7dce9a5db2e3d2d6c9dfd2f7d8For HTTPS termination at a reverse proxy, set the exact public origin:
services:
pasturestack-server:
image: ghcr.io/pasturestack/server:v1.6.517@sha256:2bf411c5828b7090f9dab950942befcc22295c7dce9a5db2e3d2d6c9dfd2f7d8
restart: unless-stopped
ports:
- "8080:8080"
environment:
PROXY_PLATFORM_PUBLIC_ORIGIN: https://stack.example.com
volumes:
- pasturestack-cattle:/var/lib/cattle
- pasturestack-mysql:/var/lib/mysql
- pasturestack-mysqllog:/var/log/mysql
volumes:
pasturestack-cattle:
pasturestack-mysql:
pasturestack-mysqllog:PROXY_PLATFORM_PUBLIC_ORIGIN accepts only scheme://host[:port], without
credentials, path, query, or fragment. Configure HTTPS, authentication, backups,
and access policies before exposing the platform. Supported JVM and embedded
MariaDB environment variables are in performance settings.
Back up the database and volumes, test a restore, then follow the
upgrade guide. Preserve existing volume names,
environment variables, restart policy, AppArmor, and reverse-proxy configuration.
Do not replace existing volumes with new empty ones or run docker compose down -v.
Persisted image/download/catalog/Docker compatibility settings can outlive an image upgrade; review their effective values. The migration tool is read-only by default and requires explicit apply/rollback. Keep the previous image and backup: after a database migration, rollback may require restoring matching data, not merely selecting an older image tag.
GitHub Releases contain
versioned assets, SHA-256 checksums, and release records. Built-in templates come
from pinned catalog-templates
source. Historical changes belong in release notes.
Server consumes pinned source commits and verified component artifacts. For local source/shell validation:
bash scripts/test
bash scripts/check-server-source-gates.shRuntime, database migration, registration, backup/restore, and upgrade validation use isolated hosts. Publication is a separate, manually dispatched workflow. See ORIGIN.md and SECURITY.md.
The console packages thirteen locales, including Traditional Chinese for Taiwan.
Server bootstrap messages accept PASTURESTACK_LOCALE=en-US or zh-TW;
protocol fields and persisted identifiers are not translated.
The inherited project uses Apache License 2.0, with attribution in COPYRIGHT_DETAILS.md. Bundled components retain their own licenses and notices.