Apache 2.0 CI on every PR

Node-RED Control Center

One Docker stack = one Node-RED 5 control plane.

NRCC is a trustworthy visual configuration control plane for Node-RED 5.x. One Go binary supervises one Node-RED process. Validated settings.js edits, persistent backups, env-var management, npm-node management, live logs, and explicit security surfaces — all behind a single static binary with an embedded React UI.

Compatibility

Node-RED 5.x is the supported target.

Earlier and future majors are detected and inspected read-only. Destructive edit flows are blocked outside the supported range.

Overview

Configure Node-RED without SSH.

Day-to-day Node-RED operation usually means SSH-ing in, hand-editing settings.js, juggling archive files for backups, and tailing logs by hand. NRCC wraps one Node-RED per stack into a persistent control plane: JWT auth and RBAC, validated settings.js edits, persistent backups, env-var management, npm-node management, and live logs — all behind a single Go binary with an embedded React UI.

Need a second Node-RED? Add a second Compose service with different host ports and its own volumes. Each stack stays isolated: its own users, credentials, backups, and settings. There is no central control plane in this release.

Stack

  • Go 1.26
  • Chi router
  • JWT + bcrypt
  • Cobra CLI
  • React 19
  • Vite
  • TanStack Query 5
  • Zod
  • Tailwind + daisyUI
  • Vitest
  • Playwright

One static binary with the React UI embedded via //go:embed. Cross-compiled on every tag to Linux amd64 / arm64 / armv7, macOS amd64 / arm64, and Windows amd64 — plus the multi-arch Docker image that is the canonical install path.

Configuration

Edit settings.js safely.

  • Persistent volumes. Flows, credentials, settings.js, env vars, npm node_modules, users, snapshots.
  • Validated editor. Round-trips through real settings.js; backup before every save; restart prompt.
  • Env vars + secrets. Typed variables (string, number, boolean, secret); encryption at rest.
  • npm via UI. Install, search, uninstall from the same panel that uses them.

Security

Explicit boundaries per surface.

  • Auth + RBAC. JWT + bcrypt, admin/viewer roles, MFA, last-admin guard.
  • Auth surfaces. Node-RED admin, legacy dashboard, FlowFuse dashboard — each with named control surface.
  • TLS + credential secret. credentialSecret, requireHttps, httpsKey / httpsCert are first-class fields.
  • Backups. Manual + scheduled snapshots with pre-restore safety backup.

Recovery

Three paths to a working stack.

  • Restore from snapshot. One click; pre-restore safety snapshot taken first.
  • Rollback a settings apply. Records effective state; failed restart triggers rollback.
  • Logs + metrics. SSE log ring buffer; CPU/mem/disk sampled every 30 s; Prometheus /metrics.

Verified captures

What the control plane looks like.

Real screenshots replace these placeholders once the redesigned UI (issue #766) stabilises. See the placeholder policy in docs/sections/screenshots.md for the capture process.

Overview placeholder
Overview — single command: docker compose up -d.
Configuration placeholder
Configuration — settings.js editor with restart prompt.
Security placeholder
Security — named control surfaces per authentication domain.

Roadmap status

Six of nine clusters green.

The 9 sub-clusters of the control-plane roadmap track NRCC's progress towards a trustworthy Node-RED 5 control plane. Status is mirrored from docs/control-plane.md.

Overall: 6 green, 3 amber, 0 red. The three amber items are policy / evidence gaps, not implementation gaps — see docs/control-plane.md.

Limitations

What NRCC does NOT do.

Quick start

One stack in one command.

The canonical install path is Docker Compose. One docker-compose.yml, one command, one stack.

  1. 01
    Drop the compose file curl -fsSL https://raw.githubusercontent.com/fgjcarlos/nrcc/main/docker-compose.yml -o docker-compose.yml
  2. 02
    Bring it up docker compose up -d
  3. 03
    Open NRCC and create the admin http://localhost:3001

The image is published as ghcr.io/fgjcarlos/nrcc for linux/amd64, linux/arm64, and linux/armv7.