NRCC is a trustworthy visual configuration control plane for
Node-RED 5.x.
One Go binary supervises one Node-RED process. Validated
settings.js
edits, persistent backups, env-var management, npm-node
management, live logs, and explicit security surfaces — all
behind a single static binary with an embedded React UI.
4.xRead-only. Detection, inspection, and migration guidance. Destructive edit flows blocked.
>=6.0 (future)Read-only until a dedicated adapter / catalog is verified for that major.
Overview
Configure Node-RED without SSH.
Day-to-day Node-RED operation usually means SSH-ing in, hand-editing settings.js, juggling archive files for backups, and tailing logs by hand. NRCC wraps one Node-RED per stack into a persistent control plane: JWT auth and RBAC, validated settings.js edits, persistent backups, env-var management, npm-node management, and live logs — all behind a single Go binary with an embedded React UI.
Need a second Node-RED? Add a second Compose service with different host ports and its own volumes. Each stack stays isolated: its own users, credentials, backups, and settings. There is no central control plane in this release.
Stack
Go 1.26
Chi router
JWT + bcrypt
Cobra CLI
React 19
Vite
TanStack Query 5
Zod
Tailwind + daisyUI
Vitest
Playwright
One static binary with the React UI embedded via //go:embed. Cross-compiled on every tag to Linux amd64 / arm64 / armv7, macOS amd64 / arm64, and Windows amd64 — plus the multi-arch Docker image that is the canonical install path.
Backups. Manual + scheduled snapshots with pre-restore safety backup.
Recovery
Three paths to a working stack.
Restore from snapshot. One click; pre-restore safety snapshot taken first.
Rollback a settings apply. Records effective state; failed restart triggers rollback.
Logs + metrics. SSE log ring buffer; CPU/mem/disk sampled every 30 s; Prometheus /metrics.
Verified captures
What the control plane looks like.
Real screenshots replace these placeholders once the redesigned UI
(issue #766) stabilises. See the placeholder policy in
docs/sections/screenshots.md
for the capture process.
Overview placeholder
Overview — single command: docker compose up -d.
Configuration placeholder
Configuration — settings.js editor with restart prompt.
Security placeholder
Security — named control surfaces per authentication domain.
Overall: 6 green, 3 amber, 0 red. The three amber items are policy / evidence gaps, not implementation gaps — see docs/control-plane.md.
Limitations
What NRCC does NOT do.
Not a flow editor.
Use the Node-RED editor (port 1880) to author flows. NRCC configures; it does not author.
Not a cluster orchestrator.
A central NRCC that manages multiple remote Node-REDs is deferred — see
#428.
Each NRCC instance supervises exactly one Node-RED.
Not a npm library browser.
NRCC installs, searches, and uninstalls the npm packages that flows need, but it does not replace npm itself.
Read-only on Node-RED 4 and unknown future majors.
NRCC supports full editing on Node-RED >=5.0 <6.0. Earlier and future majors are detected, inspected read-only, and routed to a migration guide.
No Docker socket.
NRCC does not manage sibling containers and does not mount
/var/run/docker.sock.
Bring up a second stack as a second Compose service with different host ports.
Local backups only.
Off-host encrypted backups (Restic / S3 / SFTP / B2) are deferred — see
#432.
Quick start
One stack in one command.
The canonical install path is Docker Compose. One
docker-compose.yml,
one command, one stack.
01
Drop the compose filecurl -fsSL https://raw.githubusercontent.com/fgjcarlos/nrcc/main/docker-compose.yml -o docker-compose.yml
02
Bring it updocker compose up -d
03
Open NRCC and create the adminhttp://localhost:3001
The image is published as
ghcr.io/fgjcarlos/nrcc
for linux/amd64,
linux/arm64, and
linux/armv7.