Connect each node
Run Noderaft Agent beside the Docker runtime. Rootless Docker is supported when the agent runs with access to the owning user's socket.
Loading Noderaft
Self-hosted Docker fleet operations
See the state that needs you, manage Compose releases, and give each client a scoped workspace — without putting Docker in the browser.
Noderaft is currently available to authorized platform users. Installation, licensing and commercial terms are not published here.
How it works
Run Noderaft Agent beside the Docker runtime. Rootless Docker is supported when the agent runs with access to the owning user's socket.
Group containers into workloads, adopt existing Compose projects, or manage validated Compose revisions through a release lifecycle.
Keep attention, active operations, runtime health and recent failures in context instead of jumping between individual hosts.
Operational clarity
Noderaft keeps runtime state, managed releases and operator actions connected to the workload they belong to.
Active conditions are grouped by root cause, with acknowledgement, silence and maintenance controls for operators.
Validate revisions, review diffs and plans, follow deployment progress, inspect releases and roll back through the same workflow.
Client roles see tenant-scoped workloads and explicitly granted actions. Platform administration stays outside their workspace.
Privileged actions and deployment events retain actor, target, result and timing context for later review.
Security architecture
The product reduces exposure through constrained paths and least-privilege controls; it does not present those controls as a blanket security guarantee.
The browser talks to the Noderaft control plane. Docker access stays on the server-to-agent path.
Role and tenant checks are enforced in API routes and service logic, not left to hidden navigation or client-side state.
The agent exposes explicit container and Compose operations. Noderaft does not provide an arbitrary shell command endpoint.
Session tokens are stored as hashes, browser sessions use httpOnly cookies, and managed secret values are encrypted at rest.
Noderaft platform
Sign in to the Noderaft platform with an account issued by your administrator.
platform.noderaft.ee