Docs
Guides and reference for installing and running Kwerft on Hetzner servers.
New to Kwerft? Start with Getting started: it takes you from a bare server to your first app on HTTPS.
Start
RequirementsThe server, operating system, memory, disk, network and DNS Kwerft needs, and what the installer changes on the host.ConceptsProjects, apps, jobs, volumes, secrets, domains and clusters, how a change in the console reaches Kubernetes, and how to leave the console when you need to.
Run apps
AppsDeploy a container image, set environment variables, ports and public hostnames, mount volumes, scale, roll back, and read logs or open a shell.Builds from GitConnect a Git host, deploy a repository built from its Dockerfile or with Railpack, deploy on every push, and follow builds and commit checks.Templates & ComposeStart PostgreSQL, Redis, MinIO, n8n or Plausible from a template, or turn a Docker Compose file into apps, volumes and secret sets, with a review before anything is created.JobsRun one-off tasks from an app or a schedule, put jobs on a cron schedule, and follow every run with its exit code and logs.SecretsKeep passwords and API keys in write-only secret sets, let Kwerft generate and derive values, use them as environment variables or files, and reveal or copy them as an owner or admin.Domains & TLSThe console's hostname and how to move it, an apps domain for your apps, HTTP-01 or wildcard certificates through Hetzner DNS, managed DNS records, and the sslip.io fallback.
Operate
Overview and infrastructure mapWhat the Overview lists under Needs attention, and how to read the infrastructure map of a cluster's apps, jobs, volumes, domains, traffic rules and firewall.MonitoringMetrics for nodes and apps, a log search across your projects, alerts and silences, alert rules, and notification channels for Slack, email, webhooks and ntfy.NetworkProject isolation, traffic rules with live Hubble counts, the servers' host firewall with lock-out protection, and the Hetzner Cloud Firewall sync.AccessInvite members, choose roles and project access, set up passkeys and two-factor sign-in, single sign-on, API tokens and kubeconfigs, and review shell recordings and the audit log.Clusters & nodesConnect Hetzner Cloud, add servers as node pools, join dedicated servers, make the control plane highly available, run builds on their own servers, and manage more clusters from one console.BackupsBack up projects, volumes and the console to S3-compatible storage, encrypted with a recovery key, restore a project or some apps, rebuild the whole console on a new server with --restore, and etcd snapshots.UpgradesUpgrade Kwerft from the console with automatic rollback, upgrade Kubernetes node by node, take connected clusters along with Upgrade all, and choose an update policy and channel.
Reference
Installer referenceEvery flag of install.sh, the --config file, environment variables, remembered settings, the install stages, re-running to repair or upgrade, version pinning, restoring from a backup, exit codes, the firewall rescue and uninstalling.TroubleshootingAnswers for the problems people run into most, from DNS and certificates to firewall lock-outs, a lost setup token, failed upgrades and restores, and where to find logs.Security modelHow Kwerft protects the console, acts on Kubernetes as each user, isolates projects, stores secrets, encrypts backups, runs upgrades and records shells, for anyone evaluating it.