Documentation menu

Community Edition

Run StackRadar in your own cluster with one Helm command, or on a laptop with Docker Compose: the open-source community edition, what it includes, and where its manual lives.

StackRadar is open source. The community edition is the same server and UI that run app.stackradar.io, configured as the dashboard for the one cluster it runs in: you run Postgres and the vulnerability mirror, sign in with a local account or your identity provider, and the scanner is installed alongside, already scanning. The code is AGPL-3.0; the cloud-only parts (billing, email, the live demo) live under their own directory and licence and are mounted only on the cloud.

One command on any Kubernetes cluster

bash
helm install stackradar oci://ghcr.io/lockdep/helm-charts/stackradar \
  --create-namespace -n stackradar
kubectl -n stackradar port-forward svc/stackradar-client 3000:3000

Open http://localhost:3000, sign in as admin@stackradar.local with the password admin, and change it when asked. Your cluster's images appear with findings once the vulnerability mirror has bootstrapped — minutes, depending on your connection.

The bare install uses a bundled single-node Postgres and public fixture credentials, and prints a warning naming each one still in effect. Replace them before relying on it; the Helm walkthrough says how.

Without a cluster

bash
curl -LO https://raw.githubusercontent.com/lockdep/stackradar/main/deploy/compose/docker-compose.yml
docker compose up -d

Three containers, the same default credentials. Compose cannot run the scanner, so the walkthrough uploads an SBOM with two curl lines to see findings.

The manual

The self-hosting documentation lives next to the code, in the repository's docs/self-hosting/, so a page and the release it describes change together. Every page says which edition it applies to.

  • Kubernetes with Helm — The real install: the fixtures to replace before keeping it, Ingress, resources, the split topology, GitOps.
  • Docker Compose — The laptop try-out without a cluster; proves the platform with an SBOM you upload by hand.
  • Users and local login — The bootstrap admin, roles, creating local users, lockouts, and resetting an admin you are locked out of.
  • OpenID Connect — Keycloak, Authentik, Microsoft Entra ID, Okta and the rest, with a group mapped to platform admin.
  • Your own Postgres — Pointing the install at a database you run, and moving off the bundled one.
  • Upgrading — What to read before an upgrade and in which order; how migrations run; rolling back.
  • Backups — What to back up (one database, one encryption key), how, and how to prove the restore works.

Community Edition or the cloud?

One cluster, self-hosted, free: the community edition. Several clusters in one dashboard, across networks and accounts, with email alerts and nothing to run but the scanner: the cloud, from one free cluster on the pricing page. Both run the same images; the quick start is the cloud's install, and the comparison table in the repository README lists the differences row by row.

Questions about a self-hosted install go to GitHub Discussions; defects to Issues.

Next steps