Docs
Guides and reference for installing and running Kwerft on Hetzner servers.
New to Kwerft? Start with Getting started: it takes you from a bare server to your first app on HTTPS.
Start
RequirementsThe server, operating system, memory, disk, network and DNS Kwerft needs, and what the installer changes on the host.ConceptsProjects, apps, jobs, volumes, domains and clusters, how a change in the console reaches Kubernetes, and how to leave the console when you need to.
Run apps
AppsDeploy a container image, set environment variables, ports and public hostnames, mount volumes, scale, roll back, and read logs or open a shell.Builds from GitConnect a Git host, deploy a repository built from its Dockerfile or with Railpack, deploy on every push, and follow builds and commit checks.JobsRun one-off tasks from an app or a schedule, put jobs on a cron schedule, and follow every run with its exit code and logs.Domains & TLSThe console's hostname and how to move it, an apps domain for your apps, HTTP-01 or wildcard certificates through Hetzner DNS, managed DNS records, and the sslip.io fallback.
Operate
MonitoringMetrics for nodes and apps, a log search across your projects, alerts and silences, alert rules, and notification channels for Slack, email, webhooks and ntfy.NetworkProject isolation, traffic rules with live Hubble counts, the servers' host firewall with lock-out protection, and the Hetzner Cloud Firewall sync.AccessInvite members, choose roles and project access, set up passkeys and two-factor sign-in, single sign-on, API tokens and kubeconfigs, and review shell recordings and the audit log.Clusters & nodesConnect Hetzner Cloud, add servers as node pools, join dedicated servers, make the control plane highly available, run builds on their own servers, and manage more clusters from one console.
Reference
Installer referenceEvery flag of install.sh, the --config file, environment variables, the install stages, re-running to repair or upgrade, version pinning, exit codes, the firewall rescue and uninstalling.TroubleshootingAnswers for the problems people run into most, from DNS and certificates to firewall lock-outs, a lost setup token and where to find logs.Security modelHow Kwerft protects the console, acts on Kubernetes as each user, isolates projects, stores secrets and records shells, for anyone evaluating it.