Skip to content
SHC Docs
Search
Ctrl
K
Cancel
GitLab
Select theme
Dark
Light
Auto
Guide
Overview
Apps
Overview
Huly
Keycloak
OpenObserve
PostgreSQL
Traefik
Clouds
Overview
AWS
Azure
DigitalOcean
Exoscale
Google Cloud
Hostinger
OpenStack (OVH)
Scaleway
Vultr
Getting started
Overview
Core concepts
Installation
Quick start
Operations
Overview
Multi-node cluster setup
Disaster recovery
Observability
Storage providers
Upgrading SHC
Vault & secrets management
Troubleshooting
Overview
Common issues
Troubleshooting SSE streaming
App development
Overview
App definition
Bundled services
Creating apps — tutorial
Credential reconciliation
HTTP app repositories
Lifecycle hooks
Plugs & sockets
Presets
Source resolution
Virtual apps (vApps)
Reference
Overview
Adapter reference
Audit reference
Cron reference
Error code reference
Event reference
Glossary
Migration recipes
API
Overview
App API
Audit API
Backup API
Clone API
Cluster API
Config API
Events API
Export API
Health API
HUD API
Job API
Logs API
Node API
Quota API
Repo API
HTTP route reference
Schedule API
Search API
SSE streaming API
Stack API
Storage API
Task API
Tenant API
Vault API
Response models
Overview
app response models
audit response models
auth response models
backupmountrouter response models
backup response models
ca response models
capabilities response models
clone response models
cluster response models
config response models
connections response models
cron response models
dns response models
docker response models
doctor response models
events response models
export response models
forward response models
health response models
internalrpc response models
internalstacks response models
job response models
leader response models
license response models
logs response models
mcp response models
metrics response models
nebula response models
network response models
node response models
notification response models
Payload shapes
portforward response models
quota response models
repo response models
retention response models
schedule response models
search response models
shell response models
stack response models
storage response models
supportbundle response models
sysroutes response models
task response models
tenant response models
user response models
vault response models
CLI
Overview
App commands
shc backup
shc clone
shc cluster
shc config
shc ctx
shc doctor
shc events
shc export / import
shc forward
shc hud
shc import
shc init
shc inspect
shc job
shc logs
shc move
shc nfs
shc node
Command overview
shc preset
shc quota
shc recover
shc repo
shc retention
shc schedule
shc
shc shell
Stack commands
shc status
shc stop
shc storage
shc task
shc tenant
Utility commands
shc validate
shc vault
Comparisons
Overview
SHC vs Coolify
Platform comparison
Configuration
Overview
Configuration
Config keys reference
Environment variables
File locations
Terraform
Overview
Examples
Getting started with Terraform / OpenTofu
Module library
SHC Terraform provider
Contributing
Overview
SHC Engineering Standards
Standards
Overview
API design
Coding style
Commenting
Conventions
Error handling
Tech stack quick reference
Testing standards
Validation
Backend
Overview
API Standards
Migrations
Frontend
Overview
Accessibility
Frontend
CSS
Responsive design
Testing
Overview
Multi-node test book
Single-node test book
Multi-node deployment testing
SHC test suite
Proxmox multi-node E2E tests
Writing tests
Architecture
Overview
Architecture drift register
Next-wave plans
Access control
Deploy / Restore / Recover — reconstruction model (design)
Feature graph — human overview
Host lifecycle: prepare, install, init, run
Output & messaging contract
Security model
SHC status states
SHC Telemetry Fabric (Design)
Cluster
Overview
Mesh Architecture Diagrams
DNS Providers and Automatic HTTPS
DNS Provider Sync and Traefik ACME Architecture
SHC Network Fabric
SHC Cluster Architecture
Core
Overview
SubsystemManager — unified lifecycle management
Data model
Deployment identity
Network architecture
SHC overview
Tech stack
Diagrams
Overview
Events
Overview
Unified event bus
Job Registration System
Live Service Tracking
Flows
Overview
Flow: backup and restore
Flow: clone and move
Flow: cluster join
Flow: event lifecycle
Flow: app install
Flow: app uninstall
Flow: app upgrade / update
Modules
Overview
App module
Audit module
Backup module
Clone, move, rename
Cluster module
Completion module
Config module
Ctx module
DNS module
Docker module
Doctor module
Events module
Export module
Forward module
Health module
Hud module
Inspect module
Job module
Leader module
Logs module
Metrics module
Nebula module
Network module
Node module
Notification module
Quota module
Repo module
Retention module
Schedule module
Search module
Shell module
Stack module
Storage module
Task module
Tenant module
Vault module
Patterns
Overview
Communication patterns
Cross-Module Access Patterns
Server Privilege Model
Implicit context (Ctx)
Package Architecture
Decisions (ADRs)
Overview
ADR-0001 — Pure DI at a composition root (no DI container)
ADR-0002 — Stack state: three roles, one authority per role (the manifest model)
ADR-0003 — One data-ladder Scope type
ADR-0004 — Hermetic default test lane, engine fidelity lane
ADR-0005 — Architectural fitness functions
ADR-0006 — Thread registry.Deps through every seam; no global root pointer
Proposals
Overview
#113 quorum-safe removal v2 — reachability-aware guard + bounded RPCs + recovery hint
Symmetric node model: an shcnode for every node, shccluster becomes pure config (2026-07-15)
System-app overrides + Keycloak's own host (2026-07-15)
ACME/Let's-Encrypt issuance as first-class named providers
Canonical app.yaml metadata schema (census-driven) (2026-07-17)
ManifestAdapter interface + the coolify/umbrel/casaos adapters (2026-07-17)
Post-deploy notes templating (Helm NOTES.txt style) (2026-07-17)
Origin ingest gate + materialized transpile (2026-07-17)
Origin repos (foreign catalogs) + migrations to native apps (2026-07-17)
Resource Meta-API — self-describing resources, one contract for every client
Bundled services vs. sockets: a catalog-wide audit
Edge-CA trust: making server-side OIDC survive a non-public ACME directory
Integration-edge identity: the model
Persist the backup manifest inside the restic repo (2026-07 cross-cluster recover finding)
Daemon bind/advertise split (2026-07 mixed-cluster finding)
Retire the CLI's ROPC password grant — device-code flow as the sole interactive acquire path, client-credentials for CI
Plan: 5-level config scoping + DNS target resolver (LB override + swarm multi-A)
Cross-cloud convergence plan (2026-07-13 live campaign)
SHC Daemon DI Migration — Master Plan
Plan: deployment poll consumes recorder rows + small DNS/config knobs
Plan: hook action lists + runtime refs (full migration, no legacy)
Plan: real per-container status during shc install (install-time live service tracking)
Integration teardown: wake the 28 dead jobs, then collapse three runners into one
Live host reconfig — changing the cluster host without re-genesis
Cluster-CA succession — dual-trust rollover for the node-mTLS root
Short-lived :4003 node leaves + renewal as the passive revocation backstop
Vault envelope encryption: replace per-row PBKDF2 with a cached KEK + per-row DEK
GitLab
Select theme
Dark
Light
Auto
Proxmox multi-node E2E tests
press
`
to open the console
shc@docs:~$
press
`
or tap here to close ·
help
for commands