NuFiDocs

Installing the admin panel

The admin panel is its own image, not part of the compose stack; one container, three variables.

NuFi Admin Panel is not in deploy/platform/docker-compose.yml. It is a separate image, ghcr.io/dudaji-vn/nufichat-admin-panel, that talks to the NuFi app over the app's HTTP API and keeps its own sessions. Run it wherever it can reach the app: next to the stack, or on Railway, which is where NuFi's own copy runs (service nufichat-admin-panel, pinned to v0.0.5).

Run it

docker run -d --name nufi-admin-panel -p 3000:3000 \
  -e SESSION_SECRET="$(openssl rand -hex 32)" \
  -e VITE_API_BASE_URL=https://chat.example.com \
  -e API_SERVER_URL=http://librechat:3080 \
  ghcr.io/dudaji-vn/nufichat-admin-panel:v0.0.5
VariableRequiredWhat it is
SESSION_SECRETyes; the container refuses to start without one of at least 32 charactersencrypts the panel's own session cookie
VITE_API_BASE_URLyesthe app as the browser reaches it; the panel's page calls it directly and OAuth redirects go through it
API_SERVER_URLwhen it differsthe app as the panel's server reaches it, such as a compose service name; falls back to VITE_API_BASE_URL
PORTnolisten port, 3000
ADMIN_SSO_ONLYnohide the password form and offer only SSO, false
ADMIN_SESSION_IDLE_TIMEOUT_MSnoidle sign-out, 30 minutes
SESSION_COOKIE_SECUREnotrue in production; set false only on plain HTTP
ADMIN_PANEL_METRICS_SECRETnobearer token for /metrics; unset means the endpoint answers 401

Sign in with an account that has the ADMIN role in the app; the first account registered in the app has it. The panel's sessions are separate from the app's, so signing in to the chat is not enough here, and the cookie-sharing setup for the console does not apply.

Next to the compose stack

Put the container on the stack's network so API_SERVER_URL can use the service name:

docker run -d --name nufi-admin-panel --network npuops -p 3003:3000 \
  -e SESSION_SECRET="$(openssl rand -hex 32)" \
  -e VITE_API_BASE_URL=http://localhost:3080 \
  -e API_SERVER_URL=http://librechat:3080 \
  ghcr.io/dudaji-vn/nufichat-admin-panel:v0.0.5

Host port 3003 because 3000 is Langfuse and 3001 the console. Behind a reverse proxy it gets its own hostname; the Caddy block is on SSO and reverse proxy.

apps/admin-panel/docker-compose.yml in the repository still pulls the upstream image the panel was forked from, not this one; use the commands above until it is corrected.

Check it works

Open the panel, sign in, open Configuration: the form is built from the app's schema, so a page of settings means the API round trip works. A blank page with a network error means the browser cannot reach VITE_API_BASE_URL; a sign-in that never completes means the server cannot reach API_SERVER_URL.

Upgrade

A nufi-admin-vX.Y.Z tag on main publishes vX.Y.Z; pull it and recreate the container. There is no database to migrate: the panel stores nothing but sessions.