How to use Enver

The complete guide to the Enver application.

How Enver works

Enver is a control plane for your containers. Your applications run on your own servers; Enver keeps their configuration, tells the servers what to run and shows you what is going on. The building blocks are:

Your containers, volumes and backups never leave your servers. If Enver is unavailable, your environments keep running; you just cannot manage them until it is back.

Quick start

  1. Sign in with Google or GitHub and choose Create account (or Wait for an invite if a colleague is adding you).
  2. Connect a registry under Registries if your images are private. Public Docker Hub images work without one.
  3. Describe your services under Services: image, default tag, ports and variables.
  4. Add an edge server under Edge Servers → New server, open it and follow Install: one command on the server and a token.
  5. Create an environment under Environments, pick the edge server and Docker or Kubernetes, and add services to it.
  6. Start it. The environment detail shows the live status, uptime and logs of every service.

Accounts and team

Accounts

The user who creates an account is its owner and can do everything in it. You can own more accounts (User settings → Accounts → New account) and be a member of others; switch between them with the account switcher in the header. Account names are unique across Enver.

Inviting members

Under Account → Users, invite a colleague by e-mail. They receive an invitation e-mail and see it under User settings → Accounts → Invitations, where they accept or reject it. The invitee must sign in to Enver with that e-mail first. Pending invitations count towards the account’s user limit.

Members

The owner and user admins see who is online, edit permissions (Permissions) and the owner can remove members or Transfer ownership to another member (the previous owner loses owner privileges).

Export and deletion

Under Account → Data and deletion, the owner downloads everything Enver stores for the account as a JSON file (secret values and tokens are left out) and deletes the account. Deleting needs the paid subscriptions ended first; the account then disappears for all members at once and its data is erased within 30 days. Containers and volumes on your edge servers stay as they are. Your own profile is deleted under User settings → General → Delete profile, once you own no account.

Permissions

Members get permissions per account. Higher permissions include the lower ones.

PermissionAllows
Env AdminCreate, edit, start and stop all environments, add and configure their services.
Env Tag SwitchingSwitch tags, restart services and view logs – ideal for developers deploying their branch.
Env ViewerSee environments, their status and variables (without secret values).
Service Admin / ViewerManage or see the service catalog and service groups.
Edge Server Admin / ViewerManage (including tokens and settings) or see edge servers.
Variable Group Admin / ViewerManage or see variable groups.
Registry Admin / Viewer, Registry Tag SearchManage or see registries, search images and tags.
User AdminInvite members and change their permissions; Invites Admin, Permissions Admin and User Viewer grant the parts separately.
Monitoring ViewerSee edge server metrics.
DB Backups Admin / Operator / ViewerConfigure and delete backups / create and restore them / see them.
Secrets RevealCopy stored secret values. Every reveal is recorded in the audit log.

Per-environment permissions

In an environment, Permissions lets the owner fine-tune access for one member: a whitelist grants Env Admin, Tag Switching or Viewer in this environment only, a blacklist takes it away here only (e.g. a developer can switch tags everywhere except production). Blocking a level also blocks the levels above it.

Container registries

Under Registries, add Docker Hub or a custom registry (its URL, e.g. https://ghcr.io) with a username and an access token. The token is stored encrypted and never shown again; leave it empty when editing to keep it. Enver uses the registry to pull images on your edge servers and to suggest images and tags in forms.

Automatic redeploy from Docker Hub

For a Docker Hub registry, Set up Docker Hub webhook shows a URL to paste into the repository’s webhooks on Docker Hub. After every push, Enver restarts – pulls and recreates – every running service that uses the pushed repository and tag. Anyone who knows the URL can trigger those restarts, so keep it secret. If it leaks, issue a new one in the same dialog (Regenerate URL): the old one stops working at once, and you replace it on Docker Hub.

Services

Under Services → New service, describe an application once for the whole account:

Ports, volumes and variables are a starting point: they are copied into an environment when you add the service there, and later changes to the service don’t affect environments it is already in. A service can only be deleted once it is removed from all environments.

Variables and secrets

Where values come from

When a service is deployed, its variables are merged in this order, a later one winning:

  1. the service’s default values,
  2. assigned variable groups (the later assignment wins),
  3. values set in the environment itself.

The environment service form lists the Inherited variables with their source, and Override sets an environment value.

Secrets

A secret value is stored encrypted and never sent back to the browser – the form only shows whether it is set. Members with Secrets Reveal can copy it to the clipboard, and every reveal is recorded in the audit log. A variable the service declares secret is secret in every environment; an environment can make its own value secret, too. A stored secret only becomes public together with a new value.

Import, export and references

Service and variable groups

Service groups (Service Groups) bundle services such as “backend” so an environment can start, stop or switch the tag of all of them at once. Variable groups (Variable Groups) hold shared configuration – e.g. SMTP or a message broker – that you assign to services in environments instead of copying the values. Both support public and secret values and .env import and export.

Edge servers

Install

Under Edge Servers → New server, name the server, open it and click Install. The dialog shows the commands with your token filled in. On Debian/Ubuntu (amd64 or arm64):

curl -fsSL -o /tmp/enver-edge-server.deb "https://enver-api.apinecka.com/v1/edge-servers/installer" \
  && echo "<SHA-256 from the dialog>  /tmp/enver-edge-server.deb" | sha256sum -c - \
  && sudo dpkg -i /tmp/enver-edge-server.deb && rm /tmp/enver-edge-server.deb

On macOS (with Docker Desktop, OrbStack or Colima):

curl -fsSL -o /tmp/enver-edge-server.tar.gz "https://enver-api.apinecka.com/v1/edge-servers/installer/macos" \
  && echo "<SHA-256 from the dialog>  /tmp/enver-edge-server.tar.gz" | shasum -a 256 -c - \
  && tar -xzf /tmp/enver-edge-server.tar.gz -C /tmp && sudo /tmp/enver-edge-server/install.sh \
  && rm -rf /tmp/enver-edge-server /tmp/enver-edge-server.tar.gz

Then put the connection settings from the dialog into /etc/enver/edge-server.env and restart the agent:

EDGE_SERVER_PORT=10999
EDGE_SERVER_TOKEN=<token from the dialog>
API_URL=https://enver-api.apinecka.com
sudo systemctl restart enver-edge-server                      # Linux
sudo launchctl kickstart -k system/com.enver.edge-server      # macOS

The server turns Online within seconds. Keep the token secret – anyone with it can connect as your server. The agent keeps a connection to Enver open (outgoing only; no inbound port has to be opened to the internet), reports statuses every few seconds and host metrics every minute.

Verify the download

The commands in the dialog stop before installing unless the file’s SHA-256 matches the one Enver publishes for it. When the installers are signed, the dialog also shows how to check the GPG signature; compare the key’s fingerprint with the one we publish before you trust it:

curl -fsSL "https://enver-api.apinecka.com/v1/edge-servers/installer/signing-key" | gpg --import
curl -fsSL -o /tmp/enver-edge-server.deb "https://enver-api.apinecka.com/v1/edge-servers/installer" \
  && curl -fsSL -o /tmp/enver-edge-server.deb.asc "https://enver-api.apinecka.com/v1/edge-servers/installer.asc"
gpg --verify /tmp/enver-edge-server.deb.asc /tmp/enver-edge-server.deb && sudo dpkg -i /tmp/enver-edge-server.deb

What the agent does and what it needs

Token

The token identifies the server to Enver. If it leaks, click Regenerate token on the edge server detail: the old token stops working at once and the agent disconnects. Put the new token into /etc/enver/edge-server.env and restart the agent. Deleting an edge server disconnects it too.

Logs and uninstall

Docker settings

On the edge server detail, Docker & Kubernetes settings apply within a minute without a restart:

Kubernetes

An environment of the Kubernetes type runs its services on a cluster reached through the edge server. Prepare a service account with cluster-admin rights once (Kubernetes cluster setup in the app shows the same):

kubectl create serviceaccount enver-edge-server -n default
kubectl create clusterrole enver-edge-server --verb=get,list,watch,create,update,patch,delete \
  --resource=namespaces,deployments,pods,pods/log,services,secrets,ingresses,networkpolicies
kubectl create clusterrolebinding enver-edge-server \
  --clusterrole=enver-edge-server --serviceaccount=default:enver-edge-server
kubectl create token enver-edge-server -n default --duration=87600h
kubectl config view --minify -o jsonpath='{.clusters[0].cluster.server}'

Enter the API URL, the token and optionally the cluster’s CA certificate (PEM) in the edge server settings. Also set the ingress class (default nginx) and optionally a cert-manager ClusterIssuer to get TLS certificates for ingress hosts.

Every environment gets its own namespace, isolated from other namespaces by a network policy (the ingress controller can still reach it). Each service becomes a Deployment with a Service, an optional Ingress for its ingress host and pull secrets from your registry credentials; replicas are set per environment service.

Environments

Under Environments → New environment, set:

Start blank or Duplicate existing – every service is copied with its tag, settings, variables and groups, and starts stopped. Changing the type or the name later restarts the running services (container names are derived from the environment name).

Adding services

Add service picks a service from the catalog and sets for this environment its tag, index (start order), replicas, ingress host (Kubernetes), ports, volumes, variables and variable groups. Enver warns when an exposed port is already taken on the same edge server. Editing a service in an environment also lets you disable it or override its command. Copy to environment… copies a single service, with its settings, into another environment; @ references are pointed at the services of the target environment.

Running services

Monitoring

Monitoring shows for each edge server the CPU, memory, swap and disk usage (with free space) and its uptime over the last 24 hours. Metrics are sent every minute and kept for 7 days.

PostgreSQL backups

DB Backups lists every postgres service in your Docker environments. In Backup settings, set the backup directory on the edge server, turn on the daily automatic backup and how many backups to keep (older ones are deleted after each new backup). You can also Create backup at any time, Restore one (the current data is replaced 1:1) or delete it.

Backups are made with pg_dump inside the container and stored only on the edge server, never at Enver. Keep a copy elsewhere, too – a backup on the same machine does not survive losing its disk.

Notifications

Enver can send a push notification to your browser or phone when a service starts running a new image – a different tag, or a new build pushed under the same tag.

  1. In User settings → Notifications, click Enable on this device (once per browser or phone) and optionally limit the time range in your time zone. Notifications outside it are dropped.
  2. On the environment detail, choose for a service Notify once or Notify on every change.

Notifications are part of the PRO and Business packages or available as an add-on.

Plans and billing

The account’s plan is under Account → Plan and payments, your own billing (verification, extra accounts, all subscriptions you pay) under User settings → Subscriptions and payments. Prices are in EUR per month; yearly billing is 20 % cheaper.

FREEFREE VerifiedPRO – €10Business – €80
Environments12622
Services510unlimitedunlimited
Edge servers12622
Users1515105
Notifications––✓✓

Add-ons raise single limits: extra environment €4, extra edge server €3, extra user €1, unlimited services €5, notifications €2 and an extra owned account €5 per month. For larger needs, ask for Enterprise in the app.

When you hit a limit, Enver shows what to raise instead of failing. Full terms are in the Terms of Service.

Maintenance and feedback

Planned maintenance is announced under the header at least 2 hours ahead. During it the app shows a maintenance page and reloads itself when it’s over; your environments keep running. Found a bug or have an idea? Use Send feedback in the header – every message goes straight to the Enver team.