How to use Enver
The complete guide to the Enver application.
How Enver works
Enver is a control plane for your containers. Your applications run on your own servers; Enver keeps their configuration, tells the servers what to run and shows you what is going on. The building blocks are:
- Account – your company or team. Everything below belongs to an account, and its members get permissions in it.
- Container registry – where your images come from: Docker Hub or any OCI-compatible registry (GHCR, GitLab, Harbor…).
- Service – one application described once for the whole account: its image, default tag, ports, volumes, command and variables.
- Edge server – your server (Debian/Ubuntu or macOS) with the small Enver agent installed. It runs the containers with Docker or on your Kubernetes cluster.
- Environment – dev, staging, production… An environment sits on one edge server and contains services with its own tags, variables and settings.
Your containers, volumes and backups never leave your servers. If Enver is unavailable, your environments keep running; you just cannot manage them until it is back.
Quick start
- Sign in with Google or GitHub and choose Create account (or Wait for an invite if a colleague is adding you).
- Connect a registry under Registries if your images are private. Public Docker Hub images work without one.
- Describe your services under Services: image, default tag, ports and variables.
- Add an edge server under Edge Servers → New server, open it and follow Install: one command on the server and a token.
- Create an environment under Environments, pick the edge server and Docker or Kubernetes, and add services to it.
- Start it. The environment detail shows the live status, uptime and logs of every service.
Accounts and team
Accounts
The user who creates an account is its owner and can do everything in it. You can own more accounts (User settings → Accounts → New account) and be a member of others; switch between them with the account switcher in the header. Account names are unique across Enver.
Inviting members
Under Account → Users, invite a colleague by e-mail. They receive an invitation e-mail and see it under User settings → Accounts → Invitations, where they accept or reject it. The invitee must sign in to Enver with that e-mail first. Pending invitations count towards the account’s user limit.
Members
The owner and user admins see who is online, edit permissions (Permissions) and the owner can remove members or Transfer ownership to another member (the previous owner loses owner privileges).
Export and deletion
Under Account → Data and deletion, the owner downloads everything Enver stores for the account as a JSON file (secret values and tokens are left out) and deletes the account. Deleting needs the paid subscriptions ended first; the account then disappears for all members at once and its data is erased within 30 days. Containers and volumes on your edge servers stay as they are. Your own profile is deleted under User settings → General → Delete profile, once you own no account.
Permissions
Members get permissions per account. Higher permissions include the lower ones.
| Permission | Allows |
|---|---|
| Env Admin | Create, edit, start and stop all environments, add and configure their services. |
| Env Tag Switching | Switch tags, restart services and view logs – ideal for developers deploying their branch. |
| Env Viewer | See environments, their status and variables (without secret values). |
| Service Admin / Viewer | Manage or see the service catalog and service groups. |
| Edge Server Admin / Viewer | Manage (including tokens and settings) or see edge servers. |
| Variable Group Admin / Viewer | Manage or see variable groups. |
| Registry Admin / Viewer, Registry Tag Search | Manage or see registries, search images and tags. |
| User Admin | Invite members and change their permissions; Invites Admin, Permissions Admin and User Viewer grant the parts separately. |
| Monitoring Viewer | See edge server metrics. |
| DB Backups Admin / Operator / Viewer | Configure and delete backups / create and restore them / see them. |
| Secrets Reveal | Copy stored secret values. Every reveal is recorded in the audit log. |
Per-environment permissions
In an environment, Permissions lets the owner fine-tune access for one member: a whitelist grants Env Admin, Tag Switching or Viewer in this environment only, a blacklist takes it away here only (e.g. a developer can switch tags everywhere except production). Blocking a level also blocks the levels above it.
Container registries
Under Registries, add Docker Hub or a custom registry (its URL, e.g. https://ghcr.io) with a username and an access token. The token is stored encrypted and never shown again; leave it empty when editing to keep it. Enver uses the registry to pull images on your edge servers and to suggest images and tags in forms.
Automatic redeploy from Docker Hub
For a Docker Hub registry, Set up Docker Hub webhook shows a URL to paste into the repository’s webhooks on Docker Hub. After every push, Enver restarts – pulls and recreates – every running service that uses the pushed repository and tag. Anyone who knows the URL can trigger those restarts, so keep it secret. If it leaks, issue a new one in the same dialog (Regenerate URL): the old one stops working at once, and you replace it on Docker Hub.
Services
Under Services → New service, describe an application once for the whole account:
- Name and container image (e.g.
ghcr.io/acme/api) with its default tag, - registry for private images (suggested from the image name),
- command, if the image needs one to start (e.g.
npm run start), - default ports (internal → exposed) and volumes (container path → host path),
- default variables, each public or secret.
Ports, volumes and variables are a starting point: they are copied into an environment when you add the service there, and later changes to the service don’t affect environments it is already in. A service can only be deleted once it is removed from all environments.
Variables and secrets
Where values come from
When a service is deployed, its variables are merged in this order, a later one winning:
- the service’s default values,
- assigned variable groups (the later assignment wins),
- values set in the environment itself.
The environment service form lists the Inherited variables with their source, and Override sets an environment value.
Secrets
A secret value is stored encrypted and never sent back to the browser – the form only shows whether it is set. Members with Secrets Reveal can copy it to the clipboard, and every reveal is recorded in the audit log. A variable the service declares secret is secret in every environment; an environment can make its own value secret, too. A stored secret only becomes public together with a new value.
Import, export and references
- Import .env / Export .env move variables in the usual
.envformat. A# secretcomment line marks the next variable as secret. - Type
@in a value to reference another service of the same environment: it is replaced by that service’s container name at deploy time, e.g.postgres://@db:5432/app.
Service and variable groups
Service groups (Service Groups) bundle services such as “backend” so an environment can start, stop or switch the tag of all of them at once. Variable groups (Variable Groups) hold shared configuration – e.g. SMTP or a message broker – that you assign to services in environments instead of copying the values. Both support public and secret values and .env import and export.
Edge servers
Install
Under Edge Servers → New server, name the server, open it and click Install. The dialog shows the commands with your token filled in. On Debian/Ubuntu (amd64 or arm64):
curl -fsSL -o /tmp/enver-edge-server.deb "https://enver-api.apinecka.com/v1/edge-servers/installer" \
&& echo "<SHA-256 from the dialog> /tmp/enver-edge-server.deb" | sha256sum -c - \
&& sudo dpkg -i /tmp/enver-edge-server.deb && rm /tmp/enver-edge-server.deb
On macOS (with Docker Desktop, OrbStack or Colima):
curl -fsSL -o /tmp/enver-edge-server.tar.gz "https://enver-api.apinecka.com/v1/edge-servers/installer/macos" \
&& echo "<SHA-256 from the dialog> /tmp/enver-edge-server.tar.gz" | shasum -a 256 -c - \
&& tar -xzf /tmp/enver-edge-server.tar.gz -C /tmp && sudo /tmp/enver-edge-server/install.sh \
&& rm -rf /tmp/enver-edge-server /tmp/enver-edge-server.tar.gz
Then put the connection settings from the dialog into /etc/enver/edge-server.env and restart the agent:
EDGE_SERVER_PORT=10999
EDGE_SERVER_TOKEN=<token from the dialog>
API_URL=https://enver-api.apinecka.com
sudo systemctl restart enver-edge-server # Linux
sudo launchctl kickstart -k system/com.enver.edge-server # macOS
The server turns Online within seconds. Keep the token secret – anyone with it can connect as your server. The agent keeps a connection to Enver open (outgoing only; no inbound port has to be opened to the internet), reports statuses every few seconds and host metrics every minute.
Verify the download
The commands in the dialog stop before installing unless the file’s SHA-256 matches the one Enver publishes for it. When the installers are signed, the dialog also shows how to check the GPG signature; compare the key’s fingerprint with the one we publish before you trust it:
curl -fsSL "https://enver-api.apinecka.com/v1/edge-servers/installer/signing-key" | gpg --import
curl -fsSL -o /tmp/enver-edge-server.deb "https://enver-api.apinecka.com/v1/edge-servers/installer" \
&& curl -fsSL -o /tmp/enver-edge-server.deb.asc "https://enver-api.apinecka.com/v1/edge-servers/installer.asc"
gpg --verify /tmp/enver-edge-server.deb.asc /tmp/enver-edge-server.deb && sudo dpkg -i /tmp/enver-edge-server.deb
What the agent does and what it needs
- Access to Docker. It runs as the
enver-edge-serversystem user in thedockergroup (on macOS as a launchd service of your account). Access to the Docker socket amounts to root on the machine, which is why it only runs what you configure in Enver: it pulls images (with the registry credentials Enver sends for each deployment), creates, starts, stops and removes containers, volumes and networks, removes old images, and for PostgreSQL backups runspg_dump/pg_restoreinside the database container and writes to the backup directory you set. - Kubernetes only with the service account token you enter; the command in the dialog grants exactly the rights it uses.
- Network: only outgoing HTTPS and WebSocket connections to the Enver API. On
EDGE_SERVER_PORTit only answersGET /health; don’t expose that port. - What it sends: container states, image tags and digests, host metrics (CPU, memory, swap, disk, uptime), names and sizes of backup files, and container logs only while you view them (the last 250 lines, not stored). The contents of containers and volumes never leave the machine.
- What it receives: the desired state of your services, including their variables. Secret values are decrypted only for this and travel over the encrypted connection.
- It doesn’t update itself; a new version is installed with the same command.
Token
The token identifies the server to Enver. If it leaks, click Regenerate token on the edge server detail: the old token stops working at once and the agent disconnects. Put the new token into /etc/enver/edge-server.env and restart the agent. Deleting an edge server disconnects it too.
Logs and uninstall
- Linux:
journalctl -u enver-edge-server -f; remove withsudo apt remove enver-edge-server. - macOS:
/var/log/enver-edge-server.log; remove withsudo /opt/enver/edge-server/uninstall.sh(keeps the env file).
Docker settings
On the edge server detail, Docker & Kubernetes settings apply within a minute without a restart:
- Docker socket path – default
/var/run/docker.sock. On macOS, if the installer reports another socket (e.g.~/.docker/run/docker.sock), enter its absolute path. - Image cleanup – delete only the image a new version replaced (default), or every unused image hourly and after each update.
Kubernetes
An environment of the Kubernetes type runs its services on a cluster reached through the edge server. Prepare a service account with cluster-admin rights once (Kubernetes cluster setup in the app shows the same):
kubectl create serviceaccount enver-edge-server -n default
kubectl create clusterrole enver-edge-server --verb=get,list,watch,create,update,patch,delete \
--resource=namespaces,deployments,pods,pods/log,services,secrets,ingresses,networkpolicies
kubectl create clusterrolebinding enver-edge-server \
--clusterrole=enver-edge-server --serviceaccount=default:enver-edge-server
kubectl create token enver-edge-server -n default --duration=87600h
kubectl config view --minify -o jsonpath='{.clusters[0].cluster.server}'
Enter the API URL, the token and optionally the cluster’s CA certificate (PEM) in the edge server settings. Also set the ingress class (default nginx) and optionally a cert-manager ClusterIssuer to get TLS certificates for ingress hosts.
Every environment gets its own namespace, isolated from other namespaces by a network policy (the ingress controller can still reach it). Each service becomes a Deployment with a Service, an optional Ingress for its ingress host and pull secrets from your registry credentials; replicas are set per environment service.
Environments
Under Environments → New environment, set:
- Name and subdomain (a–z, 0–9, hyphens), both unique in the account,
- deployment type – Docker or Kubernetes,
- edge server it runs on.
Start blank or Duplicate existing – every service is copied with its tag, settings, variables and groups, and starts stopped. Changing the type or the name later restarts the running services (container names are derived from the environment name).
Adding services
Add service picks a service from the catalog and sets for this environment its tag, index (start order), replicas, ingress host (Kubernetes), ports, volumes, variables and variable groups. Enver warns when an exposed port is already taken on the same edge server. Editing a service in an environment also lets you disable it or override its command. Copy to environment… copies a single service, with its settings, into another environment; @ references are pointed at the services of the target environment.
Running services
- Start / Stop / Restart a service, a group or the whole environment. Enver keeps the desired state: the agent re-checks it every minute, so a stopped service stays stopped and a started one comes back.
- Switch tags in the tag field, with suggestions from the registry. Changes are collected; Save tags deploys them together, Discard changes drops them.
- Logs show the last 250 lines of a service live, with colours and search. Enver doesn’t store them.
- The status of an environment is Running, Stopped, Starting, Stopping, or Warning when some service is in a different state or hasn’t reported for a while. Each service shows its uptime and the last error.
Monitoring
Monitoring shows for each edge server the CPU, memory, swap and disk usage (with free space) and its uptime over the last 24 hours. Metrics are sent every minute and kept for 7 days.
PostgreSQL backups
DB Backups lists every postgres service in your Docker environments. In Backup settings, set the backup directory on the edge server, turn on the daily automatic backup and how many backups to keep (older ones are deleted after each new backup). You can also Create backup at any time, Restore one (the current data is replaced 1:1) or delete it.
Backups are made with pg_dump inside the container and stored only on the edge server, never at Enver. Keep a copy elsewhere, too – a backup on the same machine does not survive losing its disk.
Notifications
Enver can send a push notification to your browser or phone when a service starts running a new image – a different tag, or a new build pushed under the same tag.
- In User settings → Notifications, click Enable on this device (once per browser or phone) and optionally limit the time range in your time zone. Notifications outside it are dropped.
- On the environment detail, choose for a service Notify once or Notify on every change.
Notifications are part of the PRO and Business packages or available as an add-on.
Plans and billing
The account’s plan is under Account → Plan and payments, your own billing (verification, extra accounts, all subscriptions you pay) under User settings → Subscriptions and payments. Prices are in EUR per month; yearly billing is 20 % cheaper.
| FREE | FREE Verified | PRO – €10 | Business – €80 | |
|---|---|---|---|---|
| Environments | 1 | 2 | 6 | 22 |
| Services | 5 | 10 | unlimited | unlimited |
| Edge servers | 1 | 2 | 6 | 22 |
| Users | 1 | 5 | 15 | 105 |
| Notifications | – | – | ✓ | ✓ |
Add-ons raise single limits: extra environment €4, extra edge server €3, extra user €1, unlimited services €5, notifications €2 and an extra owned account €5 per month. For larger needs, ask for Enterprise in the app.
- Verification unlocks FREE Verified: you save a card in Stripe, nothing is charged and the card is not kept. One card verifies one user. Paying for anything verifies you, too.
- Changing a subscription is billed pro rata right away; higher limits apply once the difference is paid.
- Cancel renewal keeps the limits until the end of the paid period; End now with refund ends it immediately and refunds the unused part to your card.
- If a renewal can’t be paid, the limits stay for 3 more days, then the account returns to the free limits. Nothing is deleted.
- Payments and invoices opens the Stripe customer portal with your invoices and card.
When you hit a limit, Enver shows what to raise instead of failing. Full terms are in the Terms of Service.
Maintenance and feedback
Planned maintenance is announced under the header at least 2 hours ahead. During it the app shows a maintenance page and reloads itself when it’s over; your environments keep running. Found a bug or have an idea? Use Send feedback in the header – every message goes straight to the Enver team.