AI AdminPanel Documentation

Web Apps Templates

This inventory describes the v2.12.8 source manifests in the webapps category. Available means the manifest is not marked Coming Soon; it is not proof of a successful deployment, a current browser card, or a security review. The browser's unfiltered catalog is paginated; use category/search controls to find an entry. See Template System.

Template List

Template IDSource availabilityMinimum CPU coresMinimum memory MB
bookstackAvailable11024
directusAvailable11024
ghostAvailable11024
hoarderAvailable11536
mattermostAvailable11024
nextcloudAvailable11024
plausibleAvailable22048
stirling-pdfAvailable11024
supabaseComing Soon24096
umamiAvailable1512
wordpressAvailable1512

BookStack runs without no-new-privileges

Every container the panel starts runs with no-new-privileges, which stops a setuid program from raising privileges. bookstack is the one exception: both of its containers (the application and its MariaDB database, LinuxServer images) are created without that flag, because the template asks for it and the template is on a one-entry allowlist in the panel's source. The capability drops still apply. This holds for every BookStack service, including one a customer deploys through the tenant MCP, and each such container is recorded as a warning in the panel log. No other template, and no pasted Compose file, can switch the flag off.

What identifies "BookStack" here is the service's stored template name: exactly bookstack, set when the service is deployed from that catalog template. Template names are unique, and only platform administrators can create or change templates. The exemption therefore covers whatever image that template runs, and one part of that is the deployer's choice: the image tag. The template's VERSION variable selects the tag of lscr.io/linuxserver/bookstack, so a customer deploying BookStack can choose which BookStack release runs without the flag. They cannot choose another image repository, and the MariaDB image is pinned. A Git repository or pasted Compose file that names a service bookstack gets no exemption.

Before deploying

Select an available card and review its current variables, image/source version, resource limits and application instructions. Coming Soon entries cannot be deployed. Minimum memory is a declared requirement, not a capacity guarantee. Required password inputs and generated system secrets are different: a blank password field does not automatically generate a value.

Use Template Deploy for the deployment steps and Template Authoring for the manifest schema. Container health checks report readiness; they do not by themselves restart a hung application or provide automatic image/security updates.

Application accounts and data

Follow the selected application's first-login instructions. The application's account and the panel's Keycloak login are separate unless an explicit integration is configured. A template's existence does not enable every upstream feature, configure external runners/providers, or certify compliance.

Review named volumes and external dependencies before changing or retiring a service. Plan application-specific backups and inspect the backup/restore limitations.