Fleet health
Live reachability, DNS state and filter counts.
AdGuard Home updates
Automatically checked when the dashboard loads and every 15 minutes.
| Node | Installed | Latest | Status |
|---|---|---|---|
| Checking versions… | |||
DNS statistics
Combined statistics from all three AdGuard Home nodes.
Top blocked domains
Top queried domains
Top clients
DNS query log
Search recent DNS queries across one node or the entire fleet.
| Time | Node | Domain | Type | Client | Status | Reason |
|---|
DNS Configuration
Stored in data/dns-config.json. Save locally or push the same settings to all managed hosts.
Upstream DNS
Bootstrap & fallback DNS
Protection & blocking
Rate limiting
DNSSEC, EDNS & IPv6
Cache
Client & private PTR resolution
Advanced / unrecognised configuration fields
Fields returned by AdGuard that are not represented above are preserved here.
Custom filter rules
Stored in data/custom-filter-rules.txt and managed independently from blocklists.
DNS blocklists & allowlists
Stored in data/filter-lists.json and pushed identically to all managed hosts.
| Type | Enabled | Name | URL / path |
|---|
Blocked Services
Manage AdGuard Home's official built-in Blocked Services catalogue across all managed DNS nodes.
Choose a source node or reload the catalogue.
Blocked-services schedule
This preserves AdGuard Home's native schedule object. Import from a node to retain an existing schedule. Leave {} for no schedule.
Updates & maintenance
Select the nodes below, then refresh filters, check versions, or start AdGuard Home upgrades.
Version status
Installed version is compared with the latest version reported by AdGuard Home.
| Node | Installed | Latest | Status | Auto-update |
|---|---|---|---|---|
| Click Check upgrades. | ||||
Targets
Target selection applies only to maintenance/update operations.
Current activity
Ready.
Persistent history
Audit events and application logs are kept in ./data on the Docker host.
Managed AdGuard Home servers
Manage connectivity, TLS identity and credentials for every AdGuard Home node.
Add server
Provision from existing node
Clone selected AdGuard Home configuration from a known-good source to a new or replacement node. The target is backed up before any changes are made.
Select a source and target node.
Certificate source
Mounted wildcard certificate used for new-server HTTPS setup and manual TLS deployment.
TLS / SSL certificates
Validate and deploy certificates using AdGuard Home's native TLS API.
Detected TLS name comes from AdGuard Home. Configured TLS hostname is what this management app will use for future certificate deployment and HTTPS migration.
Certificate deployment
Use certificate/key paths on the AdGuard host instead
Ready.
Authentication & OIDC
Configure Authentik/OIDC and the local break-glass sign-in path.
OpenID Connect
OIDC group → role mapping
Local break-glass sign-in
When hidden, local username/password sign-in remains available only after opening the secret break-glass URL. The URL does not bypass authentication.
User management
Local accounts and role-based permissions. Passwords are stored as salted scrypt hashes.
Create user
| User | Role | Enabled | Password change | Last login | Actions |
|---|---|---|---|---|---|
| Loading users… | |||||