NETWORK CONTROL

AdGuard Management

One dashboard to manage AdGuard Home

Overview

Fleet health, statistics and update status.

Fleet health

Live reachability, DNS state and filter counts.

Checking…

AdGuard Home updates

Automatically checked when the dashboard loads and every 15 minutes.

Checking…
Temporary PKI exception: enabling self-signed/untrusted TLS skips certificate-chain verification only for that specific AdGuard Home node. Remove the exception after your internal root CA is trusted by this container.
NodeInstalledLatestStatus
Checking versions…

DNS statistics

Combined statistics from all three AdGuard Home nodes.

Top blocked domains

Top queried domains

Top clients

DNS query log

Search recent DNS queries across one node or the entire fleet.

TimeNodeDomainTypeClientStatusReason

DNS Configuration

Stored in data/dns-config.json. Save locally or push the same settings to all managed hosts.

data/dns-config.json

Upstream DNS

Bootstrap & fallback DNS

Protection & blocking

Rate limiting

DNSSEC, EDNS & IPv6

Cache

Client & private PTR resolution

Advanced / unrecognised configuration fields

Fields returned by AdGuard that are not represented above are preserved here.

Custom filter rules

Stored in data/custom-filter-rules.txt and managed independently from blocklists.

data/custom-filter-rules.txt

DNS blocklists & allowlists

Stored in data/filter-lists.json and pushed identically to all managed hosts.

data/filter-lists.json
TypeEnabledNameURL / path

Blocked Services

Manage AdGuard Home's official built-in Blocked Services catalogue across all managed DNS nodes.

data/blocked-services.json
Official AdGuard Home catalogue • loading…
0 selected

Choose a source node or reload the catalogue.

Blocked-services schedule

This preserves AdGuard Home's native schedule object. Import from a node to retain an existing schedule. Leave {} for no schedule.

Updates & maintenance

Select the nodes below, then refresh filters, check versions, or start AdGuard Home upgrades.

Version status

Installed version is compared with the latest version reported by AdGuard Home.

NodeInstalledLatestStatusAuto-update
Click Check upgrades.

Targets

Target selection applies only to maintenance/update operations.

Current activity

Ready.

Persistent history

Audit events and application logs are kept in ./data on the Docker host.

Add filter list

Browse the official AdGuard Hostlists Registry or enter a custom URL.

Loading registry…

Managed AdGuard Home servers

Manage connectivity, TLS identity and credentials for every AdGuard Home node.

Add server

Loading managed servers…

Provision from existing node

Clone selected AdGuard Home configuration from a known-good source to a new or replacement node. The target is backed up before any changes are made.

TLS excluded
Per-node identity is preserved: TLS hostname, certificates, management URL, credentials and this app's server record are not copied from the source node.
Select a source and target node.

Certificate source

Mounted wildcard certificate used for new-server HTTPS setup and manual TLS deployment.

Certificate source not loaded.

TLS / SSL certificates

Validate and deploy certificates using AdGuard Home's native TLS API.

Private-key safety: certificate deployment is blocked over plain HTTP by default. Use this after the management app is behind HTTPS.

Detected TLS name comes from AdGuard Home. Configured TLS hostname is what this management app will use for future certificate deployment and HTTPS migration.

Certificate deployment

Use certificate/key paths on the AdGuard host instead
Ready.

Authentication & OIDC

Configure Authentik/OIDC and the local break-glass sign-in path.

Loading…

OpenID Connect

OIDC group → role mapping

Local break-glass sign-in

When hidden, local username/password sign-in remains available only after opening the secret break-glass URL. The URL does not bypass authentication.

User management

Local accounts and role-based permissions. Passwords are stored as salted scrypt hashes.

Create user

UserRoleEnabledPassword changeLast loginActions
Loading users…

Role permissions

AdministratorFull access including user management.
OperatorManage DNS, rules, lists, blocked services and updates. No user management.
ViewerRead-only access to Overview, DNS Queries and History.

Reset password