rct-manager giiibates/rct-manager:latest https://hub.docker.com/r/giiibates/rct-manager bridge bash false https://github.com/Gill-Bates/rct-manager/issues https://github.com/Gill-Bates/rct-manager https://gill-bates.github.io/rct-manager/ Vendor-neutral REST gateway for RCT Power inverters. Speaks the RCT serial protocol over TCP to one or more inverters and turns it into clean JSON, a Prometheus endpoint, and optional, guarded write access. No vendor app, no protocol knowledge needed. Features: - Read any metric from the full protocol catalog (894 of 895 IDs), partial success on multi-metric requests, RFC 9457 error responses - Energy Manager for dynamic electricity tariffs: charge the battery from the grid or discharge it to the house with a target state of charge, power limit and duration - Data export to your own InfluxDB 2 or QuestDB for Grafana, Telegraf and custom analysis - Administration GUI: Overview, Inverters, Energy Manager, TSDB, Prometheus, API tokens and Settings pages with autosave - Ready-made /metrics endpoint for Telegraf, Grafana and friends; a scrape never touches the inverter - API token authentication, separate admin sessions, read and read/write roles, encrypted SQLite administration storage - Guarded writes: off by default, allowlist-based, with readback confirmation - Several inverters behind one API, requests per endpoint serialized so the device never sees a conflict - Hardened container: read-only root filesystem, all capabilities dropped, non-root user, built-in health check IMPORTANT - Required Environment Variable: - HMAC_SECRET: encrypts the administration database (data/rct.db). Generate with: openssl rand -base64 32. Changing it afterwards makes the database unreadable. First start: The container logs a boxed "FIRST START - admin login" block with the one-time "admin" password in clear text (also saved to /app/data/initial-admin-password as a fallback). The first login requires a password change. Until then, periodic reads, heartbeat and metric export stay paused. Reverse Proxy: rct-manager speaks plain HTTP inside the container. Enable "behind reverse proxy" on the admin Settings page when terminating TLS in front of it. Multi-arch image: linux/amd64 and linux/arm64, published with Trivy scanning, an SBOM and a provenance attestation. Source: https://github.com/Gill-Bates/rct-manager HomeAutomation: Tools:Utilities http://[IP]:[PORT:8000] https://raw.githubusercontent.com/Gill-Bates/unraid-app-templates/main/templates/05_rct-manager.xml https://raw.githubusercontent.com/Gill-Bates/unraid-app-templates/main/icons/05_rct-magager.png --restart unless-stopped --security-opt=no-new-privileges:true --cap-drop=ALL --cap-add=CHOWN --cap-add=SETUID --cap-add=SETGID --read-only --tmpfs /tmp:rw,noexec,nosuid,nodev,size=1m,mode=1777 2026-10-11 Updated for the 1.0.0 release: image giiibates/rct-manager, container port 8000, Energy Manager and InfluxDB 2/QuestDB export added, timezone variable removed (defaults to UTC). bridge 8000 8000 tcp /mnt/user/appdata/rct-manager/data /app/data rw HMAC_SECRET BIND_ADDRESS 0.0.0.0 BIND_PORT 8000 ALLOW_NON_LOOPBACK_BIND true DOCS_PUBLIC false LOG_LEVEL INFO 0.0.0.0 8000 true false INFO