Documentation

Cerberus Help

Self-hosted website scanner · Updated September 28, 2026

Only scan websites you own or are explicitly authorized to assess. Active tools can create load or alter state; use staging whenever possible.

Install

For requirements, standard Compose setup, the Docker Hub AIO alternative, remote-host access, and removal semantics, use the step-by-step installation guide.

The recommended setup needs Git, Docker with Compose v2, OpenSSL, and roughly 8 GB of free disk:

git clone https://github.com/vaxman14/cerberus-selfhost.git
cd cerberus-selfhost
./scripts/setup.sh

Open http://127.0.0.1:8099 on the Docker host and create the first local owner. Active scans are disabled by default.

Safe network exposure

The recommended Compose setup binds to localhost. The optional AIO command publishes the web UI on host port 8099 for LAN access; do not expose or port-forward it to the public internet. On a host with a public interface, bind AIO to one private address and enforce access with the host firewall. Never publish the tools worker or ZAP. The AIO launcher also needs Docker-socket access and therefore effective control of the Docker host.

Data and backups

History lives in the cerberus-data volume. Run ./scripts/backup.sh for a verified archive and keep secrets/cerberus_master_key in a separate protected backup. Restore into a verified fresh volume with:

./scripts/restore.sh backups/cerberus-TIMESTAMP.tar.gz --confirm-replace

Password recovery

docker compose exec cerberus \
  python -m cerberus.userctl reset-password --username admin

Password reset revokes existing sessions.

Update

git pull --ff-only
./scripts/update.sh

The update creates a verified backup before pulling images and waiting for health.

Operate and troubleshoot

docker compose ps
docker compose logs --tail=200 cerberus
docker compose logs --tail=200 cerberus-tools
docker compose logs --tail=200 zap
curl http://127.0.0.1:8099/health

For full operations and rollback instructions, read the repository guide. For bugs, open a GitHub issue without secrets or private findings. Report vulnerabilities privately through the repository Security tab.

Support

Cerberus is free software with no support contract or SLA. If it helps, feed Cerberus's dad a coffee. Contributions do not purchase priority.