New Ory Agent Security is now live! Claim your complimentary test drive. Get Started!

Skip to main content

Ory Console Lite quickstart

In this quickstart, you add Ory Console Lite, a browser-based admin interface, to your existing Ory deployment. It takes about 5 minutes. You'll authenticate to the Ory Enterprise Docker registry, start the Console Lite container with your services' admin API URLs, and confirm on the Settings page that each service reports healthy.

danger

Ory Console Lite has no authentication of its own. Anyone who can reach it has full administrative access to every identity, session, OAuth2 client, and permission in your deployment. Run it on a private network, behind a VPN, or behind an authenticating proxy — never expose it to the public internet. See Secure Ory Console Lite.

Prerequisites​

Before you start, make sure you have:

  • A valid Ory Enterprise License (Ory OEL).
  • Access to the Ory Enterprise Docker registry, which you need to download Ory OEL Docker images.
  • Docker, running. Check with docker info.
  • The gcloud CLI used to authenticate to the Ory Enterprise Docker registry. Check with gcloud version.
  • The admin API URL of at least one of Ory Kratos Identities, Ory Hydra Authorization, or Ory Keto Permissions, resolvable from wherever you run the container. Ory Console Lite will not serve without at least one admin API URL set.
  • Port 3000 free on the host where you run the container, or another port to publish on.

Authenticate to the registry​

Ory Console Lite is published to the Ory Enterprise Docker registry, which requires authorization. The steps below assume your service account key is stored in keyfile.json.

gcloud auth activate-service-account --key-file=keyfile.json
gcloud auth configure-docker europe-docker.pkg.dev

Confirm that you can reach the image. A JSON manifest means the key works and the tag exists:

docker manifest inspect europe-docker.pkg.dev/ory-artifacts/ory-enterprise-console-lite/console-oel-lite:26.3.14

Start Ory Console Lite​

Ory Console Lite is a single stateless container. It holds no configuration beyond the URLs of the services it manages, so starting it is one command. Replace the hostnames with your own admin APIs:

docker run -d --name ory-console-lite \
--platform linux/amd64 \
-p 127.0.0.1:3000:3000 \
-e ORY_KRATOS_URL=http://kratos.internal:4434 \
-e ORY_KRATOS_PUBLIC_URL=http://kratos.internal:4433 \
-e ORY_HYDRA_URL=http://hydra.internal:4445 \
-e ORY_KETO_READ_URL=http://keto.internal:4466 \
-e ORY_KETO_WRITE_URL=http://keto.internal:4467 \
-e CSRF_TOKEN_SECRET=replace-this-with-a-random-32-character-secret \
europe-docker.pkg.dev/ory-artifacts/ory-enterprise-console-lite/console-oel-lite:26.3.14

The command binds Ory Console Lite to 127.0.0.1, which keeps it on the host you start it from. Before you run it anywhere else, read Secure Ory Console Lite.

Set only the Ory services that you run. Not setting other services doesn't break anything — see Configure only the services you run.

To view Ory Console Lite, open http://localhost:3000 and it redirects to /projects/local/get-started.

note

Ory Console Lite is released for linux/amd64 only, so the platform flag is required on Apple Silicon and other ARM hosts. Docker runs it under emulation, which makes the first page load noticeably slower.

Confirm Ory Console Lite reached your services​

Open Settings. For every service that Ory Console Lite is configured for, the console displays its URL and health status. The Available features section shows all the enabled features and their health status.

The Ory Console Lite settings page listing five connected services above a table of five enabled features, with the build tag 26.3.14 at the bottom

Each configured service should display Connected, and their features should display Enabled. A service that reads as Unavailable is either down or configured with a URL that Ory Console Lite cannot resolve — remember that the console resolves these URLs from inside its own container, so http://localhost:4434 points it at itself.

If a service or feature does not read as expected, see Troubleshooting.

The build tag at the bottom of the page searches the Ory changelog for the version you are running.

Removing Ory Console Lite​

docker rm -f ory-console-lite

Ory Console Lite stores no data of its own, so removing the container leaves nothing behind. Everything it manages stays in Ory Kratos Identities, Ory Hydra Authorization, and Ory Keto Permissions.

Next steps​

Professional support?

Ory offers support for self-hosted Ory software through the Ory Enterprise License (OEL). Read more about the OEL here.