kastoria-consoleui
An Admin Console web UI served by an unprivileged NGINX as a compiled React
single-page application. The UI is designed to sit behind a
kastoria-proxy or kastoria-proxy-mtls
reverse proxy under the /console/. This application makes calls into the
kastoria-consoleapi and
kastoria-health container apps.
Runtime details
| Property | Value |
|---|---|
| Build stage | node:24-alpine (npm run build of admin-console-web-ui) |
| Runtime base image | nginxinc/nginx-unprivileged:1.31-alpine (pinned by digest) |
| Exposed port | 8081 |
| Container user | nginx (non-root) |
| Command | CMD ["nginx", "-g", "daemon off;"] |
| Health check | GET http://localhost:8081/ (every 30s, 5s timeout, 30s start period, 3 retries) |
| Stop signal | SIGTERM |
The UI is a static SPA; the API base URL and asset base path are compiled into the bundle at build time, not configured at runtime.
OCI labels
| Label | Value |
|---|---|
org.opencontainers.image.title |
Kastoria Admin Console UI |
org.opencontainers.image.description |
Admin console web UI for the Kastoria Health platform |
org.opencontainers.image.licenses |
Proprietary |
org.opencontainers.image.url |
https://github.com/merkalis-io/kastoria-health |
org.opencontainers.image.documentation |
https://github.com/merkalis-io/kastoria-health |
io.kastoria.health-endpoint |
/ |
The org.opencontainers.image.version, org.opencontainers.image.revision,
org.opencontainers.image.created, org.opencontainers.image.source,
io.kastoria.base-image, and io.kastoria.service labels are injected at
build time by the CI/CD pipeline.
Pull and verify
Promoted images are published to the Distribution Registry under the customer namespace:
docker pull acrmerkalisdist0c66.azurecr.io/<customer>/kastoria-consoleui:<release-tag>
notation verify acrmerkalisdist0c66.azurecr.io/<customer>/kastoria-consoleui:<release-tag>
See the Distribution Registry guide for authentication and trust setup.
Environment variables
| Variable | Secret | Required | Default | Description |
|---|---|---|---|---|
PORT |
No | No | 8081 |
Only used by the container HEALTHCHECK; NGINX listens on 8081. |
Deploying to an Azure Container Apps Environment
none
Available versions
v0.10.0v0.9.1— deprecated for security reasons (CVE-2026-93990); usev0.10.0