uncloud
Use when managing an Uncloud cluster — deploying services, configuring Caddy ingress, adding static proxy routes for non-cluster devices, publishing ports, scaling, inspecting logs, or managing machines and volumes with the `uc` CLI.
By affaan-m · 2,770 installs
npx skills add affaan-m/ecc --skill uncloud
Source repository · Upstream listing
Uncloud Cluster Management
Reference for the uc CLI — a decentralised self hosting platform using Docker containers, WireGuard mesh networking, and Caddy reverse proxy.
When to Activate
Use this skill when working with Uncloud clusters, especially when:
Bootstrapping or joining machines with uc machine
Deploying services from Compose files with uc deploy
Publishing HTTP, HTTPS, TCP, or UDP ports through Uncloud
Configuring Caddy ingress with x caddy , x ports , or caddyfile
Routing external LAN devices through the cluster proxy
Inspecting logs, service state, volumes, DNS, or machine placement
How It Works
Uncloud runs Docker services across peer machines connected by a WireGuard mesh. Each machine is an equal cluster member; services communicate on the overlay network and Caddy runs globally to terminate public HTTP/HTTPS traffic. Compose files can use Uncloud extensions for ingress, placement, and generated Caddy configuration, while the uc CLI handles image distribution, scheduling, scaling, logs, and cluster state.
Examples
Core Concepts
No central control plane — all machines are equal peers connected by WireGuard
Caddy runs as a global service on every machine; auto obtains TLS from Let's Encrypt
Overlay network — services communicate via 10.210.0.0/16 by default; DNS provided inside the mesh
Caddyfile is autogenerated — never edit it directly; use x caddy / caddyfile instead
CLI Quick Reference
Machines
Command Purpose
uc machine init user@host Bootstrap first machine / new cluster
uc machine add user@host Join machine to existing cluster
uc machine ls List machines
uc machine update NAME public ip IP Update public IP for ingress
uc machine rm NAME Remove machine
Key init flags: name , network 10.210.0.0/16 , no caddy , no dns , public ip auto\ IP\ none
Services
Command Purpose
uc service ls / uc ls List services
uc service run IMAGE Run a single container service
uc deploy Deploy from compose.yaml
uc deploy no build Deploy already pushed images without rebuilding
uc deploy recreate Force service recreation
uc scale SERVICE N Set replica count
uc service logs SERVICE View logs
uc service exec SERVICE Shell into container
uc service inspect SERVICE Detailed info
uc service rm SERVICE Remove service (keeps named volumes)
uc ps All containers across cluster
Images
Volumes
Caddy
DNS & Context
Port Publishing
HTTP/HTTPS (via Caddy reverse proxy)
Example Meaning
p 8080/https HTTPS with auto service name.cluster domain hostname
p app.example.com:8080/https HTTPS with custom hostname
p 8080/http HTTP only, no TLS
TCP/UDP (host bound, bypasses Caddy)
Example Meaning
p 5432:5432@host TCP 5432 on all interfaces
p 127.0.0.1:5432:5432@host TCP 5432 loopback only
p 53:5353/udp@host UDP
Compose File Extensions
Uncloud adds these extensions on top of Docker Compose:
x ports — publish ports with domains
x caddy — custom Caddy config for service
Template functions available inside x caddy :
{{upstreams [service] [port]}} — healthy container IPs
{{.Name}} — service name
{{.Upstreams}} — map of all services → IPs
x machines — placement constraints
Full multi service example
Routing to External (Non Cluster) Devices
To expose an external device (e.g. BMC, NAS, router UI) via Caddy without running a real container:
1. Create a Caddyfile snippet (e.g. ~/device.caddyfile ):
For plaintext upstream: reverse proxy http://192.168.1.x:port
2. Register as a named service with no op container:
pause is a minimal no op container — it does nothing, but gives Uncloud a service entry to attach the Caddyfile to.
3. Verify:
caddyfile cannot be combined with non @host published ports.
DNS tip: A wildcard record ( .yourdomain.com → cluster public ip ) means any new subdomain works immediately — no DNS change needed per service.
Service DNS (Internal)
Services inside the cluster resolve each other by name:
DNS name Resolves to
service name Any healthy container
service name.internal Same
rr.service name.internal Round robin
nearest.service name.internal Machine local first
Scaling & Global Services
Image Tag Templates (in compose.yaml)
Function Output
{{gitsha N}} First N chars of commit SHA
{{gitdate "format"}} Git commit date in Go format
{{date "format"}} Current date
Common Workflows
Deploy from source:
Inspect a service:
Zero downtime deploys happen automatically; Uncloud waits for health checks before terminating old containers.
Force recreate:
Common Mistakes
Mistake Fix
Editing the Caddyfile directly Use x caddy in compose or caddyfile on uc service run
Proxying an HTTPS upstream with self signed cert Add transport http { tls insecure skip verify }
uc caddy config shows no user defined blocks Caddy admin socket unreachable — check uc inspect caddy and uc logs caddy
Service can't reach external LAN IP from container Verify Caddy container's host can route to target network
Volumes lost after uc service rm Named volumes persist; only anonymous volumes are auto removed