Overview
A web interface that drives a headless Factorio server over RCON, with roles, an audit log and bounded commands.
This panel exposes a headless Factorio server through the RCON protocol, from a browser. It exists because raw RCON is an all-or-nothing door: a single password, no rate limiting, no trace, and complete control of the server for whoever gets through it.
The panel puts three things in front of that door:
- roles, so that moderating does not have to mean full power;
- an audit log, so you know who did what, refusals included;
- bounded commands, built by the server from validated fields rather than a free-form command line.
What it does#
- Custom commands
Your own catalogue in JSON, with user-filled fields and a permission per entry.
- Three roles
Viewer, moderator, administrator. The catalogue is filtered server-side, and execution re-checks.
- Audit log
Every action and every refusal, in SQLite, with the command actually sent.
- Metrics
CPU, memory, players and UPS as time series — without mounting the Docker socket into the panel.
- RCON console
A full command line with history — restricted to the administrator role.
- English and French
Language inferred from the browser, switchable, remembered. No interface text lives server-side.
Quick start#
Without cloning anything, paste
the ready-made docker-compose.yml: it
pulls the published images and starts the game server and the panel together.
From the repository, the factorio-admin service already lives in
its docker-compose.yml, next to the game server.
git clone https://github.com/EdwinAlkins/factorio-admin-rcon.git
cd factorio-admin-rcon
# Writes ./.env: one password per role, plus the session signing key
./setup-admin.sh
docker compose up -d --build factorio-admin
# → http://127.0.0.1:3010127.0.0.1. That is deliberate: it
grants full RCON access. To expose it, put an HTTPS reverse proxy in front and
read the matching section.
How to read this documentation#
- Installation
Production setup, hardened image, updating, health probes.
- Configuration
The complete environment variable reference.
- Custom commands
The file format, the field types, and the Lua pitfalls specific to a server.
- Security model
Roles, sessions, CSP, audit, and the deployment assumptions.
- HTTP API
The routes, their permissions and the error format.
- Development
Architecture, tests, translations, releases.