Deployment guide

Self-host Glance: your startpage dashboard on a VPS

Deploy on a VPS Cloud →

Tutorial

Self-host Glance: your startpage dashboard on a VPS

Security & Monitoring7 min read10 steps

Running multiple services on a VPS without a unified view means flying blind. Glance fixes that: an lightweight self-hosted dashboard that consolidates your tech news (Hacker News, RSS), live server metrics and Docker container status on a single browser-accessible page. One Go binary, zero databases, zero Redis — it starts in under a second, idles under 25 MB RAM, and is configured entirely through a YAML file. This guide covers the full installation, advanced widget configuration, Docker socket security, comparisons with alternatives and troubleshooting common errors.

Contents· Why Glance is a perfect fit for a VPS1/16
  1. 01Why Glance is a perfect fit for a VPS
  2. 02What you get out of the box
  3. 03Glance vs alternatives: Heimdall, Homepage, Homarr
  4. 04Self-hosted dashboard comparison
  5. 05Prerequisites
  6. 06What you need before starting
  7. 07Deploy Glance on your ServOrbit VPS
  8. 08Step-by-step installation
  9. 09Advanced YAML configuration: widgets, themes and layout
  10. 10Advanced configuration options
  11. 11Security: the Docker socket in read-only mode
  12. 12Risks and mitigations
  13. 13Troubleshooting: common errors
  14. 14Frequent issues and solutions
  15. 15Real-world use cases for a web agency
  16. 16How to structure Glance for an agency

Why Glance is a perfect fit for a VPS

What you get out of the box

  • Built-in widgets: RSS feeds, Hacker News, Reddit, weather, bookmarks, world clock
  • Live server metrics: CPU, RAM, disk, load average
  • Docker container status (running / stopped / paused)
  • Light/dark themes and custom colors via YAML
  • No external dependencies: single static Go binary (~15 MB)
  • Hot-reload configuration without restart

Glance vs alternatives: Heimdall, Homepage, Homarr

Self-hosted dashboard comparison

Scroll the table

ToolLanguageIdle RAMConfigDocker metricsRSS/news widgets
**Glance**Go< 25 MBPure YAMLYes (read-only)Yes (native)
HomepageNode/React~120 MBYAMLYesPartial
HomarrNode/React~150 MBGUI + JSONYesVia integration
HeimdallPHP/Laravel~200 MBGUI + MySQLNot nativeNo

Glance excels when lightness and speed matter more than a graphical configuration UI. For non-technical teams who prefer clicking over editing YAML, Homarr or Heimdall are valid alternatives.

Prerequisites

What you need before starting

  • A ServOrbit VPS running Ubuntu 22.04 / Debian 12 (≥ 1 vCPU, 512 MB RAM is enough)
  • docker and docker compose installed (Docker Engine 24+, Compose v2)
  • SSH root or sudo access
  • A subdomain pointed at your VPS (e.g. glance.mydomain.tld) — optional but recommended for HTTPS

Deploy Glance on your ServOrbit VPS

Step-by-step installation

  1. Create the working directory

    SSH into your VPS and create the folder that will hold the Glance configuration:

    mkdir -p /opt/glance && cd /opt/glance

  2. Write the `docker-compose.yml` file

    Create the following file. The read-only mount of the Docker socket is mandatory (see Security section below):

    services:
      glance:
        image: glanceapp/glance:latest
        restart: unless-stopped
        ports:
          - "8080:8080"
        volumes:
          - ./glance.yml:/app/glance.yml:ro
          - /var/run/docker.sock:/var/run/docker.sock:ro
          - /proc:/proc:ro
        environment:
          - TZ=UTC
  3. Create the base configuration `glance.yml`

    This YAML file defines your pages, columns and widgets:

    server:
      port: 8080
    
    pages:
      - name: Home
        columns:
          - size: small
            widgets:
              - type: clock
                hour-format: 24h
              - type: resource-usage
          - size: full
            widgets:
              - type: hacker-news
              - type: rss
                feeds:
                  - url: https://blog.servOrbit.com/rss
                    title: ServOrbit Blog
          - size: small
            widgets:
              - type: docker-containers
  4. Start the container

    docker compose up -d

    Check it's running: docker compose ps — status should show Up.

  5. Open the firewall (if UFW is active)

    ufw allow 8080/tcp

    Open http://<VPS-IP>:8080 in your browser to confirm Glance responds.

  6. Set up an nginx reverse proxy with HTTPS

    To serve Glance on https://glance.mydomain.tld, create an nginx vhost:

    server {
        listen 443 ssl http2;
        server_name glance.mydomain.tld;
        ssl_certificate     /etc/letsencrypt/live/glance.mydomain.tld/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/glance.mydomain.tld/privkey.pem;
    
        location / {
            proxy_pass http://127.0.0.1:8080;
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
        }
    }

    Get the certificate via Certbot: certbot --nginx -d glance.mydomain.tld.

  7. Enable HTTP basic authentication (recommended)

    Glance has no built-in auth. Protect access via nginx:

    htpasswd -c /etc/nginx/.htpasswd admin

    Add to the location / block in your vhost:

    auth_basic "Glance";
    auth_basic_user_file /etc/nginx/.htpasswd;

    Reload nginx: systemctl reload nginx.

  8. Verify system metrics

    The resource-usage widget reads /proc — the :ro mount in docker-compose.yml is therefore mandatory. If metrics don't appear, check: docker compose logs glance | grep -i proc.

  9. Reload config without restart

    Any change to glance.yml is picked up by sending SIGHUP to the container:

    docker kill --signal=SIGHUP glance_glance_1

    Alternatively: docker compose restart glance (causes ~1 s of downtime).

  10. Enable automatic updates (optional)

    Deploy [Watchtower](https://containrrr.dev/watchtower/) to keep the Glance image up to date automatically, or manage it manually:

    docker compose pull && docker compose up -d

Advanced YAML configuration: widgets, themes and layout

Glance's power lies in its YAML file. Here are the most useful customizations.

Advanced configuration options

  • Custom theme — add under server:: theme: { background-color: "240 21 15", primary-color: "217 92 83" } (HSL format without hsl())
  • Multiple pages — add as many - name: blocks under pages: as you have contexts (e.g. "Dev", "Clients", "Personal")
  • Bookmarks widget — type: bookmarks with link groups to centralize quick access to internal tools
  • Monitor widget — type: monitor with a list of URLs: Glance performs HTTP checks and displays latency + status in real time
  • GitHub releases widget — type: releases with a list of repos: ideal for tracking new versions of your tools
  • Refresh interval — each widget accepts cache: 1h (or 30m, 5m) to control polling frequency

Security: the Docker socket in read-only mode

Mounting /var/run/docker.sock inside a container gives that container potentially full control over the host Docker daemon — equivalent to root. This is the most common privilege escalation vector in Docker environments.

Risks and mitigations

  • Risk: a compromised container with :rw socket access can launch root containers, mount /, exfiltrate secrets
  • Mitigation 1 — Read-only mount: the :ro flag in docker-compose.yml blocks all writes; Glance only needs to read container state
  • Mitigation 2 — Socket proxy: deploy [Docker Socket Proxy](https://github.com/Tecnativa/docker-socket-proxy) to expose only GET /containers and GET /version endpoints
  • Mitigation 3 — Network isolation: place Glance in a dedicated Docker network, isolated from your application services
  • Verification: docker inspect glance_glance_1 | grep -A5 Mounts — the Mode line must show ro, never rw

If you don't need Docker metrics, simply remove the /var/run/docker.sock mount from docker-compose.yml and remove the docker-containers widget from glance.yml. Glance works perfectly without Docker daemon access.

Troubleshooting: common errors

Frequent issues and solutions

  • Port 8080 already in use — ss -tlnp | grep 8080 to identify the process. Change the host port in docker-compose.yml: "8181:8080" (the container port stays 8080 on Glance's side).
  • Widget not loading / permanent spinner — check outbound network connectivity from the container: docker exec glance_glance_1 curl -s https://news.ycombinator.com. If timeout, your VPS is behind a restrictive outbound firewall — open ports 80/443 outbound via ufw.
  • Docker socket refused (permission denied) — the container runs under a non-root UID without access to the docker group. Fix: add group_add: ["docker"] or mount the socket with correct permissions. Check: ls -la /var/run/docker.sock (group docker, mode 660).
  • /proc metrics missing — the /proc:/proc:ro mount is missing from docker-compose.yml. Without it, resource-usage shows null values or an error. Add the volume and restart: docker compose up -d.

Real-world use cases for a web agency

An agency managing N client projects on separate VPSes can centralize monitoring in Glance with one page per client or environment.

How to structure Glance for an agency

  • One page per client: each pages[n] block corresponds to a project — monitor widget with critical URLs (front, API, backoffice), docker-containers widget if services run locally
  • "Global infra" page: the monitor widget can check healthcheck endpoints exposed on each machine (e.g. /healthz) to aggregate multi-VPS status
  • Alert RSS feed: add the RSS feed from your monitoring tool (UptimeKuma, Gatus) to surface incidents without leaving Glance
  • GitHub releases widget: track CMS/framework releases for your clients to anticipate critical updates
  • Multi-team access: one Glance per environment (staging / prod), each protected by a separate HTTP auth via nginx, shareable by link with the relevant team

The official Glance documentation (github.com/glanceapp/glance) lists all available widgets and their options. The glance.yml reference section is the most up-to-date reference — options evolve with each minor release.

Your VPS services at a glance

Deploy Glance on a ServOrbit VPS — self-hosted dashboard with no database with live tech news and server stats in the browser.

Need help?

Browse our help center and FAQ, or reach our team — callback, WhatsApp or email. Support in French, English and Arabic.

Message us on WhatsAppopens in a new tab