Admin page
ADMIN_PORT (default 4560, 0 disables) serves a loopback-only status page
and JSON API. It binds 127.0.0.1 only and has no authentication by
design: it is safe precisely because it is not network-exposed. It is never
reachable from another device or the network, so never bind it to 0.0.0.0,
publish it, or port-forward it.
For remote access, tunnel the loopback port over SSH:
http://127.0.0.1:4560 on your local machine. Set ADMIN_PORT=0 to
disable the page entirely.
The page trusts anything on the host, so local code shares the host trust
boundary. See Security for the threat model.
Endpoints
GET /— HTML status page.GET /api/projects,GET /api/health.POST /api/projects/<channelId>/start|stop.GET /api/logs/<channelId>?lines=200— redacted log tail.GET /api/audit?limit=100— recent audit entries.
Logs
Celly logs to the console (colored on a TTY) and toDATA_DIR/bot.log as JSONL.
Each project’s supervised opencode serve child appends to
DATA_DIR/logs/<project>.log. LOG_LEVEL (debug, info, warn, error)
sets console verbosity. Tokens, passwords, and Authorization headers are
redacted before they reach either sink.
Backups and log rotation
Celly backs upDATA_DIR/bot.db with SQLite VACUUM INTO on an interval and
prunes old copies. It also rotates bot.log and every per-project server log.
Backups are written to
DATA_DIR/backups/bot-<ISO>.db (for example
bot-2026-09-27T00-00-00-000Z.db).
Restore
Stop the bot first so the database is not open while it is replaced.- Windows
- Linux
Related
- Configuration —
DATA_DIR,LOG_LEVEL, and the ops variables. - Deployment on Windows and Deployment on Linux — running Celly as a service.
- Security — why the admin page is unauthenticated.