Skip to content
Setting Up a Private Admin Panel Without Ever Opening It Myself

24 September 2026

Setting Up a Private Admin Panel Without Ever Opening It Myself

observabilitysecurity

Deploying a monitoring container with no public router meant its first-run setup wizard — creating an admin account, adding a monitor, publishing a status page — had no normal way to run. A setup flow built for someone clicking through a browser doesn't stop existing just because the plan was to keep that browser tab as short-lived as possible.

The access pattern that kept it private

An SSH tunnel forwarded a single local port to the container's internal one for the duration of setup and nothing longer — no port ever got published on the host, and the tunnel closed the moment the wizard finished. The container's designed-for-humans setup flow got completed without the container ever being reachable from anywhere but that one temporary pipe.

Driving the wizard itself

With the tunnel up, a browser automation script did the actual clicking: fill the admin form, submit, add a monitor pointed at the site's own public health endpoint, create and publish a status page. It's the same sequence a person would type by hand, run once, against a target that was never meant to be operated by hand more than that once.

What this generalizes to

Any admin panel that assumes a human at a browser can still be configured unattended, as long as the network path to it is temporary and the actions are scripted rather than improvised. The interesting property isn't that the tool has no UI — it's that the UI never needed to be reachable by anyone except, briefly, a script.