Open-Source Automation Platform

Run Ansible, Scripts & Pipelines
from a single UI

oachkatzl is a self-hosted web UI and REST API that lets your team execute automation tasks — Ansible playbooks, shell scripts, Python code, and custom apps — with role-based access, live log streaming, and full audit history.

Get Started View on GitHub
oachkatzl dashboard – template overview

🐿️

Why "oachkatzl"?

oachkatzl is Bavarian and Austrian dialect for squirrel (German: Eichhörnchen) — famously used in the tongue-twister "oachkatzlschwoaf" (squirrel's tail).

🌰

It diligently collects nuts — your playbooks and inventories — and stashes them away for the right moment.

🌿

It leaps from branch to branch — your server nodes — with speed and precision.

🌲

From the top of the tree it keeps a perfect overview of its entire domain and infrastructure.

Everything you need to automate at scale

From one-off scripts to multi-step deployment pipelines — oachkatzl keeps your automation organised, auditable, and accessible to the right people.

🎭

Role-Based Access Control

Organise users into projects with fine-grained roles: Owner, Manager, Task Runner, and Guest — so the right people can do the right things.

📋

Task Templates

Define reusable templates for Ansible playbooks, Bash scripts, Python code, or any custom application. Categorise them as task, build, or deploy workflows.

📡

Live Log Streaming

Watch stdout and stderr in real time via WebSockets. All output is archived in MongoDB so you can replay logs from any past run.

🔐

Credential Management

Store SSH keys and username/password pairs with Fernet encryption. Credentials are injected automatically as Ansible variables — no plain-text secrets in your playbooks.

💬

Survey Variables

Prompt operators for runtime input with typed fields: string, integer, enum, secret, boolean, and separator. Build interactive task launchers without writing extra code.

🔁

Task Replay

Re-run any completed task with the exact same survey answers and git revision. Perfect for reproducing issues or re-deploying a known-good state.

🔗

Visual Workflows

Chain templates into directed graphs with conditional edges. Build and edit pipelines with a drag-and-drop canvas — no YAML required.

📦

Artifact Caching

Store and retrieve project-scoped files and JSON blobs via a simple REST API. Share build artefacts between tasks or export results for downstream systems.

⏰

Scheduled Runs

Configure cron expressions for any template. Celery Beat handles recurring execution automatically — no external scheduler needed.

🪝

Webhooks & Triggers

Expose HMAC-authenticated HTTP endpoints to kick off tasks from CI/CD systems, monitoring tools, or any external service that can POST a request.

🔔

Multi-Channel Notifications

Send run results to Email, Slack, Telegram, Microsoft Teams, and more. Keep your team informed without polling the UI.

🛡️

Flexible Authentication

Local accounts with JWT tokens, two-factor authentication (TOTP), and LDAP integration for enterprise single sign-on.

⚙️

Custom Worker Pools

Route templates to dedicated Celery worker containers with specialized environments — GPU drivers, Terraform, kubectl, or custom Python packages. Each pool maps to its own queue via OACHKATZL_WORKER_QUEUES.

🚦

Approval Gates

Place a gate node anywhere in a workflow to pause execution and wait for a human decision. The operator chooses to Proceed or Cancel — with title and description dynamically pulled from a JSON artifact of the preceding task.

Built for operators, loved by teams

A clean, modern interface that makes complex automation approachable for everyone — from senior DevOps engineers to first-time task runners.

Template Library & Task Launcher

Browse your project's template library, pick a template, fill in the survey form, and hit Run. oachkatzl validates input types and injects credentials before dispatching the job to Celery workers.

Ansible Bash Python Custom Apps Survey Variables
oachkatzl task run dialog with survey variables

Live Log Console

Watch your Ansible plays, script output, and error traces stream in real time. The WebSocket-powered console auto-scrolls, highlights ANSI colours, and preserves the full log in MongoDB for later review.

WebSockets ANSI Colours MongoDB Archive
oachkatzl live Ansible log output

Visual Workflow Editor

Drag templates onto a canvas, connect them with conditional edges, and define branching logic for success and failure paths. Deploy complex multi-step pipelines without writing a single line of orchestration code.

Drag & Drop Conditional Edges Directed Graph
oachkatzl visual workflow editor

Workflow Run Status

See exactly what's happening inside a running workflow — which steps succeeded, which are pending, and where errors occurred. Each node shows its live status so you can react instantly without tailing log files.

Live Status Success / Error / Skipped Conditional Routing
oachkatzl workflow run status view

Cron Scheduling

Set any template to run automatically via a cron expression. Quick-pick presets and a live preview make it easy without leaving the UI.

Cron Expressions Quick Presets Celery Beat
oachkatzl cron schedule dialog

Artifact Caches

Store and share files or JSON between tasks and workflow runs. Each cache has a configurable retention period and is accessible via REST API using the OACHKATZL_ARTIFACT_TOKEN.

Files & JSON REST API Retention Policy
oachkatzl artifact caches

Custom Credential Types

Define reusable credential schemas with custom input fields and injector rules. Values are securely injected as env vars, extra_vars, or files — keeping secrets out of your code entirely.

Input Schema Injector Rules Fernet Encrypted
oachkatzl custom credential types editor

LDAP Group → Role Mapping

Map Active Directory groups directly to project roles. Members get the right access automatically on every login — no manual provisioning, no stale permissions.

Active Directory Auto-Sync on Login Per-Project Roles
oachkatzl LDAP group to project role mapping

Project Members & RBAC

Manage who has access to each project and at what role. Combine local users, direct LDAP user mappings, and AD group mappings in a single view.

Local Users LDAP Users AD Group Mappings
oachkatzl project members and RBAC

Approval Gates

Insert a dedicated gate node anywhere in a workflow to pause execution and wait for a human decision. A modal dialog prompts the operator to Proceed — continuing the workflow — or Cancel — stopping it immediately. The gate's title and description are sourced from a JSON artifact uploaded by the preceding task; if no artifact is provided, a default "Proceed?" prompt is shown instead.

Human-in-the-Loop Workflow Gate Node JSON Artifact Prompt Proceed / Cancel
oachkatzl approval gate modal in a workflow

Custom Worker Pools

Route templates to dedicated Celery worker containers that carry exactly the tools your tasks need — GPU drivers, Terraform, kubectl, or any custom Python packages. Define a named pool in Settings, set OACHKATZL_WORKER_QUEUES=<slug> on your worker container, and assign the pool per template or as a default for a custom app type.

Named Celery Queues Per-Template Routing GPU / Custom Binaries Independent Scaling
oachkatzl custom worker pools settings

Modern, proven components

oachkatzl is built on a robust, container-friendly stack that's easy to self-host and scale.

Backend Python 3.12+ APIFlask · Flask-SocketIO
Frontend Vue 3 Pinia · TailwindCSS · Vite
Database MongoDB 7+ Log archive & state
Message Broker Redis 7+ Celery task queue
Real-time WebSockets Flask-SocketIO
Deployment Docker Compose Single-command setup

Up and running in minutes

Pull the pre-built images from Docker Hub or build everything from source. No Kubernetes required.

# 1. Download the compose file and example environment
curl -fsSL https://raw.githubusercontent.com/lanbugs/oachkatzl/main/docker-compose.hub.yml \
     -o docker-compose.yml

curl -fsSL https://raw.githubusercontent.com/lanbugs/oachkatzl/main/.env.example \
     -o .env

# 2. Generate secrets and update .env
#    OACHKATZL_ENCRYPTION_KEY, OACHKATZL_JWT_SECRET, admin credentials …

# 3. Start all services
docker compose up -d

# Web UI  → http://localhost:8888
# API docs → http://localhost:8888/api/docs
# 1. Clone the repository
git clone https://github.com/lanbugs/oachkatzl.git
cd oachkatzl

# 2. Set up your environment
cp backend/.env.example backend/.env
# Edit backend/.env — set secrets, admin credentials, etc.

# 3. Build & start
docker compose up --build

# Web UI  → http://localhost:8888
# API docs → http://localhost:8888/api/docs

Pre-built images are available on Docker Hub (lanbugsde). Full documentation and advanced configuration in the GitHub repository.

Help build oachkatzl

oachkatzl is community-driven. Whether you fix a bug, improve the docs, or build a new feature — every contribution matters.

Fork on GitHub Contributing Guide

Open source. Self-hosted. Yours.

oachkatzl is free forever under the MIT licence. Star the repo, open an issue, or submit a pull request.

View on GitHub Docker Hub