pando. Quickstartv{{ version }}
Pando · {{ docType }} · {{ date }}

{{ docType }}

Quickstart

Install Pando with Docker Compose so it keeps itself up to date, create the administrator account, deploy your first app and install the optional CLI.

1Install the server

To run Pando on rootless Docker on Linux, see Running Pando on rootless Docker.

1.1 Download the Compose file

1.2 Turn on automatic updates

Settings made here are locked in the console. To install patch releases only when you choose, delete the last two lines.

1.3 Optional: change the ports

To use ports other than 8080 for the console and 9000–9019 for apps (one port each), add them to .env:

PANDO_PORT=8081
PANDO_APP_PORT_START=9100
PANDO_APP_PORT_END=9199

1.4 Start Pando

Open http://localhost:8080, or http://<host>:8080 from another machine, using your PANDO_PORT if you set one.

2Create the administrator account

Get the one-time setup token from Pando's log:

On Set up Pando, paste the token, enter a username, your name and a password, then choose Create account.

If the log no longer has the token, make a new one:

For an unattended install, set the password at the first start instead. The account is named admin, and you're asked to change the password when you first sign in:

To reset a lost administrator password, run this on the host. It signs that account out everywhere:

3Deploy your first app

  1. Choose Add app.
  2. Paste a git repository's URL into Repository, such as https://github.com/acme/notes, and choose Add app.
  3. Check the build method, port and services Pando proposes, and answer any questions.
  4. Choose Accept and deploy.

4Keep Pando up to date

New releases appear in System > Updates.

Release Example Installed
Patch 0.4.1 → 0.4.2 Automatically, in the maintenance window. Or earlier, when you choose Upgrade.
Minor or major 0.4.2 → 0.5.0 When you choose Upgrade.

Table 1. When each kind of release is installed, with the settings from section 1.2.

4.1 Upgrading

In System > Updates, choose Upgrade to the new version and give a passphrase for the backup taken first, or run pando upgrade.

Keep the passphrase. It isn't stored, and the backup can't be restored without it.

Apps can't be reached while Pando restarts, usually for under a minute.

Automatic patch upgrades take no full backup. Take your own in System > Backups or with pando backup create.

If you also back up Docker volumes, back up pando-secrets together with postgres-data. It holds the database password, which is made on the first start.

4.2 Going back

Pando can't run on a database a newer version has migrated. To go back, restore the backup taken before the upgrade.

5Install the CLI

Optional. Install it on your own computer, not the host.

System Install
macOS, or Linux with Homebrew brew install trypando/tap/pando
Debian, Ubuntu pando_<version>_linux_<arch>.deb
Fedora, RHEL and other RPM systems pando_<version>_linux_<arch>.rpm
Alpine pando_<version>_linux_<arch>.apk
Any macOS or Linux pando_<version>_<os>_<arch>.tar.gz, then put pando on your PATH

Table 2. CLI packages, on the latest release's page. <arch> is amd64 or arm64. There is no Windows build.

For example, on Ubuntu on Intel or AMD:

Then sign in with the console's address:

To update the CLI, run pando self-update. For Homebrew and the Linux packages it prints the package manager's command instead.

Without installing it, run docker compose exec pando pando <command> on the host.

6Where to go next

  • Using Pando: the console, the CLI, the MCP server for coding agents and the HTTP API.
  • Configuration: every setting for the pando service, including PANDO_SERVER_EXTERNAL_URL when Pando sits behind a proxy that terminates TLS.
  • CLI reference: every command and flag.
  • Running on Kubernetes: install on a cluster instead of with Docker Compose.
  • Report a problem on GitHub.

Revision history

Version Date Changes
{{ version }} {{ date }} Added a link to running Pando on rootless Docker (1) and backing up pando-secrets (4.1). Removed setting the database password, which is now generated. The port change is its own step (1.3).
1.0 9 October 2026 First published.