A standalone web GUI for Docker container management. Monitor container statuses, receive automated Apprise notifications, and seamlessly pull new image updates.
Go
0
351 commits
updated Oct 5, 2026
A lightweight, secure Docker update agent — single binary, no fuss.

DockGo is a simple, single-binary application that monitors your Docker containers for updates. It focuses on visibility and control rather than automatic unattended updates and it provides:
Most Docker update tools (like Watchtower or Ouroboros) are great, but can be:
DockGo is different:
dockgo).The fastest way to run DockGo is via Docker:
docker run -d \
--name dockgo \
-p 3131:3131 \
-v /var/run/docker.sock:/var/run/docker.sock \
-e AUTH_USERNAME=admin \
-e AUTH_PASSWORD=changeme \
ghcr.io/jisevind/dockgo:latest
Visit http://localhost:3131 to see your dashboard!
DockGo takes security seriously.
dockgo user (UID 1000), not root.docker group matching the host's socket GID, allowing the dockgo user to talk to the engine without being root.AUTH_USERNAME and map either AUTH_PASSWORD_HASH (recommended) or AUTH_PASSWORD (convenience/testing) to enable a secure login flow with HttpOnly cookies.
dockgo hash-password secret.API_TOKEN for simple script integrations.CORS_ORIGIN.ALLOWED_COMPOSE_PATHS environment variable lets you restrict which Docker Compose working directories can be updated. This is a defense-in-depth measure to prevent accidental or malicious updates outside your intended container environments. The restriction applies to both native Compose updates and fallback to standalone API recreation for Compose-managed containers. Note: This restriction only applies to updates, not discovery—DockGo will still discover and monitor all containers on your system, but will only allow updating those whose compose files are within the allowed paths.crypto/rand) fails to provide secure random bytes.[!CAUTION] CRITICAL SECURITY WARNING: Docker Socket Exposure
Mounting
/var/run/docker.sockexplicitly grants full root-level access to your host machine. This is an unavoidable requirement for any tool that manages Docker containers, but it comes with severe security implications.You MUST:
- Never expose DockGo publicly to the internet without robust authentication.
- Use Network Isolation: Run DockGo on a trusted, private local network.
- Implement a Reverse Proxy: If you must expose it, place it behind a secure reverse proxy (like Nginx, Traefik, or Caddy) equipped with SSL/TLS and preferably external Single Sign-On (SSO) or robust reverse-proxy-level authentication, in addition to DockGo's built-in authentication.
Failing to secure this endpoint is effectively equivalent to giving an attacker root-level control over the host.
--safe to pull images without restarting running containers (CLI only).LOG_LEVEL.Configure DockGo using environment variables:
| Variable | Description | Default |
|---|---|---|
PORT | Web server port | 3131 |
LOG_LEVEL | Log verbosity (debug, info, warn, error) | info |
LOG_FORMAT | Log format (json or text) | json (Docker) / text (CLI) |
DOCKGO_DEBUG | Enable internal debug endpoints (e.g., /api/debug/cache) | false |
AUTH_USERNAME | Username for web login | (empty) |
AUTH_PASSWORD_HASH | Pre-hashed bcrypt string (Recommended for production) | (empty) |
AUTH_PASSWORD | Plaintext password (Convenience/Testing) | (empty) |
AUTH_SECRET | Secret for signing session cookies | (random) |
AUTH_BCRYPT_COST | Configurable bcrypt hashing cost (min 4, max 31) | 10 |
API_TOKEN | Legacy token for API updates | (empty) |
DOCKGO_STOP_TIMEOUT | Grace period in seconds when stopping a container before it is recreated. | 10 |
DOCKGO_INITIAL_RUNTIME_CHECK | Initial verification wait in seconds for containers without healthchecks. | 10 |
DOCKGO_HEALTH_TIMEOUT | Max wait time in seconds for a container to become healthy after recreation. | 60 |
DOCKGO_STABILITY_WINDOW | Stability monitoring window in seconds post-healthcheck. | 20 |
CORS_ORIGIN | Allowed Origin for CORS (e.g. https://mydomain.com) | (disabled) |
ALLOWED_COMPOSE_PATHS | Comma-separated list of allowed base paths for Compose working directories (e.g., /opt/docker,/srv/compose) | (empty) |
COMPOSE_PATH_MAPPING | Comma-separated map of host paths to container paths (e.g. D:\Docker:/compose or /home/user/docker:/compose) when DockGo sees Compose projects at a different path than the host. | (empty) |
SESSION_STORE_PATH | Path to session persistence file | /app/data/sessions.json |
STACK_STORE_PATH | JSON file persisting registered stack definitions | /app/data/stacks.json (server) / /app/data/agent_stacks.json (agent) |
STACK_HISTORY_PATH | JSON file persisting stack action history | /app/data/stack_history.json |
LOG_FILE_PATH | Path to write persistent rotating logs (e.g., /app/data/logs/dockgo.log) | (Stdout only) |
LOG_MAX_SIZE | Maximum size in MB before a log file is rotated | 10 |
LOG_MAX_BACKUPS | Maximum number of old rotated log files to retain | 5 |
LOG_MAX_AGE | Maximum number of days to retain old log files | 28 |
LOG_COMPRESS | Compress rotated log files using gzip (true/false) | true |
APPRISE_API_HOST | Custom Apprise API connection host (e.g. http://my-notifier:8000) | http://apprise:8000 |
APPRISE_URL | Apprise notification endpoint (e.g., ntfy://...) | (empty) |
APPRISE_QUEUE_SIZE | Buffer size for outbound notification events | 100 |
SCAN_INTERVAL | Background update polling schedule (s, m, h) | 24h |
AGENT_STORE_PATH | JSON file persisting registered agent records | /app/data/agents.json |
AGENT_MAX_CONCURRENT | Per-agent concurrent operation cap | 8 |
AGENT_JWT_TTL | Lifetime of the agent channel JWT | 1h |
AGENT_JWT_SECRET | JWT signing secret for agent channels | AUTH_SECRET |
DOCKGO_SERVER_URL | Agent WebSocket endpoint (e.g. wss://dockgo.example.com/api/ws/agent) | (required) |
AGENT_KEY | One-time agent registration key (dg_...) | (required) |
AGENT_NAME | Agent display name in the dashboard | hostname |
AGENT_RECONNECT_MIN | Agent reconnect backoff floor | 5s |
AGENT_RECONNECT_MAX | Agent reconnect backoff ceiling | 60s |
AGENT_RECONNECT_MULT | Agent reconnect backoff multiplier | 2.0 |
AGENT_HEARTBEAT_INTERVAL | Agent keepalive ping interval | 30s |

DockGo can manage containers and Compose stacks on multiple remote hosts from one dashboard. A lightweight agent runs on each managed host, dials out to the server over a secure WebSocket channel, and the server relays the dashboard operations to it. No inbound ports are required on agent hosts.
AGENT_KEY) for the remote host.ghcr.io/jisevind/dockgo:agent-latest image (bundles
the Docker CLI and Compose plugin).The agent is deployed separately from the server: one
docker-compose.agent.yml.example per
managed host, never co-located with the DockGo server compose file. You only
need an agent on hosts whose Docker daemon you cannot (or do not want to) give
the DockGo server direct socket access to.
See Multi-Host Management with DockGo Agents for full setup, security, and key-rotation instructions.
Start with the new user documentation:
Additional reference material:
Example docker-compose.yml:
services:
dockgo:
image: ghcr.io/jisevind/dockgo:latest
volumes:
- /var/run/docker.sock:/var/run/docker.sock
ports:
- "3131:3131"
environment:
- LOG_LEVEL=info
- AUTH_USERNAME=admin
# Generate with: dockgo hash-password your_password
- AUTH_PASSWORD_HASH=$$2a$$10$$YOUR_GENERATED_HASH_HERE
# Optional: Restrict updates to specific Compose directories
- ALLOWED_COMPOSE_PATHS=/opt/docker,/srv/compose
# Optional: Map host paths when DockGo sees Compose projects at a
# different path than the Docker host (common on Windows).
# - COMPOSE_PATH_MAPPING=D:\Docker:/compose
If you want reliable Compose stack updates from the DockGo container, the mount layout matters.
Host NativeOn Linux, the recommended setup is to mount the Compose root into DockGo at the exact same absolute path as the host:
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ./data:/app/data
- /home/johan/docker:/home/johan/docker
With that setup:
COMPOSE_PATH_MAPPINGHost NativeThis is the most reliable option because DockGo and the Docker host resolve paths the same way, including relative bind mounts like ./app_data.
MappedIf DockGo sees the Compose project at a different path than the host, use a path mapping instead. This is the normal setup on Windows with a Linux DockGo container:
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ./data:/app/data
- D:\Docker:/compose
COMPOSE_PATH_MAPPING=D:\Docker:/compose
With that setup:
MappedD:\Docker\bazarrYou can also use Mapped on Linux if you deliberately mount the Compose root to a different internal path such as /compose, but Host Native is preferred on Linux whenever possible.
You can use the dockgo binary directly for scripting or manual checks.
# Check all containers
dockgo check
# Check with JSON output (great for scripts)
dockgo check -json
# Generate a password hash for the dashboard server configuration
dockgo hash-password supersecretpassword
dockgo check -json
# Update a specific container
dockgo update -y my-container
# Update ALL containers
dockgo update -a
# Safe Mode: Pull only, don't restart running containers
dockgo update -safe -a
# Force Mode: Restart even if running
dockgo update -force -y my-container
# Typical workflow:
dockgo check
dockgo update -a
-y <name>: Target specific container.-a: Target all containers with updates.-json: Output standard JSON.-stream: Output SSE-compatible line-delimited JSON.-preserve-network: Preserve network settings (IP/MAC) during recreation.git clone https://github.com/Jisevind/dockgo.git
cd dockgo
go build -o dockgo ./cmd/dockgo
If you want to run the DockGo binary natively on Windows (e.g. as a background service or CLI tool), you can build the .exe directly:
git clone https://github.com/Jisevind/dockgo.git
cd dockgo
$env:GOOS="windows"
$env:GOARCH="amd64"
go build -o dockgo.exe ./cmd/dockgo
If you see an error like failed to connect to Docker, ensure Docker Desktop is running. You may need to set the DOCKER_HOST environment variable if the default connection fails:
$env:DOCKER_HOST = "npipe:////./pipe/docker_engine"
If the container crashes with exec ./entrypoint.sh: no such file or directory, it likely has Windows line endings (CRLF). Ensure entrypoint.sh uses Unix line endings (LF). The build process should handle this, but if you are mounting the file locally, you may need to convert it.
A standalone web GUI for Docker container management. Monitor container statuses, receive automated Apprise notifications, and seamlessly pull new image updates.
Go
0
351 commits
updated Oct 5, 2026
A lightweight, secure Docker update agent — single binary, no fuss.

DockGo is a simple, single-binary application that monitors your Docker containers for updates. It focuses on visibility and control rather than automatic unattended updates and it provides:
Most Docker update tools (like Watchtower or Ouroboros) are great, but can be:
DockGo is different:
dockgo).The fastest way to run DockGo is via Docker:
docker run -d \
--name dockgo \
-p 3131:3131 \
-v /var/run/docker.sock:/var/run/docker.sock \
-e AUTH_USERNAME=admin \
-e AUTH_PASSWORD=changeme \
ghcr.io/jisevind/dockgo:latest
Visit http://localhost:3131 to see your dashboard!
DockGo takes security seriously.
dockgo user (UID 1000), not root.docker group matching the host's socket GID, allowing the dockgo user to talk to the engine without being root.AUTH_USERNAME and map either AUTH_PASSWORD_HASH (recommended) or AUTH_PASSWORD (convenience/testing) to enable a secure login flow with HttpOnly cookies.
dockgo hash-password secret.API_TOKEN for simple script integrations.CORS_ORIGIN.ALLOWED_COMPOSE_PATHS environment variable lets you restrict which Docker Compose working directories can be updated. This is a defense-in-depth measure to prevent accidental or malicious updates outside your intended container environments. The restriction applies to both native Compose updates and fallback to standalone API recreation for Compose-managed containers. Note: This restriction only applies to updates, not discovery—DockGo will still discover and monitor all containers on your system, but will only allow updating those whose compose files are within the allowed paths.crypto/rand) fails to provide secure random bytes.[!CAUTION] CRITICAL SECURITY WARNING: Docker Socket Exposure
Mounting
/var/run/docker.sockexplicitly grants full root-level access to your host machine. This is an unavoidable requirement for any tool that manages Docker containers, but it comes with severe security implications.You MUST:
- Never expose DockGo publicly to the internet without robust authentication.
- Use Network Isolation: Run DockGo on a trusted, private local network.
- Implement a Reverse Proxy: If you must expose it, place it behind a secure reverse proxy (like Nginx, Traefik, or Caddy) equipped with SSL/TLS and preferably external Single Sign-On (SSO) or robust reverse-proxy-level authentication, in addition to DockGo's built-in authentication.
Failing to secure this endpoint is effectively equivalent to giving an attacker root-level control over the host.
--safe to pull images without restarting running containers (CLI only).LOG_LEVEL.Configure DockGo using environment variables:
| Variable | Description | Default |
|---|---|---|
PORT | Web server port | 3131 |
LOG_LEVEL | Log verbosity (debug, info, warn, error) | info |
LOG_FORMAT | Log format (json or text) | json (Docker) / text (CLI) |
DOCKGO_DEBUG | Enable internal debug endpoints (e.g., /api/debug/cache) | false |
AUTH_USERNAME | Username for web login | (empty) |
AUTH_PASSWORD_HASH | Pre-hashed bcrypt string (Recommended for production) | (empty) |
AUTH_PASSWORD | Plaintext password (Convenience/Testing) | (empty) |
AUTH_SECRET | Secret for signing session cookies | (random) |
AUTH_BCRYPT_COST | Configurable bcrypt hashing cost (min 4, max 31) | 10 |
API_TOKEN | Legacy token for API updates | (empty) |
DOCKGO_STOP_TIMEOUT | Grace period in seconds when stopping a container before it is recreated. | 10 |
DOCKGO_INITIAL_RUNTIME_CHECK | Initial verification wait in seconds for containers without healthchecks. | 10 |
DOCKGO_HEALTH_TIMEOUT | Max wait time in seconds for a container to become healthy after recreation. | 60 |
DOCKGO_STABILITY_WINDOW | Stability monitoring window in seconds post-healthcheck. | 20 |
CORS_ORIGIN | Allowed Origin for CORS (e.g. https://mydomain.com) | (disabled) |
ALLOWED_COMPOSE_PATHS | Comma-separated list of allowed base paths for Compose working directories (e.g., /opt/docker,/srv/compose) | (empty) |
COMPOSE_PATH_MAPPING | Comma-separated map of host paths to container paths (e.g. D:\Docker:/compose or /home/user/docker:/compose) when DockGo sees Compose projects at a different path than the host. | (empty) |
SESSION_STORE_PATH | Path to session persistence file | /app/data/sessions.json |
STACK_STORE_PATH | JSON file persisting registered stack definitions | /app/data/stacks.json (server) / /app/data/agent_stacks.json (agent) |
STACK_HISTORY_PATH | JSON file persisting stack action history | /app/data/stack_history.json |
LOG_FILE_PATH | Path to write persistent rotating logs (e.g., /app/data/logs/dockgo.log) | (Stdout only) |
LOG_MAX_SIZE | Maximum size in MB before a log file is rotated | 10 |
LOG_MAX_BACKUPS | Maximum number of old rotated log files to retain | 5 |
LOG_MAX_AGE | Maximum number of days to retain old log files | 28 |
LOG_COMPRESS | Compress rotated log files using gzip (true/false) | true |
APPRISE_API_HOST | Custom Apprise API connection host (e.g. http://my-notifier:8000) | http://apprise:8000 |
APPRISE_URL | Apprise notification endpoint (e.g., ntfy://...) | (empty) |
APPRISE_QUEUE_SIZE | Buffer size for outbound notification events | 100 |
SCAN_INTERVAL | Background update polling schedule (s, m, h) | 24h |
AGENT_STORE_PATH | JSON file persisting registered agent records | /app/data/agents.json |
AGENT_MAX_CONCURRENT | Per-agent concurrent operation cap | 8 |
AGENT_JWT_TTL | Lifetime of the agent channel JWT | 1h |
AGENT_JWT_SECRET | JWT signing secret for agent channels | AUTH_SECRET |
DOCKGO_SERVER_URL | Agent WebSocket endpoint (e.g. wss://dockgo.example.com/api/ws/agent) | (required) |
AGENT_KEY | One-time agent registration key (dg_...) | (required) |
AGENT_NAME | Agent display name in the dashboard | hostname |
AGENT_RECONNECT_MIN | Agent reconnect backoff floor | 5s |
AGENT_RECONNECT_MAX | Agent reconnect backoff ceiling | 60s |
AGENT_RECONNECT_MULT | Agent reconnect backoff multiplier | 2.0 |
AGENT_HEARTBEAT_INTERVAL | Agent keepalive ping interval | 30s |

DockGo can manage containers and Compose stacks on multiple remote hosts from one dashboard. A lightweight agent runs on each managed host, dials out to the server over a secure WebSocket channel, and the server relays the dashboard operations to it. No inbound ports are required on agent hosts.
AGENT_KEY) for the remote host.ghcr.io/jisevind/dockgo:agent-latest image (bundles
the Docker CLI and Compose plugin).The agent is deployed separately from the server: one
docker-compose.agent.yml.example per
managed host, never co-located with the DockGo server compose file. You only
need an agent on hosts whose Docker daemon you cannot (or do not want to) give
the DockGo server direct socket access to.
See Multi-Host Management with DockGo Agents for full setup, security, and key-rotation instructions.
Start with the new user documentation:
Additional reference material:
Example docker-compose.yml:
services:
dockgo:
image: ghcr.io/jisevind/dockgo:latest
volumes:
- /var/run/docker.sock:/var/run/docker.sock
ports:
- "3131:3131"
environment:
- LOG_LEVEL=info
- AUTH_USERNAME=admin
# Generate with: dockgo hash-password your_password
- AUTH_PASSWORD_HASH=$$2a$$10$$YOUR_GENERATED_HASH_HERE
# Optional: Restrict updates to specific Compose directories
- ALLOWED_COMPOSE_PATHS=/opt/docker,/srv/compose
# Optional: Map host paths when DockGo sees Compose projects at a
# different path than the Docker host (common on Windows).
# - COMPOSE_PATH_MAPPING=D:\Docker:/compose
If you want reliable Compose stack updates from the DockGo container, the mount layout matters.
Host NativeOn Linux, the recommended setup is to mount the Compose root into DockGo at the exact same absolute path as the host:
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ./data:/app/data
- /home/johan/docker:/home/johan/docker
With that setup:
COMPOSE_PATH_MAPPINGHost NativeThis is the most reliable option because DockGo and the Docker host resolve paths the same way, including relative bind mounts like ./app_data.
MappedIf DockGo sees the Compose project at a different path than the host, use a path mapping instead. This is the normal setup on Windows with a Linux DockGo container:
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ./data:/app/data
- D:\Docker:/compose
COMPOSE_PATH_MAPPING=D:\Docker:/compose
With that setup:
MappedD:\Docker\bazarrYou can also use Mapped on Linux if you deliberately mount the Compose root to a different internal path such as /compose, but Host Native is preferred on Linux whenever possible.
You can use the dockgo binary directly for scripting or manual checks.
# Check all containers
dockgo check
# Check with JSON output (great for scripts)
dockgo check -json
# Generate a password hash for the dashboard server configuration
dockgo hash-password supersecretpassword
dockgo check -json
# Update a specific container
dockgo update -y my-container
# Update ALL containers
dockgo update -a
# Safe Mode: Pull only, don't restart running containers
dockgo update -safe -a
# Force Mode: Restart even if running
dockgo update -force -y my-container
# Typical workflow:
dockgo check
dockgo update -a
-y <name>: Target specific container.-a: Target all containers with updates.-json: Output standard JSON.-stream: Output SSE-compatible line-delimited JSON.-preserve-network: Preserve network settings (IP/MAC) during recreation.git clone https://github.com/Jisevind/dockgo.git
cd dockgo
go build -o dockgo ./cmd/dockgo
If you want to run the DockGo binary natively on Windows (e.g. as a background service or CLI tool), you can build the .exe directly:
git clone https://github.com/Jisevind/dockgo.git
cd dockgo
$env:GOOS="windows"
$env:GOARCH="amd64"
go build -o dockgo.exe ./cmd/dockgo
If you see an error like failed to connect to Docker, ensure Docker Desktop is running. You may need to set the DOCKER_HOST environment variable if the default connection fails:
$env:DOCKER_HOST = "npipe:////./pipe/docker_engine"
If the container crashes with exec ./entrypoint.sh: no such file or directory, it likely has Windows line endings (CRLF). Ensure entrypoint.sh uses Unix line endings (LF). The build process should handle this, but if you are mounting the file locally, you may need to convert it.