About this project
dockwatch is a self-hosted Docker container update watcher with both a CLI and a web dashboard. Unlike auto-updaters that pull new images immediately, it checks running containers against their registries, reports what is outdated, and only updates when explicitly approved. The comparison is digest-aware rather than tag-string based, so it detects when a tag such as `latest` silently points to a new image, and it is multi-arch safe by comparing the platform-specific digest.
The web dashboard provides authentication and role-based access control with eight granular permissions, an audit log, per-container log viewing, and management actions such as update, rollback, restart, and delete. One-click rollback is available for compose-managed containers. Vulnerability scanning is provided through bundled Trivy, with results cached by image ID and shown as clickable severity bars. Notifications can be sent via generic webhook, Discord, or ntfy, and are opt-in per event type.
Portainer can be used as an additional container source, allowing remote Docker hosts to be managed without direct socket access. A lightweight agent mode lets one central instance monitor multiple Docker PCs, with the central instance performing all registry checks. Health monitoring can sample container states and optionally auto-restart unhealthy containers with throttling controls. Lifecycle hooks can run commands inside containers at pre/post update, pre-stop, and pre/post rollback phases, and image pruning is available with per-repository retention guards.
The CLI exposes the same engine as the dashboard for scripts and cron jobs, including list, check, update, scan, health, prune, and agent commands. The published multi-arch image runs as a non-root user, auto-detects the Docker socket group, and includes a healthcheck. Configuration is stored in a TOML file and can be edited through the dashboard settings page.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.