Logo
Deploy Now

Stars

5,725

Forks

230

Watchers

19

Developer links

Dockhand

Dockhand is a Docker management platforms, offering a modern alternative to Portainer with free OIDC SSO and vulnerability scanning that competitors gate behind paid tiers. Real-time container management provides start, stop, restart, and remove operations with live resource monitoring across CPU, memory, and network usage on a dashboard with real-time metrics. The visual Docker Compose editor enables stack creation and modification with syntax highlighting, while Git integration deploys stacks directly from repositories with webhooks and auto-sync for GitOps workflows. Vulnerability scanning powered by Grype and Trivy analyzes container images against CVE databases, with configurable auto-update scheduling that can trigger updates based on vulnerability severity criteria. The Hawser Go agent enables management of remote Docker hosts in Standard mode for LAN environments or Edge mode using outbound WebSocket connections for hosts behind NAT, firewalls, or dynamic IPs without exposing inbound ports. Interactive terminal sessions provide shell access into running containers, while the file browser enables uploading, downloading, and editing files directly within containers. Image management includes registry browsing, pull operations, and layer inspection alongside network and volume administration. The security-focused architecture builds its own OS layer from scratch using Wolfi packages via apko with every package explicitly declared. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BSL 1.1 licensed, converting to Apache 2.0 in 2029.

Dockhand
Dockhand
Dockhand
Dockhand
Dockhand

Benefits

  • Free SSO and Vulnerability Scanning
  • OIDC single sign-on authentication and Grype plus Trivy vulnerability scanning ship free in the community edition, features that competing platforms restrict to paid enterprise tiers.
  • GitOps Docker Compose Deployment
  • Deploy Compose stacks directly from Git repositories with webhook-triggered auto-sync, visual YAML editor with syntax highlighting, and version-controlled infrastructure management workflows.
  • Remote Host Management via Hawser
  • Lightweight Go agent manages Docker hosts behind NAT, firewalls, or dynamic IPs using outbound WebSocket connections requiring no exposed ports or inbound firewall rules.
  • Real-Time Container Operations
  • Live dashboard with CPU, memory, and network metrics alongside interactive terminal sessions, container file browsing, and ANSI-colored log streaming with auto-refresh.

Features

  • Visual Compose Editor
  • Create and modify Docker Compose stacks with syntax-highlighted YAML editing, service dependency visualization, and one-click deployment from the web interface.
  • Vulnerability Scanning
  • Grype and Trivy integration scans container images against CVE databases with configurable auto-update scheduling triggered by vulnerability severity thresholds.
  • Container File Browser
  • Browse, upload, download, and edit files directly within running containers through the web interface without requiring shell access or docker cp commands.
  • Image Registry Browsing
  • Manage Docker images with pull operations, layer inspection, tag management, and registry browsing across Docker Hub and private container registries.
  • Notification Channels
  • Configure alerts via webhooks and notification channels for container state changes, vulnerability findings, and auto-update events across managed hosts.