Deploy Now

Stars

253

Forks

12

Watchers

0

Developer links

Drydock

Deploying container updates without blind surprises is what Drydock delivers through a monitor-first inspection plane that evaluates image registries, scans CVE vulnerabilities, and automates rollbacks across distributed Docker infrastructure. Systems engineers track container fleets across twenty-three public and private registries including Docker Hub, GitHub Container Registry, Harbor, and Quay using cursor-based pagination and semver classification. The integrated Update Bouncer runs Trivy and Grype static scanners against incoming candidate layers, blocking deployments that fail configurable CVE severity policies while verifying cryptographic signatures through cosign. Operators configure declarative update schedules with stabilization countdown gates that hold back brand-new releases until defined burn-in periods elapse. When updates execute, Drydock creates pre-upgrade container snapshots and evaluates post-launch container health checks, instantly restoring previous image digests and network configs if failures occur. Distributed Portwing edge agents stream live container output and system logs over encrypted WebSockets, allowing central consoles to coordinate remote daemon updates without opening inbound host firewall ports. Automated event triggers dispatch granular notifications and update payloads across seventeen communication channels including Slack, Discord, Telegram, and Home Assistant MQTT brokers. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.

Drydock
Drydock
Drydock
Drydock
Drydock
Drydock

Benefits

  • Monitor-First Semver Update Detection
  • Classifies upstream registry updates across major, minor, patch, and digest tiers before pulling images, allowing administrators to review incoming container diffs prior to executing production deployments.
  • Integrated Trivy Vulnerability Scanning
  • Scans incoming container layers with Trivy and Grype engines while verifying cosign cryptographic signatures, automatically blocking vulnerable or unsigned container updates from reaching production systems.
  • Automated Snapshot And Failure Rollback
  • Captures pre-update image states and monitors container health check statuses, immediately triggering automated rollbacks to previous digests whenever newly deployed containers crash or fail readiness tests.
  • Distributed Multi-Host Agent Architecture
  • Orchestrates remote Docker engines through lightweight Portwing edge agents over outbound WebSocket tunnels, enabling centralized update management across fleets without exposing inbound controller firewall ports.

Features

  • Twenty-Three Registry Integrations
  • Connects to Docker Hub, GHCR, Harbor, Quay, AWS ECR, and GitLab registries with token authentication and cursor-based pagination.
  • Vulnerability Bouncer Gate
  • Analyzes candidate container images using Trivy and Grype scanners to enforce configurable security policies and generate SBOM records.
  • Automated Image Rollback
  • Restores previous container image digests, network attachments, and environment variables when post-update health checks detect boot failure.
  • Maturity Stabilization Gate
  • Enforces customizable burn-in delays on newly released image tags, preventing zero-day regressions from deploying before community testing.
  • Distributed Edge Watchers
  • Monitors and updates remote Docker engines over secure WebSocket tunnels using lightweight Portwing agents without inbound open ports.
  • Multi-Channel Alert Dispatcher
  • Dispatches container events to seventeen notification platforms including Discord, Slack, Telegram, Pushover, and Home Assistant MQTT brokers.