A lightweight Docker dashboard for managing containers, logs, and services.
Features
Multi-Host Docker Management
Remote Docker Hosts — manage containers across multiple servers from a single Kontainr instance
TCP & SSH Tunnel — connect via Docker API over TCP or through SSH tunnels to remote Docker sockets
Host Selector — filter dashboard and container views by host, or view all hosts at once
Per-Host Port Links — configurable host URL for each remote server so port links resolve correctly
Container Management
Dashboard — overview of running/stopped containers, images, volumes with live CPU/RAM stats across all hosts
Crash/Restart Alerts — automatic detection of crashed or restart-looping containers with webhook notifications (Discord, Slack, or generic HTTP)
Favorites — pin containers to the top of the dashboard for quick access
Start, Stop, Restart, Remove — all with confirmation dialogs and toast notifications
Container Creation Wizard — pull image, configure ports, volumes, env vars, restart policy, network, CPU/memory limits
Container Config Editor — edit env vars, ports, restart policy, network and recreate with new config
Container Clone — duplicate any container's config as a new container with one click
Container File Browser — browse, upload, download, and manage files inside running containers
One-Click Update — pull latest image and recreate container with the same configuration
Self-Update — Kontainr can update its own container via a temporary updater sidecar, with automatic page reload
Update Checker — scan all containers for newer registry images, with "self" badge identifying Kontainr's own container
Scheduled Restarts — cron-style scheduled container restarts (daily, weekly, or interval-based)
Docker Compose Deploy — upload or paste a docker-compose.yml and deploy stacks from the UI
Docker Compose Export — export any container's configuration as a docker-compose.yml with ports, volumes, env vars, networks, and resource limits
Docker Compose Grouping — containers grouped by project with bulk start/stop/restart
Git Stacks — deploy and manage Docker Compose stacks directly from Git repositories
Health Check Badges — healthy/unhealthy/starting indicators on containers
Monitoring & Metrics
Historical Metrics — persistent CPU, memory, and network I/O metrics stored in SQLite with configurable retention (default 7 days)
Interactive Charts — historical line charts with time range selector (last hour, 24h, 7 days), aggregate stats (avg/max CPU, peak memory), and downsampled data
CPU/RAM Sparkline Graphs — real-time resource usage sparklines on container detail pages
Live Log Streaming — real-time docker logs -f with search/filter
Log Pattern Alerts — monitor container logs for user-defined regex or text patterns and trigger webhook alerts on match, with cooldown to prevent spam
Log Export — download container logs as a text file
Auto-Refresh — configurable 3s/5s/10s/30s polling with visual indicator
Clickable Port Links — port mappings link directly to the service, configurable host URL
Terminals
Interactive Container Shell — full xterm.js TTY terminal into any running container
Interactive SSH Terminal — full xterm.js TTY terminal to remote servers
Terminal Hub — all SSH connections and running containers in one place
Init Commands — configurable startup commands to escape login menus (e.g. QNAP Q, Y)
Resource Management
Images — list, pull, remove, prune dangling images
Image Inspector — view layers, entrypoint, env vars, exposed ports, volumes, architecture
Volumes — list, create, remove, prune unused volumes
Networks — list, create (bridge/host/overlay/macvlan), remove, prune unused networks
Network Topology — interactive Cytoscape.js graph showing containers connected to their networks with port mappings, color-coded edges, hover highlighting, and multiple layout options
Registry Browser — connect to private Docker registries, browse repositories and tags, pull images directly from the UI
System Info — Docker version, CPU/RAM, storage driver, kernel, full system prune
App Templates
175+ Pre-built Templates — one-click deploy for Nginx, PostgreSQL, Redis, Grafana, Pi-hole, Jellyfin, Ollama, Minecraft, the full *arr stack, and more
22 Categories — web servers, databases, monitoring, media, dev tools, security, networking, AI, gaming, productivity, and more
Template Descriptions — every template includes a searchable description explaining what the app does
Docker Hub Links — each template links directly to its Docker Hub page
Configurable Deploy — change container name, ports, env vars, network, volumes, and restart policy before deploying
Settings & Security
Required Authentication — Kontainr refuses to start without credentials; running open takes a deliberate opt-out
SSH Connection Manager — add, edit, test, delete connections with encrypted password storage
Webhook Notifications — Discord, Slack, ntfy, or generic HTTP alerts for container crashes and log pattern matches
Configurable Host URL — port links use your NAS hostname instead of localhost
Time Zone Configuration — configurable timezone for chart timestamps and all displayed times throughout the app
Persistent Data — settings and encryption keys survive container rebuilds via volume mount
Encrypted Key Ring — the Data Protection keys can themselves be encrypted at rest with a passphrase, so reading the data volume alone reveals nothing
Mutual TLS to Remote Hosts — remote Docker over TCP is verified against your own CA, and plaintext connections are refused unless explicitly allowed
Security Headers — CSP, frame-ancestors, nosniff, referrer and permissions policy on every response
Non-Root Container — the published image runs as UID 10001
Backup & Restore — export/import all settings as JSON
Global Search — search containers, images, volumes, and networks from any page
Audit Log — tracks all actions with timestamps
Dark/Light Theme — toggle between dark and light mode, persisted to settings
Mobile Responsive — fully responsive layout with collapsible sidebar, flexible grids, and touch-friendly UI for tablets and phones
Quick Start
Kontainr controls the Docker socket. Anyone who can reach it can start privileged
containers and open a shell inside any container — access to Kontainr is access to the
host. It will not start without credentials.
docker run -d \
--name kontainr \
-p 8080:8080 \
-v /var/run/docker.sock:/var/run/docker.sock \
-v kontainr-data:/app/data \
-e Auth__Username=admin \
-e Auth__Password="$(openssl rand -base64 24)" \
-e KONTAINR_KEY_PASSPHRASE="$(openssl rand -base64 32)" \
--group-add "$(getent group docker | cut -d: -f3)" \
fennch/kontainr:latest
Copy
Then open http://localhost:8080. Keep a copy of KONTAINR_KEY_PASSPHRASE somewhere other
than the data volume — it encrypts the stored SSH, registry and git credentials, and losing
it makes them unrecoverable.
The image runs as UID 10001, so --group-add is what lets it read the Docker socket. If your
host has no docker group, drop that flag and add --user root instead.
Without Authentication
Only appropriate when something in front of Kontainr already authenticates requests — an
authenticating reverse proxy, or an interface nothing untrusted can reach. Add:
-e Auth__Disabled=true
Copy
Kontainr logs a warning on every start while this is set.
Docker Compose
services:
kontainr:
image: fennch/kontainr:latest
ports:
- "8080:8080"
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- kontainr-data:/app/data
environment:
- Auth__Username=admin
- Auth__Password=change-this-to-something-long
- KONTAINR_KEY_PASSPHRASE=generate-a-long-random-value
# Replace 999 with: getent group docker | cut -d: -f3
group_add:
- "999"
restart: unless-stopped
volumes:
kontainr-data:
Copy
Configuration
Environment Variables
Variable Description Default Auth__UsernameLogin username. Required unless Auth__Disabled is set (none — startup fails) Auth__PasswordLogin password. Required unless Auth__Disabled is set (none — startup fails) Auth__DisabledRun with no authentication at all. Logs a warning on every start falseKONTAINR_KEY_PASSPHRASEEncrypts the Data Protection key ring at rest, so reading the data volume alone does not reveal stored credentials (none — key ring stored unencrypted) KONTAINR_DATAData directory for settings & metrics /app/dataKONTAINR_KEYSKey ring directory. Point this at a separate volume to keep keys away from the data they protect $KONTAINR_DATA/keysSecurity__ContentSecurityPolicyOverride the default Content-Security-Policy header (built-in policy)
Persistent Data
Mount a volume to /app/data to persist:
SSH connection configs (passwords encrypted with ASP.NET Data Protection)
Docker host configurations (remote server connections)
Registry connections and Git stack configurations
Webhook configuration, scheduled restarts, and log alert rules
Historical metrics database (SQLite)
Host URL, theme, timezone, favorites, and app settings
Encryption keys
Remote Docker Hosts
Docker's TCP socket has no authentication of its own, so Kontainr refuses to connect to a
remote TCP endpoint in the clear. Serve the daemon over TLS:
dockerd --tlsverify \
--tlscacert=/etc/docker/certs/ca.pem \
--tlscert=/etc/docker/certs/server-cert.pem \
--tlskey=/etc/docker/certs/server-key.pem \
-H tcp://0.0.0.0:2376
Copy
Then in Settings > Docker Hosts , add a TCP host pointing at tcp://your-host:2376,
leave Verify with TLS ticked, and give it a certificate directory containing ca.pem,
cert.pem and key.pem — the same layout DOCKER_CERT_PATH uses. Mount that directory into
the Kontainr container. Server certificates are checked against your ca.pem rather than the
machine trust store.
If the link is already protected some other way, tick allow an unencrypted connection
instead — but an open Docker TCP port is full control of that host, so be sure.
SSH Connections
Go to Settings in the sidebar
Click Add Connection
Enter host, port, username, password
Optionally add Init Commands (comma-separated) for servers with login menus (e.g. Q, Y for QNAP NAS)
Click Test Connection to verify, then Save
Go to Terminal in the sidebar and click Connect
Webhook Notifications
Go to Settings > Webhook Notifications
Paste a Discord webhook URL, Slack webhook URL, ntfy topic URL, or any HTTP endpoint
Enable notifications and choose alert types (crash, restart loop, log pattern match)
Kontainr auto-detects the URL format and sends rich embeds for Discord, formatted messages for Slack, priority-tagged messages for ntfy, or generic JSON for everything else
Port Link Host URL
By default, clickable port links point to http://localhost:{port}. If Kontainr runs on a NAS or remote server, go to Settings and set the Docker Host URL to your server's hostname (e.g. fennell-nas).
Development
Prerequisites
Run Locally
cd Kontainr
dotnet run
Copy
Build Docker Image
docker build -t kontainr -f Kontainr/Dockerfile Kontainr/
Copy
Tech Stack
Blazor Server (.NET 10) — real-time interactive UI
Docker.DotNet — Docker Engine API client
EF Core + SQLite — persistent metrics storage
SSH.NET — SSH client for remote terminal and Docker host tunneling
xterm.js — interactive terminal emulator
Cytoscape.js — network topology graph visualization
ASP.NET Data Protection — encrypted credential storage
Bootstrap 5 — base CSS with custom dark theme
CI/CD
Branch Docker Hub Tags Release devfennch/kontainr:devNo mainfennch/kontainr:latest + fennch/kontainr:X.X.XYes — Git tag + GitHub Release
License
This project is licensed under the MIT License — see LICENSE for details.