Sign inSign up

fennch/kontainr

By fennch

•Updated about 1 month ago

A lightweight Docker dashboard for managing containers, logs, and services.

Image
Networking
Developer tools
Monitoring & observability
0

3.4K

fennch/kontainr repository overview

Kontainr logo

Kontainr
A lightweight Docker dashboard for managing containers, logs, and services.

CI/CD Docker Pulls Docker Image Size Docker Version Release Stars Issues Last Commit License


Kontainr Dashboard


⁠Features

⁠Multi-Host Docker Management
  • Remote Docker Hosts — manage containers across multiple servers from a single Kontainr instance
  • TCP & SSH Tunnel — connect via Docker API over TCP or through SSH tunnels to remote Docker sockets
  • Host Selector — filter dashboard and container views by host, or view all hosts at once
  • Per-Host Port Links — configurable host URL for each remote server so port links resolve correctly
⁠Container Management
  • Dashboard — overview of running/stopped containers, images, volumes with live CPU/RAM stats across all hosts
  • Crash/Restart Alerts — automatic detection of crashed or restart-looping containers with webhook notifications (Discord, Slack, or generic HTTP)
  • Favorites — pin containers to the top of the dashboard for quick access
  • Start, Stop, Restart, Remove — all with confirmation dialogs and toast notifications
  • Container Creation Wizard — pull image, configure ports, volumes, env vars, restart policy, network, CPU/memory limits
  • Container Config Editor — edit env vars, ports, restart policy, network and recreate with new config
  • Container Clone — duplicate any container's config as a new container with one click
  • Container File Browser — browse, upload, download, and manage files inside running containers
  • One-Click Update — pull latest image and recreate container with the same configuration
  • Self-Update — Kontainr can update its own container via a temporary updater sidecar, with automatic page reload
  • Update Checker — scan all containers for newer registry images, with "self" badge identifying Kontainr's own container
  • Scheduled Restarts — cron-style scheduled container restarts (daily, weekly, or interval-based)
  • Docker Compose Deploy — upload or paste a docker-compose.yml and deploy stacks from the UI
  • Docker Compose Export — export any container's configuration as a docker-compose.yml with ports, volumes, env vars, networks, and resource limits
  • Docker Compose Grouping — containers grouped by project with bulk start/stop/restart
  • Git Stacks — deploy and manage Docker Compose stacks directly from Git repositories
  • Health Check Badges — healthy/unhealthy/starting indicators on containers
⁠Monitoring & Metrics
  • Historical Metrics — persistent CPU, memory, and network I/O metrics stored in SQLite with configurable retention (default 7 days)
  • Interactive Charts — historical line charts with time range selector (last hour, 24h, 7 days), aggregate stats (avg/max CPU, peak memory), and downsampled data
  • CPU/RAM Sparkline Graphs — real-time resource usage sparklines on container detail pages
  • Live Log Streaming — real-time docker logs -f with search/filter
  • Log Pattern Alerts — monitor container logs for user-defined regex or text patterns and trigger webhook alerts on match, with cooldown to prevent spam
  • Log Export — download container logs as a text file
  • Auto-Refresh — configurable 3s/5s/10s/30s polling with visual indicator
  • Clickable Port Links — port mappings link directly to the service, configurable host URL
⁠Terminals
  • Interactive Container Shell — full xterm.js TTY terminal into any running container
  • Interactive SSH Terminal — full xterm.js TTY terminal to remote servers
  • Terminal Hub — all SSH connections and running containers in one place
  • Init Commands — configurable startup commands to escape login menus (e.g. QNAP Q, Y)
⁠Resource Management
  • Images — list, pull, remove, prune dangling images
  • Image Inspector — view layers, entrypoint, env vars, exposed ports, volumes, architecture
  • Volumes — list, create, remove, prune unused volumes
  • Networks — list, create (bridge/host/overlay/macvlan), remove, prune unused networks
  • Network Topology — interactive Cytoscape.js graph showing containers connected to their networks with port mappings, color-coded edges, hover highlighting, and multiple layout options
  • Registry Browser — connect to private Docker registries, browse repositories and tags, pull images directly from the UI
  • System Info — Docker version, CPU/RAM, storage driver, kernel, full system prune
⁠App Templates
  • 175+ Pre-built Templates — one-click deploy for Nginx, PostgreSQL, Redis, Grafana, Pi-hole, Jellyfin, Ollama, Minecraft, the full *arr stack, and more
  • 22 Categories — web servers, databases, monitoring, media, dev tools, security, networking, AI, gaming, productivity, and more
  • Template Descriptions — every template includes a searchable description explaining what the app does
  • Docker Hub Links — each template links directly to its Docker Hub page
  • Configurable Deploy — change container name, ports, env vars, network, volumes, and restart policy before deploying
⁠Settings & Security
  • Required Authentication — Kontainr refuses to start without credentials; running open takes a deliberate opt-out
  • SSH Connection Manager — add, edit, test, delete connections with encrypted password storage
  • Webhook Notifications — Discord, Slack, ntfy, or generic HTTP alerts for container crashes and log pattern matches
  • Configurable Host URL — port links use your NAS hostname instead of localhost
  • Time Zone Configuration — configurable timezone for chart timestamps and all displayed times throughout the app
  • Persistent Data — settings and encryption keys survive container rebuilds via volume mount
  • Encrypted Key Ring — the Data Protection keys can themselves be encrypted at rest with a passphrase, so reading the data volume alone reveals nothing
  • Mutual TLS to Remote Hosts — remote Docker over TCP is verified against your own CA, and plaintext connections are refused unless explicitly allowed
  • Security Headers — CSP, frame-ancestors, nosniff, referrer and permissions policy on every response
  • Non-Root Container — the published image runs as UID 10001
  • Backup & Restore — export/import all settings as JSON
  • Global Search — search containers, images, volumes, and networks from any page
  • Audit Log — tracks all actions with timestamps
  • Dark/Light Theme — toggle between dark and light mode, persisted to settings
  • Mobile Responsive — fully responsive layout with collapsible sidebar, flexible grids, and touch-friendly UI for tablets and phones

⁠Quick Start

Kontainr controls the Docker socket. Anyone who can reach it can start privileged containers and open a shell inside any container — access to Kontainr is access to the host. It will not start without credentials.

docker run -d \
  --name kontainr \
  -p 8080:8080 \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -v kontainr-data:/app/data \
  -e Auth__Username=admin \
  -e Auth__Password="$(openssl rand -base64 24)" \
  -e KONTAINR_KEY_PASSPHRASE="$(openssl rand -base64 32)" \
  --group-add "$(getent group docker | cut -d: -f3)" \
  fennch/kontainr:latest

Then open http://localhost:8080. Keep a copy of KONTAINR_KEY_PASSPHRASE somewhere other than the data volume — it encrypts the stored SSH, registry and git credentials, and losing it makes them unrecoverable.

The image runs as UID 10001, so --group-add is what lets it read the Docker socket. If your host has no docker group, drop that flag and add --user root instead.

⁠Without Authentication

Only appropriate when something in front of Kontainr already authenticates requests — an authenticating reverse proxy, or an interface nothing untrusted can reach. Add:

  -e Auth__Disabled=true

Kontainr logs a warning on every start while this is set.

⁠Docker Compose
services:
  kontainr:
    image: fennch/kontainr:latest
    ports:
      - "8080:8080"
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
      - kontainr-data:/app/data
    environment:
      - Auth__Username=admin
      - Auth__Password=change-this-to-something-long
      - KONTAINR_KEY_PASSPHRASE=generate-a-long-random-value
    # Replace 999 with: getent group docker | cut -d: -f3
    group_add:
      - "999"
    restart: unless-stopped

volumes:
  kontainr-data:

⁠Configuration

⁠Environment Variables
VariableDescriptionDefault
Auth__UsernameLogin username. Required unless Auth__Disabled is set(none — startup fails)
Auth__PasswordLogin password. Required unless Auth__Disabled is set(none — startup fails)
Auth__DisabledRun with no authentication at all. Logs a warning on every startfalse
KONTAINR_KEY_PASSPHRASEEncrypts the Data Protection key ring at rest, so reading the data volume alone does not reveal stored credentials(none — key ring stored unencrypted)
KONTAINR_DATAData directory for settings & metrics/app/data
KONTAINR_KEYSKey ring directory. Point this at a separate volume to keep keys away from the data they protect$KONTAINR_DATA/keys
Security__ContentSecurityPolicyOverride the default Content-Security-Policy header(built-in policy)
⁠Persistent Data

Mount a volume to /app/data to persist:

  • SSH connection configs (passwords encrypted with ASP.NET Data Protection)
  • Docker host configurations (remote server connections)
  • Registry connections and Git stack configurations
  • Webhook configuration, scheduled restarts, and log alert rules
  • Historical metrics database (SQLite)
  • Host URL, theme, timezone, favorites, and app settings
  • Encryption keys
⁠Remote Docker Hosts

Docker's TCP socket has no authentication of its own, so Kontainr refuses to connect to a remote TCP endpoint in the clear. Serve the daemon over TLS:

dockerd --tlsverify \
  --tlscacert=/etc/docker/certs/ca.pem \
  --tlscert=/etc/docker/certs/server-cert.pem \
  --tlskey=/etc/docker/certs/server-key.pem \
  -H tcp://0.0.0.0:2376

Then in Settings > Docker Hosts, add a TCP host pointing at tcp://your-host:2376, leave Verify with TLS ticked, and give it a certificate directory containing ca.pem, cert.pem and key.pem — the same layout DOCKER_CERT_PATH uses. Mount that directory into the Kontainr container. Server certificates are checked against your ca.pem rather than the machine trust store.

If the link is already protected some other way, tick allow an unencrypted connection instead — but an open Docker TCP port is full control of that host, so be sure.

⁠SSH Connections
  1. Go to Settings in the sidebar
  2. Click Add Connection
  3. Enter host, port, username, password
  4. Optionally add Init Commands (comma-separated) for servers with login menus (e.g. Q, Y for QNAP NAS)
  5. Click Test Connection to verify, then Save
  6. Go to Terminal in the sidebar and click Connect
⁠Webhook Notifications
  1. Go to Settings > Webhook Notifications
  2. Paste a Discord webhook URL, Slack webhook URL, ntfy topic URL, or any HTTP endpoint
  3. Enable notifications and choose alert types (crash, restart loop, log pattern match)
  4. Kontainr auto-detects the URL format and sends rich embeds for Discord, formatted messages for Slack, priority-tagged messages for ntfy, or generic JSON for everything else

By default, clickable port links point to http://localhost:{port}. If Kontainr runs on a NAS or remote server, go to Settings and set the Docker Host URL to your server's hostname (e.g. fennell-nas).

⁠Development

⁠Prerequisites
⁠Run Locally
cd Kontainr
dotnet run
⁠Build Docker Image
docker build -t kontainr -f Kontainr/Dockerfile Kontainr/

⁠Tech Stack

  • Blazor Server (.NET 10) — real-time interactive UI
  • Docker.DotNet — Docker Engine API client
  • EF Core + SQLite — persistent metrics storage
  • SSH.NET — SSH client for remote terminal and Docker host tunneling
  • xterm.js — interactive terminal emulator
  • Cytoscape.js — network topology graph visualization
  • ASP.NET Data Protection — encrypted credential storage
  • Bootstrap 5 — base CSS with custom dark theme

⁠CI/CD

BranchDocker Hub TagsRelease
devfennch/kontainr:devNo
mainfennch/kontainr:latest + fennch/kontainr:X.X.XYes — Git tag + GitHub Release

⁠License

This project is licensed under the MIT License — see LICENSE⁠ for details.

Tag summary

Content type

Image

Digest

sha256:d0981b45c…

Size

119.2 MB

Last updated

about 1 month ago

docker pull fennch/kontainr