Container Update
Monitoring
Self-hosted and open source. Drydock watches every container you're running, flags what's outdated or exposed, and lets you roll out fixes on your terms.

Batteries included
Everything you need
A full update management platform out of the box — no plugins, no paid tiers.
Auto-Discovery
Automatically discovers running containers and tracks their image versions without manual configuration.
Distributed Agents
Monitor remote Docker hosts via SSE-based agents. Centralized dashboard for all environments.
Prometheus Metrics
Built-in /metrics endpoint with Grafana dashboard template. Full observability out of the box.
Container Grouping
Smart stack detection via compose project or labels. Collapsible groups with batch actions.
Audit Log
Event-based audit trail with persistent storage. Full REST API and Prometheus counters.
OIDC Authentication
Secure your instance with OpenID Connect. Works with Authelia, Auth0, and Authentik.
23 Registries
Query Docker Hub, GHCR, ECR, GCR, GAR, GitLab, Quay, LSCR, ACR, Harbor, Artifactory, Nexus, and more.
20 Triggers
Notify via Slack, Discord, Telegram, Teams, SMTP, MQTT, HTTP, Gotify, NTFY, Kafka, and more.
Webhook API
Token-authenticated HTTP endpoints for CI/CD integration. Trigger updates on demand.
Dry-Run Preview
Preview updates before applying them. Pre-update image backup with one-click rollback.
Auto Rollback
Automatic rollback on health check failure. Configurable image backup retention policies.
Container Actions
Start, stop, and restart containers directly from the UI or API. Feature-flagged for safety.
Get running
Get started in seconds
One command to try it. One compose file to run it right.
$ docker run -d \
--name drydock \
-v /var/run/docker.sock:/var/run/docker.sock \
-p 3000:3000 \
codeswhat/drydockMounts the Docker socket directly — fine for a local try, not for production.
Screenshots
See it in action!
Try the fully interactive demo below — real UI, real data*, no install required.
*Not real data
On the horizon
Roadmap
Where we've been and where we're headed.
│Role and environment-scoped permissions
│Directory and identity-provider integration
│+1 moreshow less
│Compliance posture and hardened image options
│Infrastructure visualization
│Specialized hardware monitoring
│Scheduled backup workflows
│Reusable stack templates
│+1 moreshow less
│Secret management
│Stronger operator authentication
│API key and scripting workflows
│+1 moreshow less
│CLI and developer tooling
│Container shell and file workflows
│Image build and publish workflows
│+1 moreshow less
│Day-two container maintenance tools
│Health-gated rollouts
│Canary-style deployments
│+1 moreshow less
│Durable self-update flows
│Additional orchestrator support
│Stack deployment workflows
│+1 moreshow less
│Native Podman provider direction
│Live configuration surfaces
│Config file and API foundation
│+1 moreshow less
│Fleet-scale operations and storage path
│Dependency-aware update flows
│Image cleanup and static-image monitoring
│+1 moreshow less
│Operator quality-of-life workflows
│Notification templates and preferences
│Declarative and maturity policy workflows
│+1 moreshow less
│Dashboard, responsive table/card views, and consistent resource-action toolbars
│Recreation-safe maturity policy retention
│Pinned-tag digest detection and informational insights
│+1 moreshow less
│Tag-policy inheritance and visibility refinements
│Security, registry, and secret-handling fixes
│Maturity gate and maintenance-window reliability
│+1 moreshow less
│Container detail polish and final i18n coverage
│Live observability and notification workflows
│Dashboard customization and design-system refresh
│+2 moreshow less
│Localized UI and edge-agent foundation
│Bulk scan and update eligibility workflows
│Headless mode
│Maturity-based update policy
│+1 moreshow less
│Agent and login polish
│Modern UI shell and command palette
│Compose-native YAML-preserving updates
│+2 moreshow less
│Compose-safe updates and stronger rollback flows
│Self-update controller and dashboard customization
│Trivy vulnerability scanning
│Update Bouncer deployment gate
│+2 moreshow less
│SBOM generation
│Cosign signature verification
│Audit log and REST API
│Image backup and rollback
│+2 moreshow less
│Container actions and webhooks
│Lifecycle hooks, maintenance windows, and metrics
│Application log viewer
│Agent log source selector
│+1 moreshow less
│Container log access
│TypeScript app foundation
│ReDoS and XSS hardening
│+1 moreshow less
│Vitest migration and broader coverage
Why Drydock
How we compare
A quick look at what we support that Portainer, Diun, and others don't.
| Feature | Drydock | Portainer | Diun | WatchtowerArchived |
|---|---|---|---|---|
| Web UI | Yes | Yes | No | No |
| Update notifications | Yes | Partial | Yes | Yes |
| Multi-registry support | Yes | Partial | Partial | Partial |
| Vulnerability scanning | Yes | No | No | No |
| Dry-run + rollback | Yes | No | No | No |
| Distributed agents | Yes | No | No | No |
Ecosystem
Part of the CodesWhat stack
Drydock is one piece of a small, focused toolkit — each tool does one job, and they compose.

Container update monitoring

Scoped Docker socket proxy

Secure remote Docker agent
FAQ
Frequently asked questions
Common questions about how Drydock works and how it fits into your stack.

