Skip to content
v1.6.0-rc.9· Open Source

Container Update
Monitoring

Self-hosted and open source. Drydock watches every container you're running, flags what's outdated or exposed, and lets you roll out fixes on your terms.

23registries
20triggers
100%coverage
AGPL-3.0license

Batteries included

Everything you need

A full update management platform out of the box — no plugins, no paid tiers.

⌘K
Core

Auto-Discovery

Automatically discovers running containers and tracks their image versions without manual configuration.

Distributed Agents

Monitor remote Docker hosts via SSE-based agents. Centralized dashboard for all environments.

Prometheus Metrics

Built-in /metrics endpoint with Grafana dashboard template. Full observability out of the box.

Container Grouping

Smart stack detection via compose project or labels. Collapsible groups with batch actions.

Security

Audit Log

Event-based audit trail with persistent storage. Full REST API and Prometheus counters.

OIDC Authentication

Secure your instance with OpenID Connect. Works with Authelia, Auth0, and Authentik.

Integrations

23 Registries

Query Docker Hub, GHCR, ECR, GCR, GAR, GitLab, Quay, LSCR, ACR, Harbor, Artifactory, Nexus, and more.

20 Triggers

Notify via Slack, Discord, Telegram, Teams, SMTP, MQTT, HTTP, Gotify, NTFY, Kafka, and more.

Webhook API

Token-authenticated HTTP endpoints for CI/CD integration. Trigger updates on demand.

Operations

Dry-Run Preview

Preview updates before applying them. Pre-update image backup with one-click rollback.

Auto Rollback

Automatic rollback on health check failure. Configurable image backup retention policies.

Container Actions

Start, stop, and restart containers directly from the UI or API. Feature-flagged for safety.

12 of 12 capabilities
↑↓ navigateesc close

Get running

Get started in seconds

One command to try it. One compose file to run it right.

Quick start · docker run
$ docker run -d \
  --name drydock \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -p 3000:3000 \
  codeswhat/drydock

Mounts the Docker socket directly — fine for a local try, not for production.

Screenshots

See it in action!

Try the fully interactive demo below — real UI, real data*, no install required.

demo.getdrydock.com

*Not real data

On the horizon

Roadmap

Where we've been and where we're headed.

ReleasedCurrent (HEAD)Planned
roadmap
v3.1.0🔐Enterprise Access & Compliance

Role and environment-scoped permissions

Directory and identity-provider integration

+1 more

Compliance posture and hardened image options

v3.0.0🔮Advanced Platform

Infrastructure visualization

Specialized hardware monitoring

v2.4.0📦Data Safety & Templates

Scheduled backup workflows

Reusable stack templates

+1 more

Secret management

v2.3.0🔧Automation & Developer Experience

Stronger operator authentication

API key and scripting workflows

+1 more

CLI and developer tooling

v2.2.0💻Container Operations

Container shell and file workflows

Image build and publish workflows

+1 more

Day-two container maintenance tools

v2.1.0🎯Progressive Delivery

Health-gated rollouts

Canary-style deployments

+1 more

Durable self-update flows

v2.0.0🌍Platform Expansion

Additional orchestrator support

Stack deployment workflows

+1 more

Native Podman provider direction

v1.8.0⚙️Fleet Management & Live Config

Live configuration surfaces

Config file and API foundation

+1 more

Fleet-scale operations and storage path

v1.7.0🚀Smart Updates & UX

Dependency-aware update flows

Image cleanup and static-image monitoring

+1 more

Operator quality-of-life workflows

HEAD -> v1.6.0-rc.9📨Notifications, Policy & Release Intel

Notification templates and preferences

Declarative and maturity policy workflows

+1 more

Dashboard, responsive table/card views, and consistent resource-action toolbars

v1.5.2🛡️Maturity & Pinned-Tag Reliability

Recreation-safe maturity policy retention

Pinned-tag digest detection and informational insights

+1 more

Tag-policy inheritance and visibility refinements

v1.5.1🔧Security & Maintenance

Security, registry, and secret-handling fixes

Maturity gate and maintenance-window reliability

+1 more

Container detail polish and final i18n coverage

v1.5.0Observability & Localization

Live observability and notification workflows

Dashboard customization and design-system refresh

+2 more

Localized UI and edge-agent foundation

Bulk scan and update eligibility workflows

v1.4.1Patch & Polish

Headless mode

Maturity-based update policy

+1 more

Agent and login polish

v1.4.0🎨UI Stack Modernization

Modern UI shell and command palette

Compose-native YAML-preserving updates

+2 more

Compose-safe updates and stronger rollback flows

Self-update controller and dashboard customization

v1.3.0🛡️Security Integration

Trivy vulnerability scanning

Update Bouncer deployment gate

+2 more

SBOM generation

Cosign signature verification

v1.2.0Core Platform

Audit log and REST API

Image backup and rollback

+2 more

Container actions and webhooks

Lifecycle hooks, maintenance windows, and metrics

v1.1.0Observability

Application log viewer

Agent log source selector

+1 more

Container log access

v1.0.0Foundation

TypeScript app foundation

ReDoS and XSS hardening

+1 more

Vitest migration and broader coverage

(initial commit)

Community

Star History

Growing every week — join us on GitHub.

Why Drydock

How we compare

A quick look at what we support that Portainer, Diun, and others don't.

FeatureDrydockPortainerDiunWatchtowerArchived
Web UIYesYesNoNo
Update notificationsYesPartialYesYes
Multi-registry supportYesPartialPartialPartial
Vulnerability scanningYesNoNoNo
Dry-run + rollbackYesNoNoNo
Distributed agentsYesNoNoNo
Yes Partial No

Ecosystem

Part of the CodesWhat stack

Drydock is one piece of a small, focused toolkit — each tool does one job, and they compose.

FAQ

Frequently asked questions

Common questions about how Drydock works and how it fits into your stack.