MangoDock documentation
How to run it, what every screen does, and the reference tables — in that order, because somebody arriving here has not installed it yet.
- Running it covers the install, connecting hosts, sitting behind a reverse proxy, the database choice, backing MangoDock itself up, and the air-gapped path.
- The middle of the manual is one section per entry in the app's own left rail, in the order the app puts them. Each covers what the page shows and what you can do from it. Advanced then carries the subjects a screen tour only gestures at: vulnerability scanning, GitOps, deadlines and limits, Podman, how backups actually move data, and notifications.
- Access is who may sign in and as what — local accounts and the three roles, then SSO, LDAP and two-factor. Reference is the environment variables, the HTTP API and the troubleshooting list.
- Every section ends with what changes when the network is isolated. Where there is nothing to say, it says so, which is more useful than silence.
- Accounts are mandatory on every install. Three roles — admin, operator, viewer — are enforced on the server, not just hidden in the interface.
- Console and Events were called Shell and Activity until 0.1.7. Both old paths still redirect, so saved links keep working.
32 sections
Install and first run
One container, one process, nothing to configure first. If Docker is already on the machine, MangoDock is up in about thirty seconds.
Adding hosts
One control plane for many Docker hosts, with nothing installed on any of them.
Behind a reverse proxy
MangoDock serves plain HTTP on one port and expects to sit behind whatever already terminates your TLS.
SQLite and PostgreSQL
SQLite by default, Postgres if you would rather. One thing stays on disk either way.
Backing up MangoDock
Backing up the tool itself — as distinct from the Backups feature inside it, which protects what you run.
Air-gapped install
MangoDock makes no requests to the internet on its own. What an isolated network needs is a way to get the software and its data in.
Updating and uninstalling
Both are one command, and neither touches what MangoDock manages.
Dashboard
One card per Docker host, and the switch between them.
Containers
The table, and the full lifecycle behind it.
Stacks
Compose projects, their dependency graph, and deploys from git.
Logs
Container output as a page of its own.
Console
An interactive shell inside a running container.
Images
What is on each host, and what is wrong with it.
Events
What happened, and who asked for it.
Registry
Where images come from.
Volumes
Persistent storage, and what is using it.
Networks
Docker networks and what is attached to them.
Swarm
For the clusters that still run it.
Schedules
Redeploys that happen without anyone asking.
Backups
What you run, and where copies of it go.
Settings
Accounts, hosts, credentials and the rest of the configuration.
Vulnerability scanning
Trivy, Grype, or both, run against the image on the host that owns it — and offline if that is where you are.
GitOps
Deploy a Compose stack straight from a git repository, and keep the two in step.
Deadlines and limits
A stack that removes itself at a set time, and ceilings on what a stack may consume.
Podman
MangoDock manages Podman hosts too, with the differences named rather than discovered.
How backups work
A helper container on the host that owns the data pushes straight to your destination. MangoDock only ever sees the exit code.
Notifications
Being told when something unattended fails, which is the only time a message is worth sending.
Accounts and roles
Authentication is mandatory and three roles are enforced on the server, not hidden in the interface.
SSO, LDAP and two-factor
Three ways to stop maintaining a separate list of passwords, each optional and each configured by an admin.
Environment variables
Every variable the binary reads. There is no configuration file — these and the UI are the whole surface.
Troubleshooting
The errors MangoDock actually emits, and what each one is telling you.
The HTTP API
Everything the interface does, it does over this API. Scripts use the same routes with a token instead of a cookie.