Access
Accounts and roles
Authentication is mandatory and three roles are enforced on the server, not hidden in the interface.
The first request against a fresh install is a “create the admin account” screen, not an open API. There is no environment variable that disables this.
That is a deliberate departure. Other self-hosted Docker UIs ship with authentication off until somebody opts in, and the honest reading of that default is that many installs never get around to turning it on. MangoDock can start and stop production containers and holds the SSH credentials for every host it manages.
The three roles
| Role | What it can do |
|---|---|
| admin | Everything, including users, hosts, credentials, and the authentication settings themselves. |
| operator | Day-to-day operation — start, stop, deploy, exec, pull. Not the settings that decide who may do those things. |
| viewer | Read what is there. No action that changes a container, a stack or a setting. |
Enforced on the server
The role is checked in the route handler, not by hiding a button. A viewer who crafts the request by hand gets the same refusal as a viewer who cannot find the button.
Sessions
A session is a random opaque token looked up against a database row on every request — not a signed, JWT-style token verified locally. That costs a query per request, and buys the thing worth having in an admin tool: “log out”, and “an admin disables a compromised account”, take effect on the next request instead of waiting out a token's lifetime.
The cookie lasts 30 days and slides, refreshed on every authenticated request, so somebody managing infrastructure is not re-prompted in the middle of an incident. Immediate revocation is what bounds the risk of that, rather than a short expiry.
Passwords are hashed with Argon2. The session token is 32 random bytes, travels only in an HttpOnly cookie, and is never echoed back in a response body once issued.
The cookie is not marked Secure, on purpose
Setting it would silently break every plain-HTTP deployment — a LAN tool, or one behind a reverse proxy that terminates TLS in front of it, where the browser never sees https:// on this origin. HttpOnly still blocks JavaScript from reading it, which is the theft vector that matters. If you are crossing an untrusted network, put TLS in front of it: see Behind a reverse proxy.
Air-gapped
- Local accounts need nothing outside your network. SSO and LDAP need whatever you point them at, which inside an enclave is your own directory.