Running it
Behind a reverse proxy
MangoDock serves plain HTTP on one port and expects to sit behind whatever already terminates your TLS.
There is no built-in certificate handling and nothing to configure inside MangoDock. Publish the port to the proxy rather than to the world, and point the proxy at it.
All three configurations below were tested against a running instance — the UI, the Server-Sent Event streams and the terminal's WebSocket upgrade. Caddy needed nothing beyond what is shown, Traefik nothing beyond the three labels, and nginx the two additions called out under it.
Caddy
docker.example.com {
reverse_proxy mangodock:3100
}nginx
# in the http block: $connection_upgrade does not exist on its own
map $http_upgrade $connection_upgrade { default upgrade; '' close; }
location / {
proxy_pass http://mangodock:3100;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_buffering off; # Server-Sent Events: logs, stats, events
proxy_read_timeout 3600s; # these streams are long-lived by design
}Two separate additions, for two different mechanisms. The Upgrade and Connection headers are for the container terminal, which is a WebSocket. proxy_buffering off is for logs, stats and events, which are Server-Sent Events — nginx buffers those by default, so without that line they connect and then sit silent while every ordinary page works.
Traefik
labels:
- "traefik.enable=true"
- "traefik.http.routers.mangodock.rule=Host(`docker.example.com`)"
- "traefik.http.services.mangodock.loadbalancer.server.port=3100"If Traefik answers 404 with those labels in place, check its version before anything else: 3.3 could not read a Docker Engine 29.6 socket at all, so it built no routers and every request missed. 3.7 reads the same labels and the same daemon without complaint.
Serve it over HTTPS
The session cookie is HttpOnly and SameSite=Lax but not Secure, because MangoDock cannot know whether it is behind TLS. On plain HTTP over a network, anyone in the middle can read the session. This is the same reason to put a proxy in front of it at all.
Two things to keep in mind
- Let long connections live, and do not buffer them. A proxy that cuts idle connections after a minute, or that buffers responses, makes exactly those features look broken while every ordinary page works.
- Drop the ports: mapping from the compose file once the proxy is on the same Docker network. MangoDock is then reachable only through the proxy, which is the point.
Air-gapped
- A reverse proxy works the same inside an enclave. Nothing here needs a public certificate authority — an internal CA is fine.