A feature-focused fork of Dockge that turns its simple Compose management experience into a broader Docker management platform — with multi-server federation, stack migration and replication, Restic backups, image and self-updates with rollback, security scanning, monitoring, automation, notifications, and Docker resource management, all from the web UI.
🇬🇧 English · 🇫🇷 Français · 🇪🇸 Español · 🇨🇳 简体中文
Using it? Liking it? ⭐ Drop a star! — takes two seconds.
| Area | Dockge Enhanced adds |
|---|---|
| Multi-server | Full-mesh federation between Dockge-Enhanced instances, management from any linked server, server grouping and selection, remote update status, transactional stack copy/migration, resumable transfers, and scheduled cold replication |
| Stack management | Pinned stacks, compact status and resource indicators, collapsible/resizable navigation, flexible Logs/Compose workspace, raw YAML copy, per-stack and per-container actions and scheduling, Build + Recreate, notes, Git tools, host start prerequisites, and automatic recreation of services sharing VPN/network namespaces |
| Backup & recovery | Multi-destination Restic backups, bind mounts and volumes, per-stack consistency, selective restore, repository checks, snapshot verification and diffs, plus recovery workflows used by protected updates |
| Updates | Image update detection, manual or automatic container updates with rollback, a shared maintenance window, remote update badges, global/per-image pause controls, and protected Dockge-Enhanced self-updates with mandatory backup, integrity checks and automatic recovery |
| Migration & replication | Transactional stack transfers between instances, Compose and persistent-data migration, resumable jobs, explicit move finalization, scheduled cold replicas, recovery snapshots and failover workflows |
| Automation & audit | Permission-scoped REST API, per-stack webhooks, Home Assistant examples, scheduled operations, and centralized history including operation origin, status and duration |
| Docker resources | Management of images, volumes, networks and unmanaged containers, bulk operations, auto-prune and safeguards around destructive actions |
| Security | Trivy vulnerability scanning, CVE exceptions, protected update workflows, 2FA, trusted-proxy authentication and Cloudflare Turnstile |
| Monitoring | System, stack and container statistics, configurable system status bar, dashboard health cards, crash-loop detection, healthcheck auto-heal, responsive/fullscreen logs, and optional Kula and managed Dozzle integrations |
| Integrations | PlugNPiN plus per-service label assistance for Nginx Proxy Manager, Pi-hole and AdGuard Home |
| Notifications & access | Discord and Apprise notifications localized in EN/FR/ES/zh-CN, multi-instance awareness, 2FA, trusted proxy support, Turnstile and third-party mobile clients |
Update schedules: when automatic Dockge-Enhanced updates use a maintenance window, the same window applies to every automatic container image update. Updates detected outside it are queued until the next allowed window. Per-image schedules remain available when no global window is configured, while Update now always remains immediate.
Show the latest changes
The most important recent changes are grouped here so you can quickly see what has changed in Dockge-Enhanced.
Reliable automatic image cleanup
Automatic cleanup no longer skips the next scheduled slot when a previous run finished a few seconds late. Tagged images referenced by any container, including stopped containers, and rollback images are preserved. Old Dockge-Enhanced images pulled by digest become eligible at the next cleanup at least 48 hours after a successful self-update; the active image and recovery images are kept. Docker errors from the most recent cleanup are shown in Docker Resources.
Federation availability alerts without overnight spam
Circuit-breaker availability notifications are now tied to a continuous outage episode: each linked instance sends at most one alert while a peer remains offline, and the alert is re-armed only after that peer successfully authenticates online again. Each remote instance can also be marked locally as Intermittent machine — do not alert when unavailable. This is intended for desktops, laptops and other peers that are routinely powered off or suspended; automatic reconnects, backoff and circuit-breaker protection remain active. Because the preference is local, mark the intermittent peer on every always-on Dockge instance from which you do not want availability alerts.
Process-wide federation transport
Federation now uses one shared outbound transport per Dockge-Enhanced process instead of one connection set per WebUI socket. Linked instances are loaded from SQLite and connected automatically when the server starts listening. Opening several WebUIs no longer multiplies remote sockets, closing the last browser no longer disconnects linked instances, and the circuit-breaker retry continues after about 5 minutes even with no WebUI open. Credential changes, mesh repair and peer removal immediately resynchronize the shared transport.
Federation reconnect-storm hardening
Federated sockets now use a lightweight authentication path and no longer execute the WebUI stack/agent bootstrap. Socket.IO reconnects are explicitly bounded with exponential backoff, jitter and a 5-minute circuit breaker. Excessive inbound federation handshakes are rejected before authentication and simultaneous inbound federation sockets are capped. If a reconnect guard trips or SQLite/Knex contention is detected, the existing Discord/Apprise configuration emits a rate-limited alert without querying SQLite.
Network namespace-safe targeted updates
Targeted image updates, service recreations and image rollbacks now resolve the complete Compose model before replacing a container. When other services share its network namespace through network_mode: service:<service> or network_mode: container:<container_name>, every direct and transitive consumer is force-recreated with the provider in one targeted Compose operation. Unrelated services are left untouched, while VPN, Gluetun and sidecar stacks no longer retain a removed container's stale network namespace.
External stacks (Beta)
Enhanced can detect existing Docker Compose projects, adopt them without moving their Compose/.env or data, and then manage them from the normal stack UI. If a source path is not yet available inside Enhanced, protected one-click authorization patches Enhanced's own Compose automatically. Adopted stacks keep their project name without a redundant external- prefix and are marked External; source-file deletion requires an additional explicit confirmation. The scanner also maps Enhanced's stacks directory to its host-side bind mount, so stacks already managed by the instance are excluded even when Docker Compose labels contain host paths.
When permanent source deletion is selected, Enhanced now removes the source bind and allowlist entry from its own Compose through the protected helper, recreates only its own container, and then deletes the host folder. This avoids EBUSY failures caused by trying to remove a directory that is still one of Enhanced's mount points.
A supported example is Gluetun-Companion: it may recreate an Enhanced-managed Gluetun stack from a bind-mounted /compose path. Enhanced now resolves this kind of Compose path alias back to the managed stack and does not offer it for external adoption.
Anonymous installation count
To get an approximate number of active Dockge-Enhanced installations without running a separate analytics service, Enhanced downloads a tiny technical asset from a dedicated GitHub release at most once per month. GitHub's public download_count for that monthly asset is the only aggregate used for the count.
No installation identifier is generated or sent for this count. The request contains no hostname, instance name, stack, container, Docker image, configuration, path, GitHub account, email, architecture or build identifier. As with any GitHub asset download, the connection itself is handled by GitHub; Dockge-Enhanced does not receive or store installation IP addresses.
The already-counted month is stored only in the local data directory so the same installation downloads the asset at most once per month. Counting is enabled by default and can be disabled with DOCKGE_USAGE_COUNT=false. Recreating or deleting the data directory can make the same installation count again for the current month, so the figure is intentionally approximate.
The mechanism is fully public: Enhanced-side code, GitHub workflow that creates the monthly assets, and aggregate monthly counters.
Repository owners can add an Actions secret named USAGE_COUNT_DISCORD_WEBHOOK to receive a provisional count every Monday and the final count for the previous month on the first day of each month. The workflow can also be run manually to send the current count immediately. The webhook value remains encrypted by GitHub and is never committed to the repository.
Global multi-instance search V2 (Ctrl+K)
The global palette now supports fuzzy matching for small typing mistakes and assisted operators such as type:, stack:, image:, port:, instance: and operational filters including is:update, is:stopped, is:vulnerable, is:critical and is:backup-failed. Operator chips are displayed directly in the palette so the syntax does not need to be memorized. Compose and .env results open the matching stack and scroll CodeMirror directly to the matching line. Recent searches and pinned searches are stored locally in the browser.
Historical configuration search in recent Restic snapshots can be enabled explicitly from the palette; it is bounded to 5 recent snapshots and 80 Compose/.env files per instance to protect remote repositories. Searching inside .env values is also an explicit opt-in: values are used only for matching, are never returned/displayed, and while this sensitive mode is active the query is never stored in recent or pinned searches. Linked instances use the V2 agent protocol when available, with a V1 fallback for simple searches on older linked instances.
Automatic self-update protection while editing Compose/.env
When a compose, override or .env file has unsaved changes in the WebUI, the owning Dockge-Enhanced instance temporarily blocks its automatic self-update — including edits opened from another linked WebUI. The editor keeps a short-lived heartbeat lease so stale browser sessions expire automatically. If an update becomes ready while unsaved work is present, the user gets a dialog to save and update, defer for 30 minutes, defer for 1 hour, or keep working. The backend re-checks blockers again before preparing and launching the updater sidecar so an edit started during backup/verification cannot be interrupted by the restart.
Linked-instance overview on the home page
The existing agent panel on the home page now doubles as a compact infrastructure overview. Each linked Dockge-Enhanced instance shows its stack totals and states, host CPU/RAM usage, uptime and pinned-stack count while keeping the existing rename, reauthentication, removal and add-agent controls. Clicking an instance summary filters the stack list on the left to that server; clicking it again restores the all-servers view.
Per-stack CPU/RAM stats across linked instances
The Show CPU / RAM statistics per stack option is now owned by each Dockge-Enhanced instance. When enabled on a server, that server collects its own Docker statistics and exposes them through the existing linked-instance channel. Every linked WebUI displaying that server shows the same CPU/RAM badges for its stacks and containers. Hiding the server hides its statistics; disabling the option on the owning instance stops collection and exposure for that instance.
Server-persisted pinned stacks across linked instances
Pinned stacks are now owned by the Dockge-Enhanced instance that hosts them instead of by one browser's localStorage. Pinning a stack on Garuda, DockerLab or LincStation stores that preference on the corresponding server. Any linked WebUI that displays that server sees the same pinned stack; hiding that server hides its pins without deleting them. Pins therefore survive logout/login, browser changes and Dockge-Enhanced updates. Existing browser-local pins are migrated automatically when their owning instances are reachable.
Dedicated self-update backup retention
Mandatory Restic snapshots created before protected Dockge-Enhanced self-updates now use a dedicated retention policy. After the new snapshot has been created and verified, Dockge-Enhanced keeps the 2 latest self-update snapshots for this installation and prunes older generations before launching the updater sidecar. A stable installation-specific tag prevents cleanup from touching another Dockge-Enhanced instance sharing the same Restic repository. Normal backup retention (keepLast, daily, weekly, monthly) is unchanged. If this dedicated pruning fails, the verified backup is kept and the update may continue; the cleanup error is logged and a later self-update will try again.
Docker Compose project-name reconciliation
Managed stacks whose directory name contains dots or uppercase characters are now reconciled with Docker Compose using the actual ConfigFiles path instead of relying only on Docker's sanitized project name. This prevents duplicate “managed/stopped” and “external/running” entries for the same stack.
Compose long port syntax support
Container cards now support both short and long Compose port syntax. Definitions using published, target, protocol, mode or host_ip no longer trigger split is not a function and no longer make the container card disappear. IPv6 host_ip values are also formatted correctly in generated links.
Compose YAML repair and formatter
The stack editor includes a Fix / format YAML action for compose.yaml. Valid documents are normalized to 2-space indentation. When YAML is invalid because of common Compose indentation mistakes, Dockge-Enhanced attempts to realign service keys and lists (services, service options, environment, ports, volumes, healthcheck.test, etc.), validates the repaired document, then formats it. Comments and leading-zero tmpfs.mode permissions are preserved. If a safe repair cannot be produced, the original content is left untouched and the error is shown.
tmpfs permission modes preserved by the Compose editor
The visual Compose editor now preserves leading-zero octal values such as tmpfs.mode: 01777 when it regenerates YAML. Editing another field no longer silently rewrites that permission value as 1777.
Stack path traversal hardening
Stack names supplied to backend operations are now validated before any path is resolved, including code paths that intentionally skip filesystem discovery. Crafted names such as ../outside can no longer escape the managed stacks directory to access another application's Compose or .env files.
Protected Dockge-Enhanced self-updates
Dockge-Enhanced can now update itself through a deliberately restricted sidecar. Every update requires a Restic backup and repository integrity check before the running container is replaced. The new version must then pass readiness checks or the previous immutable image is automatically restored.
Remote image update status
Image update information is retrieved independently from every connected Dockge-Enhanced instance, so remote stacks display their own update badges without mixing servers or identically named stacks.
Clear build identity and update progress
The Updates page now identifies installed and available builds using OCI metadata, including build date, Git commit and immutable digest. Update stages, Restic progress, elapsed time and remaining-time estimates are displayed consistently.
Remote announcements
Dockge-Enhanced can display a text-only operational announcement published from this GitHub repository, independently of the Docker image update mechanism. This safety channel was added after the self-update incident at the end of August / beginning of September 2026: if a future build has a serious issue, an affected installed version can receive a warning without waiting for that same update mechanism to work.
Announcements come from remote-announcements.json. They are optional, HTTPS-only, schema-validated, limited in size/count, can be targeted by application version, Git revision or OCI build date, and cannot execute commands, inject HTML or trigger an update. Links are restricted to the Dockge-Enhanced GitHub repository. If GitHub is unavailable or the document is invalid, Dockge-Enhanced simply shows no announcement.
Closing an announcement only hides it for the current browser session. Do not show again stores its ID in the persistent Dockge-Enhanced data directory; publishing a new announcement uses a new ID.
Linked-instance compatibility
Copy, Move and Replicate negotiate a transfer protocol independently from the build SHA. Different builds remain allowed when their protocol is compatible. When protocols are incompatible, no transfer starts. A sufficiently recent remote instance can be updated from the WebUI through the normal self-update path (Restic backup, sidecar, health check and rollback), and Dockge-Enhanced waits up to 2 hours for it to reconnect before resuming. An instance too old to answer the handshake requires a manual update. Permanent replication switches to Waiting for compatibility and retries roughly every 10 minutes without modifying data.
Persistent local instance identification
The local instance name configured in Dockge Agents is permanently visible in the desktop/mobile header and in the browser tab title (InstanceName · Dockge-Enhanced). If no name is configured, the host (IP:port or domain) is used as a fallback. No additional setting is required.
Unread release-news journal
The release-news popup now tracks each release entry individually. If several automatic updates are installed while the WebUI is not opened, all accumulated changes are shown on the next visit. Opening or reloading the page does not mark anything as read: displayed entries are acknowledged only when the user explicitly closes the popup. Tracking uses release IDs and no longer depends on their position in the list. The legacy releaseNewsSeen marker is migrated automatically without replaying the full history to existing users.
Transactional stack migration and replication
Stacks can be copied or moved between Dockge-Enhanced instances together with their Compose configuration and persistent data. Transfers are resumable, validated on the destination and protected by rollback mechanisms.
Host prerequisites and automatic recovery
A stack can require host mounts or systemd services before it starts. Dockge-Enhanced can also monitor these dependencies and safely handle their disappearance and recovery.
Responsive interface and richer monitoring
Stack navigation, the Logs/Compose workspace, resource indicators, health cards, themes and mobile display were extensively reworked.
Show all features
- Full-mesh federation between Dockge-Enhanced instances
- Administration from any linked instance
- Server selection and grouping
- Remote stack and image-update status
- Dedicated federation tokens
- Recovery of broken federation links
- Unified multi-instance management
- Linked-instance overview with reachability and direct WebUI access
- Global multi-instance search across stacks, Compose/.env files, Docker resources and recent Restic snapshots
- Version-aware capability negotiation between mixed Dockge-Enhanced releases
- Create, edit, start, stop and recreate Compose stacks
- Server-persisted pinned stacks shared across linked WebUIs
- External Compose stack discovery and adoption without moving files or data
- Protected one-click authorization for external stack paths
- Optional complete removal of adopted external stacks, including their source folder and Enhanced access mount
- Label-based permanent cleanup for broken external stacks, with a frozen resource inventory and reinforced confirmations before containers, volumes, networks, images and Compose sources are removed
- Sort by creation date or last update
- Per-stack notes
- Git tools
- Build + Recreate
- Per-service and per-container actions
- Scheduled operations
- Host mount and
systemdprerequisites - Automatic recreation of direct and transitive services sharing a VPN/network namespace through
service:orcontainer: - Collapsible and resizable stack sidebar
- Compact status, CPU and RAM indicators
- Compose editor support for long port syntax and preserved
tmpfspermission modes
- Copy or move stacks between instances
- Compose configuration transfer
- Bind mount and named-volume transfer
- Resumable jobs
- SHA-256 verification
- Transactional deployment and rollback
- Local Docker image transfer when required
- Secure private-registry credential transfer
container_nameconflict detection- Scheduled cold replication
- Recovery snapshots and workflows
- Restic backups
- Multiple backup destinations
- Stack-consistent backups
- Bind mounts and volumes
- Selective restore
- Repository integrity checks
- Snapshot testing and comparison
- Backup history
- Integration with protected update and recovery workflows
- Docker image update monitoring
- Remote update detection
- Manual and automatic image updates
- Rollback to the previous image
- Scheduled updates
- Global and per-image pause
- Protected Dockge-Enhanced self-update
- Reliable current-container discovery with custom Compose
hostname:values and a visible degraded state when update verification is unavailable - Mandatory Restic backup and integrity verification
- Readiness validation and automatic recovery
- Protection against self-update while Compose or
.envchanges are unsaved - Compose project-name reconciliation and exact stack context during updates
- Centralized stack-name validation blocks path traversal outside the managed stacks directory
- Trivy vulnerability scanning
- CVE exceptions
- 2FA
- Cloudflare Turnstile
- Trusted proxy
- Restricted self-update sidecar and signed update plan
- Destructive-operation safeguards
- Encrypted private-registry credential transfer
- System, stack and container statistics
- Configurable system status bar
- Dashboard health cards
- Crash-loop detection
- Healthcheck auto-heal
- Live and fullscreen logs, including a since last restart range and one-click copy of the latest 50 / 100 / 150 or all loaded lines
- Autoscroll pause and long-line handling
- Kula and Dozzle integrations
- Per-stack CPU/RAM statistics from local and linked instances
- Images, volumes, networks and unmanaged containers
- Bulk actions
- Auto-prune
- Risky-deletion safeguards
- Permission- and stack-scoped REST API
- Per-stack webhooks
- Home Assistant examples
- Scheduled operations
- Centralized history with origin, status and duration
- PlugNPiN
- Nginx Proxy Manager, Pi-hole and AdGuard Home label assistants
- Dozzle
- Kula
- Discord and Apprise
- Notifications localized in EN / FR / ES / zh-CN
- Remote operational announcements
- Persistent unread release-news journal
- Optional weekly and monthly anonymous installation-count reports via a GitHub Actions Discord webhook
- 2FA, trusted proxy and Cloudflare Turnstile
- Third-party mobile clients
Show the protected update workflow
Dockge-Enhanced handles the complete workflow automatically: mandatory Restic backup, integrity verification, controlled container replacement, health check and final confirmation. Discord/Apprise notifications also let users follow the operation without keeping the WebUI open.
Before an automatic self-update starts, Enhanced also checks that no sensitive operation is running: Restic backup or restore, stack copy/move/data transfer or replication, Docker image checks/updates, Trivy scans and protected external-stack integration. When an operation blocks the update, it enters a waiting state, the reason is shown in the WebUI and sent through Discord/Apprise, and the watcher retries automatically.
Show screenshots
# compose.yaml
services:
dockge:
image: ghcr.io/aerya/dockge-enhanced:latest
container_name: dockge-enhanced
restart: unless-stopped
ports:
- 5001:5001
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ../../data:/app/data
- ../../opt/stacks:/opt/stacks
- ../../backup/dockge:/backup # optional — dedicated local backup volume
- ../../docker:/dockers-data # optional — extra data to back up
environment:
- DOCKGE_STACKS_DIR=/opt/stacks
- DOCKGE_DATA_DIR=/app/data
# - DOCKER_API_VERSION=x.xx # optional — for NAS devices with older Docker API
- TZ=Europe/Paris # timezone (affects scheduled updates)docker compose up -dOpen http://localhost:5001, create your admin account, then click Monitoring in the navigation bar.
The
/backup:/backupvolume is optional but recommended if you use local as a Restic backup destination — set the destination path to/backupso your snapshots land on a dedicated host directory outside the container.
Backing up multiple data directories? Add as many volumes as you need (e.g.
../../media:/media-data), then register each container path in the Backup tab under Additional paths — Restic will include them all in every backup run.
Monitoring a disk partition other than
/? Disk stats are read from inside the container withdf. If you want to track a host path like/mnt/data, mount it read-only and add it in the Monitoring tab under Monitored disk partitions:- /mnt/data:/mnt/data:ro
Dockge and Dockge-Enhanced can run on the same Docker host, but their default Compose configurations cannot be used unchanged because both publish port 5001.
To test them side by side:
- install Dockge-Enhanced from a separate Compose directory;
- use another host port, for example
5002:5001; - use a separate
/app/datadirectory; - preferably use a separate stacks directory with a dedicated test stack.
Example:
ports:
- 5002:5001
volumes:
- ./enhanced-data:/app/data
- /opt/dockge-enhanced-test-stacks:/opt/stacks
environment:
- DOCKGE_STACKS_DIR=/opt/stacks
- DOCKGE_DATA_DIR=/app/dataYou can then open Dockge-Enhanced at http://localhost:5002 while your existing Dockge installation remains available on port 5001.
Both applications may access the same stacks directory, but they should never edit, deploy, update or otherwise operate on the same stack simultaneously. Using a separate stacks directory for testing is safer.
Migration is straightforward because Dockge-Enhanced shares the same foundation as Dockge:
-
Stop Dockge.
-
Back up your Dockge Compose file, data directory and stacks directory.
-
In your existing Dockge Compose file, replace the image with:
image: ghcr.io/aerya/dockge-enhanced:latest
-
Keep your existing
/app/dataand stacks volume mappings. -
Pull the image and restart the Compose project:
docker compose pull docker compose up -d
Dockge-Enhanced will start with your existing account, settings and stacks.
Keep the backup created before migration. If you decide to return to Dockge, stop Dockge-Enhanced and restore that backup before restarting the original Dockge image.
Show setup details
Open Settings → Integrations to configure PlugNPiN. The integration remains fully inactive until Enable PlugNPiN is selected and the form is saved. Enabling it creates the managed plugnpin-dockge-enhanced stack; disabling it runs Compose down and removes the generated stack directory.
Nginx Proxy Manager credentials are required by PlugNPiN. Pi-hole, AdGuard Home, metrics, and debug logging remain individually optional. Passwords are written through stdin into the dedicated dockge_enhanced_plugnpin_secrets Docker volume and are never returned to the browser or included in the generated Compose file.
To publish a service, edit its stack and use PlugNPiN publication (optional) below the Compose editor. The assistant generates and can apply the required plugNPiN.ip and plugNPiN.url labels plus selected NPM options. Existing mapping-form labels and comments are preserved. For list-form labels, Dockge deliberately offers copy-only output instead of rewriting the existing structure.
Disabling the controller stops its containers but cannot guarantee immediate removal of entries it created while labeled application containers are still running. Remove the labels or stop the affected applications while PlugNPiN is running if those entries must be deleted first.
PlugNPiN
1.0.0is currently published upstream foramd64only. Dockge keeps the integration disabled with a clear message on unsupported architectures; the rest of Dockge Enhanced remains multi-architecture.
| Variable | Default | Description |
|---|---|---|
DOCKGE_STACKS_DIR |
/opt/stacks |
Directory containing Docker Compose stacks |
DOCKGE_DATA_DIR |
/opt/dockge/data |
Dockge data directory (set to /app/data) |
DOCKGE_PUBLIC_URL |
(none) | Public URL used in Discord notification links (e.g. https://dockge.example.com) |
DOCKER_API_VERSION |
(none) | Fixes the Docker API version negotiated by the client — useful on certain NAS systems (e.g. Synology DSM 7.x) |
TZ |
UTC |
Container timezone — important for scheduled auto-updates to fire at the right local time (e.g. Europe/Paris) |
DOCKGE_PORT |
5001 |
Web UI port |
DOCKGE_SSL_KEY / DOCKGE_SSL_CERT |
— | Enable HTTPS |
DOCKGE_AUTH_MODE |
(unset) | Authentication mode: local, disabled, or trusted-proxy. When unset, the historical behavior and disableAuth setting are preserved |
DOCKGE_AUTH_PROXY_HEADER |
x-forwarded-user |
Header containing the proxy-validated identity in trusted-proxy mode |
DOCKGE_AUTH_PROXY_TRUSTED_NETWORKS |
(required in proxy mode) | Comma-separated addresses or CIDRs allowed to provide the identity header |
DOCKGE_BOOTSTRAP_USERNAME |
(none) | First administrator name, created only when the database contains no users |
DOCKGE_BOOTSTRAP_PASSWORD_FILE |
(none) | Secret file containing the password; recommended for automated bootstrap |
DOCKGE_BOOTSTRAP_PASSWORD |
(none) | Direct password alternative, less secure because it is visible in the container environment |
DOCKGE_TRANSFER_RSYNC_PROFILES |
[] |
JSON array of local SSH/rsync profiles (label, host, port, user, path, keyPath, optional bandwidthKbps). Configure the same destination identity on both instances; key paths never leave their instance |
⚠️ Always setDOCKGE_DATA_DIR=/app/datato match the volume mount, otherwise settings won't persist after a restart.
ℹ️
DOCKGE_PUBLIC_URLis optional. If not set, Discord notifications are sent without a link. Works with reverse proxies and HTTPS domains.
SSH/rsync profiles require the private key and a populated
known_hostsfile to be mounted read-only in every participating Dockge instance.StrictHostKeyChecking=yesis always enforced; passwords and arbitrary remote commands are not accepted from the WebUI.
Existing installations require no changes. Without the variables above, accounts, the login page, 2FA, and the Disable authentication setting work exactly as before. On the first start of a new installation, open /setup and create the administrator normally. Once initialized, the server rejects every further setup attempt even if the SPA URL remains known.
For a non-interactive bootstrap, preferably mount a secret and set only these optional variables:
services:
dockge:
environment:
- DOCKGE_BOOTSTRAP_USERNAME=admin
- DOCKGE_BOOTSTRAP_PASSWORD_FILE=/run/secrets/dockge_admin_password
secrets:
- dockge_admin_password
secrets:
dockge_admin_password:
file: ./secrets/dockge_admin_passwordBootstrap is ignored as soon as a user exists, so it never changes an existing account or password.
To delegate access to OAuth2 Proxy or Traefik ForwardAuth:
environment:
- DOCKGE_AUTH_MODE=trusted-proxy
- DOCKGE_AUTH_PROXY_HEADER=x-forwarded-user
- DOCKGE_AUTH_PROXY_TRUSTED_NETWORKS=172.20.0.0/24Replace the example CIDR with the proxy’s exact network and configure it to pass the selected header. The Dockge port must not be directly reachable: only declared proxies may provide an identity. Every user authorized by the proxy receives administrator rights because Dockge Enhanced does not currently provide separate roles. Never exempt /setup, /socket.io, or /api/* from authentication; the proxy must forward WebSockets and protect the entire host.
This fork tracks upstream Dockge releases automatically via GitHub Actions:
- Daily — checks for a new stable release
- If found — merges upstream changes and opens a PR
- On merge — rebuilds and publishes Docker images (
amd64+arm64) to GHCR - On authentication conflicts — temporarily keeps the Enhanced version in the sync branch and explicitly lists files that require comparison before merging
The in-app maintenance window configured on the Updates tab is global: when enabled for automatic Dockge-Enhanced updates, it also gates all automatic image updates. Images detected outside the allowed days and hours remain queued. Manual Update now actions are never delayed by this window.
Dockge-Enhanced is free and open-source.
There is currently no official iOS or Android app maintained by this project.
Third-party clients may exist, but they are independent from Dockge-Enhanced unless explicitly listed here.
If your app, service, article or integration uses Dockge-Enhanced features, API endpoints, screenshots, documentation or branding, please credit the project and link to this repository.
Commercial third-party clients are allowed by the license, but must not imply official affiliation without permission.
- Dockge by louislam — the original project (MIT licence)
- Trivy — vulnerability scanner
- Restic — encrypted backup tool
- Apprise — multi-platform notification gateway
- Kula by c0m4r — lightweight system monitor (AGPLv3)
- Dozzle by Amir Rajan — real-time Docker log viewer (MIT licence)
- PlugNPiN by DeepSpace2 — optional DNS and Nginx Proxy Manager automation (GPLv3)
- crossly/Dockge-Enhanced — source of significant UI/UX, theming, internationalization and frontend architecture improvements adapted into this project
MIT — see LICENSE.






























