Docklite Manual & Reference
Docklite is a local Docker management interface written in Go & Astro. A single native binary for Linux and Windows, direct communication with the Docker socket (docker.sock), and no external database. Actual resource use depends on the environment and load.
Standalone Binary: The entire web cockpit is embedded directly into the Go binary via go:embed. No Node.js, Nginx, or external database required.
Why Docklite? Comparison with Portainer
Docklite ships as a single binary with an embedded web interface and reads Docker state through a socket or named pipe. Portainer is a separate product with different deployment and storage options. Earlier RAM and startup comparisons lacked reproducible measurements, so they are not presented as performance claims.
Core Features & Architecture
Direct Docker Socket
Communicates natively via HTTP-over-Unix-Socket (/var/run/docker.sock) on Linux or Named Pipe on Windows.
In-Browser Terminal
Interactive shell via WebSockets directly into any running container with PTY window resize synchronization.
Docker Compose Stacks
Automatic grouping by Compose projects with 1-click actions for restarting, stopping, and inspecting logs.
Volume & Network Pruning
Quickly clean up unused volumes and orphaned networks via 1-click or REST API endpoints.
Installation & CLI Options
Quick start with Go
go install github.com/benzjeremy/docklite@latest
docklite --port 8080CLI options
Usage of docklite:
-docker-host string
Docker socket path or URI (default: unix:///var/run/docker.sock)
-host string
Host address to bind to (default: "127.0.0.1")
-open
Automatically open the default browser upon launch
-port int
HTTP port for dashboard and REST API (default: 8080)
-token string
Optional security token for API authentication (X-Docklite-Token)
-version
Show version and exitREST API & Server-Sent Events
| Method | Path | Description |
|---|---|---|
GET | /api/v1/ping | Health check and Docker reachability |
GET | /api/v1/containers | Container list (?all=true, ?stats=true) |
GET | /api/v1/containers/{id}/stats | Live CPU%, RAM, network receive/transmit |
GET | /api/v1/containers/{id}/logs | Demultiplexed logs (?tail=150) |
POST | /api/v1/containers/{id}/restart | Restart container |
GET | /api/v1/live | Server-Sent Events (SSE) container event stream |
Security Architecture
The source includes the following safeguards. Docker socket access grants broad privileges; do not expose the interface to a network without additional access controls:
- DNS rebinding protection: Requests with an invalid
Hostheader are rejected. - CSRF and WebSocket origin checks: The server checks
Originfor mutating requests and terminal connections. - Security headers: The server sends
X-Content-Type-Options,X-Frame-Options, and a Content Security Policy. - Optional API token:
--tokenenablesX-Docklite-Tokenauthentication for API requests.