Skip to content

Docklite Manual & Reference ​

Docklite is a local Docker management interface written in Go & Astro. A single native binary for Linux and Windows, direct communication with the Docker socket (docker.sock), and no external database. Actual resource use depends on the environment and load.

Standalone Binary: The entire web cockpit is embedded directly into the Go binary via go:embed. No Node.js, Nginx, or external database required.

Why Docklite? Comparison with Portainer ​

Docklite ships as a single binary with an embedded web interface and reads Docker state through a socket or named pipe. Portainer is a separate product with different deployment and storage options. Earlier RAM and startup comparisons lacked reproducible measurements, so they are not presented as performance claims.

Core Features & Architecture ​

Direct Docker Socket ​

Communicates natively via HTTP-over-Unix-Socket (/var/run/docker.sock) on Linux or Named Pipe on Windows.

In-Browser Terminal ​

Interactive shell via WebSockets directly into any running container with PTY window resize synchronization.

Docker Compose Stacks ​

Automatic grouping by Compose projects with 1-click actions for restarting, stopping, and inspecting logs.

Volume & Network Pruning ​

Quickly clean up unused volumes and orphaned networks via 1-click or REST API endpoints.

Installation & CLI Options ​

Quick start with Go ​

go install github.com/benzjeremy/docklite@latest
docklite --port 8080

CLI options ​

Usage of docklite:
  -docker-host string
        Docker socket path or URI (default: unix:///var/run/docker.sock)
  -host string
        Host address to bind to (default: "127.0.0.1")
  -open
        Automatically open the default browser upon launch
  -port int
        HTTP port for dashboard and REST API (default: 8080)
  -token string
        Optional security token for API authentication (X-Docklite-Token)
  -version
        Show version and exit

REST API & Server-Sent Events ​

MethodPathDescription
GET/api/v1/pingHealth check and Docker reachability
GET/api/v1/containersContainer list (?all=true, ?stats=true)
GET/api/v1/containers/{id}/statsLive CPU%, RAM, network receive/transmit
GET/api/v1/containers/{id}/logsDemultiplexed logs (?tail=150)
POST/api/v1/containers/{id}/restartRestart container
GET/api/v1/liveServer-Sent Events (SSE) container event stream

Security Architecture ​

The source includes the following safeguards. Docker socket access grants broad privileges; do not expose the interface to a network without additional access controls:

  • DNS rebinding protection: Requests with an invalid Host header are rejected.
  • CSRF and WebSocket origin checks: The server checks Origin for mutating requests and terminal connections.
  • Security headers: The server sends X-Content-Type-Options, X-Frame-Options, and a Content Security Policy.
  • Optional API token: --token enables X-Docklite-Token authentication for API requests.