↓ Skip to main content
  1. Posts/
  2. Docker UI/

Dockhand: A Web UI for Docker with Traefik Integration

··1351 words·7 mins· loading · loading · ·
Stilicho2011
Author
Stilicho2011
Writing about homelab, self-hosting, automation and open-source solutions
Table of Contents
Docker UI Panels - This article is part of a series.
Part : This Article

If you’re tired of living in the terminal, Portainer isn’t cutting it for you anymore, and you want to manage containers quickly through a browser - Dockhand might be exactly what you need.

I’ve watched a lot of Portainer replacements come and go. Most of them never quite catch up to its feature set. Real competitors are actually pretty thin on the ground:

  • Komodo - fully open source, but the developers are clearly aiming at the enterprise segment.
  • Arcane - haven’t personally tried it, so no opinion there.
  • Dockge - not really a full replacement: it’s aimed squarely at homelabbers, and the feature set is noticeably lighter compared to tools built for a professional environment.

Which brings us to today’s subject - Dockhand, a lightweight, minimalist web UI for Docker that fits nicely into any homelab and works particularly well paired with the Traefik reverse proxy.

What Dockhand can do
#

Dockhand isn’t just a Docker web UI - it’s a proper container infrastructure management tool built around convenience, automation, and security. Here’s what stood out as actually useful, not just a full feature dump.

Container management
#

The basics are all covered: start, stop, restart, remove containers, create new ones with advanced configuration, inspect processes and environment variables inside a running container. There’s a built-in web terminal - no more SSHing in for a quick check - plus browsing and transferring files right from the interface. It’s a genuine replacement for the day-to-day CLI operations, no need to keep a terminal window open at all times.

Docker Compose and stacks
#

Multi-container apps are handled well: full Compose and stack support, including stacks that were created outside the app itself (I show how in the video). There’s a visual Compose editor so you don’t have to hand-write YAML, deploying stacks straight from Git repos with automatic sync on push via webhooks, re-pulling images and forced redeploys, importing projects from other container managers, and a scheduler for updates and deployments. A solid option if you’re going the GitOps route in your homelab.

Observability
#

Live CPU and memory metrics per container, real-time streaming logs with ANSI colors, an activity log, disk usage monitoring, and notifications over email or webhooks - all without spinning up Prometheus and Grafana (I’ll cover setting up that whole stack - LGTM, Loki + Grafana + Tempo + Mimir - in a separate article, coming soon) just for a handful of containers. For a home server where a full monitoring stack would be overkill, this is exactly the right amount of visibility.

Security
#

OIDC/SSO with any provider comes free; LDAP/Active Directory integration and full RBAC are paid features. There’s also built-in vulnerability scanning via Grype/Trivy (more on that below - in practice it’s not as clean as it sounds on paper). Plugging it into an existing IAM setup is straightforward.

Multi-host management
#

Dockhand isn’t limited to a single Docker host: connect through a local socket, manage remote hosts over TCP+TLS, a dedicated Hawser agent for getting around NAT and firewalls, fast switching between environments, and a separate dashboard tile per environment. Handy if you’re running more than one server and don’t want a dozen browser tabs open.

UI customization
#

Light/dark theme, adjustable font size, column management (hide/show/reorder), resizable dashboard tiles, saved personal preferences. The interface genuinely adapts to you, rather than the usual “this is how it looks, deal with it.”

Transparency and licensing
#

The source is fully open on GitHub, with a move to Apache 2.0 planned for 2029 (right now it’s under the Business Source License - I go into the details of that in the comparison article with Arcane and Komodo). “Trust, but verify” actually works here, since the code is right there to read.

System requirements
#

ComponentRequirement
Docker Engine20.10 or newer
Docker API1.41 or newer
Memory512 MB minimum, 1 GB recommended
BrowserChrome, Firefox, Safari, Edge
DatabaseSQLite (default) or PostgreSQL 14+

Before you install
#

Warning

Dockhand uses /var/run/docker.sock, which means the container gets full access to Docker - effectively root on the system. Only run it on a trusted network, and lock access down behind a reverse proxy with authentication (Traefik + Authelia/Authentik, for example).

The docker-compose I used in the video:

services:
  dockhand:
    image: fnsys/dockhand:latest
    container_name: dockhand
    restart: unless-stopped
    #ports:
    #  - 3000:3000
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
      - /home/stilicho/docker/dockhand/data:/app/data
    networks:
      proxy:
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.dockhand.entrypoints=web"
      - "traefik.http.routers.dockhand.rule=Host(`dockhand.stilicho.ru`)"
      - "traefik.http.routers.dockhand.middlewares=dockhand-https-redirect"
      - "traefik.http.middlewares.dockhand-https-redirect.redirectscheme.scheme=https"
      - "traefik.http.routers.dockhand-secure.entrypoints=websecure"
      - "traefik.http.routers.dockhand-secure.rule=Host(`dockhand.stilicho.ru`)"
      - "traefik.http.routers.dockhand-secure.tls=true"
      - "traefik.http.routers.dockhand-secure.service=dockhand"
      - "traefik.http.services.dockhand.loadbalancer.server.port=3000"
      - "traefik.docker.network=proxy"

networks:
  proxy:
    external: true

A quick breakdown:

  • /var/run/docker.sock - the Docker API access mentioned in the warning above; without it the app can’t manage containers at all.
  • ports commented out - uncomment it and you get direct access without Traefik, which is sometimes faster for testing, but not something to leave in place long-term.
  • HTTP/HTTPS routers - the usual HTTPS-redirect-plus-TLS-termination pattern you’ll see across every Traefik-fronted service on this site.
  • loadbalancer.server.port=3000 - Traefik grabs the container’s IP on the proxy network and talks to that port directly inside the Docker network, not through localhost or published ports.

I run it on the built-in SQLite, but it works fine with Postgres too. More deployment options are on the official site.

First launch
#

After starting the container and heading to its subdomain, I was genuinely surprised there’s no initial user-registration screen. From where I stand, that’s not the safest default - it would be better to force whoever’s setting it up to create an admin account rather than leave that door open. Hopefully the developers add this at some point.

Instead you land on an empty dashboard, since no environment is connected yet.

Dashboard
#

The dashboard gives you a clear, real-time overview of all your Docker environments, built around tiles - one per environment. Tiles can be resized, moved around, and arranged to fit your own workflow, so the interface actually adapts to what you’re doing instead of the other way around.

Environment tiles
#

Each environment shows up as its own tile with a name, an icon, and a connection status - so you can tell at a glance whether it’s reachable, a small thing that adds up to a genuinely pleasant interface.

The containers block shows running, stopped, and total counts, plus health and resource usage - enough to gauge system load at a glance, which is genuinely useful.

There’s also a health-status indicator: warnings for problems, plus explicit tags for containers stuck in unhealthy or restarting. Saves you from opening every container’s logs one by one just to find what’s broken.

Update checking
#

Dockhand checks for image updates against their repositories - in my opinion, this is the killer feature, and it’s what lets me retire a separate Diun instance. You can turn on auto-updates too, but that one’s for enthusiasts only: pulling a new version automatically, without reading the changelog first, can just as easily hand you a broken container as a fixed one. Getting notified that an update exists is always useful; trusting it to update itself is your call.

Vulnerability scanning
#

There’s a built-in vulnerability scanner for containers. It sounds great on paper, but in practice it’s not that useful: built-in scanners will almost always find something (a topic for its own article), which either panics newcomers or gets the system to flag a perfectly healthy container as compromised. It’s more of a checkbox feature than a real security tool - though to be fair, Grype and Trivy underneath are legitimate scanners, you just shouldn’t take their output at face value for someone else’s Docker image without checking it yourself.

Screenshots
#

Dockhand update dialog with changelog
Adding a new environment via Unix socket
Dockhand general settings
Container list in Dockhand
Compose stack list in Dockhand

Bottom line
#

Dockhand’s dashboard gives you a full overview of every environment in one place, fast problem diagnosis, a clear picture of load and activity, and a UI you can actually make your own.

Bottom line - Dockhand is a solid Portainer replacement for a home setup, and a good pick if what you want is a balance between simplicity and functionality rather than a full enterprise platform with all the setup overhead that comes with it.

Docker UI Panels - This article is part of a series.
Part : This Article

Related