docker
A scale-out production-ready vendor-neutral OCI-native container image/artifact registry (purely based on OCI Distribution Specification)
A CLI/TUI that simplifies launching VSCode projects, with a focus on dev containers.
ℹ️ This repo contains questions and exercises on various technical topics, sometimes related to DevOps and SRE.
Linux, Jenkins, AWS, SRE, Prometheus, Docker, Python, Ansible, Git, Kubernetes, Terraform, OpenStack, SQL, NoSQL, Azure, GCP, DNS, Elastic, Network, Virtualization. DevOps Interview Questions
Migrate from Docker to Podman.
fly-to-podman is a small bash script that helps you migrate from Docker to Podman. It will migrate your Docker containers, images, and volumes to Podman, as well as keep your container data and configurations (mounts, ports, etc.) intact.
Wireshark forDocker containers. See all incoming and outgoing requests in Docker containers with just one command.
Subtrace is Wireshark for your Docker containers. It lets developers see all incoming and outgoing requests in their backend server so that they can resolve production issues faster.
The ultimate Docker Compose files and configs to build your desired media stack, quickly and easily, with secure outbound network traffic and secure remote access using multifactor authentication.
With many people owning digital media such as CDs, DVD, and Blu-ray disks, home movies, personal photos, personal music collection, its common that people want to build home media servers in order to manage and access their digital libraries from any device within their home network, their mobile devices, and even remotely when they may be away on holidays or having a lunch break at work.
Related contents:
Nginx webserver and reverse proxy with php support and a built-in Certbot (Let's Encrypt) client. It also contains fail2ban for intrusion prevention.
Related contents:
nerdctl is a Docker-compatible CLI for containerd.
contaiNERD CTL - Docker-compatible CLI for containerd, with support for Compose, Rootless, eStargz, OCIcrypt, IPFS, ...
Related contents:
🚀 Geodesic is a DevOps Linux Toolbox in Docker.
Geodesic is a robust Linux toolbox container, crafted to optimize DevOps workflows. This container comes loaded with essential dependencies for a DevOps toolchain. It's designed to bring consistency and boost efficiency across development environments. It achieves this without the need for installing additional software on your workstation. Think of Geodesic as a containerized parallel to Vagrant, offering similar functionality within a Docker container context.
Simple backup with restic for docker-compose setups.
A service to keep container images up-to-date. Made for Kubernetes and Docker..
Cupdate is a zero-config service that helps you keep your container images up-to-date. It automatically identifies container images in use in your Kubernetes cluster or on your Docker host. Cupdate then identifies the latest available version and makes this data and more available to you via a UI, API or through an RSS feed.
Control panel to Start/Stop/View Logs for apps in Docker, Systemd, VMs or anything else (with user scripts).
TUI for journalctl, file system logs, as well Docker and Podman containers for quick viewing and filtering with fuzzy find, regex support (like fzf and grep) and coloring the output, written in Go with the gocui library.
Terminal user interface for journalctl, file system logs, as well Docker and Podman containers for quick viewing and filtering with fuzzy find, regex support (like fzf and grep) and coloring the output, written in Go with the awesome-gocui (fork gocui) library.
Scale to Zero.
An free and open-source software to start workloads on demand and stop them after a period of inactivity.
Sablier is a free and open-source software that can scale your workloads on demand. Start your containers on demand, shut them down automatically when there's no activity. Docker, Docker Swarm Mode and Kubernetes compatible.
Compose craft is a tool to help you manage, edit and share docker compose files in a GUI way.
Modmanager is a centralised tool for downloading and updating docker mods for all your other Linuxserver containers.
Related contents:
Very simple proxy with Tailscale. Fast, simple and easy for virtual services in Tailscale.
TsDProxy simplifies the process of securely exposing services and Docker containers to your Tailscale network by automatically creating Tailscale machines for each tagged container. This allows services to be accessible via unique, secure URLs without the need for complex configurations or additional Tailscale containers.
Related contents:
Simple, lightweight server monitoring.
Beszel is a lightweight server monitoring platform that includes Docker statistics, historical data, and alert functions.
It has a friendly web interface, simple configuration, and is ready to use out of the box. It supports automatic backup, multi-user, OAuth authentication, and API access.
Related contents:
- Episode 140: When Upgrades Go Wrong @ Self Hosted.
- Beszel — Lightweight self-hosted server monitoring for your homelab @ Akash Rajpurohit! 👋 .
- Monitoring a Docker Homelab with Coroot @ Writings about IT adventures and life.
- Beszel: Multiple Server Monitoring Made SIMPLE! @ DB Tech's YouTube.
- I replaced Portainer, Grafana, and Prometheus with this stack @ XDA.
- Beszel - Le monitoring de serveur simple et ultra-léger @ Korben :fr:.
A TUI tool for a live view of your docker containers running on a remote server.
Related contents:
Kubernetes for Prod, Tilt for Dev. A toolkit for fixing the pains of microservice development. Define your dev environment as code. For microservice apps on Kubernetes.
Tilt powers microservice development and makes sure they behave! Run tilt up to work in a complete dev environment configured for your team.
Tilt automates all the steps from a code change to a new process: watching files, building container images, and bringing your environment up-to-date. Think docker build && kubectl apply or docker-compose up.
Related contents:
A lightweight, self-hosted Docker tool to deploy Git-hosted sites locally. Clone, build, and deploy Hugo, Go, or Node.js sites with custom commands, branch selection, and private repo access. Detect changes and auto-redeploy — a flexible alternative to SaaS tools like Cloudflare Pages or GitHub Pages.
Lightweight universal DDNS Updater program. Container to update DNS records periodically with WebUI for many DNS providers. Program to keep DNS A and/or AAAA records updated for multiple DNS providers
A simple, easy-to-use, elegant open-source personal cloud system.
Community-based open source software focused on delivering simple personal cloud experience around Docker ecosystem.
Advent of Docker is a 24-day challenge to learn Docker, created by the Founders (Jonas and Lukas) of Sliplane.
Advent of Docker is an educational initiative designed to make learning Docker fun and accessible. Each day in December leading up to Christmas, we release a new Docker challenge or tutorial. The format is inspired by the popular “Advent of Code” concept, but focused entirely on Docker and container technology.
SOCI Snapshotter is a containerd snapshotter plugin. It enables standard OCI images to be lazily loaded without requiring a build-time conversion step. "SOCI" is short for "Seekable OCI", and is pronounced "so-CHEE".
Related contents:
A dynamic docker->redis->traefik discovery agent.
Solves the problem of running a non-Swarm/Kubernetes multi-host cluster with a single public-facing traefik instance.
traefik-kop solves this problem by using the same traefik docker-provider logic. It reads the container labels from the local docker node and publishes them to a given redis instance. Simply configure your traefik node with a redis provider and point it to the same instance, as in the diagram above.
Automated Container Management and Notifications w/ beautiful WebUI.
Simple UI driven way to manage updates & notifications for Docker containers. No external database is required, all settings are stored locally in an sqlite3 database.
the set and forget docker container manager/updater.
A lightweight bash script that automatically deploys and updates all of your docker containers run with 'docker run'. MacOS and Linux compatible. Can be scheduled with CRON to keep your docker run containers automatically up to date.
An open source server monitoring application.
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations.
Learn to build and deploy your distributed applications easily to the cloud with Docker.
Pterodactyl® is a free, open-source game server management panel built with PHP, React, and Go. Designed with security in mind, Pterodactyl runs all game servers in isolated Docker containers while exposing a beautiful and intuitive UI to end users.
Related contents:
Docker Scout is a solution for proactively enhancing your software supply chain security. By analyzing your images, Docker Scout compiles an inventory of components, also known as a Software Bill of Materials (SBOM). The SBOM is matched against a continuously updated vulnerability database to pinpoint security weaknesses.
Android in docker solution with noVNC supported and video recording
Docker-Android is a docker image built to be used for everything related to Android. It can be used for Application development and testing (native, web and hybrid-app).
Linux virtual machines, with a focus on running containers.
Lima launches Linux virtual machines with automatic file sharing and port forwarding (similar to WSL2).
Related contents:
Boot and upgrade via container images.
Transactional, in-place operating system updates using OCI/Docker container images. bootc is the key component in a broader mission of bootable containers.
The original Docker container model of using "layers" to model applications has been extremely successful. This project aims to apply the same technique for bootable host systems - using standard OCI/Docker containers as a transport and delivery format for base operating system updates.
Easy to use reverse proxy with docker integration.
A lightweight, easy-to-use, and performant reverse proxy with a Web UI and dashboard.
A curated list of Docker Compose samples.
These samples provide a starting point for how to integrate different services using a Compose file and to manage their deployment with Docker Compose.
Internal Tools Deployment Platform. Webapp Management for Internal Tools.
Platform for securely developing and deploying web tools across a team. Application server for containerized webapps. Create and share webapps for CLI applications.
Clace combines the functionality of a reverse proxy, a hypermedia based micro-framework and a container orchestrator (using Docker or Podman) in a single lightweight binary. After starting the Clace server and ensuring Docker or Podman is running, new apps can be installed in one command from GitHub source repo. Clace builds the image and starts the container lazily, on the first API call. Clace can also automatically build simple form based UI for backend APIs.
WUD (aka What's up Docker?) gets you notified when a new version of your Docker Container is available.
Gets you notified when new versions of your Docker containers are available and lets you react the way you want.
The Registry is a stateless, highly scalable server side application that stores and lets you distribute container images and other content.
This repository's main product is the Open Source Registry implementation for storing and distributing container images and other content using the OCI Distribution Specification. The goal of this project is to provide a simple, secure, and scalable base for building a large scale registry solution or running a simple private registry. It is a core library for many registry operators including Docker Hub, GitHub Container Registry, GitLab Container Registry and DigitalOcean Container Registry, as well as the CNCF Harbor Project, and VMware Harbor Registry.
Related contents:
Lightweight swiss-knife-like VPN client to multiple VPN service providers.
VPN client in a thin Docker container for multiple VPN providers, written in Go, and using OpenVPN or Wireguard, DNS over TLS, with a few proxy servers built-in.
Related contents:
- Gluetun WebUI @ GitHub.
- Episode 585 - Choosy Moms Choose Ubuntu @ Linux Unplugged.
- The Ultimate Torrent Setup - Put Any Container Behind A VPN With HTTPS @ Jim's Garage's YouTube.
- Imgur Geo-Blocked the UK, So I Geo-Unblocked My Entire Network @ Tymscar.
- Setting up WireGuard on Synology DSM 7 using Docker and Gluetun @ Nelson Figueroa.
nginx-proxy sets up a container running nginx and docker-gen. docker-gen generates reverse proxy configs for nginx and reloads nginx when containers are started and stopped.
CLI tool to automate docker image updates. Selective, notifications, autoprune, no pre-pulling.
A Terraform provider for managing Docker services.
Manage Docker-hosted resources (such as repositories, teams, organization settings, and more) using Terraform.
Code signing and transparency for containers and binaries. Signing OCI containers (and other artifacts) using Sigstore! Cosign aims to make signatures invisible infrastructure.
Related contents:
WebRTC/RTSP/RTMP/LL-HLS bridge for Wyze cams in a docker container.
Your entire server infrastructure at your fingertips. Manage all your servers from your local desktop. No remote setup required.
XPipe is a new type of shell connection hub and remote file manager that allows you to access your entire server infrastructure from your local machine. It works on top of your installed command-line programs and does not require any setup on your remote systems. So if you normally use CLI tools like ssh, docker, kubectl, etc. to connect to your servers, you can just use XPipe on top of that.
Docker is one of the most popular services to run containerized applications and it utilizes containerd and runc at a low level. This became popular because of its ease of use and intuitive experience. There are some misconfigurations that are left in the setup that can easily be exploited and few of them even let you break out of the containerized environment.
In this series, I will be explaining to you the basic concepts of the docker internals and how you can exploit certain misconfigurations to gain root user access or breakout of the containerization via both remote and local exploits. Also later in this course, you will learn how to secure your existing docker environment by following best practices from the experts.
Dagu is a powerful Cron alternative that comes with a Web UI. It allows you to define dependencies between commands as a Directed Acyclic Graph (DAG) in a declarative Writing DAGs. Additionally, Dagu natively supports running Docker containers, making HTTP requests, and executing commands over SSH. Dagu was designed to be easy to use, self-contained, and require no coding, making it ideal for small projects.
Related contents:
This script simplifies the deployment and management of Docker containers by automating tasks such as container creation, configuration, and deployment.
validate the structure of your container images.
The Container Structure Tests provide a powerful framework to validate the structure of a container image. These tests can be used to check the output of commands in an image, as well as verify metadata and contents of the filesystem.
Related contents:
Docking station is a webapp for managing and updating your docker containers. It is built using Nextjs and FastAPI.
Repack docker images to optimize for pulling speed.
This tool repacks a Docker image into a smaller, more efficient version that makes it significantly faster to pull. It does this by using a few different techniques such as removing redundant data and improving compression ratios.
Convert your Docker Compose file to Kubernetes or OpenShift.
Kompose is a conversion tool for Docker Compose to container orchestrators such as Kubernetes (or OpenShift).
Related contents:
A fully automated HTTPS server powered by Nginx, Let's Encrypt and Docker.
HTTPS-PORTAL is a fully automated HTTPS server powered by Nginx, Let's Encrypt and Docker. By using it, you can run any existing web application over HTTPS, with only one extra line of configuration.
🦎 a tool to build and deploy software on many servers 🦎
Related contents:
- Terraform Provider for Komodo @ GitHub.
- Komodo is a Free, OpenSource Docker Manager with Inbuilt CI/CD - Check It Out! @ Jim's Garage.
- How To: Automate version updates for your self-hosted Docker containers with Gitea, Renovate, and Komodo @ nickcunningh.am.
- Using Komodo to Run Docker Commands from a Web Interface @ Noted.
- FerretDB Was Eating My CPU: Migrating Komodo from SQLite to Postgres @ mauveRANT.
- Renovate + Komodo - Updating at Scale in a Large Homelab @ FoxxMD Blog.
Cloud-native high-performance edge/middle/service proxy. Envoy is an open source edge and service proxy, designed for cloud-native applications.
A Firecracker micro VM management tool. Run Docker images as micro VMs.
Self-hostable clone of lazydocker for the web. Manage your Docker fleet with ease.