<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Vasili Pascal</title>
    <description>The latest articles on DEV Community by Vasili Pascal (@vasilipascal).</description>
    <link>https://dev.to/vasilipascal</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4071259%2F0d6c8bb5-6e37-45b4-b22d-3ce4352e2395.jpg</url>
      <title>DEV Community: Vasili Pascal</title>
      <link>https://dev.to/vasilipascal</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/vasilipascal"/>
    <language>en</language>
    <item>
      <title>Docker Web UI Security in 2026: Who Actually Publishes a Threat Model</title>
      <dc:creator>Vasili Pascal</dc:creator>
      <pubDate>Tue, 25 Aug 2026 15:52:27 +0000</pubDate>
      <link>https://dev.to/vasilipascal/docker-web-ui-security-in-2026-who-actually-publishes-a-threat-model-2h07</link>
      <guid>https://dev.to/vasilipascal/docker-web-ui-security-in-2026-who-actually-publishes-a-threat-model-2h07</guid>
      <description>&lt;p&gt;Recently I posted a comparison of 10 Docker web UIs on r/selfhosted. A commenter asked a question I hadn't answered in the original article:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;If I were selecting a Docker web UI, I think my first and highest concern would be security. If you're running rootful Docker, compromising the Docker web UI means achieving root access to the host.&lt;/p&gt;

&lt;p&gt;Do any of these options support rootless Docker?&lt;/p&gt;

&lt;p&gt;Do they publish any information about their security architecture and how they approach minimizing their attack surface?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Fair question. I went through the docs of all 10 tools and built a matrix. This is that writeup.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;TL;DR:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Only &lt;strong&gt;Portainer&lt;/strong&gt; explicitly documents rootless Docker support (with caveats)&lt;/li&gt;
&lt;li&gt;Only &lt;strong&gt;Rancher&lt;/strong&gt; and &lt;strong&gt;Portainer&lt;/strong&gt; publish comprehensive security architecture&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Dockhand&lt;/strong&gt; and &lt;strong&gt;Arcane&lt;/strong&gt; publish serious security-adjacent artifacts (hardened image / SBOM / disclosure policy)&lt;/li&gt;
&lt;li&gt;Almost everyone else is silent on the topic&lt;/li&gt;
&lt;li&gt;"Connect via TCP" is not a rootless workaround - it's a common misconception worth clearing up&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  First: a technical point nobody in my Reddit thread got right
&lt;/h2&gt;

&lt;p&gt;Several commenters (including me, initially) reached for "you can expose Docker via TCP so it doesn't need root." That's wrong, and Docker's own documentation is explicit about it.&lt;/p&gt;

&lt;p&gt;Docker's &lt;a href="https://docs.docker.com/engine/daemon/remote-access/" rel="noopener noreferrer"&gt;remote-access docs&lt;/a&gt; state:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;If steps aren't taken to secure the connection, it's possible for remote non-root users to gain root access on the host.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Translation: &lt;strong&gt;the transport (Unix socket vs TCP) is orthogonal to whether the daemon runs as root&lt;/strong&gt;. Exposing the API over TCP just changes how you connect - the daemon behind the socket is still rootful unless you specifically configured &lt;a href="https://docs.docker.com/engine/security/rootless/" rel="noopener noreferrer"&gt;rootless mode&lt;/a&gt;. TLS on the TCP connection protects against network sniffing, not against "compromise the client = root on host."&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Setup&lt;/th&gt;
&lt;th&gt;Root on host if UI compromised?&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Rootful daemon + Unix socket&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Rootful daemon + TCP + TLS&lt;/td&gt;
&lt;td&gt;Yes (TLS doesn't help here)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Rootless daemon + Unix socket&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Rootless daemon + TCP + TLS&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Rootless mode is a separate daemon configuration - different install script (&lt;code&gt;dockerd-rootless-setuptool.sh&lt;/code&gt;), user-namespace based, with real functional limitations (some storage drivers, cgroups behavior, networking). It's the only meaningful mitigation for the "UI compromise = host root" risk.&lt;/p&gt;

&lt;p&gt;That's the frame. Now the matrix.&lt;/p&gt;




&lt;h2&gt;
  
  
  The matrix
&lt;/h2&gt;

&lt;p&gt;Fetched from each tool's official documentation. Where I couldn't find explicit documentation, I marked "not documented" rather than guessing.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;Rootless Docker&lt;/th&gt;
&lt;th&gt;Auth&lt;/th&gt;
&lt;th&gt;Security docs&lt;/th&gt;
&lt;th&gt;CVE process&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Portainer&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Partial - docs say "some limitations, requires additional configuration"&lt;/td&gt;
&lt;td&gt;LDAP (CE), OIDC (BE)&lt;/td&gt;
&lt;td&gt;Yes - &lt;a href="mailto:security@portainer.io"&gt;security@portainer.io&lt;/a&gt; + GitHub advisories&lt;/td&gt;
&lt;td&gt;Mature: regular CVE remediation in changelog&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Dockge&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Not documented&lt;/td&gt;
&lt;td&gt;Basic (README shows no auth details)&lt;/td&gt;
&lt;td&gt;SECURITY.md file exists in repo&lt;/td&gt;
&lt;td&gt;Not disclosed publicly&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Dockhand&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Partial - v1.0.23 changelog: "Fix vulnerability scanning failing with rootless Docker"&lt;/td&gt;
&lt;td&gt;OIDC/SSO (Free), LDAP/AD (Enterprise), TOTP MFA, API tokens&lt;/td&gt;
&lt;td&gt;Hardened container (Wolfi from scratch), AES-256-GCM at rest, Trivy/Grype safe-pull&lt;/td&gt;
&lt;td&gt;No explicit CVE page found&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Arcane&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Not documented in visible docs&lt;/td&gt;
&lt;td&gt;OIDC (docs page exists at /docs/authentication/oidc)&lt;/td&gt;
&lt;td&gt;SECURITY.md + AI_POLICY.md + published SBOM at getarcane.app/sbom&lt;/td&gt;
&lt;td&gt;Disclosure to &lt;a href="mailto:info@getarcane.app"&gt;info@getarcane.app&lt;/a&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Dokploy&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Not documented&lt;/td&gt;
&lt;td&gt;2FA + SSO (per docs nav)&lt;/td&gt;
&lt;td&gt;"Security" nav section exists&lt;/td&gt;
&lt;td&gt;Not visible&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Coolify&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Not documented&lt;/td&gt;
&lt;td&gt;SSH key-based; separate "non-root user" guide referenced&lt;/td&gt;
&lt;td&gt;SSH hardening advice only&lt;/td&gt;
&lt;td&gt;Not visible&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Komodo&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Not documented&lt;/td&gt;
&lt;td&gt;OAuth/OIDC providers per nav&lt;/td&gt;
&lt;td&gt;Not found&lt;/td&gt;
&lt;td&gt;Not visible&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Runtipi&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;No - install script requires sudo, manages Docker itself&lt;/td&gt;
&lt;td&gt;Local + optional OAuth&lt;/td&gt;
&lt;td&gt;No prominent SECURITY.md&lt;/td&gt;
&lt;td&gt;Not visible&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Rancher&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;N/A - Kubernetes-focused; supports rootless K3s&lt;/td&gt;
&lt;td&gt;OIDC, SAML, LDAP, AD, GitHub, Google, Keycloak, generic OIDC&lt;/td&gt;
&lt;td&gt;Extensive: CIS Benchmark, kube-bench, SELinux, Pod Security Standards, Cure53 pentest reports&lt;/td&gt;
&lt;td&gt;
&lt;a href="mailto:security-rancher@suse.com"&gt;security-rancher@suse.com&lt;/a&gt; + public CVE list&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;strong&gt;Stacker&lt;/strong&gt; (my project)&lt;/td&gt;
&lt;td&gt;Not documented; CLI itself doesn't need root on the runner&lt;/td&gt;
&lt;td&gt;Casbin RBAC + OIDC (managed tier); OSS CLI uses SSH keys&lt;/td&gt;
&lt;td&gt;Just added &lt;a href="https://github.com/trydirect/stacker/blob/main/SECURITY.md" rel="noopener noreferrer"&gt;SECURITY.md&lt;/a&gt;; extensive &lt;code&gt;tests/security_*.rs&lt;/code&gt; suite&lt;/td&gt;
&lt;td&gt;Coordinated disclosure via &lt;a href="mailto:security@try.direct"&gt;security@try.direct&lt;/a&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  What jumps out
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Rancher is in a different league
&lt;/h3&gt;

&lt;p&gt;Rancher publishes CIS Benchmark alignment, integrates kube-bench for automated compliance scanning, ships SELinux packages, supports Pod Security Standards, and has public pentest reports from Cure53. That's a mature enterprise-grade security posture. If you're running Kubernetes at any real scale and security is your primary lens, this is the only serious answer in the list.&lt;/p&gt;

&lt;h3&gt;
  
  
  Portainer is the mature Docker-native option
&lt;/h3&gt;

&lt;p&gt;Every recent release note includes explicit CVE remediation entries (upgrading containerd, oras-go, grpc, go-git, etc. to address specific CVEs). They publish a security email, run GitHub Security Advisories, and their rootless docs at least exist even if they say "some limitations." That's more than 7 of the other 9 tools can claim.&lt;/p&gt;

&lt;h3&gt;
  
  
  Dockhand and Arcane are punching above their weight
&lt;/h3&gt;

&lt;p&gt;Both are much smaller projects than Portainer or Rancher but ship real security artifacts:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Dockhand&lt;/strong&gt;: hardened container image built from Wolfi packages (rather than Alpine), AES-256-GCM at rest, Grype+Trivy scanning with "safe-pull protection" (new images scanned before deployment)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Arcane&lt;/strong&gt;: published SBOM, formal SECURITY.md disclosure process, an explicit AI_POLICY.md for security reports (they've clearly been hit by AI CVE farming - refreshingly honest about it)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Neither has full architecture documentation, but they've done the meaningful work.&lt;/p&gt;

&lt;h3&gt;
  
  
  Almost nobody explicitly documents rootless
&lt;/h3&gt;

&lt;p&gt;This surprised me. Rootless Docker has been GA for years. It has real limitations (some storage drivers, cgroup v2 requirements, no &lt;code&gt;--privileged&lt;/code&gt;, no host network mode) - but the fact that even security-focused UIs don't clearly say "we support it" or "we don't" is a gap the category as a whole should fix.&lt;/p&gt;

&lt;h3&gt;
  
  
  "Connect via TCP" is not a mitigation
&lt;/h3&gt;

&lt;p&gt;I already covered this above, but it bears repeating because I've seen it as commentary in multiple threads: exposing the Docker API over TCP does &lt;strong&gt;not&lt;/strong&gt; reduce root privilege risk. Rootless mode is the only real answer here.&lt;/p&gt;




&lt;h2&gt;
  
  
  What "rootless" actually costs you
&lt;/h2&gt;

&lt;p&gt;Rootless Docker isn't free. If you're evaluating it, the trade-offs are:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Storage drivers&lt;/strong&gt;: &lt;code&gt;overlay2&lt;/code&gt; requires kernel ≥ 5.11 with fuse-overlayfs fallback. Some setups end up on the slower &lt;code&gt;vfs&lt;/code&gt; driver.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Networking&lt;/strong&gt;: no host network mode. Port publishing &amp;lt; 1024 requires additional capability setup. Some overlay networks behave differently.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;--privileged&lt;/code&gt; containers&lt;/strong&gt;: don't work.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;cgroup v2 required&lt;/strong&gt; for full functionality (fine on modern distros, painful on older ones).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Some Docker features unavailable&lt;/strong&gt;: no &lt;code&gt;docker run --sysctl&lt;/code&gt;, limited access to certain namespaces.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For most self-hosted workloads (web apps, databases, background workers), these limitations are fine. For workloads that need privileged containers, host networking, or specialised kernel features, rootless will be too restrictive.&lt;/p&gt;

&lt;p&gt;Docker's &lt;a href="https://docs.docker.com/engine/security/rootless/" rel="noopener noreferrer"&gt;rootless docs&lt;/a&gt; list the current known limitations - worth reading before committing.&lt;/p&gt;




&lt;h2&gt;
  
  
  Recommendations by risk profile
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;"I run 5 self-hosted apps at home and my threat model is 'don't get pwned by a drive-by'"&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Portainer or Dockge are both fine. Put them behind a reverse proxy with auth, don't expose them to the internet, and you're covered against 95% of what actually gets you in a home setup.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;"I run this at a small company and someone will eventually run an audit"&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Portainer CE at minimum, Portainer BE if you can afford it. The published CVE remediation trail is what an auditor will actually check. Enable rootless mode if your workloads support it.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;"I'm hosting client workloads and my liability is real"&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Rancher if you're on Kubernetes. If you're on plain Docker, no tool in this category really meets a "clients pay us to protect their data" bar - you'll be layering on your own controls (Falco, Sysdig, network policies) regardless.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;"I care about supply chain and provenance"&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Dockhand (Wolfi-from-scratch image) or Arcane (published SBOM) are the standouts. Both are much less established than Portainer, so you're trading feature depth for a better security artifact.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;"I want infrastructure-as-code and no web UI at all"&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;This is where &lt;a href="https://github.com/trydirect/stacker" rel="noopener noreferrer"&gt;Stacker&lt;/a&gt; (my project) fits - config-file-first, one YAML per stack, no dashboard by default. But the "no dashboard" position is a security posture choice, not a rootless-Docker feature. Stacker itself doesn't currently document rootless mode either - fixing that is on my list.&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  What I updated after doing this research
&lt;/h2&gt;

&lt;p&gt;Two things worth mentioning honestly:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. Added a SECURITY.md to the Stacker repo.&lt;/strong&gt; I was calling out other tools for not publishing one - felt fair to close my own gap first. It's at &lt;a href="https://github.com/trydirect/stacker/blob/main/SECURITY.md" rel="noopener noreferrer"&gt;github.com/trydirect/stacker/blob/main/SECURITY.md&lt;/a&gt; - includes disclosure contact, response SLA, in/out-of-scope definitions, and coordinated disclosure timing.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. Rootless documentation is a real gap for the entire category.&lt;/strong&gt; I'm going to actually test Stacker + rootless Docker on the target server, document the result, and publish either "supported" or "here's what breaks and why" - because right now I don't know for certain and neither do most of the tools in this list.&lt;/p&gt;




&lt;h2&gt;
  
  
  What I'd like to hear from readers
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Anyone running any of these tools successfully against a rootless daemon? What broke, what worked?&lt;/li&gt;
&lt;li&gt;If you use Portainer BE at work, does the "rootless with some limitations" story hold up in practice?&lt;/li&gt;
&lt;li&gt;Anyone at Coolify / Dokploy / Komodo / Runtipi able to say officially where their teams stand on rootless support?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Drop it in the comments. I'll update this article as answers come in.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was assisted by an AI in drafting and structuring; every technical claim above was verified against a source I fetched from the tool's official documentation, GitHub repository, or docs.docker.com. Links are all verified working as of publication. If something's wrong, tell me and I'll correct it.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>docker</category>
      <category>devops</category>
      <category>security</category>
      <category>selfhosted</category>
    </item>
    <item>
      <title>Docker Web UIs Compared in 2026: Portainer is No Longer the Only Answer</title>
      <dc:creator>Vasili Pascal</dc:creator>
      <pubDate>Mon, 10 Aug 2026 16:57:56 +0000</pubDate>
      <link>https://dev.to/vasilipascal/8-docker-web-uis-compared-in-2026-portainer-is-no-longer-the-only-answer-3a2m</link>
      <guid>https://dev.to/vasilipascal/8-docker-web-uis-compared-in-2026-portainer-is-no-longer-the-only-answer-3a2m</guid>
      <description>&lt;p&gt;For years the answer to "what web UI should I use for Docker?" was &lt;strong&gt;Portainer&lt;/strong&gt;, full stop. In 2026 that answer is more nuanced. A new generation of tools has emerged - full self-hosted PaaS platforms (Dokploy, Coolify), cluster-aware orchestrators (Komodo), minimalist compose viewers (Dockge), homelab app stores (Runtipi) - and the right pick genuinely depends on what you're doing.&lt;/p&gt;

&lt;p&gt;I run an OSS deployment tool (&lt;a href="https://github.com/trydirect/stacker" rel="noopener noreferrer"&gt;Stacker&lt;/a&gt;, MIT-licensed) so I spend a lot of time thinking about this space. Here's an honest 2026 comparison of the eight tools I'd actually recommend, with a job-to-be-done matrix at the end so you don't have to read all eight sections.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;TL;DR&lt;/strong&gt; - jump to How to choose.&lt;/p&gt;




&lt;h2&gt;
  
  
  1. Portainer - the default single-server dashboard
&lt;/h2&gt;

&lt;p&gt;Still the most-installed Docker UI in the world. For a single server, hard to beat. Manages containers, images, networks, volumes, and Compose stacks. Works with Docker and Docker Swarm. Free CE is enough for most teams; Business Edition adds multi-cluster + RBAC.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best if:&lt;/strong&gt; you have one server and want a general-purpose dashboard to inspect, restart, and update containers.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Skip if:&lt;/strong&gt; you want a full deploy pipeline (git → build → SSL → live). Portainer stops at compose deployment.&lt;/p&gt;

&lt;p&gt;🔗 &lt;a href="https://www.portainer.io/" rel="noopener noreferrer"&gt;portainer.io&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  2. Dokploy - self-hosted Vercel-style deploy platform
&lt;/h2&gt;

&lt;p&gt;One of the fastest-growing entries in this space. Not just a container UI - a full &lt;strong&gt;deployment platform&lt;/strong&gt;. Push to GitHub, Dokploy pulls, builds, deploys, and issues an SSL cert. Managed databases (Postgres, MySQL, Redis, MongoDB) are first-class objects rather than raw containers. Traefik-based reverse proxy configured for you.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best if:&lt;/strong&gt; you want the Heroku or Vercel workflow - git-push, auto-deploy, SSL - on your own server.&lt;/p&gt;

&lt;p&gt;🔗 &lt;a href="https://dokploy.com/" rel="noopener noreferrer"&gt;dokploy.com&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  3. Coolify - the popular open-source alternative to Heroku
&lt;/h2&gt;

&lt;p&gt;Same "self-hosted PaaS" niche as Dokploy, more mature and more widely deployed. Multi-server support out of the box. Handles docker-compose applications, static sites, plain Docker services, and one-click databases. Very active development, large Discord community for troubleshooting.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best if:&lt;/strong&gt; you like Dokploy's approach but need multi-server or a larger community.&lt;/p&gt;

&lt;p&gt;🔗 &lt;a href="https://coolify.io/" rel="noopener noreferrer"&gt;coolify.io&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  4. Komodo - cluster-aware Rust-based orchestrator
&lt;/h2&gt;

&lt;p&gt;Previously "Monitor". Written in Rust, built around &lt;strong&gt;fleets of servers&lt;/strong&gt;, not a single host. Ships with strong monitoring baked in - CPU / RAM / disk metrics, log aggregation, alerting - so you don't need to bolt on Prometheus. Config lives in TOML files you can commit to git.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best if:&lt;/strong&gt; you have 3+ servers and want unified management + monitoring without stitching multiple tools together.&lt;/p&gt;

&lt;p&gt;🔗 &lt;a href="https://komo.do/" rel="noopener noreferrer"&gt;komo.do&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  5. Dockge - a minimalist compose viewer
&lt;/h2&gt;

&lt;p&gt;From the maker of Uptime Kuma. Deliberately narrow scope: a clean web UI over your existing compose files. No build pipeline, no CI hooks, no monitoring bells - just start, stop, view logs, edit the compose file inline.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best if:&lt;/strong&gt; you already run compose files on a single server and want a "&lt;code&gt;docker ps&lt;/code&gt; but pretty" tool without adopting a whole PaaS.&lt;/p&gt;

&lt;p&gt;🔗 &lt;a href="https://dockge.kuma.pet/" rel="noopener noreferrer"&gt;dockge.kuma.pet&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  6. Arcane - gitops-native dashboard for many nodes
&lt;/h2&gt;

&lt;p&gt;One of the fastest-moving newcomers of the last year. Fits somewhere between Portainer and Coolify: proper multi-node support, deploy stacks from a git repo instead of the UI, per-node and cross-node secret management. Feedback I keep hearing from homelab folks running it at real scale (8+ nodes, 100+ containers) is that it holds up.&lt;br&gt;
Best if: you’ve outgrown Portainer’s single-host feel but don’t want a full self-hosted PaaS, and you want your stack definitions to live in git.&lt;br&gt;
🔗 &lt;a href="https://github.com/getarcaneapp/arcane" rel="noopener noreferrer"&gt;Arcane on GitHub&lt;/a&gt;&lt;/p&gt;


&lt;h2&gt;
  
  
  7. Dockhand - focused single-host Docker manager
&lt;/h2&gt;

&lt;p&gt;Docker-only (no Swarm support, on purpose). Very focused on the single-host operator: view stacks, restart services, browse logs, adjust configuration - without the surface area of Portainer or the deploy pipeline of Coolify. Community momentum has been strong in 2026, especially for the “more than Dockge, less than Coolify” crowd.&lt;br&gt;
Best if: you run Docker on one host, don’t need Swarm, and want a slightly richer UI than Dockge without moving to a PaaS.&lt;br&gt;
Skip if: you’re running Docker Swarm - Dockhand doesn’t cover it. Portainer or Komodo do.&lt;br&gt;
🔗 &lt;a href="https://dockhand.pro/" rel="noopener noreferrer"&gt;Dockhand&lt;/a&gt;&lt;/p&gt;


&lt;h2&gt;
  
  
  8. Runtipi - homelab-focused app store
&lt;/h2&gt;

&lt;p&gt;Trades the “raw docker-compose” interface for a curated app store. Two-click installs for 200+ common self-hosted apps (Nextcloud, Jellyfin, Vaultwarden, Immich, Home Assistant, Bitwarden, Grafana…). Perfect for a home server that non-technical family members will use.&lt;br&gt;
Best if: you’re running a home server for family/friends and want approachable UX first, customization second.&lt;br&gt;
&lt;strong&gt;Best if:&lt;/strong&gt; you're running a home server for family/friends and want approachable UX first, customization second.&lt;/p&gt;

&lt;p&gt;🔗 &lt;a href="https://runtipi.io/" rel="noopener noreferrer"&gt;runtipi.io&lt;/a&gt;&lt;/p&gt;


&lt;h2&gt;
  
  
  9. Rancher - enterprise Kubernetes + Docker
&lt;/h2&gt;

&lt;p&gt;Now owned by SUSE. In 2026 its focus is squarely on &lt;strong&gt;Kubernetes&lt;/strong&gt;. Docker Compose support remains but is no longer the primary use case. If you're running K8s at enterprise scale, Rancher is the mature choice.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best if:&lt;/strong&gt; your team is committed to Kubernetes and needs enterprise-scale multi-cluster management.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Skip if:&lt;/strong&gt; you're on plain Docker Compose - most tools above are a better fit today.&lt;/p&gt;

&lt;p&gt;🔗 &lt;a href="https://www.rancher.com/" rel="noopener noreferrer"&gt;rancher.com&lt;/a&gt;&lt;/p&gt;


&lt;h2&gt;
  
  
  10. Stacker - config-as-code alternative to a web UI
&lt;/h2&gt;

&lt;p&gt;Full disclosure: this is my project. &lt;strong&gt;Different niche&lt;/strong&gt; from the seven above - instead of a web dashboard over your Docker setup, Stacker treats each stack as a single &lt;code&gt;stacker.yml&lt;/code&gt; file you commit to git.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;umami&lt;/span&gt;
&lt;span class="na"&gt;app&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;type&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;custom&lt;/span&gt;
  &lt;span class="na"&gt;image&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;ghcr.io/umami-software/umami:postgresql-latest&lt;/span&gt;
  &lt;span class="na"&gt;ports&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;3000:3000"&lt;/span&gt;
&lt;span class="na"&gt;proxy&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;type&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;nginx-proxy-manager&lt;/span&gt;
  &lt;span class="na"&gt;auto_detect&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;
  &lt;span class="na"&gt;domains&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;domain&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;analytics.example.com&lt;/span&gt;
      &lt;span class="na"&gt;ssl&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;auto&lt;/span&gt;
      &lt;span class="na"&gt;upstream&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;umami:3000&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Then:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;stacker deploy
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;One command: provisions a server (or reuses one you have), generates the compose file, wires an Nginx reverse proxy with auto-SSL, sets up backups and healthchecks, starts everything. Same YAML deploys locally, to a Linux server you own, or to Hetzner / DO / AWS / Linode / Vultr.&lt;/p&gt;

&lt;p&gt;MIT-licensed. Ships with &lt;a href="https://github.com/trydirect/awesome-selfhosted-stacker" rel="noopener noreferrer"&gt;67+ ready-to-deploy templates&lt;/a&gt; (Nextcloud, Ghost, Vaultwarden, Dify, Open WebUI, etc.).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best if:&lt;/strong&gt; you like your infrastructure as code more than as clicks - and value reproducibility across dev / staging / prod.&lt;/p&gt;

&lt;p&gt;🔗 &lt;a href="https://github.com/trydirect/stacker" rel="noopener noreferrer"&gt;github.com/trydirect/stacker&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  How to choose the right tool
&lt;/h2&gt;

&lt;p&gt;Match the tool to the job - not to whatever's most-starred on GitHub this month.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;If you want to…&lt;/th&gt;
&lt;th&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Poke at containers on one server&lt;/td&gt;
&lt;td&gt;
&lt;strong&gt;Portainer&lt;/strong&gt; , &lt;strong&gt;Dockge&lt;/strong&gt; or &lt;strong&gt;Dockhand&lt;/strong&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Deploy web apps from GitHub with auto-SSL&lt;/td&gt;
&lt;td&gt;
&lt;strong&gt;Dokploy&lt;/strong&gt; or &lt;strong&gt;Coolify&lt;/strong&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manage Docker across 3+ servers&lt;/td&gt;
&lt;td&gt;
&lt;strong&gt;Komodo&lt;/strong&gt;, &lt;strong&gt;Portainer BE&lt;/strong&gt; or &lt;strong&gt;Arcane&lt;/strong&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Run a home server for family / friends&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Runtipi&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Run Kubernetes at enterprise scale&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Rancher&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Version-control your infrastructure&lt;/td&gt;
&lt;td&gt;
&lt;strong&gt;&lt;a href="https://github.com/trydirect/stacker" rel="noopener noreferrer"&gt;Stacker&lt;/a&gt;&lt;/strong&gt; (config-as-code)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Wrapping up
&lt;/h2&gt;

&lt;p&gt;There's no single "best" Docker web UI in 2026 - the right tool depends on how many servers you have, whether you want a dashboard or a full deploy pipeline, and how much you care about reproducibility. The good news: the ecosystem is richer than it's ever been, and every tool here is free and open source.&lt;/p&gt;

&lt;p&gt;If you're just starting: &lt;strong&gt;Portainer&lt;/strong&gt; or &lt;strong&gt;Dockge&lt;/strong&gt; get you visibility fast. If you want a proper deploy workflow: &lt;strong&gt;Dokploy&lt;/strong&gt; or &lt;strong&gt;Coolify&lt;/strong&gt;. If you're operating a fleet: &lt;strong&gt;Komodo&lt;/strong&gt;. If you want your infrastructure in git rather than a dashboard, take a look at &lt;a href="https://github.com/trydirect/stacker" rel="noopener noreferrer"&gt;Stacker&lt;/a&gt; - I'd love your feedback.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;What did I miss?&lt;/strong&gt; If you're running something not on this list - Yacht, CasaOS, LazyDocker, Docui, or a homegrown thing - drop it in the comments. Always looking to add to the list.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;P.S. - the joke isn't lost on me.&lt;/strong&gt; Yes, you &lt;em&gt;can&lt;/em&gt; use Stacker to deploy Coolify. There's a &lt;a href="https://github.com/trydirect/awesome-selfhosted-stacker/tree/main/stacker-projects/coolify" rel="noopener noreferrer"&gt;&lt;code&gt;stacker-projects/coolify&lt;/code&gt;&lt;/a&gt; template, so &lt;code&gt;stacker deploy&lt;/code&gt; gets you a fresh box with Coolify running on it, ready for its own web UI to take over deploying your other stuff. Turtles all the way down. 🐢&lt;/p&gt;

&lt;p&gt;Templates for Portainer and Dockge aren't in the catalog yet - PRs enthusiastically welcomed if you'd like to make the joke fully true.&lt;/p&gt;

</description>
      <category>docker</category>
      <category>devops</category>
      <category>selfhosted</category>
      <category>showdev</category>
    </item>
  </channel>
</rss>
