This morning I updated the OS on my NAS. It rebooted, came back, everything looked fine. It wasn't. Three containers didn't come back up, and one of them was the reverse proxy that sits in front of everything public. My photos site was down for about 35 minutes before I noticed.
The annoying bit is I already run a security tool on this network. I wrote it. It's called warden, and it was sat there reading logs, scanning for CVEs and checking files for changes the whole time, with no idea anything was wrong. It never asked "is the box up, and is the stuff on it actually running?"
Turns out the update had run docker stop on its way down, and Docker treats that as you stopping them on purpose. So restart: unless-stopped did exactly what it says and left them off. Fair enough, but I'd have liked to know.
So that's most of warden v3. Here's what's new.
A heartbeat for every box
Every 5 minutes warden checks every server and container: up, down, stopped, or unknown, and how long it's been up.
The bit I'm pleased with: on a Proxmox node it's one SSH call for the node and every container on it. pvesh already knows the status and uptime of every container, so I just ask it. My 2 nodes, 9 containers and 2 other servers take 4 SSH calls and about 6 seconds.
If a box misses three beats you get one message. When it's back you get another, and if the uptime is shorter than the outage it tells you it rebooted. If a whole node stops answering, its containers show as "unknown", not "down", so one dead node is one message, not twenty.
Who last signed in
Every box now shows who last signed in over SSH or the console, from where, and when, plus failed attempts in the last 24 hours.
First time I ran it, every single box said the last login was warden itself, a few minutes ago. Obviously. warden signs in to check things, and so does my agent setup on the same box. When I counted, about three sign-ins in four were my own automation. So sign-ins made with a key that lives on the warden box get tagged and left out, and you can name your other automation keys so they show as jobs, not people.
After that, the first read of each box is a quiet baseline. From then on, a user, address and key a box has never seen sends you a message.
It also turned up something I didn't know about: two failed sign-ins this morning on an old container I'd parked. Still working out what that was, which is sort of the point.
A network map that draws itself
I wanted a network diagram but I didn't want to draw one, because a hand-drawn diagram is wrong the week after you draw it.
So the Network tab draws it from stuff warden already knows: internet and line health, the router, Cloudflare and which box runs the tunnel, each subnet with your servers (containers inside their node, coloured by heartbeat) and every other device counted by kind. Click a server and you go to its details, click "bulb 38" and it lists your bulbs. It works on a phone as well, which took two goes.
The rest since v2
- No scanner binary any more. I used trivy, then its own releases got compromised (CVE-2026-33634). Now warden reads package lists off each box and checks them straight against OSV.dev, ranked by known-exploited first.
- What the internet can reach: vulnerable containers that are actually exposed go to the top.
- Every device in the house: one inventory from the LAN sweep, router leases and Home Assistant. It learns what each bulb or TV normally looks up and only asks me about odd ones.
- Internet health every minute, with who was using the line when it went bad.
- An attack map by country, more log formats (Caddy, Traefik, Authentik), and an optional Beszel card.
What it still can't do
Being straight about it: warden still doesn't check individual Docker containers, so this morning's outage would only show up today as "box is up". That's the next fix. Sign-ins through pct exec or the Proxmox web console don't get logged anywhere warden can read, so they don't show. Container heartbeats need Proxmox. The full list is in the repo's KNOWN-ISSUES.md, and I've pointed my coding agent at that file so the fixes come in as PRs I review.
It's free, AGPL, runs on 512 MB, and it's detect-only by default, so nothing gets changed without you saying yes.
Repo: https://github.com/casareanderson/warden
If you run it, let me know what it finds. And if you've got a better idea for spotting stopped containers than polling docker ps, I'm all ears.


Top comments (2)
Official Platform Update
Security protocols have been updated for all developer accounts.
That looks like someone phoning up dev.to claiming to be them, I don't run anything on dev.to itself so I can't say whether your update is legit. Warden does scan packages against OSV.dev when they get compromised (trivy did once), which was where I got started, but I've never built it to watch external sites or spot social-engineering posts like this.