Running it
Air-gapped install
MangoDock makes no requests to the internet on its own. What an isolated network needs is a way to get the software and its data in.
No telemetry, no update check, no third-party fonts or scripts in the page, and the vulnerability scanners are told not to phone home either.
Getting it across
- On a machine with internet access, download the offline bundle from the MangoDock download page, together with its signature file. Nothing else is needed on that machine — no Docker.
- Check the signature with cosign (below) before the file goes anywhere. It proves the bundle is the one MangoDock published and that not a byte of it has changed.
- Carry the one file across, unpack it, and run ./install.sh. The installer refuses to go on if any file fails its checksum, loads the images, installs the vulnerability databases with scanning set to Offline, and starts MangoDock on port 3100.
Verify the download
cosign verify-blob --key https://mangossh.com/keys/mangodock-cosign.pub \
--bundle mangodock-offline-linux-x64.tar.gz.sigstore.json \
mangodock-offline-linux-x64.tar.gzPrints "Verified OK". Any other result means do not carry the file across. The same command works in PowerShell and cmd with the line breaks removed.
The bundle holds the MangoDock image, its backup helper image and the agent image, fresh Trivy and Grype vulnerability databases (most of its ~720 MB), a compose file pinned to that version with pulls disabled, an installer and a SHA256SUMS file. The isolated host needs Docker with the compose plugin, on x86-64.
Prefer to build it yourself — newer scanner databases than the release's, or no download at all? The MangoDock image builds the same bundle on any machine with Docker: docker run --rm -v /var/run/docker.sock:/var/run/docker.sock -v "$PWD:/out" ghcr.io/mangossh/mangodock:0.1.10 bundle --with-db (in PowerShell, ${PWD} instead of $PWD).
Inside the enclave
- Internal registries — under Settings ▸ Credentials ▸ Registry mirrors, map docker.io, ghcr.io and quay.io to your proxy cache. Every pull then goes through the mirror and keeps the original image name; update checks ask the mirror, and stack deploys pre-pull through it.
- Vulnerability databases — Settings ▸ Hosts ▸ Edit ▸ Security. Import the archives from a newer bundle or from a connected MangoDock's export buttons, or switch to Internal mirror if your registry hosts trivy-db. Their age is shown, and offline they are used however old they get rather than refused.
- Update checks against a registry the network cannot reach give up after 15 seconds and skip that registry's other images for the rest of the check, so a check never stalls on the air gap.
- Upgrading — unpack the newer bundle and run its install.sh. The data volume is kept.
Installer options
| Variable | Effect |
|---|---|
| MANGODOCK_PORT=8080 | Start on a different port. |
| MANGODOCK_NO_SOCKET=1 | Leave out the local Docker socket mount. |
Air-gapped
- This page is the air-gapped path. Everything else in these docs works the same way inside an enclave once the bundle is in.