Running it
Adding hosts
One control plane for many Docker hosts, with nothing installed on any of them.
The container you just started is MangoDock. It does not manage its own host unless you added the socket mount. Either way the next step is the same: Dashboard ▸ Add host.
Three kinds of connection
- This machine — only offered if you mounted /var/run/docker.sock.
- SSH, recommended for anything remote — point it at any host you can already ssh into. Nothing is installed on that host and no port is opened; MangoDock reaches its Docker socket over the SSH session itself.
- TCP, for a host that already exposes the Engine API directly. Use mutual TLS on 2376.
Plain 2375 is refused on public addresses
Port 2375 has no authentication and no encryption — anyone who can reach it has root on that host. MangoDock accepts it only for loopback and private ranges (127.x, 10.x, 172.16–31.x, 192.168.x, link-local, and 100.64/10 where Tailscale lives), and never sends a stored registry credential over it, so private images cannot be pulled through a plaintext connection. If the host really is reachable only through a VPN or a firewall rule, MANGODOCK_ALLOW_PUBLIC_PLAINTEXT=1 overrides it — a server setting rather than a checkbox, on purpose.
SSH is the one worth knowing about: if you can SSH into a box today, you can manage its containers in MangoDock half a minute later, with nothing added to that host. This is the main reason to run MangoDock rather than docker directly — one UI, every host, no agent anywhere.
Air-gapped
- All three connection kinds are local to your network. None involves a broker or a relay outside it.