Skip to content

docs: platform guides, hardening, cloud compose example, complete env reference - #95

Merged
marvinvr merged 2 commits into
mainfrom
issue-82
Sep 30, 2026
Merged

marvinvr merged 2 commits into
mainfrom
issue-82

Conversation

@marvinvr

Copy link
Copy Markdown
Owner

Documentation for running DockTail beyond a plain Linux Docker host, a clean set of Compose examples, and an environment reference that matches the code.

What changes

  • Platform guides (docs/02-platforms.md, new): Podman, Synology, Unraid, TrueNAS SCALE, macOS and Windows, Docker Swarm, Kubernetes. Each one says how well it is known to work. It is either reported by users (I may just be dumb, but does this not work in Unraid? #12, Docker Swarm Version #43, Support multiple docker sockets (for podman) #49, Macos Support #68), not tested by the maintainers, or not supported (Kubernetes: no Docker Engine API and no Helm chart). The Swarm layout is based on the one reported working in Docker Swarm Version #43: a global DockTail plus tailscaled per node, top-level container labels: instead of deploy.labels, at most one replica per node, and no start-first for the sidecar.

  • Hardening (docs/02-security.md, new):

    • why :ro on docker.sock protects nothing;
    • the Docker API calls DockTail makes (list, inspect and events; plus info, version, stats and logs with Cloud);
    • a tecnativa/docker-socket-proxy setup with the exact sections (CONTAINERS, INFO for Cloud, plus the default EVENTS/PING/VERSION, POST=0);
    • cap_drop: [ALL] + no-new-privileges, and the caveat that *_FILE secrets must then be readable by root through normal permission bits.
  • Compose files:

    • The dev stack (version:, build: ., test containers, unused volume) moves to docker-compose.dev.yaml. make up/down/logs follow it, and logs now names the right container.
    • docker-compose.yaml is now a deployment example.
    • New docker-compose.cloud.yaml enables Cloud reporting.
  • docs/06-cloud.md:

    • Cloud is a paid service (linked to the pricing page, no hardcoded prices).
    • A new workspace can connect one host as an unmonitored preview.
    • A first subscription can come with an introductory offer.
    • A "Before you start" block names Tailscale API credentials first.
    • The enrollment window no longer reads as fixed at one hour.
  • docs/07-reference.md and .env.example: every variable DockTail reads, now including the Docker client's DOCKER_API_VERSION / DOCKER_CERT_PATH / DOCKER_TLS_VERIFY, plus NO_COLOR, DOCKTAIL_HOST_ROOT and the dev-only cloud overrides. Two descriptions were wrong:

    • DOCKTAIL_LOG_LEVEL is read but has no effect; LOG_LEVEL sets the cloud module's level.
    • TAILSCALE_SOCKET only feeds the socket checks. The bundled tailscale CLI is never passed --socket and always uses /var/run/tailscale/tailscaled.sock.

    .env.example now also says that only variables listed under a service's environment: reach DockTail.

Section edits to 06-cloud.md, 07-reference.md, 02-installation.md and README.md are kept small so they sit alongside the open doc PRs. git merge-tree against #90, #92, #93 and #94 is clean.

Notes for merging

Follow-ups found while writing this (not changed here)

  • TAILSCALE_SOCKET is not passed to the tailscale CLI (tailscale/utils.go tailscaleCmd).
  • DOCKTAIL_LOG_LEVEL is parsed but Config.ZerologLevel is never used.
  • RECONCILE_INTERVAL=0s (or negative) parses and then panics in time.NewTicker.

Refs marvinvr/docktail-cloud#82

… reference

- docs/02-platforms.md: Podman, Synology, Unraid, TrueNAS SCALE, macOS and
  Windows, Docker Swarm and Kubernetes, each saying how well it is known to work.
- docs/02-security.md: what :ro on the Docker socket does not do, a read-only
  docker-socket-proxy with the API sections DockTail uses, and dropping
  capabilities.
- docker-compose.yaml is now a deployment example; the development stack moves
  to docker-compose.dev.yaml (make up/down/logs follow). New
  docker-compose.cloud.yaml enables DockTail Cloud reporting.
- docs/06-cloud.md: Cloud is a paid service, the unmonitored preview host,
  prerequisites with Tailscale API credentials first, the enrollment window
  choices.
- docs/07-reference.md and .env.example: every variable DockTail reads,
  including the Docker client variables, NO_COLOR and DOCKTAIL_HOST_ROOT;
  DOCKTAIL_LOG_LEVEL and TAILSCALE_SOCKET now say what they actually do.
Keep DockTail on a normal network next to the socket proxy, hedge the
Unraid, SELinux and Swarm notes to what users reported, drop the untested
non-root paragraph, and make .env.example say which variables reach
DockTail.
@marvinvr
marvinvr merged commit 42e30c3 into main Sep 30, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant