Dozzle
Live Docker container logs in a browser
What is Dozzle?
Dozzle is a small web app that streams the logs of all your containers in real time, with search, colour and filtering. It replaces the ritual of SSH-ing into a host and running docker logs on the right container name.
Best for
Watching container logs without leaving the browser
Why choose Dozzle
Dozzle solves one narrow problem very well: reading Docker logs. It streams all container output into a browser with live tail, colour, search and per-container filtering, so you stop running docker logs against the wrong container name and stop losing the scrollback the moment you reconnect over SSH. It is a tiny image and the whole interface is available within seconds of starting it. Because it mounts the Docker socket, it sees every container on the host, including the ones that keep restarting before you can catch them. For anyone who runs containers and troubleshoots them interactively, it removes a recurring five-minute friction several times a day.
Replaces
- Datadog Logs
- Papertrail
- Docker Desktop
Key features
- Live streaming logs for every container
- Search and filter across containers
- Works with a remote Docker socket
- Very small footprint
What to watch out for
Dozzle mounts the Docker socket, which is effectively root on the host — anyone who can reach its interface can do severe damage, and it must never be exposed publicly without authentication and TLS in front. Its default view shows recent logs rather than persisting them, so it is not a substitute for centralised log storage when you need history across restarts. Very noisy containers can overwhelm the browser. Because it reads from the Docker daemon, it only covers containers on hosts where it is running, so a multi-node setup needs it deployed per node or behind something that aggregates.
How to deploy
- Single container mounting the Docker socket
- Add authentication before exposing it
- Point it at remote agents for multi-host setups
Getting started
Run it alongside your containers with the Docker socket mounted read-only where possible, and enable its built-in authentication before it is reachable by anything but localhost. Put it behind a reverse proxy with TLS rather than publishing the port directly. Set a sensible log line limit so a chatty service does not freeze the tab, and use the search and container filters rather than scrolling. Confirm it can see containers that restart quickly, since catching the failure output is usually the reason you installed it. Keep it out of any public-facing network entirely.
Typical setup
It runs as one small container on each Docker host, with the socket mounted read-only where the host supports it, and its own authentication enabled before anything but localhost can reach it. A reverse proxy provides TLS, and the port is never published directly to the internet. Log line limits are set so a chatty service cannot freeze a browser tab. It stores nothing, so it never appears in a backup, and it is treated as an operational convenience rather than a logging system — anything that needs to be kept goes to a real log store.
Who should look elsewhere
Never expose this to the internet, and do not deploy it on a shared host where other tenants could reach the port — the socket mount makes it a privilege escalation path. It is also the wrong tool if you need searchable log history, alerting on log patterns or correlation with metrics; that is Loki or a similar system. And if you do not run Docker, it does nothing at all.
Project health
- GitHub stars: 14,528
- Last code push: 2026-10-01
- Open issues: 5
- Status: actively developed
Figures pulled from the GitHub API and refreshed periodically.