Omahub
← All plugins
E

OmiDocker

by Erruviel

Docker containers and compose stacks for Omarchy

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
73e1392
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs sudo README.md:51

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo usermod -aG docker $USER

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
73e1392
Reviewed
1 month ago

No malicious or obfuscated code was found in the sampled executable files; the plugin runs docker CLI commands as the invoking user via the Docker socket and uses systemctl/polkit for daemon control. The deterministic scan's medium finding is a README-only `sudo usermod` prerequisite, not part of the plugin's runtime, so it does not elevate install-time privileges. Overall the plugin is safe to publish, with the usual caveat that Docker-socket access is a privileged capability.

  • README line 51 instructs the user to add themselves to the `docker` group manually; this is documentation, not executed by the plugin, but Docker group membership is effectively root-equivalent and should be understood by users.
  • The plugin's intended functionality includes starting/stopping/removing containers, pruning images/build cache, and opening `docker exec` shells; these are user-initiated panel actions with confirmation for destructive operations, so they present intended functionality risk rather than hidden malicious behavior.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Erruviel/omarchy-docker --enable
Developer Tools #bar #quickshell #system

OmiDocker

Docker containers and compose stacks on the Omarchy bar.

Panel preview

A whale in the status bar, a control panel one click away:

  • Compose stacks — containers grouped by com.docker.compose.project. Stack start runs docker compose up -d (recreates removed containers, picks up compose.yml changes); stack stop is a plain docker stop, never a destructive down.
  • Per-container controls — start, stop, restart, unpause, and remove (stopped containers only, behind a confirm dialog).
  • Logs and shell — one click opens a floating terminal with docker logs -f or an interactive docker exec shell.
  • CPU/memory per container — sampled with docker stats while the panel is open; the closed widget costs nothing.
  • Clickable ports — a published port opens http://localhost:<port> in the browser.
  • Live updates — the panel follows docker events, so work done in a terminal (compose up, stops, health flips) shows up immediately.
  • Health at a glance — unhealthy containers turn urgent in the panel, put a badge dot on the bar icon, and raise a desktop notification when they flip (can be turned off).
  • Port-conflict hints — a stopped container whose published host port is held by a running one is told exactly who is squatting on it.
  • Clean up — see how much space dangling images and build cache hold, and prune them behind a confirm dialog. Stopped containers and volumes are never touched.
  • Daemon switch and autostart — start/stop docker.service and toggle enable-at-boot from the panel, authorized through the regular polkit prompt.

Install

omarchy plugin add https://github.com/Erruviel/omarchy-docker.git --enable

That's it. The plugin runs entirely unprivileged: container data and actions go through the docker CLI (your docker group membership), and the daemon switch calls systemctl as your user, which authenticates through polkit. Nothing is installed outside the plugin directory, and nothing runs as root.

Requirements

  • docker CLI and, to see any containers, membership in the docker group:

    sudo usermod -aG docker $USER
    

    (log out and back in afterwards). Without it the panel explains what to do.

  • jq (ships with Omarchy).

If Docker is not installed at all, the widget hides itself.

Settings

In ~/.config/omarchy/shell.json, on the widget entry:

Key Default Meaning
interval 10 Background poll interval in seconds while the panel is closed. Events refresh the panel regardless; this is the safety net.
showCount false Show the number of running containers next to the whale on the bar.
notifyUnhealthy true Desktop notification when a container turns unhealthy.
{ "id": "erruviel.docker", "interval": 30, "showCount": true }

Uninstall

omarchy plugin remove erruviel.docker

License

MIT — see LICENSE.