Omahub
← All plugins
T

Dockmarchy

by This_Is_NPC

Docker and Podman status in the Omarchy bar: containers, images, volumes, and networks.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
14ac95c
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs sudo README.md:19

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo or pkexec. The plugin runs as your user inside

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
14ac95c
Reviewed
1 month ago

Dockmarchy is a legitimate bar widget that queries Docker/Podman CLIs and performs user-initiated container/resource actions. The code is transparent, runs as the user without sudo, and contains no obfuscation, persistence, or credential theft. The deterministic scan's medium finding is a false positive: the flagged line is README text explicitly stating 'No sudo or pkexec'.

  • The plugin executes docker/podman commands (ps, stats, start/stop/restart, remove, logs) as the user; this is expected functionality but grants the widget the same container-management privileges the user already has.
  • The deterministic scan flagged a sudo reference in the README, but it is documentation only and actually states the plugin does not use sudo.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/This-Is-NPC/dockmarchy --enable
System #bar #system

Dockmarchy

Docker and Podman container status in the Omarchy bar.

The bar widget is the engine logo. The panel lists containers, images, volumes, and networks. Containers are grouped by compose project, with hardware usage, search, bulk start/stop/restart, and logs. The other tabs list engine resources and can remove selected items.

Dockmarchy panel with hardware gauges, compose groups, and container actions

Install

omarchy plugin add https://github.com/This-Is-NPC/dockmarchy.git --enable

Requires Docker and/or Podman on PATH. No sudo or pkexec. The plugin runs as your user inside omarchy-shell and calls the engine CLIs (ps, stats, start/stop/restart, remove, logs).

Usage

Click the logo to open or close the panel. Press Escape to close it.

The widget is the Docker whale or the Podman seal, depending on which engine answered. Hover shows the running count; after the panel has opened once, it also includes last-seen CPU, RAM, and disk. It turns urgent when something running is unhealthy, restarting, paused, or dead. Right-click refreshes; middle-click opens logs for the first visible container.

Hardware is three small gauges — CPU, RAM, and disk — against the machine totals, for example 12GiB/46GiB. Disk is the Docker/Podman footprint (docker system df) against the root filesystem.

Containers are grouped by compose project. Filter by all / running / stopped, then search by name, service, project, or image. Check rows (or a whole compose group) and use the command bar to start, stop, restart, or open logs. Logs open a new terminal per selected container on the active workspace. Running containers follow with -f; stopped containers show history and keep the window open.

Switch the top chips to Images, Volumes, or Networks. Those lists group the same way (compose project, or repository for images). Select rows and Remove from the command bar. Default networks (bridge, host, none) are listed but not removed. Docker refuses a delete when the resource is still in use; the panel shows that error.

Language defaults to English. Switch to Portuguese from the footer.

Action Mouse Keyboard
Open / close Click the logo Esc closes
Refresh Right-click the logo, or the refresh icon r
Filter The three chips 1 2 3
Kind Containers / Images / Volumes / Networks c i v n
Search The search field /
Select Checkbox or row Space, a for all visible
Start / stop Command bar s, x
Restart Command bar t
Logs Command bar l
Remove Command bar (images, volumes, networks) d
Language PT / EN —
Move Hover arrows or hjkl

Engine detection is automatic: Docker if the CLI is there, Podman if it is, both when both answer. Force one in the widget settings (Auto / Docker / Podman). Refresh interval defaults to 15 seconds. While the panel is closed, only the container list is polled so the bar stays cheap; hardware gauges and images/volumes/networks load when you open the panel.

Configure

omarchy bar move io.github.this-is-npc.dockmarchy --section right

Remove

omarchy plugin remove io.github.this-is-npc.dockmarchy

Development

node test/model-test.js     # parser, compose labels, grouping, i18n
omarchy plugin validate .   # manifest against the shell's schema

Model.js has no Qt in it, so the list engine runs in node. Panel.qml only paints state.

While hacking on this checkout, copy it into the user plugin directory (the shell refuses a symlink there):

rsync -a --delete --exclude .git --exclude test \
  ./ ~/.config/omarchy/plugins/io.github.this-is-npc.dockmarchy/
omarchy-shell shell rescanPlugins
omarchy plugin enable io.github.this-is-npc.dockmarchy --section right

MIT. See LICENSE.