EnderDash

Install on Docker

Start the standalone image with a persistent data volume and Docker Engine access.

Before you begin

You need Docker Engine, permission to use its socket, and the agent key from Setup. Docker management also needs the corresponding organization plan feature.

The socket grants host control

Mounting /var/run/docker.sock gives the agent control of the Docker daemon. A read-only filesystem mount does not make Docker API operations read-only. Use a host whose administrators accept this access.

Start the agent

docker run -d --name enderdash-agent \
  --restart unless-stopped \
  -e ENDERDASH_AGENT_KEY='<agentKey>' \
  -v enderdash-agent-data:/enderdash/data \
  -v /var/run/docker.sock:/var/run/docker.sock \
  ghcr.io/enderdash-com/enderdash-agent:latest

Replace the key before running the command. The volume retains agent state when the container is replaced. Use a reviewed image tag or digest if you need reproducible releases.

Verify both connections

docker ps --filter name=enderdash-agent
docker logs --tail 100 enderdash-agent

Confirm Online in EnderDash. Open Docker and check that the containers are from the intended daemon. The agent's registration can work even when its Docker socket access fails.

If Docker is unavailable, inspect the socket path and agent-user permissions. If the agent is offline, use offline recovery.

Use Compose instead

The deployment repository provides a Compose file. Download it into a dedicated directory and review it before starting:

curl -fsSLO https://raw.githubusercontent.com/enderdash-com/deploy/main/agent/compose.yaml
cat > .env <<'EOF'
ENDERDASH_AGENT_KEY=<agentKey>
EOF
chmod 600 .env
docker compose up -d
docker compose ps

This installs the agent through Compose. Managing other Compose projects from EnderDash additionally requires a Compose CLI available to the agent.

Update or stop

For this Compose installation:

docker compose pull
docker compose up -d

Verify live data after replacement. docker compose down stops and removes the agent container while retaining its named volume. Remove that volume only if you intend to discard agent state.

Container installations use image replacement and disable automatic binary downloads by default. Read agent maintenance for key rotation and removal.

Was this page helpful?

Send a quick note if anything is missing or unclear.

Last updated on

On this page