Nebcon · v0.4 · macOS 14+

One window for Apple container and Docker.

Nebcon is a Mac app for your containers. It works with Apple's container runtime and with any Docker engine you have, one at a time or all in one list. It shows your projects, containers, images and volumes in a window (and in the menu bar), and it works through the docker CLI you already use.

Download for macOS

1.9 MB · Apple silicon · unsigned build

Nebcon — Projects
The Projects screen: four cards for containers, processor, memory and disk space, above a grid of project cards, each with a run ring, its containers, and what it is using.
What's running and what it costs, then one card per project. Each of these is in a different state: half up with a crashed worker, missing its compose file, missing its folder, paused, not started yet, and running. You can tell which is which at a glance.

01 Runtimes

Apple's runtime, a Docker engine, or both at once.

Pick a runtime from the toolbar and everything on screen is about that one. Pick All runtimes and you get one list across all of them.

Apple container

Nebcon finds Apple's runtime by its socktainer socket, so there's nothing to configure. It knows where that runtime differs from Docker: it hides Pause and Commit, which Apple's runtime doesn't have, and it reads processor and memory from Apple's own container tool.

Docker engines

Anything the docker CLI has a context for shows up in the same picker: Docker Desktop, OrbStack, Colima, or a remote engine over SSH. A context with nothing behind it is marked offline instead of being offered as if it worked.

All runtimes

Projects, containers, images and volumes from every runtime that answers, in one list, with the usage figures added up. Each card says which runtime it's on, and its buttons go to that runtime.

Same project, two engines

If the same compose project is up on Apple's runtime and on Docker, you get two cards, each with only its own containers. Stopping one doesn't touch the other.


02 Usage

See what each project is costing you.

The Projects screen opens with four numbers: how many containers are running, and how much processor, memory and disk they're using. Every project and every container carries the same three figures, so you can see which one is the heavy one.

Open a project and each container gets its own card. It says in a word whether it's running, healthy, stopped or crashed. A published port is shown as localhost:5432, and clicking it opens the browser. On Apple's runtime every container has an address of its own, reachable from your Mac whether or not you published a port, so the card shows that too. Click it to copy. When a container fails its health check or exits with an error, the card says so and puts the logs one click away.

Nebcon — atlas-analytics
A project opened: its processor, memory and disk use, a notice that the worker stopped with an error, and one card per container with its port, its own address, and Start, Stop, Restart and Logs.

03 Projects stay put

Stopping a project doesn't make it disappear.

When you run compose down, the containers get deleted, and with them the only record of which project they belonged to. Most apps then drop the project from the list, so the button you'd use to bring it back is gone too. Nebcon remembers your projects, so a stopped one stays right where it was, with a Start button on it.

When something breaks, you get an actual explanation instead of a spinner. Errors show up in red. Warnings, where the command ran but something looked off, show up in amber.

Nebcon — Projects
The same screen with three banners at the top: a red compose error, an amber warning about missing variables, and a runtime update notice.

04 Deleting

You see exactly what gets deleted.

Deleting a project is the only thing in Nebcon that really destroys data, so it doesn't just ask "Are you sure?". It lists every container and every volume, with sizes. If another project is still using one of those volumes, Nebcon keeps it and tells you who's using it.

Even the button is specific. It doesn't say Delete. It says Delete 2 containers + 1 volume + files.

Delete storefront
The delete sheet listing two containers, one volume to remove at 69.4 MB, and one volume kept at 318.8 MB because another container still uses it.

05 Setup

It can set up Apple's runtime for you.

Apple's runtime needs four command-line tools: Apple's container, socktainer (which lets Docker talk to it), the docker CLI and Docker Compose. Settings shows which versions you have and lets you install or update them with Homebrew. A Docker engine you already run needs none of this.

Installing does the whole job. It downloads the kernel, starts the services, and fixes the Compose plugin link, which is often still pointing at an app you uninstalled ages ago.

The same pane shows Apple's image builder. It's a container of its own, and it holds on to its memory until you stop it, so you can see whether it's running, stop it, and choose how much it gets next time. And when it's the runtime itself that's misbehaving, Logs shows what its services have been saying.

Settings — Runtime tools
The runtime tools pane: four tools with their versions and status, a note saying the update is installed but the old version is still running, and the image builder running with 4 CPUs and 8 GB.
That amber note shows up when an update has installed but the old version is still running. Hit Restart and you're done.

06 Cards

Everything is a card, at any window size.

Every container is a card with its name, its state, where to reach it and what it's using. Start, Stop, Restart and Logs are buttons with words on them, not icons you have to hover to find. The cards reflow to fit the window, down to a single column when you make it narrow. The Containers screen opens with the same four numbers as Projects.

Nebcon — Containers
The Containers screen: four cards for containers, processor, memory and disk space, above a grid of container cards. Running, stopped, paused and crashed containers, each with its addresses, its processor, memory and disk figures, and Stop, Restart and Logs buttons.

07 Logs and images

Fewer reasons to open a terminal.

The things you'd otherwise type a command for are in the menu on each card and each image.

Logs that go back further

A log window starts from the last 300 lines, and you can ask for the last 1,000, the last 10,000, or everything. On a Docker engine you can also start from the last five minutes, hour or day. Save writes what you're looking at to a file.

The boot log

On Apple's runtime a container is a small VM. When one won't start, its own log is empty, because it never got that far. Tick Boot and you see what the kernel and init said instead.

Inspect

The full JSON for a container or an image, to read, copy or save.

Run one image

Run starts a container from an image with a name, ports, environment and a command. It's for the database you want to try something against. Anything bigger belongs in a compose file.

Rebuild

Start reuses an image it has already built, even if the Dockerfile has changed since. A project that builds its own images gets Rebuild and start, and you watch the build as it runs.

Tag, push and log in

Give an image a second name, push it, and log in to a registry. Your password goes straight to docker login. Nebcon doesn't keep it.


08 Why use it

The small stuff that saves you time.

Nobody asks for features like these. I only added each one after it caught me out.

It checks your compose file first

If a variable from your .env is missing, Compose quietly fills in a blank and starts anyway. You end up with a database that won't start and no idea why. Nebcon checks first and tells you which variable is missing.

It hides buttons that won't work

Apple's runtime can't pause containers or save them as images. So Nebcon doesn't show those buttons there, instead of letting you click one and get an error. On a Docker engine they're in the menu.

It switches when a runtime goes away

If the runtime you're using stops responding (maybe you restarted it, or uninstalled something), Nebcon moves to one that works and lets you know it did.

Red means something is wrong

A container you stopped isn't a problem, and Nebcon doesn't paint it like one. Red is kept for a container that exited with an error or is failing its health check.

It handles socktainer's quirks

socktainer renames some Compose labels, turning working_dir into working-dir, and never answers docker stats. Nebcon reads both spellings and gets the numbers another way, so your projects still group correctly and the usage figures still show.

It shows real volume sizes

socktainer reports every volume as -1B. Nebcon measures the volume's disk image instead, so you see how much space it actually takes.

It won't start the wrong project

If a folder has no compose file, Compose looks in the parent folder and may start a completely different project. Nebcon won't run Compose there. It tells you why, and Start and Stop still work on the containers that exist.

It frees space by name

Free up space lists every stopped container, unused image and unused volume with its size, and says which ones can't be brought back. Nothing is ticked until you tick it.


09 Limits

What it doesn't do.

Nebcon is just the app on top. If you want the engine, a VM and everything else in one package, there are other tools made for that.

No engine
It doesn't include a runtime, VM or kernel. It uses the docker CLI, so you need a runtime installed and running.
No Kubernetes or Linux VMs
Just containers, images, volumes and Compose projects.
Adding needs one runtime
Under All runtimes you can start, stop and delete anything, but adding a project, pulling an image and logging in to a registry are turned off. Each of those has to go to one runtime, so pick it first.
Exec isn't a full terminal
The built-in exec runs one command at a time. For anything interactive, use Open in Terminal from the same menu.
Updates on a timer
Apple's runtime doesn't send live updates, so Nebcon checks every two seconds while its window is open and every ten when it isn't. Processor and memory are sampled every five.
Not signed
The app isn't signed or notarized by Apple, so macOS will warn you the first time you open it.

10 Get it

Up and running in a minute.

Download Nebcon 0.4

1.9 MB · macOS 14+ · Apple silicon


  1. Open the disk image and drag Nebcon into Applications.
  2. Open Nebcon. macOS will block it the first time because it isn't signed.
  3. Go to System Settings › Privacy & Security, scroll down to the message about Nebcon, and click Open Anyway.

Or use Terminal

xattr -dr com.apple.quarantine /Applications/Nebcon.app

This removes the flag macOS puts on apps you download. That flag is exactly what the warning is for, so only do this if you trust where the app came from.


What you need

A Mac with Apple silicon running macOS 14 or later, plus a container runtime: Apple's container with socktainer, a Docker engine you already have, or both. Homebrew is optional, but with it Nebcon can install and update Apple's runtime for you.