Nebcon · v0.4 · macOS 14+
One window for Apple container and Docker.
Nebcon is a Mac app for your containers. It works with Apple's
container runtime and with any Docker engine you have, one at a time or
all in one list. It shows your projects, containers, images and volumes
in a window (and in the menu bar), and it works through the
docker CLI you already use.
01 Runtimes
Apple's runtime, a Docker engine, or both at once.
Pick a runtime from the toolbar and everything on screen is about that one. Pick All runtimes and you get one list across all of them.
Apple container
Nebcon finds Apple's runtime by its socktainer socket,
so there's nothing to configure. It knows where that runtime differs
from Docker: it hides Pause and Commit, which Apple's runtime doesn't
have, and it reads processor and memory from Apple's own
container tool.
Docker engines
Anything the docker CLI has a context for shows up in
the same picker: Docker Desktop, OrbStack, Colima, or a remote engine
over SSH. A context with nothing behind it is marked offline instead
of being offered as if it worked.
All runtimes
Projects, containers, images and volumes from every runtime that answers, in one list, with the usage figures added up. Each card says which runtime it's on, and its buttons go to that runtime.
Same project, two engines
If the same compose project is up on Apple's runtime and on Docker, you get two cards, each with only its own containers. Stopping one doesn't touch the other.
02 Usage
See what each project is costing you.
The Projects screen opens with four numbers: how many containers are running, and how much processor, memory and disk they're using. Every project and every container carries the same three figures, so you can see which one is the heavy one.
Open a project and each container gets its own card. It says in a word
whether it's running, healthy, stopped or crashed. A published port is
shown as localhost:5432, and clicking it opens the
browser. On Apple's runtime every container has an address of its own,
reachable from your Mac whether or not you published a port, so the
card shows that too. Click it to copy. When a container fails its
health check or exits with an error, the card says so and puts the
logs one click away.
03 Projects stay put
Stopping a project doesn't make it disappear.
When you run compose down, the containers get deleted, and
with them the only record of which project they belonged to. Most apps
then drop the project from the list, so the button you'd use to bring
it back is gone too. Nebcon remembers your projects, so a stopped one
stays right where it was, with a Start button on it.
When something breaks, you get an actual explanation instead of a spinner. Errors show up in red. Warnings, where the command ran but something looked off, show up in amber.
04 Deleting
You see exactly what gets deleted.
Deleting a project is the only thing in Nebcon that really destroys data, so it doesn't just ask "Are you sure?". It lists every container and every volume, with sizes. If another project is still using one of those volumes, Nebcon keeps it and tells you who's using it.
Even the button is specific. It doesn't say Delete. It says Delete 2 containers + 1 volume + files.
05 Setup
It can set up Apple's runtime for you.
Apple's runtime needs four command-line tools: Apple's
container, socktainer (which lets Docker talk
to it), the docker CLI and Docker Compose. Settings shows
which versions you have and lets you install or update them with
Homebrew. A Docker engine you already run needs none of this.
Installing does the whole job. It downloads the kernel, starts the services, and fixes the Compose plugin link, which is often still pointing at an app you uninstalled ages ago.
The same pane shows Apple's image builder. It's a container of its own, and it holds on to its memory until you stop it, so you can see whether it's running, stop it, and choose how much it gets next time. And when it's the runtime itself that's misbehaving, Logs shows what its services have been saying.
06 Cards
Everything is a card, at any window size.
Every container is a card with its name, its state, where to reach it and what it's using. Start, Stop, Restart and Logs are buttons with words on them, not icons you have to hover to find. The cards reflow to fit the window, down to a single column when you make it narrow. The Containers screen opens with the same four numbers as Projects.
07 Logs and images
Fewer reasons to open a terminal.
The things you'd otherwise type a command for are in the menu on each card and each image.
Logs that go back further
A log window starts from the last 300 lines, and you can ask for the last 1,000, the last 10,000, or everything. On a Docker engine you can also start from the last five minutes, hour or day. Save writes what you're looking at to a file.
The boot log
On Apple's runtime a container is a small VM. When one won't start, its own log is empty, because it never got that far. Tick Boot and you see what the kernel and init said instead.
Inspect
The full JSON for a container or an image, to read, copy or save.
Run one image
Run starts a container from an image with a name, ports, environment and a command. It's for the database you want to try something against. Anything bigger belongs in a compose file.
Rebuild
Start reuses an image it has already built, even if the Dockerfile has changed since. A project that builds its own images gets Rebuild and start, and you watch the build as it runs.
Tag, push and log in
Give an image a second name, push it, and log in to a registry. Your
password goes straight to docker login. Nebcon doesn't
keep it.
08 Why use it
The small stuff that saves you time.
Nobody asks for features like these. I only added each one after it caught me out.
It checks your compose file first
If a variable from your .env is missing, Compose quietly
fills in a blank and starts anyway. You end up with a database that
won't start and no idea why. Nebcon checks first and tells you which
variable is missing.
It hides buttons that won't work
Apple's runtime can't pause containers or save them as images. So Nebcon doesn't show those buttons there, instead of letting you click one and get an error. On a Docker engine they're in the menu.
It switches when a runtime goes away
If the runtime you're using stops responding (maybe you restarted it, or uninstalled something), Nebcon moves to one that works and lets you know it did.
Red means something is wrong
A container you stopped isn't a problem, and Nebcon doesn't paint it like one. Red is kept for a container that exited with an error or is failing its health check.
It handles socktainer's quirks
socktainer renames some Compose labels, turning
working_dir into working-dir, and never
answers docker stats. Nebcon reads both spellings and
gets the numbers another way, so your projects still group correctly
and the usage figures still show.
It shows real volume sizes
socktainer reports every volume as -1B. Nebcon measures
the volume's disk image instead, so you see how much space it actually
takes.
It won't start the wrong project
If a folder has no compose file, Compose looks in the parent folder and may start a completely different project. Nebcon won't run Compose there. It tells you why, and Start and Stop still work on the containers that exist.
It frees space by name
Free up space lists every stopped container, unused image and unused volume with its size, and says which ones can't be brought back. Nothing is ticked until you tick it.
09 Limits
What it doesn't do.
Nebcon is just the app on top. If you want the engine, a VM and everything else in one package, there are other tools made for that.
- No engine
-
It doesn't include a runtime, VM or kernel. It uses the
dockerCLI, so you need a runtime installed and running. - No Kubernetes or Linux VMs
- Just containers, images, volumes and Compose projects.
- Adding needs one runtime
- Under All runtimes you can start, stop and delete anything, but adding a project, pulling an image and logging in to a registry are turned off. Each of those has to go to one runtime, so pick it first.
- Exec isn't a full terminal
- The built-in exec runs one command at a time. For anything interactive, use Open in Terminal from the same menu.
- Updates on a timer
- Apple's runtime doesn't send live updates, so Nebcon checks every two seconds while its window is open and every ten when it isn't. Processor and memory are sampled every five.
- Not signed
- The app isn't signed or notarized by Apple, so macOS will warn you the first time you open it.
10 Get it
Up and running in a minute.
- Open the disk image and drag Nebcon into Applications.
- Open Nebcon. macOS will block it the first time because it isn't signed.
- Go to System Settings › Privacy & Security, scroll down to the message about Nebcon, and click Open Anyway.
xattr -dr com.apple.quarantine /Applications/Nebcon.app
This removes the flag macOS puts on apps you download. That flag is exactly what the warning is for, so only do this if you trust where the app came from.
A Mac with Apple silicon running macOS 14 or later, plus a container
runtime: Apple's container with socktainer,
a Docker engine you already have, or both. Homebrew is optional, but
with it Nebcon can install and update Apple's runtime for you.