ShipLog

ShipLog

Plugin from Junker der Provinz

Overview

Read the changelog before you update - right inside Unraid's Docker tab. Next to each container ShipLog shows WHAT changes between your running image and the newest: the release notes, a risk badge (patch / minor / major) and the real version jump (e.g. 1.7 -> 1.8). Read-only by construction - updates always run through Unraid's own mechanism, including the one-click "Update all (N)" button ShipLog adds next to the Basic/Advanced toggle. Registry-friendly: HEAD-only manifest checks (no Docker Hub pull-limit cost), token caching and host-wide backoff; digest-pinned and locally built images are labelled honestly instead of guessing. Optional AI summary (Ollama) + Matrix alerts.

ShipLog

Build  Lint  Docker Pulls  Image Size  Arch  Unraid  License: AGPL-3.0


⚓ ShipLog reads the changelog before you update, right inside Unraid's native Docker tab. Next to each container it shows what actually changes between your running image and the newest: the release notes, a deterministic risk badge (patch / minor / major) and the real version jump (e.g. 1.7 → 1.8).

Read-only: it never pulls, recreates or stops anything. Optional: AI changelog summaries via a local Ollama, and Matrix notifications.

A one-knight job: I build it, keep it running, work through the issues and add what people ask for, until nothing is missing. It is free, with no accounts, no telemetry, no ads and no paid tier. No asterisk anywhere. Nothing readable ever leaves your own walls. Forged on evenings and weekends, with heart and stubbornness.

If it has earned a place on your server or computer, toss a coin to your knight: it helps cover the costs and keeps the project alive. It also makes this knight's heart beat a little faster. Three ways below, whichever suits you.


Buy me a coffee   PayPal   Donate with crypto


Table of Contents

  1. What is this?
  2. Screenshots
  3. Features
  4. Install on Unraid
  5. Configuration
  6. How it works
  7. Security
  8. License
  9. How AI is used here
  10. Support this project

1. What is this?

A single static Go binary on a distroless image (~tens of MB, low idle RAM) that polls the read-only Docker socket, resolves which images have updates, fetches the changelog for the version span, classifies the risk, and serves it on a small status page and JSON API. The changelog bubble next to each container in Unraid's Docker tab ships as a companion Unraid plugin; this engine is the brain and works on any Docker host via its status page.

2. Screenshots

ShipLog changelog bubble in Unraid's Docker tab
Click the Changelog chip on any container. The bubble shows the version jump, a risk badge, the release notes, an optional AI summary, and a read-only Update-now button, right in Unraid's Docker tab.


A Changelog chip on every container in the Docker tab
A Changelog chip sits on every container: a coloured dot when an update is waiting, grey when you're up to date.


ShipLog settings page
Settings: poll interval, a live engine-status line, optional GitHub / Docker Hub tokens for more changelogs, Ollama (with autodetect) for AI summaries, and Matrix alerts.


3. Features

Feature list
  • What changed, not just "update available": changelog between your running tag and the newest, newest-first, with a link to the full release notes.
  • Deterministic risk badge: digest/patch = low, minor = medium, major = high, non-semver = unknown (with a reason). Colour by default, with a colour ⇄ monochrome toggle.
  • Breaking-change escalation: when a release note in the update span flags a breaking change (a required database migration, a removed extension, a dropped API), the badge is bumped to critical and raises an Unraid alert, so a rolling :latest digest move that would otherwise read as a harmless "low" no longer slips past.
  • Honest degradation: when no changelog is machine-findable, ShipLog says so and shows what it does know.
  • Fix a wrong changelog source: an image's OCI source label often points at the packaging wrapper (LinuxServer's docker-<app>), is wrong (inherited from a base image), or is missing. Click source on any row of the status page and point it at the correct GitHub repo; the override sticks to the image and survives container recreation. Common LinuxServer apps (Radarr, Sonarr, Lidarr, Prowlarr, Readarr, Whisparr, Bazarr) resolve to their upstream project out of the box.
  • Read-only by construction: never writes to the Docker socket.
  • Registry-friendly by construction: manifest checks are HEAD requests, which do not count against Docker Hub's pull rate limit. Bearer tokens are cached, duplicate images share one lookup per sweep, and a rate-limiting registry is backed off host-wide instead of hammered.
  • Knows what has no upstream: digest-pinned containers (image@sha256:…) and locally built images are labelled as such instead of producing bogus updates or permanent errors.
  • Flags a dead-end app: when a container's Unraid template has been pulled from Community Applications, its image is gone, or its source repo is archived, the changelog chip is replaced with a red Unmaintained badge. Still clickable: the bubble explains why, and shows the last changelog it ever found. Self-built containers (no Unraid template, or a hand-authored one) and anything with a manual source override are exempt automatically, since those were never in Community Applications to begin with. For anything else that gets flagged wrongly, click mute unmaintained on the status page to silence it for that container, permanently.
  • Flags an editorially demoted app: Community Applications can also just hide an app from its default search while it stays fully listed, installable and updated by its own maintainer (CA's own "Deprecated" flag, distinct from the dead end above). ShipLog checks the same feed CA's own plugin reads, replaces the chip with an amber Deprecated badge, and surfaces the moderator's own note when there is one (often naming a better-maintained alternative).
  • Update all in one click: a counter button next to the Basic/Advanced toggle triggers Unraid's own bulk update for every container with a pending update (ShipLog itself stays read-only).
  • Update controls: optional confirmation before an update, and an optional silent update that skips Unraid's pop-up download-log window (Settings → Updates).
  • Scheduled auto-update, gated by SemVer level (Unraid plugin only): optionally let ShipLog apply updates on a schedule, but only up to a level you choose: patch, minor or major. Unknown / non-versioned tags are never auto-applied, and :latest / digest-only moves have their own separate toggle. Runs daily, at boot, or every N hours / days, with a dry-run mode that only reports what would update, to the ShipLog log and to Matrix if configured. It hands the work to Unraid's own container-update path, so containers come back identical to a manual update. The engine itself still never writes to the Docker socket.
  • Localised: the settings page and the changelog bubble follow Unraid's configured language across 26 languages.
  • Optional, off by default: AI changelog summaries via a local Ollama; enriched Matrix notifications.
  • Tiny and multi-arch (amd64, arm64), pure-Go (no cgo), boot-smoke-gated CI.

4. Install on Unraid

The Community Applications template is published in the unraid-apps feed (search ShipLog in the Apps tab once it lands). The only required mount is the Docker socket, read-only:

-v /var/run/docker.sock:/var/run/docker.sock:ro
-v /mnt/user/appdata/shiplog:/config
-p 8484:8484

Open the WebUI on port 8484.

5. Configuration

On the Unraid plugin the settings page groups these into tabs (General, Updates, Notifications, Sources), so it stays tidy as it grows. The AUTOUPDATE_* keys below are Unraid-plugin only (the generic container image stays a read-only advisor).

Variable Default Notes
PORT 8484 engine API and status page
DOCKER_SOCKET /var/run/docker.sock mounted read-only
DATA_DIR /config SQLite database and curated-mapping override
POLL_INTERVAL 6h how often to re-check (e.g. 1h, 12h, 24h)
IGNORE_UNMANAGED false skip third-party containers not created from an Unraid template (Docker Compose, Dockhand, plain docker run); only Unraid-managed containers are tracked
GITHUB_TOKEN (none) optional; raises the anonymous GitHub API limit for changelog fetching
OLLAMA_URL / OLLAMA_MODEL (none) optional AI summaries
MATRIX_HOMESERVER / MATRIX_TOKEN / MATRIX_ROOM (none) optional enriched notifications
UNRAID_NOTIFY false (plugin only) also send update alerts through Unraid's own notification system (the notification centre and every agent you configured: email, Discord, Telegram, ...)
CONFIRM_UPDATE true ask for confirmation before "Update now" triggers Unraid's update
SILENT_UPDATE false run the update without Unraid's pop-up download-log window (it still runs in the background)
AUTOUPDATE_ENABLED false (plugin only) master switch for scheduled auto-update
AUTOUPDATE_LEVEL off highest bump to auto-apply: off / patch / minor / major
AUTOUPDATE_DIGEST false also auto-apply :latest / digest-only moves (they carry no SemVer level)
AUTOUPDATE_DRYRUN false report what would update (ShipLog log and Matrix if set), apply nothing
AUTOUPDATE_SCHED_MODE off off / daily / boot / hours / days
AUTOUPDATE_SCHED_TIME 04:00 run time for daily
AUTOUPDATE_SCHED_EVERY 6 interval for hours / days
AUTOUPDATE_EXCLUDE_WORDS (empty) comma-separated words; block an otherwise-eligible update whose changelog text contains any of them, case-insensitive (e.g. breaking, migration required). Catches a release that names its own danger even at a minor/patch bump

6. How it works

Every POLL_INTERVAL, for each container:

  1. Discover via the read-only Docker socket (image ref, digest, OCI labels). Digest-pinned (image@sha256:…), image-ID-referenced and locally built containers are recognised here and honestly labelled: they have no upstream to check, so no registry call is made for them.
  2. Resolve the newest tag and same-tag digest from the registry (Docker Hub / GHCR / generic OCI v2, anonymous). Manifest checks are HEAD-only and don't consume Docker Hub's pull rate limit; the tags/list call is subject only to generic throttling, which ShipLog meets with per-request retries (honouring Retry-After), a per-host request gate, bearer-token caching, one lookup per distinct image per sweep, and a host-wide backoff after a hard 429.
  3. Changelog via a layered provider chain, first hit wins: the image's org.opencontainers.image.source label → GitHub releases between the tags; otherwise a version-delta fallback with a compare link.
  4. Risk is a deterministic function of the version delta, then escalated to critical if a release note in the update span flags a breaking change (required migration, removed extension, dropped API).
  5. CA status: for containers installed from an Unraid template, cross-check Community Applications' own feed for a pulled listing (dead end) or an editorial "Deprecated" flag (still maintained, just hidden from default search), replacing the changelog chip with the matching badge when either applies.
  6. Store in SQLite (status and a small per-container version history) and surface on the API and status page.

7. Security

ShipLog mounts the Docker socket read-only and never issues a write call over it. The engine itself cannot start, stop, recreate, or pull anything directly. Update actions (the one-click bulk update, and on the Unraid plugin the opt-in scheduled auto-update) are handed to Unraid's own container-update tooling, which performs the pull and recreate; ShipLog only triggers it, and only for a container it has already classified as having an eligible update. The generic container image has no update path at all and stays a pure read-only advisor. v1 has no authentication and is intended for a trusted LAN; do not expose port 8484 to the internet. It makes outbound HTTPS calls to image registries and (for changelogs) GitHub.

8. License

Copyright (C) 2026 Junker der Provinz.

ShipLog is free software under the GNU Affero General Public License v3.0 (AGPL-3.0); see LICENSE. You may run, study, share and modify it. If you distribute it, or run a modified version as a network service, you must release your source under the same AGPL-3.0 terms and keep the existing copyright and attribution notices intact.

Name and branding are not licensed. The AGPL covers the source code only. "ShipLog", its logo and its branding remain reserved: a fork or derivative must use its own distinct name and branding, and may not present itself as ShipLog. This keeps it unambiguous which project is the original.

9. How AI is used here

One knight builds this, and AI is one of the tools I work with, the same way I work with an editor or a compiler. It helps me write code and documentation and it checks my work, and that saves me a good many evenings. It does not make the decisions, though. I read and understand everything before it ships, and if something here breaks, that is on me and not on the tool.

You do not have to take my word for it. The code is open and every release note is written by hand. The issue tracker shows how problems actually get handled, including the ones I got wrong the first time. If you find something that is not right, open an issue and I will look at it.


10. Support this project

Questions? Check the support thread. Bugs, ideas or feature requests? Please open a GitHub issue.

A one-knight job: I build it, keep it running, work through the issues and add what people ask for, until nothing is missing. It is free, with no accounts, no telemetry, no ads and no paid tier. No asterisk anywhere. Nothing readable ever leaves your own walls. Forged on evenings and weekends, with heart and stubbornness.

If it has earned a place on your server or computer, toss a coin to your knight: it helps cover the costs and keeps the project alive. It also makes this knight's heart beat a little faster. Three ways below, whichever suits you.

Buy me a coffee   PayPal   Donate with crypto

Install ShipLog on Unraid in a few clicks.

Find ShipLog in Community Apps on your Unraid server, review the template, and click Install. Unraid handles the Docker app or plugin setup from the published template.

Open the Apps tab on your Unraid server Search Community Apps for ShipLog Review the template variables and paths Click Install

Download Statistics

178
Total Downloads
31
This Month
15
Avg / Month

Downloads by Month

Loading chart...

Related apps

Details

Repository
https://raw.githubusercontent.com/junkerderprovinz/shiplog/main/plugin/shiplog.plg
Last Updated2026-09-24
First Seen2026-06-29