Skip to content
Overview

Overview

Watchtower has an optional HTTP API server that is enabled by configuring the http-api-endpoints and http-api-token configuration options and publishing the HTTP API port (default: 8080).

This HTTP API server extends Watchtower’s functionality by providing HTTP endpoints that allows for programmatic access to functionality, such as checking the current status of monitored containers and requesting Watchtower to perform container updates. Parameters, such as container and image name filters, can be used to further fine-tune HTTP requests.

Deprecation of HTTP API Endpoint Configuration Options

The following options have been deprecated in favor of the unified http-api-endpoints configuration option and will be removed with the v2.x.x release of Watchtower:

Endpoints

The following endpoints can be enabled by using thehttp-api-endpoints configuration option and the respective configuration value.

NameConfiguration ValueMethodEndpointAuthParametersDescription
UpdateupdatePOST/v1/updateAPI tokenimage, container, asyncTriggers container updates and returns JSON results of the operation
CheckcheckPOST/v1/checkAPI tokenimage, containerChecks containers for available updates via registry digest query
ContainerscontainersGET/v1/containersAPI tokenname, imageLists watched containers and their current running image digests
Container DetailscontainersGET/v1/containers/detailsAPI tokenname, imageReturns detailed information about each watched container including running state and configuration flags
HistoryhistoryGET/v1/historyAPI tokensince, until, limitReturns historical scan results from the in-memory ring buffer (up to 500 entries)
ImagesimagesGET/v1/imagesAPI tokenname, idLists tracked images with their current digests and container counts
ConfigconfigGET/v1/configAPI tokenReturns the active Watchtower configuration settings
EventseventsGET/v1/eventsEvents tokenStreams real-time operational events via Server-Sent Events
StatusmetricsGET/v1/statusAPI tokenReturns the summary of the most recent scan
MetricsmetricsGET/v1/metricsAPI tokenExposes Prometheus-compatible metrics for monitoring and alerting
SwaggerswaggerGET/swagger/*NoneInteractive API documentation via Swagger UI
LivenesshealthGET/livezNoneReturns 200 OK when the server is running
ReadinesshealthGET/readyzNoneReturns 200 OK when Docker client is connected, 503 otherwise
StartuphealthGET/startupzNoneReturns 200 OK once the server has started
  • Endpoints enforce HTTP method restrictions using method-based routing.
  • Requests with unsupported methods will receive a 405 Method Not Allowed response.
  • Watchtower will not start if http-api-endpoints has incorrect values or is combined with all (which enables all endpoints).

Examples

services:
    watchtower:
        image: nickfedor/watchtower:latest
        volumes:
            - /var/run/docker.sock:/var/run/docker.sock
        environment:
            - WATCHTOWER_HTTP_API_ENDPOINTS=check
            - WATCHTOWER_HTTP_API_TOKEN=your-secure-token
        ports:
            - 8080:8080
        restart: unless-stopped

Security considerations

Watchtower was originally designed to be a stateless application with direct access to the Docker socket. By having direct access to the Docker socket, the application effectively runs with root-level privileges. It is worth taking a moment to review and familiarize yourself with the Docker Engine security documentation and explore other security tools such as Docker socket proxies.

  • !!! Warning “The HTTP API should never be directly exposed to the Internet!”
  • !!! Warning “Using the HTTP API without TLS encryption is insecure and not recommended!”
  • !!! Warning “Only enable the endpoints that you need!”

Authentication, TLS, trusted proxies, CORS, and rate limiting are covered under Authentication, TLS, and the HTTP API configuration reference.

Last updated on