Skip to content

Docker access profiles

The installed profile sets the most Companion can ever do. Within that limit, the active mode is chosen in the dashboard.

Profile Compose files Installed maximum
Read only docker-compose.example.yml Discovery, status and logs
Management adds docker-compose.management.yml Docker writes, without container exec
Management + shell adds docker-compose.shell.yml Docker writes and container exec

Every profile starts in Read only mode. To go higher, the owner raises the mode from Docker access, up to the installed maximum.

docker compose -f docker-compose.example.yml up -d --build
docker compose \
  -f docker-compose.example.yml \
  -f docker-compose.management.yml \
  up -d --build
docker compose \
  -f docker-compose.example.yml \
  -f docker-compose.management.yml \
  -f docker-compose.shell.yml \
  up -d --build

Keep the file order

Use the same Compose file order every time you recreate the installation. If you use the mobile profile, put docker-compose.mobile.yml after any file that changes ports.

Management grants broad authority

With a Management profile installed, the Companion process has broad Docker authority even when the active mode is lower. Install only the profile you need.

For full details, see Docker access in the QM Companion repository.