1. Docktor
  2. Guides
  3. Monitor Docker Compose over SSH

Monitor Docker Compose over SSH, no agent

A plain Linux host already tells you almost everything. Here are the read-only commands and kernel files worth knowing, and where doing it by hand stops scaling.

Updated October 6, 2026

The short answer

Yes. Everything you need to understand a Docker host is readable over a normal SSH session: the Docker CLI reports containers, health and events, and the Linux kernel exposes per-container CPU, memory and I/O counters through cgroups and pressure stall information (PSI). None of it requires an agent on the server. The cost is that something has to keep asking, and it can only watch while it is connected.

What you can read without installing anything

These are all read-only. They need a user that can run docker, and that is usually membership of the docker group, which is root-equivalent on the host. No sudo is needed for the commands below on most systems.

Read-only sources on a Docker host
QuestionWhere to look
Which containers form one app?docker ps --format '{{.Names}}\t{{.Label "com.docker.compose.project"}}'
Is everything up and healthy?docker ps --format '{{.Names}}\t{{.Status}}'. Health appears in the status text.
What is each container using now?docker stats --no-stream
Did anything restart or get OOM-killed?docker events --since 1h --until "$(date +%s)" --filter event=die --filter event=oom
Is a container held back by its CPU limit?cpu.stat in its cgroup. See Docker CPU throttling.
Is a container near its memory limit, or being killed?memory.current and memory.events in its cgroup. See Docker OOM kills.
Are processes stalling on CPU, memory or disk?/proc/pressure/cpu, memory and io, and each cgroup’s *.pressure files.

Find a container’s cgroup

On a host that uses cgroup v2, first confirm it:

stat -fc %T /sys/fs/cgroup
# cgroup2fs means cgroup v2

Then find the container’s directory. With the systemd cgroup driver, which is the common default on current distributions, it looks like this:

id=$(docker inspect -f '{{.Id}}' web)
cd /sys/fs/cgroup/system.slice/docker-$id.scope
ls cpu.stat memory.current memory.events io.stat cpu.pressure

With the cgroupfs driver the directory is /sys/fs/cgroup/docker/$id instead. Hosts still on cgroup v1 expose different files, and PSI may be unavailable.

Read the counters

cat cpu.stat           # usage_usec, nr_throttled, throttled_usec
cat memory.events      # high, max, oom, oom_kill
cat /proc/pressure/io  # some avg10=0.00 avg60=0.00 avg300=0.00 total=...

Most of these are cumulative counters, so a single reading says little. Sample twice and compare, or keep a history so you can tell what is normal for that service.

What is hard to do by hand

  • Keeping a history. A problem that happened 20 minutes ago is gone from docker stats.
  • Knowing what normal looks like. 70% memory might be fine for postgres and alarming for a small worker.
  • Connecting signals. A slow endpoint, a throttled container and a restart are three observations. The useful part is how they relate in time.
  • Saying how sure you are. Correlated is not the same as caused, and a good answer says which one it has.

Where Docktor fits

Docktor automates exactly this approach. It uses your existing SSH setup (~/.ssh/config, keys, agent and jump hosts), runs a fixed catalog of read-only commands, takes one small round trip about every 15 seconds that reads kernel counters, and groups containers into Compose deployments. Rules turn the evidence into findings that say what is likely wrong, how confident Docktor is, and what to check next. Nothing is installed on the server, and the history stays on your Mac.

The limits are real: Docktor monitors only while your Mac is awake and the app is open, and it is not external uptime monitoring. If you need alerts at 3 a.m., pair it with a tool built for that. See how Docktor compares.

See what’s wrong before you open a terminal.

Diagnose Docker Compose issues over SSH, with the evidence on your Mac.

Download for Mac

v0.1.0 · macOS 15+ · Apple silicon & Intel