Udon is under active development. Documentation not final.
udonudon
Containers

Deploy a container

Run a container from any image in the Run dialog with its ports, volumes, and environment variables, or build a Docker Compose stack in the Composer.

There are two ways to deploy: the Run dialog, for one container at a time on either engine, and the Composer, for a multi-service stack on OrbStack.

Run a container

The Run a container dialogThe Run a container dialog

Open the Run dialog

On the Containers page, click the + in the toolbar. On OrbStack it opens a menu; pick Container. On Apple Container it opens Run a container directly.

Point it at an image

Enter an image reference, such as nginx:latest or ghcr.io/owner/app:tag; it's the only required field. Name is optional. If the name matches an existing container, the button becomes Reinstall: Udon pulls the image first, and only then removes the old container and runs the new one. If the pull fails, the old container stays and the dialog shows the error.

Add ports, storage, and environment

Publish ports (host port to container port, tcp or udp), mount a host folder or a named volume under Storage, and set any environment variables the image needs.

Set resources and network

Optionally cap CPUs and memory, set a working directory, and pick a network. OrbStack also lets you set a restart policy.

Open Advanced for anything else

Entrypoint, user, raw mounts, capabilities, DNS, and more are on the Advanced tab; see the table below.

Run it

Click Run to stream the pull and start-up output. When the run succeeds, an Access section lists a LAN URL for each published TCP port, and Done closes the dialog. If the run fails or disconnects, the addresses stay hidden and Try again returns you to the form.

Fields

FieldNotes
ImageRequired. Registry, repo, tag, or digest in one string.
NameOptional. An existing container's name switches Run to Reinstall.
CommandOverrides the image's command. Quote an argument that contains spaces.
Published portsHost IP (blank publishes on every address), host port, container port, tcp or udp.
EnvironmentKEY=value pairs.
StorageA host folder (with a folder picker) or a named volume, mounted at a path, optionally read-only.
CPUs, Memory, Working dirCPUs is a whole number. Blank uses the engine's defaults.
NetworkA defined network. OrbStack adds None (no networking) and sharing a running container's network.
Restart policyOrbStack only: No, Unless stopped, Always, or On failure.
Read-only root filesystemMounts the container's own filesystem read-only.
EntrypointOverrides the image's ENTRYPOINT.
HostnameOrbStack only.
UserA name or uid[:gid].
UID, GIDApple Container only; OrbStack folds these into User.
MountsRaw --mount strings, for anything Storage can't express.
tmpfsIn-memory mount paths.
DevicesHost device paths to pass through. OrbStack only.
Env filesHost paths to .env files.
CapabilitiesAdd or drop Linux capabilities.
DNSServers, search domains, and options; Apple Container can also skip DNS setup.
Remove automatically when it stopsDeletes the container once it exits (--rm).
Extra flagsRaw flags added to the run command, separated by spaces.

Options that need an admin

Five kinds of option let a container reach past its sandbox, and each needs an admin: host folder mounts and any raw --mount, device passthrough, extra flags, escalating capabilities (ALL, SYS_ADMIN, NET_ADMIN, SYS_PTRACE, and others of that class), and sharing a host namespace (--network host, --pid host, --ipc host, --userns host, or --privileged). On OrbStack, the Run dialog and the assistant refuse host namespaces for everyone. On either engine, nobody can mount the Mac's root folder.

The same rule covers the Run dialog, compose files in the Composer, and the AI assistant, and a refused single container names what tripped it. Editing, reinstalling, or updating a container that uses any of these (including through Update all) needs an admin too, whoever created it.

Editing a container

Edit, in a container's row menu or at the bottom of its detail panel, opens Edit <name> filled in from the running container. There's no in-place update: Save & recreate pulls the image, then removes the old container and runs the edited one. A few settings can't be read back from a running container, so check them before saving: Extra flags and Remove automatically when it stops come back blank, and on Apple Container so do tmpfs and the DNS switch.

Build a stack in the Composer

The Composer builds a multi-service compose stack on OrbStack. Apple Container has no compose, so there the page says so instead of showing the canvas. Open it from the toolbar's + menu (Stack), or with Edit in Composer on a stack's menu.

A new stack starts from Start blank (one nginx service) or Load a compose file, uploaded from your device or picked from the server. The header holds the stack name, a … menu with New compose and Import, the Visual and YAML switch, the save icon, and Deploy.

The Composer's Visual view with a new stack: one service connected to the default networkThe Composer's Visual view with a new stack: one service connected to the default network
  • In Visual, the Components panel lists services, networks, and volumes, each group with a +. A new service starts from a Docker Hub image search; a network can be new or an existing one. When the panel is closed, the Components icon at the canvas's top-left opens it.
  • On the canvas, drag from a service to a network to connect them, or to another service to make it a dependency. Select a component to edit its settings on the right, from image and ports to health checks and resource limits.
  • YAML edits the same document, comments and unsupported fields included, with Undo and Redo icons at the right of the status bar. The status bar also says whether the file is valid.
  • The save icon writes a new stack's compose file to a folder you choose on the server, or saves an existing stack's file without redeploying. Deploy brings the stack up once it has a name and the file checks out. An existing stack shows Redeploy.

Once it's running, manage the stack from the Stacks page.

Ask AI

Answers from Udon's documentation.

Ask how to install Udon, run containers, or share folders.