Docker
Accounts
- Accounts
- Company overview
- Manage company organizations, owners, and members
- Create new company
- Docker individual accounts
- Create a Docker account
- Deactivate a Docker account
- Manage a Docker account
- Organization accounts
- Activity logs
- Insights
- Manage your organization
- Deactivate an organization
- Change general organization information
- Create and manage a team
- Manage license assignment
- Manage usage and access for Docker products
- Manage subscription seats
- Invite and manage organization members
- Set up your organization
- Convert an account into an organization
- Onboard your organization
- Create your organization
Agentic Platform
Ai
- AI and Docker Compose
- Define AI Models in Docker Compose applications
- Docker Agent
- Gordon
- Concepts
- Gordon's capabilities
- Data privacy and Gordon
- How-to guides
- Using Gordon via CLI
- Configure Gordon's tools
- Using Gordon in Docker Desktop
- Gordon's permission model
- Gordon usage limits and tiers
- Gordon use cases and examples
- Docker MCP Catalog and Toolkit
- Docker MCP Catalog
- Use MCP Toolkit from the CLI
- Dynamic MCP
- E2B sandboxes
- MCP Toolkit FAQs
- Get started with Docker MCP Toolkit
- MCP Gateway
- MCP Profiles
- Docker MCP Toolkit
- Docker Model Runner
- DMR REST API
- Configuration options
- DMR examples
- Get started with DMR
- IDE and tool integrations
- Inference engines
- Open WebUI integration
- Docker Sandboxes
- Supported agents
- Claude Code
- Codex
- Copilot
- Cursor
- Devin
- Docker Agent
- Droid
- Gemini
- Kiro
- OpenCode
- Shell
- Architecture
- Configure Docker Sandboxes
- Manage credentials
- Sandbox environment files
- Enable NVIDIA GPU passthrough
- Configure a registry mirror
- Configure an upstream proxy
- Customizing sandboxes
- Build your own agent kit
- Kit examples
- Kit spec reference
- Kits
- Templates
- FAQ
- Get started with Docker Sandboxes
- Governance
- Access controls
- Filesystem access policies
- Local policy
- MCP access policies
- Network access policies
- Organization policies
- AI Governance Audit Logs
- Configure audit delivery
- Local audit logs
- Audit record reference
- SIEM forwarding
- View and export audit events
- Policy concepts
- Monitor and enforce
- Monitoring policies
- Sign-in enforcement
- Reference
- AI Governance API
- MCP policy reference
- Install Docker Sandboxes
- Editor and app integrations
- Connect ChatGPT to a sandbox
- Connect Claude Desktop to a sandbox
- Connect Cursor to a sandbox
- Connect T3 Code to a sandbox
- Connect VS Code to a sandbox
- MCP gateway
- Docker Sandboxes release notes
- Security model
- Default security posture
- Isolation layers
- Troubleshooting
- Usage
- Workflow patterns
- Share agent skills
- Authenticate command-line tools
- Run sandboxes in CI
- Develop and test locally
- Use Git with sandboxes
Build
- Docker Build
- Bake
- Building with Bake from a Compose file
- Using Bake with additional contexts
- Expression evaluation in Bake
- Functions
- Inheritance in Bake
- Introduction to Bake
- Matrix targets
- Overriding configurations
- Remote Bake file definition
- Bake targets
- Variables in Bake
- Builders
- Build drivers
- Cloud driver
- Docker container driver
- Docker driver
- Kubernetes driver
- Remote driver
- Manage builders
- Building
- Base images
- Building best practices
- Container Device Interface (CDI)
- Export binaries
- Multi-platform builds
- Multi-stage builds
- Build secrets
- Build variables
- BuildKit
- Configure BuildKit
- Dockerfile release notes
- Custom Dockerfile syntax
- Docker build cache
- Cache storage backends
- Azure Blob Storage cache
- GitHub Actions cache
- Inline cache
- Local cache
- Registry cache
- Amazon S3 cache
- Build garbage collection
- Build cache invalidation
- Optimize cache usage in builds
- Checking your build configuration
- Continuous integration with Docker
- Docker Build GitHub Actions
- Add image annotations with GitHub Actions
- Add SBOM and provenance attestations with GitHub Actions
- GitHub Actions build summary
- Cache management with GitHub Actions
- Validating build configuration with GitHub Actions
- Configuring your GitHub Actions builder
- Copy image between registries with GitHub Actions
- Export to Docker with GitHub Actions
- Docker GitHub Builder
- Docker GitHub Builder architecture
- Bake with Docker GitHub Builder
- Build with Docker GitHub Builder
- Local registry with GitHub Actions
- Manage tags and labels with GitHub Actions
- Multi-platform image with GitHub Actions
- Named contexts with GitHub Actions
- Push to multiple registries with GitHub Actions
- Reproducible builds with GitHub Actions
- Using secrets with GitHub Actions
- Share built image between jobs with GitHub Actions
- Test before push with GitHub Actions
- Update Docker Hub description with GitHub Actions
- Core concepts
- Build context
- Dockerfile overview
- Docker Build Overview
- Debugging
- OpenTelemetry support
- Exporters overview
- Image and registry exporters
- Local and tar exporters
- OCI and Docker exporters
- Metadata
- Annotations
- Build attestations
- SBOM attestations
- Provenance attestations
- Validating build inputs with policies
- Built-in functions
- Debugging build policies
- Policy templates and examples
- Input reference
- Introduction to build policies
- Test build policies
- Using build policies
- Validating Git repositories
- Validating image inputs
- Release notes
Build Cloud
Compose
- Docker Compose
- Overview of Compose Bridge
- Customize Compose Bridge
- Use the default Compose Bridge transformation
- Use Docker Model Runner with Compose Bridge
- Using the Compose SDK
- Docker Compose Quickstart
- Index
- Build dependent images
- Environment variables in Compose
- Best practices for working with environment variables in Docker Compose
- Environment variables precedence in Docker Compose
- Configure pre-defined environment variables in Docker Compose
- Set environment variables within your container's environment
- Set, use, and manage variables in a Compose file with interpolation
- Use Compose Watch
- Run Docker Compose services with GPU access
- Use init containers in Compose
- Using lifecycle hooks with Compose
- Use multiple Compose files
- Extend your Compose file
- Include
- Merge Compose files
- Networking in Compose
- Package and deploy Docker Compose applications as OCI artifacts
- Use Compose in production
- Using profiles with Compose
- Specify a project name
- Use provider services
- Control startup and shutdown order in Compose
- Manage secrets securely in Docker Compose
- Overview of installing Docker Compose
- Install the Docker Compose plugin
- Install the Docker Compose standalone (Legacy)
- Uninstall Docker Compose
- Introduction to Compose
- How Compose works
- Why use Compose?
- History and development of Docker Compose
- Release notes
- Index
- Frequently asked questions about Docker Compose
- Give feedback
- Trust model for Compose files
Desktop
- Docker Desktop
- Resolve the recent Docker Desktop issue on macOS
- Docker Desktop Enterprise
- Index
- containerd image store
- Use the Docker Desktop CLI
- GPU support in Docker Desktop for Windows
- Networking on Docker Desktop
- Explore networking how-tos on Docker Desktop
- Synchronized file shares
- Using USB/IP with Docker Desktop
- Virtual Machine Manager
- Wasm workloads
- Docker Desktop WSL 2 backend on Windows
- WSL 2 best practices for Docker Desktop on Windows
- Custom kernels on WSL
- Develop with Docker Desktop using WSL 2 on Windows
- Docker Desktop for Mac 2.x release notes
- Docker for Windows 2.x release notes
- Docker Desktop for Mac 3.x release notes
- Docker for Windows 3.x release notes
- Previous releases
- Release notes for previous versions
- Release notes for previous versions
- Docker Desktop for Mac Edge release notes
- Docker Desktop for Windows Edge Release notes
- Docker Desktop release notes
- Index
- How to back up and restore your Docker Desktop data
- Change your Docker Desktop settings
- Index
- Allowlist for Docker Desktop
- Install
- Install Docker Desktop on Linux
- Install Docker Desktop on Arch-based distributions
- Install Docker Desktop on Debian
- Install Docker Desktop on Fedora
- Install Docker Desktop on RHEL
- Install Docker Desktop on Ubuntu
- Install Docker Desktop on Mac
- Understand permission requirements for Docker Desktop on Mac
- Install Docker Desktop on Windows
- Understand permission requirements for Windows
- Sign in to Docker Desktop
- Run Docker Desktop for Windows in a VM or VDI environment
- Index
- FAQs
- General FAQs for Desktop
- FAQs for Docker Desktop for Linux
- FAQs for Docker Desktop for Mac
- FAQs on Docker Desktop releases
- FAQs for Docker Desktop for Windows
- Give feedback
- Troubleshoot Docker Desktop
- Known issues
- Fix "Docker.app is damaged and can't be opened" on macOS
- Troubleshoot topics for Docker Desktop
- Uninstall Docker Desktop
- Explore Docker Desktop
- Explore the Builds view in Docker Desktop
- Explore the Containers view in Docker Desktop
- Explore the Images view in Docker Desktop
- Explore the Kubernetes view
- Explore the Logs view in Docker Desktop
- Pause Docker Desktop
- Docker Desktop's Resource Saver mode
- Explore the Volumes view in Docker Desktop
Dhi
- Docker Hardened Images
- Explore Docker Hardened Images
- Available types of Docker Hardened Images
- How Docker Hardened Images are built
- Malware scanning
- Understanding roles and responsibilities for Docker Hardened Images
- Scanner integrations
- Security concepts
- Attestations
- CIS Benchmark
- Common Vulnerabilities and Exposures (CVEs)
- Image digests
- Minimal or distroless images
- FIPS
- glibc and musl support in Docker Hardened Images
- Base image hardening
- Immutable infrastructure
- Image provenance
- Software Bill of Materials (SBOMs)
- Code signing
- Supply-chain Levels for Software Artifacts (SLSA)
- Software Supply Chain Security
- Secure Software Development Lifecycle
- STIG
- Vulnerability Exploitability eXchange (VEX)
- How Docker Hardened Images are tested
- What are hardened images and why use them?
- Docker Hardened Images quickstart
- How-tos
- Create and build a Docker Hardened Image
- Customize a Docker Hardened Image or chart
- Use Hardened System Packages
- Use a Docker Hardened Image chart
- Mirror a Docker Hardened Image repository
- Apply Docker Hardened Image policies to your images
- Scan Docker Hardened Images
- Search and evaluate Docker Hardened Images
- Get started with DHI Select and Enterprise
- Troubleshoot
- Use a Docker Hardened Image
- Verify a Docker Hardened Image or chart
- Query VEX for a Docker Hardened Image
- Migration
- Migration checklist
- Migration examples
- .NET
- Go
- Java
- Node.js
- Python
- Migrate from Alpine or Debian
- Migrate from Ubuntu
- Migrate from Wolfi
- Migrate using Gordon
- Release notes
- DHI CLI release notes
- Docker Hardened Images release notes
- Resources and feedback
- Tools
- Use the DHI API
- Use the DHI CLI
- Use Docker Hub
- Use the DHI MCP server
- Use the DHI Terraform provider
Docker Hub
- Docker Hub
- Content library
- Generative AI content
- Mirror the Docker Hub library
- Docker Hub search
- Trusted content
- Docker Hub MCP server
- Docker Hub quickstart
- Docker Hub release notes
- Repositories
- Archive or unarchive a repository
- Create a repository
- Delete a repository
- Manage
- Access management
- Automated builds
- Advanced options for autobuild and autotest
- Automated repository tests
- Configure automated builds from GitHub and BitBucket
- Manage autobuilds
- Migrate from Autobuilds
- Set up automated builds
- Troubleshoot your autobuilds
- Export organization repositories to CSV
- Image management
- Bulk migrate images
- Immutable tags on Docker Hub
- Image Management
- Move images between repositories
- Software artifacts on Docker Hub
- Push images to a repository
- Tags on Docker Hub
- Repository information
- Trusted content
- Docker-Sponsored Open Source Program
- Docker Verified Publisher Program
- Insights and analytics
- Docker Official Images
- Image security insights
- Webhooks
- Settings
- Troubleshoot Docker Hub
- Docker Hub usage and limits
- Best practices for optimizing Docker Hub usage
- Docker Hub pull usage and limits
Engine
- Docker Engine
- CLI
- Completion
- Filter commands
- Format command and log output
- OpenTelemetry for the Docker CLI
- Use a proxy server with the Docker CLI
- Containers
- GPU access
- Run multiple processes in a container
- Resource constraints
- Runtime metrics
- Start containers automatically
- Docker daemon configuration overview
- Alternative container runtimes
- Run containerd in the Docker daemon
- Use IPv6 networking
- Live restore
- Read the daemon logs
- Collect Docker metrics with Prometheus
- Daemon proxy configuration
- Configure remote access for Docker daemon
- Start the daemon
- Troubleshooting the Docker daemon
- Install Docker Engine
- Install Docker Engine from binaries
- Install Docker Engine on CentOS
- Install Docker Engine on Debian
- Install Docker Engine on Fedora
- Linux post-installation steps for Docker Engine
- Install Docker Engine on Raspberry Pi OS (32-bit / armhf)
- Install Docker Engine on RHEL
- Install Docker Engine on Ubuntu
- View container logs
- Configure logging drivers
- Logging drivers
- Amazon CloudWatch Logs logging driver
- ETW logging driver
- Fluentd logging driver
- Google Cloud Logging driver
- Graylog Extended Format logging driver
- Journald logging driver
- JSON File logging driver
- Local file logging driver
- Splunk logging driver
- Syslog logging driver
- Use docker logs with remote logging drivers
- Customize log driver output
- Use a logging driver plugin
- Manage resources
- Docker contexts
- Docker object labels
- Prune unused Docker objects
- Networking overview
- Use CA certificates with Docker
- Network drivers
- Bridge network driver
- Host network driver
- IPvlan network driver
- Macvlan network driver
- None network driver
- Overlay network driver
- Docker with iptables
- Docker with nftables
- Legacy container links
- Packet filtering and firewalls
- Port publishing and mapping
- Docker Engine 17.03 release notes
- Docker Engine 17.04 release notes
- Docker Engine 17.05 release notes
- Docker Engine 17.06 release notes
- Docker Engine 17.07 release notes
- Docker Engine 17.09 release notes
- Docker Engine 17.10 release notes
- Docker Engine 17.11 release notes
- Docker Engine 17.12 release notes
- Docker Engine 18.01 release notes
- Docker Engine 18.02 release notes
- Docker Engine 18.03 release notes
- Docker Engine 18.04 release notes
- Docker Engine 18.05 release notes
- Docker Engine 18.06 release notes
- Docker Engine 18.09 release notes
- Docker Engine 19.03 release notes
- Docker Engine 20.10 release notes
- Docker Engine 23.0 release notes
- Docker Engine 24.0 release notes
- Docker Engine 25.0 release notes
- Docker Engine 26.0 release notes
- Docker Engine 26.1 release notes
- Docker Engine version 27 release notes
- Docker Engine version 28 release notes
- Docker Engine version 29 release notes
- Release notes
- Docker Engine prior releases
- Docker Engine security
- Antivirus software and Docker
- AppArmor security profiles for Docker
- Verify repository client with certificates
- Readme
- Docker security non-events
- Protect the Docker daemon socket
- Rootless mode
- Tips
- Troubleshooting
- UID/GID mapping
- Seccomp security profiles for Docker
- Content trust in Docker
- Deploy Notary Server with Compose
- Automation with content trust
- Delegations for content trust
- Manage keys for content trust
- Play in a content trust sandbox
- Isolate containers with a user namespace
- Storage
- Bind mounts
- containerd image store with Docker Engine
- Storage drivers
- AUFS storage driver
- BTRFS storage driver
- Device Mapper storage driver (deprecated)
- OverlayFS storage driver
- Select a storage driver
- VFS storage driver
- windowsfilter storage driver
- ZFS storage driver
- Image mounts
- tmpfs mounts
- Volumes
- Swarm mode
- Administer and maintain a swarm of Docker Engines
- Store configuration data using Docker Configs
- How swarm works
- How nodes work
- Manage swarm security with public key infrastructure (PKI)
- How services work
- Swarm task states
- Use Swarm mode routing mesh
- Join nodes to a swarm
- Swarm mode key concepts
- Manage nodes in a swarm
- Manage swarm service networks
- Raft consensus in swarm mode
- Manage sensitive data with Docker secrets
- Deploy services to a swarm
- Deploy a stack to a swarm
- Run Docker Engine in swarm mode
- Getting started with Swarm mode
- Add nodes to the swarm
- Create a swarm
- Delete the service running on the swarm
- Deploy a service to the swarm
- Drain a node on the swarm
- Inspect a service on the swarm
- Apply rolling updates to a service
- Scale the service in the swarm
- Lock your swarm to protect its encryption key
Enterprise
- Deploy Docker Desktop
- Dev box
- Enterprise deployment FAQs
- Install Docker Desktop from the Microsoft Store on Windows
- MSI installer
- PKG installer
- Deploy with Intune
- Deploy with Jamf Pro
- Security for enterprises
- Enforce sign-in for Docker Desktop
- Configure sign-in enforcement
- Hardened Docker Desktop
- Air-gapped containers
- Enhanced Container Isolation
- Configure Docker socket exceptions and advanced settings
- Enable Enhanced Container Isolation
- Enhanced Container Isolation FAQs
- Enhanced Container Isolation limitations
- Image Access Management
- Namespace access control
- Registry Access Management
- Settings Management
- Desktop settings reporting
- Configure Settings Management in Docker Home
- Configure Settings Management with a JSON file
- Settings reference
Extensions
- Docker Extensions
- Overview of the Extensions SDK
- Extension architecture
- Extension metadata
- Extension security
- Part one: Build
- Add a backend to your extension
- Create an advanced frontend extension
- Create a simple extension
- UI styling overview for Docker extensions
- Design guidelines for Docker extensions
- Docker design principles
- MUI best practices
- Developer SDK tools
- Extension APIs
- Extension Backend
- Navigation
- Dashboard
- Docker
- Extension UI API
- Continuous Integration (CI)
- Test and debug
- CLI reference
- Package and release your extension
- Part two: Publish
- Extension image labels
- Build multi-arch extensions
- Publish in the Marketplace
- Share your extension
- Validate your extension
- Developer Guides
- Invoke host binaries
- Interacting with Kubernetes from an extension
- Authentication
- Use the Docker socket from the extension backend
- The build and publish process
- Quickstart
- Marketplace extensions
- Non-marketplace extensions
- Configure a private marketplace for extensions
- Settings and feedback for Docker Extensions
Faqs
Offload
Reference
- Reference documentation
- API reference
- Docker AI Governance API
- DVP Data API
- Docker Verified Publisher API changelog
- Deprecated Docker Verified Publisher API endpoints
- Docker Verified Publisher API reference
- Docker Engine API
- Latest
- Develop with Docker Engine SDKs
- Examples using the Docker Engine SDKs and Docker API
- API reference by version
- Docker Engine API v1.40 reference
- Docker Engine API v1.41 reference
- Docker Engine API v1.42 reference
- Docker Engine API v1.43 reference
- Docker Engine API v1.44 reference
- Docker Engine API v1.45 reference
- Docker Engine API v1.46 reference
- Docker Engine API v1.47 reference
- Docker Engine API v1.48 reference
- Docker Engine API v1.49 reference
- Docker Engine API v1.50 reference
- Docker Engine API v1.51 reference
- Docker Engine API v1.52 reference
- Docker Engine API v1.53 reference
- Docker Engine API v1.54 reference
- Docker Engine API v1.55 reference
- Docker Engine API v1.56 reference
- Interface: BackendV0
- Interface: DesktopUI
- Interface: Dialog
- Interface: Docker
- Interface: DockerCommand
- Interface: DockerDesktopClient
- Interface: Exec
- Interface: ExecOptions
- Interface: ExecProcess
- Interface: ExecResult
- Interface: ExecResultV0
- Interface: ExecStreamOptions
- Interface: Extension
- Interface: ExtensionCli
- Interface: ExtensionHost
- Interface: ExtensionVM
- Interface: Host
- Interface: HttpService
- Interface: NavigationIntents
- Interface: OpenDialogResult
- Interface: RawExecResult
- Interface: RequestConfig
- Interface: RequestConfigV0
- Interface: ServiceError
- Interface: SpawnOptions
- Interface: Toast
- Extensions API Reference
- Docker Hub API
- Docker Hub API changelog
- Deprecated Docker Hub API endpoints
- Docker Hub API reference
- Index
- Registry authentication
- Supported registry API for Docker Hub
- CLI reference
- Compose file reference
- Compose Build Specification
- Configs top-level element
- Compose Deploy Specification
- Compose Develop Specification
- Extensions
- Fragments
- Use include to modularize Compose files
- Interpolation
- Legacy versions
- Merge Compose files
- Models
- Define and manage networks in Docker Compose
- Learn how to use profiles in Docker Compose
- Secrets
- Define services in Docker Compose
- Version and name top-level elements
- Define and manage volumes in Docker Compose
- Glossary
- Samples overview
- Agentic AI samples
- AI/ML samples
- Angular samples
- Cloudflared samples
- Django samples
- .NET samples
- Elasticsearch / Logstash / Kibana samples
- Express samples
- FastAPI samples
- Flask samples
- Gitea samples
- Go samples
- Java samples
- JavaScript samples
- MariaDB samples
- Minecraft samples
- MongoDB samples
- MS-SQL samples
- MySQL samples
- Nextcloud samples
- NGINX samples
- Node.js samples
- PHP samples
- Pi-hole samples
- Plex samples
- Portainer samples
- PostgreSQL samples
- Prometheus samples
- Python samples
- Rails samples
- React samples
- Redis samples
- Ruby samples
- Rust samples
- Spark samples
- Spring Boot samples
- Traefik samples
- TypeScript samples
- Vue.js samples
- WireGuard samples
- WordPress samples
Scout
- Docker Scout
- Deep dive
- Advisory database sources and matching service
- Data collection and storage in Docker Scout
- Explore
- Docker Scout image analysis
- Dashboard
- Manage vulnerability exceptions
- Image details view
- Docker Scout metrics exporter
- How-tos
- Use Scout with different artifact types
- Configure Docker Scout with environment variables
- Create an exception using the GUI
- Create an exception using the VEX
- Docker Scout SBOMs
- Install Docker Scout
- Integrating Docker Scout with other systems
- Using Docker Scout in continuous integration
- Integrate Docker Scout with Microsoft Azure DevOps Pipelines
- Integrate Docker Scout with Circle CI
- Integrate Docker Scout with GitHub Actions
- Integrate Docker Scout with GitLab CI/CD
- Integrate Docker Scout with Jenkins
- Integrating Docker Scout with environments
- Generic environment integration with CLI
- Integrate Docker Scout with a container registry
- Policy Evaluation
- Evaluate policies
- Docker Scout quickstart
- Release notes
- Cli
- Docker Scout release notes
Security
- Security
- Access tokens
- Organization access tokens
- Personal access tokens
- Enable two-factor authentication for your Docker account
- Recover your Docker account
- Authentication
- OIDC connections overview
- Create and manage OIDC connections
- OIDC connections rulesets and subject claims
- Single sign-on overview
- Set up single sign-on
- Manage SSO domains and connections
- Troubleshoot single sign-on
- Provision users
- Auto-provisioning
- Add and manage domains
- Just-in-Time provisioning
- SCIM overview
- Group mapping
- Migrate JIT to SCIM
- Set up SCIM provisioning
- Troubleshoot provisioning
- Docker organization roles and permissions
- Docker core roles and permissions
- Custom roles and permissions overview
- Manage custom roles in Docker Home
- Custom role permissions reference
- Docker security announcements
Subscription Billing
- Subscription and billing
- Docker Desktop license agreement
- Use 3D Secure authentication for Docker billing
- Manage billing
- Update your billing details
- Billing and invoice history
- Add or update a payment method
- Manage plans
- Sales tax exemption and VAT
- Plans
- AI Governance plan
- DHI plans
- Docker Agentic Platform plans
- Docker Verified Publisher plans
- Docker plans
- Gordon plans